本文へ移動
cccskills
無料GitHub で公開

run-dev

Build, test, format, and develop CubeSandbox components. Use when asked to build, compile, run tests, format code, or do development work on this project.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md6.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

CubeSandbox Development Skill

CubeSandbox is a monorepo sandbox service (Go + Rust + Web). All component builds run inside a Docker builder container via make targets at the repo root. The builder image provides Go 1.24, Rust 1.89, protoc, and all build dependencies.

Paths in this document are relative to the repo root

Prerequisites

# Docker must be running
docker info > /dev/null 2>&1 || { echo "Docker is not running"; exit 1; }

The builder image is built once (or when toolchains change):

make builder-image

Build

All builds happen inside the cube-sandbox-builder:ubuntu2004 Docker image. Binaries land in _output/bin/.

Build all Go components

make all

This builds: cubemaster, cubelet, cubevsmapdump, network-agent, agent, cubeapi, shim.

Build individual components

CommandComponentLanguageTime
make cubemasterMaster scheduler + CLIGo~30s
make cubeletPer-node sandbox agent + CLIGo + Rust (cubecow SDK)~90s
make agentIn-guest agent daemonRust~2min
make cubeapi or make cube-apiE2B-compatible REST APIRust (musl)~3min
make shimcontainerd shim + runtimeRust~2min
make network-agentNetwork managementGo~30s
make cubevsmapdumpeBPF map dump toolGo~20s
make cube-proxy-sidecarProxy sidecar (dev only)Go~20s
make cubecow-smokeCubeCoW smoke testGo + Rust~60s
make cube-init / make guest-initGuest PID1 (cube-init)Rust (musl)~30s
make agent-ext4 / make cube-agent-ext4Independent cube-agent.ext4 (+ version)Rust + e2fsprogs~2min
make pmem-assetscube-init + agent-ext4—~2min

Agent-independent pmem outputs:

make cube-init     # → _output/bin/cube-init
make agent-ext4    # → _output/cube-agent/cube-agent.ext4 (+ version)
make pmem-assets   # both of the above

Verify a build

# Check files in `_output/bin/`
file _output/bin/cubemaster

Test

Tests run inside the builder container. Some tests need external services (Redis, KVM) and will fail without them — see Gotchas.

Run component tests

# Agent tests (Rust) — 101+ tests, most pass without KVM
make builder-run BUILDER_CMD='cd /workspace/agent && make test'

# CubeMaster tests (Go) — unit-style cmd and pkg packages
make cubemaster-test

# Cubelet tests (Go) — full self-contained set (all packages except api/ and
# integration/); root/host-capability tests probe and skip themselves
make cubelet-test

# Cubelet mount tests — focused privileged lane for CAP_SYS_ADMIN tests
make cubelet-mount-test

# CubeCoW native tests (Go + CGO, needs cubecow SDK built)
make cubecow-test-native

# Integration tests — require a running CubeSandbox cluster (dev-env or one-click deploy)

Run a single test

# CubeMaster: single package with verbose output
make builder-run BUILDER_CMD='cd /workspace/CubeMaster && CI=true CUBE_MASTER_CONFIG_PATH=/workspace/CubeMaster/test/conf.yaml go test -v -run TestSomething ./pkg/base/...'

# Agent: single test
make builder-run BUILDER_CMD='cd /workspace/agent && cargo test -p cube-agent test_name'

Format and Lint

# Format all components (Go + Rust)
make fmt

# Web UI lint
make web-lint

For a single component:

# Go component
make builder-run BUILDER_CMD='cd /workspace/CubeMaster && make fmt'

# Rust component — fmt automatically runs in builder
make builder-run BUILDER_CMD='cd /workspace/CubeAPI && cargo fmt --check'

Web UI

The web dashboard lives in web/ (Vite + Vue + TypeScript).

make web-install     # Install npm dependencies (~30s)
make web-build       # Build static assets → web/dist/ (~2s)
make web-dev         # Start Vite dev server (localhost:5173)
make web-lint        # Lint check
make web-preview     # Preview built assets

Sync OpenAPI types after CubeAPI changes:

make web-api-sync

Gotchas

  1. Tests need Redis/KVM/MicroVM context.

    • CubeMaster/pkg/base/wrapredis tests panic if Redis is not reachable.
    • agent sandbox tests (9 of 110) fail without a running KVM MicroVM.
    • Run with -short or filter to the relevant package when iterating.
  2. CubeMaster tests use CUBE_MASTER_CONFIG_PATH. Must be set to test/conf.yaml inside the container (absolute path from /workspace).

  3. go covdata not available. The builder's Go toolchain (1.25) removed covdata. Use -coverprofile directly or skip coverage:

    go test -short ./pkg/...    # no coverage flag
    
  4. Builder container runs as host UID:GID. The builder-run target mounts the workspace with --user $(UID):$(GID). Files written by the builder (e.g., _output/bin/*) are owned by the host user.

  5. All builds are sequential. The Makefile uses builder-run which spawns one Docker container per target. Building make all runs each component sequentially. For parallel builds, use separate terminals or background processes.

  6. Agent build runs embedded unit tests before linking. make agent includes cargo test for the logging crate as part of the build. These are pure unit tests and always pass.

  7. CubeCoW SDK must be built before cubelet. make cubelet handles this automatically via the cubecow-sdk dependency, but if you build cubelet outside the make flow, run make cubecow-sdk first.

  8. KVM required for running sandboxes. Building works without KVM, but actually creating/starting sandboxes needs /dev/kvm with nested virtualization enabled. This container has it (/dev/kvm exists with nested=Y).

Troubleshooting

SymptomFix
docker: Cannot connectDocker daemon not running. sudo systemctl start docker
make: *** [builder-image] ErrorDocker build failed. Check network, retry with make builder-image BUILDER_FORCE_REBUILD=1. From China, add MIRROR=cn to source the clang-14 apt packages from a China mirror
error: protoc not installed inside builderBuilder image is outdated. Rebuild: make builder-image BUILDER_FORCE_REBUILD=1
go: no such tool "covdata"Don't use -coverprofile flag with make test in CubeMaster. Use raw go test instead.
cargo: command not found on hostRust builds run inside Docker. Use make <target>, not raw cargo.
Build hangs on "Download modules"Go module download is slow. The builder persists GOPATH at ~/.cache/cube-sandbox-builder/go, so retry is faster.
panic: nil pointer dereference in Redis testExpected — no Redis in builder. Filter: -run 'Test[^D]' or skip wrapredis package.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Cube Sandbox 安全沙箱执行技能。当需要安全执行 Python 代码、Shell 命令,或需要隔离环境运行不受信任的代码时使用。 适用场景: (1) 用户要求"在沙箱中执行代码"、"跑一段 Python"、"安全执行"、"隔离环境运行"; (2) 需要执行可能有副作用的代码(文件操作、网络请求、安装包等),希望通过沙箱隔离风险; (3) 需要读写沙箱内文件、挂载宿主机目录到沙箱; (4) 需要控制沙箱网络策略(完全断网、白名单、黑名单); (5) 需要暂停/恢复沙箱(保留内存快照以实现快速复用)。 Cube Sandbox 兼容 E2B SDK,通过环境变量 E2B_API_URL 指向 Cube 部署地址即可使用。

日本語の概要は準備中です。原文の説明を表示しています。

TencentCloud/CubeSandbox1.3万2026年10月10日 更新

TencentCloud のスキルをすべて見る

このスキルの問題を報告する