NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #277 by repository stars
Last release 6 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 15 of 15 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
428 releases · first in 2026
One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
CLI help text corrections (#478): Fixed incorrect command names (e.g., cuebcli → cubecli), spelling mistakes, outdated deprecation hints, and truncate…
CubeSandbox 0.4.0 introduces CubeEgress, an OpenResty-based security proxy that brings credential injection, domain filtering, and access auditing to sandbox egress traffic. This release also delivers container log forwarding with a new cubecli logs command, a node component version matrix with cluster-wide visibility, template replica compatibility checking, a daemonless template image build pipeline, and significant network performance improvements (35% faster network P50). The builder base image has been downgraded to ubuntu:20.04, lowering the minimum glibc requirement from 2.34 to 2.31 for broader distribution compatibility. 58 commits from 15 contributors.
CubeEgress is a new OpenResty-based egress gateway that sits in the sandbox outbound traffic path via TPROXY, enforcing L7 policy before requests leave the cluster. It consists of ~2,200 lines of Lua across 9 modules running on OpenResty/nginx, plus Go-side integration in CubeMaster (CA provisioning, policy push), network-agent (TPROXY iptables rules), and Cubelet (per-sandbox routing, protobuf egress rule model).
EgressRule.inject — user code inside the sandbox never handles raw credentials. The CubeNetworkConfig protobuf message (formerly CubeVSContext) now carries L7 egress rules with match conditions (SNI, host, method, path, scheme) and actions (allow/deny, audit, inject). Credential material is redacted as ***REDACTED*** in CubeMaster safe-log output (#520).redactor Lua module, enabling downstream compliance review.tx-tcp-mangleid-segmentation are enabled on TAP devices so redirected packets skip GSO before reaching the guest./admin/v1/health endpoint extension, release manifest entries, and cubelet-side file-based collection.New files: CubeEgress/ (20 files — Lua modules, nginx config, Dockerfile, iptables scripts, systemd units, CA generation); CubeMaster/pkg/service/httpservice/cube/ca_download.go; CubeMaster/pkg/templatecenter/cube_egress_ca/; CubeMaster/pkg/templatecenter/cube_egress_ca_bake.go; DB migration 0005_cube_egress.sql.
Container init-process stdout/stderr is now streamed from the agent to the shim via a dedicated vsock connection and appended to log files on the host. A new cubecli cubebox logs subcommand lets operators read these logs from outside the sandbox.
cube.container.log_forwarding=true annotation into the OCI spec, causing the agent to create stdout/stderr pipes (1 MiB buffer, O_NONBLOCK) for the init process. A dedicated vsock channel carries the log stream to the shim, which appends to /data/log/template/<id>/stdout|stderr during template builds and to ./stdout / ./stderr in the bundle directory for normal sandboxes. Log forwarding is cleanly cancelled before pause/snapshot/teardown, and pipe write fds are closed on process exit so readers receive EOF (#541). Exec I/O relay (FIFO-based) is kept separate from init log forwarding.cubecli cubebox logs (#528): New subcommand to read container stdout/stderr from /data/cubelet/state/io.containerd.runtime.v2.task/default/<id>/stdout|stderr. Supports --tail N, --head N, --all, and --stderr flags. Since log files live inside the cubelet mount namespace, the command re-execs itself via the existing C constructor in pkg/cubemnt/nsenter.c to safely enter the namespace before any Go code runs. Includes openNoFollow() path validation hardened against symlink-following attacks.A new version tracking infrastructure gives operators cluster-wide visibility of component versions across all nodes, with a dedicated Web UI page.
node_component_version table (DB migration 0004). The matrix groups nodes by reported version for each component, surfaces version skew, and exposes summary and detail APIs through CubeAPI.build.rs. A machine-readable release-manifest.json is generated in one-click release bundles so every artifact is traceable to the same release. The cubecli version and cubemastercli version output formats are unified across components.Versions.tsx page (762 lines) with i18n support (en/zh) shows per-component version distribution across nodes. The sidebar and Settings About section now display the actual release tag (injected at build time as __APP_VERSION__) instead of hardcoded versions.New files: CubeMaster/pkg/nodemeta/versionmatrix.go; web/src/pages/Versions.tsx; web/src/locales/en/versions.json, zh/versions.json; DB migration 0004_node_component_version.sql.
Template replicas are now checked against node component versions, with stale/missing replicas surfaced in both the API and Web UI.
template_versions (DB migration 0006) and exposed via /templates/compat (summary) and /templates/compat/{id} (per-template detail). Version binding management lets operators pin a template to specific component versions at creation time.CompatBadge, CompatSection, CompatWarning, CompatNodeCard, VersionDeltaList.New files: CubeMaster/pkg/templatecenter/compat.go; CubeMaster/pkg/service/httpservice/cube/template_compat.go; DB migration 0006_template_replica_compat.sql.
The template image build pipeline has been rearchitected to support daemonless operation via skopeo/umoci, with a 72% reduction in peak disk usage and file-level content deduplication.
skopeo copy into a local OCI layout and unpacked with umoci unpack --rootless, eliminating the Docker daemon requirement. Falls back to Docker for backward compatibility. The export strategy is chosen once at image resolution time so preparation and export stay consistent.tar -xf stdin via a 1 MiB pipe (F_SETPIPE_SZ), eliminating the intermediate rootfs.tar file.CUBEMASTER_DISK_SPACE_SAFETY_MARGIN, default 1.5×).
SHA256 computation uses a 4 MiB buffer to reduce read syscalls. A loop-mount streaming ext4 build phase (gated behind CUBEMASTER_LOOP_MOUNT_EXT4_ENABLED, default false) is also implemented with CAP_SYS_ADMIN detection.POST /templates and Python/Go SDKs now expose DNS, egress CIDRs, registry auth, command/args, network type, and node scope options, matching the full cubemastercli template create-from-image option set.New files: CubeMaster/pkg/templatecenter/image/ (export, ext4, disk, command, ref, source, types, paths, util); CubeMaster/pkg/templatecenter/artifact_build.go, artifact_cleanup.go, distribution.go, fingerprint.go, image_job_runner.go, job_constants.go, job_dto.go.
TAP fd acquisition optimization (#487): A three-tier GetTapFile strategy replaces the old single-path approach:
state.tap.File is already cached, return it immediately (0 syscalls).open + TUNSETIFF), skipping the expensive restoreTap flow (netlink lookup, LinkSetUp, SetMTU, TC filter attach, ARP entry).restoreTap only when there is no in-memory state or the tap is held externally.The fdserver JSON response now includes the ifindex, allowing cubelet to skip its own netlink.LinkByName call — eliminating a serialization point during concurrent sandbox creation. Cubelet falls back to LinkByName only when ifindex is 0 (backward-compatible with older agents).
A TOCTOU race between EnsureNetwork and ReleaseNetwork is fixed by replacing singleflight-style dedup with a per-sandbox creating guard channel registered in the same critical section as the state check. Includes a pprof debug server (--pprof-listen flag) and 390 lines of concurrency tests (6 functions, 64-goroutine stress test clean under -race).
