Skip to main content
A sandbox runs Windows programs on its Linux desktop through Wine. The programs open as normal windows on the desktop stream, so you can watch them and the sandbox’s agents can click, type, and read them with the built-in computer tools. Install once, then fork the set-up sandbox as many times as you need.

What we tested

Every app below ran on a Boat sandbox with the set-up on this page. “Extra step” lists what the app needs beyond that set-up. These did not work, and no set-up fixes them:

Install Wine

Run this script once inside the sandbox. It takes about 5 minutes. Send it with boat ssh bx_f7k2q9hd 'bash -s' < install-wine.sh, or pass it as the command of POST /sandboxes/{sandboxId}/commands or the SDK command call with detached: true. Without detached, the command stops after its 30-second default timeout and leaves Wine half-installed. Poll the command status until it finishes.
install-wine.sh
What each part does:
  • WineHQ staging. Ubuntu’s own Wine is version 9. Steam, Paint.NET 5.2, and Direct3D games need Wine 11 or newer.
  • The libgd3 pin. The sandbox ships a PHP repository whose libgd3 exists only for 64-bit. 32-bit Wine needs the same version for both. The pin selects Ubuntu’s version. PHP’s gd extension is removed as a side effect.
  • mesa-vulkan-drivers. A sandbox has no GPU. This software Vulkan driver lets DXVK run Direct3D 8 to 11 on the CPU.
  • WINEDLLOVERRIDES="mscoree,mshtml=". A new Wine set-up opens a “Wine Mono Installer” window and waits for a click. This skips it. Apps that need .NET get Microsoft’s runtime from winetricks instead.
  • winetricks. Installs Microsoft’s free redistributables: core fonts, the Visual C++ 2015 to 2022 runtime, DXVK, and the Direct3D shader compiler.

Run an app

Download the official installer or portable archive in the sandbox, install it, and start it on the desktop. Every GUI command needs DISPLAY=:0. This example installs the MicroDicom medical image viewer and opens a CT scan:
On the first start, MicroDicom asks to become the default viewer and does not open the file. Press Escape, close MicroDicom, and run the last command again. From then on, the scan opens at once.
  • Use wine start /unix <path> to start a program. Programs written in Python (Blender, FreeCAD) and many others crash without it, because start gives them normal Windows console handles.
  • Most installers have a silent switch: /S (NSIS), /VERYSILENT (Inno Setup), msiexec /i app.msi /qn (MSI).
  • To find an official download link, open the app’s manifest in winget-pkgs. The InstallerUrl field is the vendor’s own link.
  • Windows paths map to Linux paths: C:\ is ~/.wine/drive_c, and Z:\ is the Linux root /.

Recipes for harder apps

Steam

Steam needs the Arial font and must not use Wine’s DirectWrite. Its web view must not use a GPU.
The first start updates Steam and takes about 2 minutes. Then the sign-in window opens.

Paint.NET

Paint.NET 5.2 ships a separate build for Wine. It needs Wine 11.15 or newer, which the set-up above installs. Its installer makes its own Wine set-up and needs Wine Mono, so it opens the “Wine Mono Installer” window. The xdotool loop presses Install for you.
Pick the x64 file. The release also has an arm64 file that does not run on a sandbox. The Wine build is experimental and expires 12 weeks after its build date. Download a new one when it expires. Paint.NET 5.1 and older do not run.

Sysinternals

Process Explorer and Autoruns show a licence window on the first start. Accept it ahead of time so an agent does not have to. Autoruns rejects the /accepteula flag, so set the registry value for both:

Direct3D games

DXVK from the set-up runs Direct3D 8, 9, 10, and 11 games on the software Vulkan driver. Simple 2D and older 3D games run at playable speed. Modern 3D games are too slow without a GPU. Old games that switch the screen resolution can leave a full-screen window over the desktop. Stop Wine from changing the resolution:

Let an agent drive it

The Windows windows are ordinary windows on the sandbox desktop. A prompt is enough:
For scripted steps, xdotool and wmctrl are installed. For example, wmctrl -l lists the open windows and wmctrl -a HeidiSQL brings one to the front. Record the run with ascii-record-desktop.

Set up once, fork many times

The Wine set-up lives in ~/.wine and the system packages. Stop, resume, and fork keep both. In our test, a sandbox with Wine and 40 Windows apps (16 GB) did this: Make one sandbox with the apps your agents need, then fork it for each task. See Snapshots & Copies. Running Windows programs do not survive a stop or a fork. Start them again after a resume.

Troubleshooting

Licences

Install only software you have the right to use. Download it from the vendor, as on this page. Do not copy Windows system files into Wine: Microsoft’s licence does not allow it, and Wine does not need them for the apps above. The winetricks components on this page are Microsoft’s free redistributables.