Decisions

Why lnk-openclaw runs OpenClaw the way it does. Link's own decisions about harnesses are on its Agents Decisions page.

Where is OpenClaw's workspace?

In its home (~/Link/Agents/main/Harnesses/openclaw/.openclaw/workspace), with its personality and memory, and ~/Link/Agents/main/Home as the shared folder. Hermes works in Home.

How does OpenClaw use a local model?

Only through Ollama, registered with its address and Ollama's own API, and a context window of 32,768 tokens on both sides: OpenClaw's budget and Ollama's num_ctx. Ollama's default window, a few thousand tokens, is smaller than OpenClaw's own instructions.

OpenClaw 2026.9.6's Slack plugin gives its socket (Socket Mode, undici 7) a proxy dispatcher from OpenClaw's own undici 8, which refuses it before it connects, whenever a proxy is set. Behind Link's proxy the socket never opens: the log shows socket-mode … WebSocket error! SMWebsocketError every 15 seconds, and no message arrives. So with Slack or Discord connected, OpenClaw asks for lan, which connects it without the proxy.

lan only with Slack or Discord connected, whose sockets can't use Link's proxy; no sandbox only with OpenAI on a Mac, where Codex's runtime runs ps, which no macOS sandbox runs. Each depends on the settings needs reads, so an agent on Telegram with Anthropic runs with Link's defaults, and connecting Slack later asks for lan at the start that follows. Asking for less where it isn't needed keeps the sandbox whole for most agents.

Why is its browser off without the sandbox, or with lan?

Because there its managed browser's debugging port asks for no credential on the machine's loopback, where every user and program reaches it, and so drives the browser as you. Its other browser ports ask for a token, or don't open in the sandbox. OpenClaw runs well without its browser, so the safe answer is the default: needs names it as a risk it runs without, browser, and only your yes in a terminal, or lnk agent openclaw allow browser, turns it on. In the sandbox on a Mac it stays on, since OpenClaw finds no Chrome to start there; on Linux it stays on behind its proxy, where the port stays in the sandbox's network. Link tells the adapter whether it runs behind its proxy (proxied in its settings), so lan (Slack or Discord) is asked about as no sandbox is; the adapter counts the lan it asks for itself before it's granted, and takes a Link that doesn't say as no proxy.

How does OpenClaw reach Signal?

Through the signal-cli it starts itself, on a Mac over a unix socket in its home (transport.socketPath), elsewhere over HTTP on a port in the agent's block. signal-cli's daemon asks for no credential, and a Mac has no network of the sandbox's own, so a port there is open to every user and program of the Mac. OpenClaw speaks to signal-cli over a socket itself, and checks before each connection that the socket and its folder are the user's alone, so nothing stands between them. On Linux that check wants every folder above the socket to be the user's or root's, which the sandbox's user namespace shows root's as no one's, and behind its proxy the port stays in the sandbox's own network.