Benchmarks (BMI5, Xeon Platinum 8255C, kernel 6.6.119): Network P50 35.3→23.1ms (35% faster), Network P99 86.6→51.2ms (41% faster), Total P50 106.1→92.0ms (13% faster), Throughput 194.8→209.8 sandboxes/s (8% higher).
BPF checksum optimization (#469): bpf_csum_diff() is replaced with bpf_{l3,l4}_csum_replace helpers in both from_world and from_cube BPF programs. Combined with the TAP TX offload work (#505), this enables TSO/UFO/CSUM offloads to be re-enabled on virtio-net TAPs (reverting #110), and the disableGRO() requirement on host NICs is dropped.
overcommit_ratio (default CPU=3, Mem=2) with optional per-instance-type overrides via overcommit_ratio_conf, and ignore_redis_allocation (default false) to treat Redis-recorded allocations as zero. Applied consistently across filter and score plugins, with non-positive ratios clamped back to defaults. Physical load guards (CPU utilization ceiling, real-time free memory) are intentionally preserved.com.nodeaffinity.selector annotation now accepts arbitrary NodeSelectorRequirements (In, NotIn, Exists, DoesNotExist, Gt, Lt) as a JSON array of {key, operator, values}. Node labels from registration are carried through Node.NodeLabels, merged into Labels() with an atomic.Pointer cache and InvalidateLabelsCache() for mutation safety. DoS hardening: max annotation size 4 KB, 10 selectors per request, 50 values per In/NotIn. Configurable allowed keys default to zone, cluster-id, cpu-type, memory-size, cpu-cores, instance-type. 872 lines of tests covering 47 cases.tpl- prefix across all creation paths (API, CLI, Web UI, sandbox commit). User-specified IDs are accepted for backward compatibility but silently ignored — the server always returns an auto-generated tpl- prefixed ID as the authoritative template identifier. Validation rejects bare tpl- / snap- prefixes and non-conforming annotation prefixes.ubuntu:22.04 to ubuntu:20.04, lowering the minimum glibc requirement from 2.34 to 2.31. Affects Dockerfile.builder, one-click installer preflight checks, CI workflows, and documentation.createRequest. A dedicated "Network Policy" section includes per-rule copy buttons. A BoolBadge component is extracted as a shared UI primitive.LOCALVERSION is renamed to a clean descriptive scheme so the distribution base and host/guest role are obvious from uname -r. Deployment configs, user-facing guides, and blog references are updated to match.These fixes address issues present in v0.3.1:
AllowOut to ensure DNS resolution works through egress policy. Includes regression test coverage.cleanupHostDirVolumes now resolves base-path symlinks when walking sandbox directories, so bind mounts under paths like /data → /mnt/ssd/data are correctly identified and unmounted instead of leaking or having their backing directories wiped.AllowInternetAccess=false, resolved DNS servers are no longer appended to allow_out, so the deny-all outbound policy consistently blocks DNS resolution. Fixes #408.ripgrep. Shell checks now use grep-based helpers.MigrationOnError::GuestError instead of Abort. Per-inode failures during snapshot restore surface as guest FS errors (ENOENT/EIO) on the affected paths rather than tearing down the entire live migration.process_queue_serial() no longer panics on malformed descriptors. Failures are recovered by writing an EIO FUSE error reply to the guest and continuing to serve the queue. A new device_memory view is added for device-backed memory regions (virtio-pmem, virtio-fs DAX, ivshmem/zshm BARs).cgroups-rs and attaches container processes through cgroup.procs, avoiding v1 controller name failures in unified cgroup mode. Process ID collection for cleanup and signals also reads from cgroup.procs.ldd --version output is now fully captured before parsing, preventing strict-mode preflight checks from exiting on an expected SIGPIPE.IPOverrideTransport are now buffered before copying, so multipart uploads no longer fail with RequestNotRead.cuebcli → cubecli), spelling mistakes, outdated deprecation hints, and truncated descriptions in both cubecli and cubemastercli.e2b_code_interpreter examples, CUBE_API_URL + CubeProxy settings for CubeSandbox SDK examples.--template-id flags from create-from-image documentation and examples since template IDs are now auto-generated with tpl- prefix.install.sh, online-install.sh, and check-deps.sh. Updated install docs to use direct links to the Releases page..PHONY declarations replace the single bulk list. A new clean-rust-target-dirs target removes target/ under each top-level Rust workspace. The all target is driven from a shared BINARIES list.fmt targets are added to all component Makefiles (Go and Rust), with a new .github/workflows/fmt-check.yml CI workflow that runs format checking on PRs. The agent's fmt target automatically generates required files (version.rs, protocol .rs) before formatting.--body-file -) instead of temp files, keeping review content out of the checkout directory.[t, 1.5t]) to prevent thundering herd issues when multiple agents start concurrently.CubeSandbox 0.4.0 引入了 CubeEgress,一个基于 OpenResty 的安全代理,为沙箱出站流量提供凭据注入、域名过滤和访问审计能力。本版本还带来了容器日志转发及配套的 cubecli logs 命令、节点组件版本矩阵(集群范围版本可见性)、模板副本兼容性检查、无守护进程的模板镜像构建管线,以及显著的网络性能提升(网络 P50 延迟降低 35%)。构建基础镜像已降级至 ubuntu:20.04,将最低 glibc 要求从 2.34 降低到 2.31,以覆盖更广泛的发行版。58 个 commits,15 位贡献者。
CubeEgress 是一个全新的基于 OpenResty 的出站网关,通过 TPROXY 截获沙箱出站流量,在请求离开集群之前执行 L7 策略。它由运行在 OpenResty/nginx 上的 9 个 Lua 模块(约 2200 行代码)以及 Go 端的集成组成——CubeMaster(CA 颁发、策略下发)、network-agent(TPROXY iptables 规则)和 Cubelet(按沙箱路由、protobuf 出站规则模型)。
EgressRule.inject 在代理层附加到出站请求中——沙箱内的用户代码永远不会接触到原始凭据。CubeNetworkConfig protobuf 消息(原 CubeVSContext)现在携带 L7 出站规则,包含匹配条件(SNI、host、method、path、scheme)和动作(allow/deny、audit、inject)。凭据信息在 CubeMaster 安全日志输出中被替换为 ***REDACTED***(#520)。redactor Lua 模块进行可选的请求体脱敏,便于下游合规审查。tx-tcp-mangleid-segmentation,使重定向的数据包在到达客户机之前无需进行 GSO。/admin/v1/health 端点扩展、发布清单条目和 cubelet 端基于文件的版本采集能力。新增文件:CubeEgress/(20 个文件——Lua 模块、nginx 配置、Dockerfile、iptables 脚本、systemd 单元、CA 生成);CubeMaster/pkg/service/httpservice/cube/ca_download.go;CubeMaster/pkg/templatecenter/cube_egress_ca/;CubeMaster/pkg/templatecenter/cube_egress_ca_bake.go;数据库迁移 0005_cube_egress.sql。
容器 init 进程的 stdout/stderr 现在通过专用的 vsock 连接从 agent 流式传输到 shim,并追加到宿主机的日志文件中。新增的 cubecli cubebox logs 子命令允许运维人员从沙箱外部读取这些日志。
cube.container.log_forwarding=true 注解,指示 agent 为 init 进程创建 stdout/stderr 管道(1 MiB 缓冲区,O_NONBLOCK)。专用的 vsock 通道将日志流传输到 shim,在模板构建期间写入 /data/log/template/<id>/stdout|stderr,普通沙箱写入 bundle 目录下的 ./stdout 和 ./stderr。日志转发在暂停/快照/销毁之前会被干净地取消,进程退出时管道的写端文件描述符被关闭以确保读取端收到 EOF(#541)。exec I/O 中继(基于 FIFO)与 init 日志转发保持分离。cubecli cubebox logs(#528):新增子命令,用于从 /data/cubelet/state/io.containerd.runtime.v2.task/default/<id>/stdout|stderr 读取容器 stdout/stderr。支持 --tail N、--head N、--all 和 --stderr 选项。由于日志文件位于 cubelet 的挂载命名空间内,该命令通过 pkg/cubemnt/nsenter.c 中现有的 C 构造函数重新执行自身,在任何 Go 代码运行之前安全地进入该命名空间。包含 openNoFollow() 路径验证以防止符号链接跟随攻击。全新的版本追踪基础设施为运维人员提供了集群范围内所有节点组件版本的可见性,并配有专属的 Web UI 页面。
node_component_version 表(数据库迁移 0004)中维护版本矩阵,按组件对报告同一版本的节点进行分组,暴露版本偏差,并通过 CubeAPI 对外提供汇总和详情接口。build.rs 接收 version、commit 和 build-time 元数据。一键部署发布包中生成机器可读的 release-manifest.json,确保每个构建产物都可追溯到同一发布版本。cubecli version 和 cubemastercli version 的输出格式在各组件间保持一致。Versions.tsx 页面(762 行),支持中英文国际化,展示各组件在节点间的版本分布。侧边栏和设置页的"关于"部分现在显示实际的发布标签(构建时注入为 __APP_VERSION__),而非硬编码的版本号。新增文件:CubeMaster/pkg/nodemeta/versionmatrix.go;web/src/pages/Versions.tsx;web/src/locales/en/versions.json、zh/versions.json;数据库迁移 0004_node_component_version.sql。
模板副本现在与节点组件版本进行对比检查,过时/缺失的副本会在 API 和 Web UI 中暴露出来。
template_versions 表(数据库迁移 0006)中,通过 /templates/compat(汇总)和 /templates/compat/{id}(单个模板详情)接口对外暴露。版本绑定管理允许运维人员在创建时将模板固定到特定的组件版本。CompatBadge、CompatSection、CompatWarning、CompatNodeCard、VersionDeltaList。新增文件:CubeMaster/pkg/templatecenter/compat.go;CubeMaster/pkg/service/httpservice/cube/template_compat.go;数据库迁移 0006_template_replica_compat.sql。
模板镜像构建管线经过重新架构,支持通过 skopeo/umoci 进行无守护进程操作,峰值磁盘使用量降低 72%,并具备文件级内容去重能力。
无守护进程导出路径(#492, #506):当 CubeMaster 节点上可用 skopeo 和 umoci 时,模板镜像通过 skopeo copy 拉取到本地 OCI 布局,并用 umoci unpack --rootless 解包,完全消除对 Docker 守护进程的依赖。不可用时自动回退到 Docker 以保证向后兼容。导出策略在镜像解析时一次性选定,确保准备和导出阶段保持一致。
制品管理(#506):新增 job runner 编排完整管线(镜像导出 → rootfs 制品构建 → 分发),支持 redo(重做)操作并可从中断的阶段恢复。文件级内容指纹(SHA256)实现制品跨构建去重,制品清理通过结构化的生命周期进行管理。Redo 操作现在通过 working request 携带正确的模板 ID(#544)。
磁盘使用优化(#472):通过五项互补优化,将镜像到 ext4 构建过程中的峰值磁盘使用量从约 4.2 倍镜像大小降低到约 1.2 倍:
F_SETPIPE_SZ)直接连接到 tar -xf 的标准输入,消除中间的 rootfs.tar 文件。CUBEMASTER_DISK_SPACE_SAFETY_MARGIN,默认 1.5 倍)。SHA256 计算使用 4 MiB 缓冲区以减少 read 系统调用。基于 loop-mount 的流式 ext4 构建阶段(由 CUBEMASTER_LOOP_MOUNT_EXT4_ENABLED 控制,默认关闭)也已实现,含 CAP_SYS_ADMIN 能力检测。
SDK 对齐(#485):CubeAPI POST /templates 以及 Python/Go SDK 现在支持 DNS、出口 CIDR、镜像仓库认证、command/args、网络类型和节点范围等选项,与 cubemastercli template create-from-image 的完整选项集保持一致。
新增文件:CubeMaster/pkg/templatecenter/image/(export、ext4、disk、command、ref、source、types、paths、util);CubeMaster/pkg/templatecenter/artifact_build.go、artifact_cleanup.go、distribution.go、fingerprint.go、image_job_runner.go、job_constants.go、job_dto.go。
TAP fd 获取优化(#487):三层的 GetTapFile 策略取代了旧的单一获取路径:
state.tap.File 已缓存时立即返回(0 次系统调用)。open + TUNSETIFF)重新打开,跳过昂贵的 restoreTap 流程(netlink 查找、LinkSetUp、SetMTU、TC filter 挂载、ARP 条目)。restoreTap。fdserver JSON 响应现在包含 ifindex,使 cubelet 可以跳过自身的 netlink.LinkByName 调用——消除了并发沙箱创建过程中的一个序列化点。当 ifindex 为 0 时 cubelet 回退到 LinkByName(与旧版 agent 向后兼容)。
通过用注册在同一临界区内的 per-sandbox creating 守护通道替换 singleflight 风格的去重,修复了 EnsureNetwork 和 ReleaseNetwork 之间的 TOCTOU 竞态条件。包含 pprof 调试服务器(--pprof-listen 选项)和 390 行并发测试(6 个测试函数,64 协程压力测试通过 -race 检测)。
基准测试(BMI5, Xeon Platinum 8255C, kernel 6.6.119):网络 P50 35.3→23.1ms(提升 35%),网络 P99 86.6→51.2ms(提升 41%),总 P50 106.1→92.0ms(提升 13%),吞吐量 194.8→209.8 sandboxes/s(提升 8%)。
BPF 校验和优化(#469):在 from_world 和 from_cube 两个 BPF 程序中,将 bpf_csum_diff() 替换为 bpf_{l3,l4}_csum_replace 辅助函数。结合 TAP TX 卸载工作(#505),使 TSO/UFO/CSUM 卸载得以在 virtio-net TAP 上重新启用(回滚 #110),同时取消了对宿主机网卡的 disableGRO() 要求。
overcommit_ratio(默认 CPU=3, Mem=2),支持通过 overcommit_ratio_conf 按实例类型覆盖;ignore_redis_allocation(默认 false),将 Redis 中记录的已分配资源视为零。在 filter 和 score 插件中一致生效,非正数的比例值会被重置为默认值。物理负载保护(CPU 利用率上限、实时空闲内存)被有意保留。com.nodeaffinity.selector 注解现在接受任意的 NodeSelectorRequirements(In、NotIn、Exists、DoesNotExist、Gt、Lt),以 JSON 数组 {key, operator, values} 的形式传入。节点注册标签通过 Node.NodeLabels 传递,合并到 Labels() 中,并使用 atomic.Pointer 缓存和 InvalidateLabelsCache() 确保变更安全。DoS 防护:最大注解大小 4 KB,每个请求最多 10 个选择器,每个 In/NotIn 最多 50 个值。可配置的允许键默认包括 zone、cluster-id、cpu-type、memory-size、cpu-cores、instance-type。872 行测试覆盖 47 个场景。tpl- 前缀。为保持向后兼容,用户指定的 ID 仍然被接受但会被静默忽略——服务端始终返回自动生成的 tpl- 前缀 ID 作为权威模板标识符。验证逻辑拒绝裸的 tpl- / snap- 前缀以及不符合规范的注解前缀。ubuntu:22.04 更换为 ubuntu:20.04,将最低 glibc 要求从 2.34 降至 2.31。影响 Dockerfile.builder、一键部署预检脚本、CI 工作流和文档。createRequest 解析)。新增的"网络策略"区域包含每条规则的快捷复制按钮。BoolBadge 组件被提取为共享 UI 原语。LOCALVERSION 被重命名为清晰、自描述的风格,使发行版基础和宿主机/客户机角色可通过 uname -r 一目了然。部署配置、用户指南和博客引用均已同步更新。以下修复针对 v0.3.1 中已存在的问题:
AllowOut,确保 DNS 解析能够通过出站策略。包含回归测试覆盖。cleanupHostDirVolumes 现在遍历沙箱目录时会解析基础路径的符号链接,使得位于符号链接路径下(如 /data → /mnt/ssd/data)的 bind mount 能够被正确识别并卸载,避免泄漏或误删后端目录。AllowInternetAccess=false 时,解析出的 DNS 服务器不再被追加到 allow_out,使 deny-all 出站策略能够一致地阻断 DNS 解析。修复 #408。ripgrep。Shell 检查已改用基于 grep 的辅助函数。MigrationOnError::GuestError 替代 Abort。快照恢复期间的单文件错误会以客户机 FS 错误(ENOENT/EIO)的形式体现在受影响的路径上,而不会中断整个热迁移。process_queue_serial() 不再因畸形描述符而 panic。失败时通过向客户机回复 EIO FUSE 错误并继续处理队列来恢复。新增 device_memory 视图用于设备后端内存区域(virtio-pmem、virtio-fs DAX、ivshmem/zshm BAR)。cgroups-rs 提供的 cgroup v2 创建路径,并通过 cgroup.procs 挂载容器进程,避免了在 unified cgroup 模式下使用 v1 控制器名称导致的失败。清理和信号发送的进程 ID 收集也从 cgroup.procs 读取。ldd --version 的输出现在会在解析前完整捕获,避免严格模式下的预检因预期的 SIGPIPE 而退出。IPOverrideTransport 中的请求体现在在复制前会被缓冲,使 multipart 上传不再因 RequestNotRead 而失败。cubecli 和 cubemastercli 中错误的命令名称(如 cuebcli → cubecli)、拼写错误、过时的弃用提示以及截断的描述文本。e2b_code_interpreter 示例使用 E2B 变量,CubeSandbox SDK 示例使用 CUBE_API_URL + CubeProxy 设置。create-from-image 文档和示例中移除 --template-id 选项,因为模板 ID 现在会自动生成 tpl- 前缀。install.sh、online-install.sh 和 check-deps.sh 的 XFS 文件系统检查错误消息中添加 GitHub issue #311 的排障链接。更新安装文档,使用指向 Releases 页面的直接链接。.PHONY 声明按目标拆分。新增 clean-rust-target-dirs 目标,清理每个顶层 Rust 工作区下的 target/ 目录。all 目标现在通过共享的 BINARIES 列表驱动。fmt 目标(Go 和 Rust),并新增 .github/workflows/fmt-check.yml CI 工作流在 PR 上运行格式化检查。Agent 的 fmt 目标会在格式化前自动生成必要的文件(version.rs、协议 .rs 文件)。--body-file -)传递,而非临时文件,避免审查内容残留在 checkout 目录中。[t, 1.5t] 范围内均匀分布),防止多个 agent 同时启动时产生惊群效应。Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
CubeSandbox 0.3.1 is a stabilization and hardening release following v0.3.0, focused on one-click installer robustness, network stability fixes, Agent
CubeSandbox 0.3.1 is a stabilization and hardening release following v0.3.0, focused on one-click installer robustness, network stability fixes, AgentHub refinements, and expanded documentation with real-world benchmark data. 14 commits from 7 contributors.
CUBE_SANDBOX_NETWORK_CIDR at install time to avoid conflicts with existing host network subnets. Includes CIDR format validation, host interface/route overlap detection, and a bypass flag (CUBE_SANDBOX_NETWORK_CIDR_SKIP_CONFLICT_CHECK) for advanced scenarios. The chosen CIDR is persisted to .one-click.env after successful config patching.ExecStart, ExecStartPre, ExecStartPost, and ExecStop directives with /usr/bin/bash to avoid 203/EXEC errors from systemd-executor on OpenCloudOS 9.4+.kvm_pvm kernel module is loaded on the host, the installer verifies that CUBE_PVM_ENABLE=1 is set. Without this check, PVM hosts would silently install the wrong guest kernel (ordinary vmlinux instead of vmlinux-pvm), causing VM template creation to fail later with obscure errors. Configurable via ONE_CLICK_SKIP_PVM_CHECK=1.network-agent restarted, restoreTap() unconditionally tried to acquire the tap fd via TUNSETIFF, even when the TAP was still held by a running sandbox. With IFF_ONE_QUEUE, the kernel rejected the second open with EBUSY, the TAP was pushed into the abnormal pool, and the stale-cleanup branch removed its BPF map entry — silently dropping egress traffic. The fix skips getTapFd when tap.InUse is true and surfaces a clear error when no fd is available.resolv.conf was rewritten before CoreDNS was listening, causing a DNS deadlock. The installer now waits for CoreDNS to bind its port, preserves one upstream fallback resolver, and filters reserved nameserver addresses from upstream resolution paths.mirrors.tencent.com is no longer available and downloads fail. Bumped the default image URL in both prepare_image.sh and run_vm.sh to the latest 9.6-20260514.2 GenericCloud image.trpc-agent-go leverages Cube Sandbox as a secure code execution backend, with sidebar entries in both EN and ZH documentation.vmm.log path, added template creation command to section 2.2, and moved general conventions from section 3.1 to section 4.0 in both language versions./data/cubelet from 300 GB to 50 GB, with a 200 GB recommendation for building multiple templates.7 contributors made this release possible:
@LoGin (jinlong), @ls (ls-ggg), @cherrycao, @chengjoey, @Hengqi Chen, @joeytao, @tinklone (maxlong)
CubeSandbox 0.3.1 是 v0.3.0 之后的稳定性与加固版本,专注于一键安装脚本的健壮性增强、网络稳定性修复、AgentHub 功能完善,以及基于真实基准测试数据的文档扩展。14 个提交,7 位贡献者。
CUBE_SANDBOX_NETWORK_CIDR 指定沙箱网络 CIDR,以规避与宿主机现有网络子网的冲突。支持 CIDR 格式校验、宿主机接口/路由重叠检测,并提供绕过标志(CUBE_SANDBOX_NETWORK_CIDR_SKIP_CONFLICT_CHECK)用于高级场景。配置成功后会持久化到 .one-click.env。ExecStart、ExecStartPre、ExecStartPost 和 ExecStop 指令添加 /usr/bin/bash 前缀,避免 OpenCloudOS 9.4+ 上 systemd-executor 导致的 203/EXEC 错误。kvm_pvm 内核模块时,安装脚本会验证是否设置了 CUBE_PVM_ENABLE=1。如果没有此检查,PVM 宿主机将静默安装错误的 guest 内核(普通 vmlinux 而非 vmlinux-pvm),导致 VM 模板创建在后续阶段以难以排查的错误失败。可通过 ONE_CLICK_SKIP_PVM_CHECK=1 跳过。network-agent 重启时,restoreTap() 无条件尝试通过 TUNSETIFF 获取 TAP fd,即使该 TAP 仍被运行中的沙箱持有。由于 IFF_ONE_QUEUE,内核以 EBUSY 拒绝第二次打开,TAP 被推入异常池,清理分支将其 BPF 映射条目删除——导致出口流量被静默丢弃。修复方案:当 tap.InUse 为 true 时跳过 getTapFd,并在没有可用 fd 时向调用方返回明确错误。resolv.conf,导致 DNS 死锁。安装脚本现在等待 CoreDNS 绑定端口,保留一个上游回退 DNS 服务器,并在上游解析路径中过滤预留的 nameserver 地址。mirrors.tencent.com 上已不再可用,下载失败。将 prepare_image.sh 和 run_vm.sh 中的默认镜像 URL 升级至最新的 9.6-20260514.2 GenericCloud 镜像。trpc-agent-go 如何基于 Cube Sandbox 作为安全代码执行后端,中英文侧边栏均已添加条目。vmm.log 路径,在 2.2 节添加模板创建命令,将通用约定从 3.1 节移至 4.0 节,中英文两个版本均已更新。/data/cubelet 的最低磁盘空间要求从 300 GB 降低至 50 GB,构建多个模板时建议 200 GB 及以上。7 位贡献者共同完成了此版本:
@LoGin (jinlong), @ls (ls-ggg), @cherrycao, @chengjoey, @Hengqi Chen, @joeytao, @tinklone (maxlong)
Prometheus upgrade (#328): Upgraded prometheus client to 0.14.0, dropping the vulnerable protobuf 2.28.0 dependency.
CubeSandbox 0.3.0 introduces CubeCoW, a Copy-on-Write snapshot engine that brings hundred-millisecond snapshot, clone, and rollback capabilities to AI Agent sandboxes. This release also adds the AgentHub digital assistant console (Preview), a Web UI for visual management, and the Go SDK. With 82 commits from 22 contributors, v0.3.0 is the largest release since open-sourcing.
sync_all() calls from all snapshot write paths, significantly reducing snapshot write latency without compromising data integrity.systemctl integration.check.sh and collect-logs.sh scripts for one-click deployment health verification and log collection.goose for database schema migrations, enabling versioned, automated schema management across upgrades./v1/metrics, enabling real-time monitoring of sandbox scheduling and resource utilization.NodeStatusUpdateFrequency to use tomlext.Duration for correct TOML duration parsing.cube-proxy.service is now ordered after cube-sandbox-dns.service, preventing DNS resolution failures at startup.protobuf 2.28.0 dependency.rustls-webpki CVE.go-jose/v4 to the latest secure version..md extensions to cross-file documentation references.e2b_ prefix, and corrected clone state documentation.rand.Seed calls across the codebase.crossbeam-channel from 0.5.13 to 0.5.15 in the hypervisor crate.22 contributors made this release possible:
@fslongjin, @ls, @tinklone, @kami-lu, @chenggui53, @cherrycao, @Hengqi Chen, @NovaHe, @maxlong, @Yi Wang, @liciazhu, @Nemo, @Feng King, @Songqian Li, @Joohwan., @Stary, @xiongxz, @yangjie, @YangYuS8, @wangchenglong-hj, @John Eismeier, @dependabot[bot]
CubeSandbox 0.3.0 引入了 CubeCoW Copy-on-Write 快照引擎,为 AI Agent 沙箱带来百毫秒级快照、克隆与回滚能力。本次发布还新增了 AgentHub 数字助理控制台(Preview 预览版)、Web UI 可视化管理界面,以及 Go SDK。82 个提交,22 位贡献者,这是开源以来规模最大的版本。
sync_all() 调用,在不影响数据完整性的前提下显著降低快照写入延迟。systemctl 集成。check.sh 和 collect-logs.sh,用于一键部署的健康验证与日志收集。goose 管理数据库 schema 迁移,支持版本化、自动化的 schema 升级。/v1/metrics 暴露调度器 Prometheus 指标,支持沙箱调度与资源利用的实时监控。NodeStatusUpdateFrequency 使用 tomlext.Duration 以确保 TOML 时长正确解析。cube-proxy.service 排在 cube-sandbox-dns.service 之后启动,避免 DNS 解析失败。protobuf 2.28.0 依赖。rustls-webpki 相关 CVE。go-jose/v4 至最新安全版本。.md 扩展名。e2b_ 前缀,更正克隆状态文档说明。rand.Seed 调用。crossbeam-channel 从 0.5.13 升级至 0.5.15。22 位贡献者共同完成了此版本:
@fslongjin, @ls, @tinklone, @kami-lu, @chenggui53, @cherrycao, @Hengqi Chen, @NovaHe, @maxlong, @Yi Wang, @liciazhu, @Nemo, @Feng King, @Songqian Li, @Joohwan., @Stary, @xiongxz, @yangjie, @YangYuS8, @wangchenglong-hj, @John Eismeier, @dependabot[bot]
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
`hypervisor`: `vmm-sys-util` bumped to 0.12.1 (CVE-2023-50711, GHSA-875g-mfp6-g7f9): FamStructWrapper::deserialize failed to verify header length agai…
hypervisor: vmm-sys-util bumped to 0.12.1 (CVE-2023-50711, GHSA-875g-mfp6-g7f9): FamStructWrapper::deserialize failed to verify header length against the flexible-array length, allowing out-of-bounds memory access from safe Rust code. Now pinned to the workspace version shared by all other hypervisor crates.agent / hypervisor: bytes and env_logger security bumps as part of the same dependency-refresh pass.time crate bump (CVE-2026-25727): CubeSandbox only uses Rfc3339 for outbound timestamp formatting and never parses untrusted Rfc2822 input — the affected attack vector is not reachable. The upgrade was rolled back pending an MSRV bump and will be tracked separately.CubeMaster): A request_id column with a unique index on (request_id, operation) makes job submissions idempotent, preventing duplicate build jobs from concurrent or retried API calls.cubecli exec nil-deref panic on stdin EOF: StdinCloser.Read triggered a nil-pointer dereference at stdin EOF, silently aborting the exec lifecycle. Fixed using errors.Is(err, io.EOF) for proper error-wrapping compatibility; shim logs now emit the expected paired exec lifecycle entries.RefreshArtifactRuntimeFiles, validateArtifactRuntimeFilesPresent, and ensureArtifactRuntimeFiles are simplified to handle only kernel files; copyKernelFileAtomically is renamed to CopyFileAtomically for reuse outside the package.CubeMaster is now the single source of truth — hardcoded defaults removed from Cubelet and network-agent.cubelet: configurable cmdTimeout via storage plugin TOML config: A new optional cmd_timeout field replaces the hardcoded 3 s default, letting operators raise the limit for multi-GiB ext4 operations without recompiling. Default behavior is unchanged when the field is absent.cubelet: richer diagnostics on newExt4RawByReflinkCopy failures: Error messages now include elapsed time, file sizes, and free space — e.g. [step=N/4 cmd="…" elapsed=…ms target=size=… base=size=… free=…B]..env: cubemaster.yaml now uses __CUBE_SANDBOX_MYSQL_PORT__ / __CUBE_SANDBOX_REDIS_PORT__ placeholders substituted by install.sh, enabling non-default MySQL/Redis ports without manual YAML edits.cubecli: removed dead listmd command: The unreachable listmd subcommand and its 128-line implementation are deleted..agents/agents/. Automated workflows handle PR review, duplicate issue detection, and issue label triage. Helper scripts gh.sh and edit-issue-labels.sh added under scripts/.CONTRIBUTING.md: CONTRIBUTING_zh.md added as a full Chinese translation of the contribution guide.CONTRIBUTING.md and CONTRIBUTING_zh.md now allow single-language submissions; bilingual docs are optional.docs/architecture/network.md (EN & ZH) now documents the three port-range buckets: 10000–19999 (network-agent), 20000–29999 (CubeProxy), 30000–65535 (CubeVS SNAT).docs.cubesandbox.ai to cubesandbox.com.browser-sandbox example: Added missing load_dotenv() call and python-dotenv dependency.hypervisor: vmm-sys-util 升级至 0.12.1(CVE-2023-50711, GHSA-875g-mfp6-g7f9):FamStructWrapper::deserialize 未验证 header 长度与柔性数组长度是否匹配,可导致 safe Rust 代码触发越界内存访问。现已固定为 hypervisor workspace 所有 crate 共享的版本。agent / hypervisor: bytes 和 env_logger 安全依赖升级,作为同批依赖刷新的一部分。time crate 升级(CVE-2026-25727):CubeSandbox 仅使用 Rfc3339 进行时间戳格式化输出,从不对不可信输入执行 Rfc2822 解析,攻击面不可达。该升级已回滚,待 MSRV 就绪后单独跟进处理。template_image_job 表新增 request_id 字段并添加 (request_id, operation) 唯一索引,使任务提交具备幂等性,彻底消除并发或重试 API 调用引发的重复构建任务。cubecli exec 在 stdin EOF 时的 nil 指针 panic:StdinCloser.Read 在 stdin 到达 EOF 时触发 nil 指针解引用,导致 exec 生命周期被静默中断。修复后改用 errors.Is(err, io.EOF) 进行正确的错误包装比对,shim 日志现可正常输出成对的 exec 生命周期记录。RefreshArtifactRuntimeFiles、validateArtifactRuntimeFilesPresent 和 ensureArtifactRuntimeFiles,使其仅处理内核文件;将 copyKernelFileAtomically 重命名为 CopyFileAtomically,支持在包外复用。CubeMaster 成为默认端口的唯一权威来源,Cubelet 和 network-agent 中的硬编码默认值已移除。cmdTimeout:在存储插件 TOML 配置中新增可选 cmd_timeout 字段,替代原有硬编码的 3 秒超时,允许运维人员在高并发负载下提高大文件 ext4 操作的超时限制,无需重新编译。字段缺省时行为不变。newExt4RawByReflinkCopy 错误诊断增强:错误信息现在包含操作耗时、目标/基础文件大小及可用磁盘空间,格式为 [step=N/4 cmd="…" elapsed=…ms target=size=… base=size=… free=…B]。.env 同步 CubeMaster 自定义端口:cubemaster.yaml 引入 __CUBE_SANDBOX_MYSQL_PORT__ / __CUBE_SANDBOX_REDIS_PORT__ 占位符,由 install.sh 从 .env 文件自动替换,无需手动修改 YAML。cubecli: 移除废弃的 listmd 命令:删除无法访问的 listmd 子命令及其 128 行实现代码。.agents/agents/ 下引入五个 AI 审查 Agent(代码质量、性能、安全、测试覆盖率、文档准确性)。自动化工作流负责 PR 代码审查、重复 issue 检测和 issue 标签分类。新增 scripts/gh.sh 和 scripts/edit-issue-labels.sh 辅助脚本。CONTRIBUTING_zh.md:CONTRIBUTING.md 的完整中文翻译版本。CONTRIBUTING.md 和 CONTRIBUTING_zh.md 均改为支持单语种提交,双语文档为可选项。docs/architecture/network.md(中英文)新增三段端口范围说明:10000–19999(network-agent)、20000–29999(CubeProxy 沙箱访问)、30000–65535(CubeVS SNAT)。docs.cubesandbox.ai 切换至 cubesandbox.com。browser-sandbox 示例:新增缺失的 load_dotenv() 调用和 python-dotenv 依赖,确保 .env 变量在脚本运行前正确加载。Nothing published for this version
Nothing published for this version
Official Python SDK (`cubesandbox` v0.1.0): A first-party Python SDK shipped under sdk/python/, fully aligned with the CubeAPI OpenAPI spec. Covers fu
cubesandbox v0.1.0): A first-party Python SDK shipped under sdk/python/, fully aligned with the CubeAPI OpenAPI spec. Covers full sandbox lifecycle (create/connect/pause/kill/list/health), code execution with streaming stdout/stderr, filesystem access, direct-connect transport, and network policy. Includes 12 worked examples, a concurrency benchmark, and 76/76 tests passing.SyncKernelFile into EnsureKernelFilePresent (copy-if-missing, fast path) and RefreshKernelFile (force-refresh with verification), removing the expensive per-boot SHA256 comparison. Normal startup latency drops significantly on hosts with many templates.docker pull in CubeMaster: Source image pulls are now bypassed when the image already exists locally, removing unnecessary registry round-trips during template builds.shim: protobuf bumped 3.4.0 → 3.7.2 (RUSTSEC, stack overflow on crafted unknown fields). Co-upgrades containerd-shim-protos, containerd-shim, and nix.cubeapi / agent / shim / hypervisor: rand 0.8.5 → 0.8.6 (GHSA-cq8v-f236-94qc, soundness issue with ThreadRng reseeding).CubeVS: golang.org/x/net → v0.38.0, golang.org/x/sys → v0.38.0.network-agent: google.golang.org/grpc → 1.79.3.CubeAPI/examples: pygments → 2.20.0.Seccomp initialization now sets DefaultAction = ActAllow; an empty syscall list short-circuits as a no-op instead of silently blocking everything.shim stderr being routed through stdout: The Exec stream-forwarding path was incorrectly calling the stdout read method for stderr; stderr is now properly captured and forwarded.CubeProxy workers sharing the same PRNG seed: OpenResty workers now seed the RNG per-worker in init_worker with (ngx.now() * 1000 + ngx.worker.id()), preventing synchronized cache-expiration stampedes.cube-shim symlinks: cube-runtime and containerd-shim-cube-rs are now written to ${TOOLBOX_ROOT}/cube-shim/bin, preserving the toolbox symlink layout.ca-certificates is now installed before apt sources are swapped to internal mirrors.cubemastercli tpl watch — phase-oriented output: Replaced the old multi-line full-status dump with concise [N/7] PHASE progress lines plus a terminal summary; much friendlier in CI logs.net/netip; IP ↔ index conversions via encoding/binary.BigEndian; bounds checks, safety limits, and nil guards added; reserved-address semantics documented; comprehensive table-driven and concurrency tests.CubeAPI/examples/ to top-level examples/, with dedicated host-mount and network-policy directories (each with its own README); comments translated to English.cube-bench promoted to examples/cube-bench: Now a standalone Go module with its own Makefile.CubeVS and network-agent upgraded to Go 1.24.8.cubecli internationalization: Remaining Chinese usage strings in benchrun.go translated to English.Makefile builder-image now builds from ./docker instead of the repo root.dl-cdn.alpinelinux.org to mirrors.tencent.com.Signed-off-by trailer.push triggers on several workflows now scoped to master only; PR validation runs exclusively via pull_request — halving CI cost.sync-to-cnb: Uses the CNB_GIT_PASSWORD secret.pvm-deploy.md.README_zh.md.cubesandbox v0.1.0):随仓库发布的第一方 Python SDK,位于 sdk/python/,与 CubeAPI OpenAPI 规范完全对齐。覆盖沙箱全生命周期管理(创建/连接/暂停/销毁/列表/健康检查)、代码执行(流式 stdout/stderr)、文件系统访问、直连传输及网络策略配置。附带 12 个完整示例、并发性能基准测试,76/76 测试全部通过。SyncKernelFile 拆分为 EnsureKernelFilePresent(按需拷贝,快速路径)和 RefreshKernelFile(强制刷新并校验),消除每次启动的高开销 SHA256 比对。在模板数量较多的主机上,正常启动延迟显著降低。docker pull:当源镜像已存在于本地时,跳过镜像拉取,消除模板构建时不必要的镜像仓库往返请求。shim: protobuf 3.4.0 → 3.7.2(RUSTSEC,恶意构造的未知字段可导致栈溢出)。同步升级 containerd-shim-protos、containerd-shim 和 nix。cubeapi / agent / shim / hypervisor: rand 0.8.5 → 0.8.6(GHSA-cq8v-f236-94qc,修复 ThreadRng 重新播种时的健全性问题)。CubeVS: golang.org/x/net → v0.38.0, golang.org/x/sys → v0.38.0。network-agent: google.golang.org/grpc → 1.79.3。CubeAPI/examples: pygments → 2.20.0。Seccomp 初始化现在设置 DefaultAction = ActAllow,空系统调用列表直接短路为空操作,而非静默阻止所有调用。shim stderr 被错误路由到 stdout:Exec 流转发路径中 stderr 错误调用了 stdout 的读取方法;现在 stderr 可被正确捕获并转发。CubeProxy 多 Worker 共享相同 PRNG 种子:OpenResty Worker 现在在 init_worker 中以 (ngx.now() * 1000 + ngx.worker.id()) 为每个 Worker 独立播种,避免缓存 TTL 抖动失效和同步缓存过期风暴。cube-shim 软链接:cube-runtime 和 containerd-shim-cube-rs 现在写入 ${TOOLBOX_ROOT}/cube-shim/bin,保留工具箱软链接布局。ca-certificates,避免 TLS 证书缺失导致引导失败。cubemastercli tpl watch — 阶段性进度输出:将原有的多行全量状态刷新替换为简洁的 [N/7] PHASE 进度行加终端摘要;在 CI 日志中更加友好。net/netip 重写校验逻辑;通过 encoding/binary.BigEndian 简化 IP 与索引互转;为 Allocate / Release / Assign 添加边界检查和安全性限制;所有 IPAM 方法增加 nil 防护;明确文档化保留地址语义;新增全面的表驱动测试和并发测试。CubeAPI/examples/ 迁移至顶层 examples/,新增独立的 host-mount 和 network-policy 目录(各自附带 README);注释翻译为英文。cube-bench 提升为 examples/cube-bench:现为独立 Go 模块,带自己的 Makefile。CubeVS 和 network-agent 升级至 Go 1.24.8,与 Cubelet / CubeMaster 保持一致。cubecli 国际化:benchrun.go 中残余的中文使用说明翻译为英文。Makefile 构建器镜像现在从 ./docker 构建,而非仓库根目录。dl-cdn.alpinelinux.org 切换至 mirrors.tencent.com。Signed-off-by 签名时阻断合入。push 触发器现在仅限 master 分支;PR 验证仅通过 pull_request 事件运行 — CI 成本减半。sync-to-cnb:改用 CNB_GIT_PASSWORD 密钥。pvm-deploy.md 新增分步操作章节。README_zh.md 更新微信/助手二维码。Nothing published for this version
Web Management Console (Dashboard): A brand-new visual management UI with cluster overview, node and sandbox status, template management, and API key
Web Management Console (Dashboard): A brand-new visual management UI with cluster overview, node and sandbox status, template management, and API key management; new CubeAPI web endpoints added to back the Dashboard.
PVM Deployment Mode: Powered by PVM (Pagetable-based Virtual Machine), ordinary cloud servers can now run CubeSandbox without bare-metal or nested virtualization. Tencent Cloud has deployed and validated PVM instances at scale in production, with improvements open-sourced in the OpenCloudOS kernel.
cubemastercli template gains a --dns flag, allowing a custom DNS server address to be specified when creating a template image.Fixed disk QoS (blk_qos) having no effect: Cubelet was reading the QoS annotation with the wrong key, silently ignoring IOPS/bandwidth limits; limits now apply as configured.
Fixed host-mount requests being silently dropped: CubeAPI wrote the annotation with key host-mount while CubeMaster read with hostdir-mount; the mismatch caused all host directory mounts to be ignored. Keys are now aligned and host-mount works correctly.
Fixed Cubelet mount namespace not receiving host mount events: Cubelet created its mount namespace in private mode, blocking propagation of subsequent host mounts; changed to slave mode so host mount events propagate one-way into the Cubelet namespace without affecting the host.
Fixed DeadGC permanently freezing paused sandboxes: scanDeadContainer issued a state() call to the shim while the sandbox held its mutex (during pausing/paused), causing a 5 s timeout, Cubelet marking the sandbox UNKNOWN, and CubeMaster giving up on resume. DeadGC now skips sandboxes in pausing/paused states.
myPrint output in cubecli sub-commands (cubebox, network, storage, volume, etc.) to structured logging.AppId field from CubeMaster affinityutil tests.新增 Web 管理控制台(Dashboard):全新可视化管理界面,支持集群概览、节点与沙箱状态查看、模板管理、API 密钥管理等核心功能;同步新增 CubeAPI Web 端点为 Dashboard 提供数据支撑。
新增 PVM 部署模式:借助 PVM(Pagetable-based Virtual Machine),普通云服务器无需裸金属,也无需嵌套虚拟化,即可完整运行 CubeSandbox。腾讯云已在生产环境大规模部署并验证,相关改进已开源至 OpenCloudOS 内核。
cubemastercli template 命令新增 --dns 参数,支持在创建模板镜像时指定 DNS 服务器地址。修复磁盘 QoS(blk_qos)配置完全失效问题:Cubelet 读取 QoS annotation 时使用了错误的 key,导致沙箱磁盘 IOPS/带宽限速静默不生效;修复后配置按预期生效。
修复 Host Mount 请求被静默丢弃问题:CubeAPI 写入 host-mount annotation 时 key 与 CubeMaster 读取时的 hostdir-mount 不一致,导致所有宿主机目录挂载请求被忽略;修复后两侧 key 对齐,功能恢复正常。
修复 Cubelet 挂载命名空间无法接收宿主机 mount 事件:Cubelet 以私有模式创建挂载命名空间,导致宿主机后续挂载无法传播至 Cubelet;修复后改为 slave 模式,宿主机挂载事件单向传播,沙箱 host-mount 功能完整可用。
修复 DeadGC 误判 pause 中的沙箱导致其永久冻结:scanDeadContainer 在沙箱处于 pausing/paused 状态时向 shim 发起 state 查询,因 shim 持有互斥锁而超时,Cubelet 将状态标记为 UNKNOWN,沙箱无法恢复;修复后 DeadGC 主动跳过此类沙箱。
cubecli 各子命令中遗留的 myPrint 自定义输出统一迁移为标准结构化日志。AppId 字段。Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed the issue where CubeMaster returned a 5xx error instead of a 4xx error when the sandbox template does not exist.
Fixed the issue where the latest vmlinux was not used during template reconstruction, improving the stability of the sandbox environment.
cubebox destroy command, enabling sandbox deletion via the CLI.cnb.cool/CubeSandbox/CubeSandbox.cubebox destroy 命令,支持通过 CLI 删除沙箱。cnb.cool/CubeSandbox/CubeSandbox 的能力。Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
Cube Sandbox is a high-performance, out-of-the-box secure sandbox service built on RustVMM and KVM. It supports both single-node deployment and can be easily scaled to a multi-node cluster. It is compatible with the E2B SDK, capable of creating a hardware-isolated sandbox environment with full service capabilities in under 60ms, while maintaining less than 5MB memory overhead.
Blazing-fast cold start: built on resource pool pre-provisioning and snapshot cloning technology, average end-to-end cold start time for a fully serviceable sandbox is < 60ms.
High-density deployment on a single node: extreme memory reuse via CoW technology combined with a Rust-rebuilt, aggressively trimmed runtime keeps per-instance memory overhead below 5MB — run thousands of Agents on a single machine.
True kernel-level isolation: each Agent runs with its own dedicated Guest OS kernel, eliminating container escape risks and enabling safe execution of any LLM-generated code.
Zero-cost migration (E2B drop-in replacement): natively compatible with the E2B SDK interface. Just swap one URL environment variable — no business logic changes needed.
Network security: CubeVS, powered by eBPF, enforces strict inter-sandbox network isolation at the kernel level with fine-grained egress traffic filtering policies.
Cube Sandbox has been validated at scale in Tencent Cloud production environments, proven stable and reliable — before this day it ever existed as open source, it had already quietly run behind real AI Agent workloads, serving real users, at production load.
In real production deployments, a single physical machine can spin up tens of thousands of sandboxes within minutes.
We open-source it today not as a prototype, but as production-hardened infrastructure that has already stood the test of real-world scale.
Before this code was ever public, it was already doing its job: spinning up sandboxes in milliseconds, isolating Agent workloads at the kernel level, and holding up under real production load at Tencent Cloud. None of that happened by accident.
Today we open the door. The high-performance Agent infrastructure you shaped now belongs to the world — to every developer who believes that safe, instant, and lightweight code execution should be open and self-hostable.
To those who contributed before this day: you built the foundation. To those who will contribute after: you are what turns a foundation into an ecosystem.
Open source shines because of you!
面向 AI Agent 的极速、高并发、安全且轻量化沙箱。
Cube Sandbox 是一款基于 RustVMM 与 KVM 构建的高性能、开箱即用的安全沙箱服务。它既支持单机部署,也可以轻松扩展到多机集群。Cube Sandbox 对外兼容 E2B SDK,能够在 60ms 内创建具备完整服务能力的硬件隔离沙箱环境,同时将单实例内存开销控制在 5MB 以下。
在开源之前,Cube Sandbox 已在腾讯云生产环境经历大规模验证,稳定可靠。 在它正式开源前,就已经支撑真实 AI Agent 业务负载并服务真实用户。
在真实生产部署中,单台物理机可在数分钟内拉起数以万计的沙箱实例。
我们今天开源的不是一个原型,而是一套已经通过真实规模考验的生产级基础设施。
在这套代码公开之前,它就已经在完成自己的使命:毫秒级启动沙箱、在内核级隔离 Agent 负载,并在腾讯云真实生产流量下稳定运行。这一切并非偶然。
今天,我们打开这扇门。你们共同塑造的高性能 Agent 基础设施,将走向整个社区,属于每一位相信「安全、即时、轻量的代码执行应当开源且可自托管」的开发者。
致过去的贡献者:你们打下了地基。
致未来的贡献者:你们将把地基发展成生态。
开源因你们而闪耀!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →