Skip to content
CAI
Software that uses CAICheck a score

arcboxlabs/arcbox

66.0

Adequate · 30 September 2026

251.1k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

ArcBox is a local development platform that provides isolated, disposable microVM sandboxes for running code and containers. It manages the full lifecycle of these virtual machines, including provisioning, networking, and storage, while offering a Docker API compatibility layer to integrate seamlessly with existing tooling. The system exposes its capabilities through a unified RPC interface and provides SDKs for Rust, Python, and TypeScript to programmatically control the environment.

Features

Add util-linux backend for block device operations

The snapshot CoW manager now supports a \util-linux\ backend for loop device and block size operations, in addition to the existing \busybox\ backend. This new \UtilLinuxBlockTools\ implementation uses \losetup -f --show\ for atomic allocation and attachment, eliminating the race-condition retry loop required by busybox's limited applets. The module exposes a \BlockTools\ trait with \BusyboxBlockTools\ and \UtilLinuxBlockTools\ implementations, allowing the system to automatically detect and use the appropriate userland tools based on the environment.

_engine/arcbox-snapshot/src/snapshot\_cow/block\tools · high confidence

Add virtio-balloon device with free page reporting support

The virtio-balloon device is now available, implementing the traditional memory balloon subset of VirtIO 1.2. It supports inflating and deflating guest memory via dedicated queues and advertises the \VIRTIO\_BALLOON\_F\_DEFLATE\_ON\_OOM\ feature, allowing the guest to reclaim balloon pages during out-of-memory conditions. Additionally, it implements free page reporting (\VIRTIO\_BALLOON\_F\_REPORTING\), enabling the guest kernel to periodically hand batches of free pages to the host for release, facilitating continuous idle memory drain. The device uses a pluggable \PageReleaser\ interface, defaulting to \madvise(MADV\_DONTNEED)\ on Linux and allowing custom implementations (such as for HV backends) to handle host-specific memory reclamation.

virt/arcbox-virtio-balloon · high confidence

Added Python SDK code-generation scripts for protobuf and sync wrappers

Two new scripts were added to the Python SDK to automate code generation. \gen\_proto.py\ regenerates the internal \arcbox/\_gen\ module by running \protoc\ on sandbox protocol buffers and rewriting imports for location independence. \gen\_sync.py\ uses \unasync\ to mechanically generate synchronous API wrappers (e.g., \ArcBox\, \Sandbox\) from the existing asynchronous \\_async\ source trees, ensuring parity between sync and async surfaces.

sdk/python/scripts · high confidence

Added macOS host-tunnel proof harness for ArcBox data plane

A new \tun\_proxy\ example has been added to the \virt/arcbox-net\ crate, providing a macOS-only proof harness that drives real host egress traffic through the ArcBox data plane stack (including \FrameClassifier\, \TcpBridge\, and \HostEgress\). This tool opens a \utun\ interface and forwards TCP traffic to an upstream SOCKS5 proxy, demonstrating that the same stack used by the VM datapath can power a host-level proxy. It is intended for experimental verification rather than production use, requiring root privileges and offering best-effort writes without backpressure.

virt/arcbox-net/examples · high confidence

Added macOS-specific VM boot and performance benchmarking tools

Two new command-line binaries, \arcbox-boot\ and \arcbox-perf\, are now available for macOS to manage and evaluate Linux virtual machines. \arcbox-boot\ allows users to start a VM with configurable resources (vCPUs, memory), kernel/initrd paths, and optional features like NAT networking, vsock, and VirtioFS sharing. \arcbox-perf\ provides a benchmarking tool that measures and reports the timing of hypervisor initialization, VM creation, console setup, and total boot time, comparing results against defined performance targets.

virt/arcbox-hypervisor/src/bin · high confidence

Automatic container domain routing and HTTPS termination

The agent now automatically maps container domains (e.g., \http://web.arcbox.local\) to running containers by detecting their listening ports and installing iptables DNAT rules to redirect port 80. It intelligently selects the HTTP port using a \dev.arcbox.http-port\ label, the container's exposed ports, or the lowest listening port, while ignoring port 443 to preserve TLS. Additionally, if a local CA is available, the agent terminates TLS for HTTPS traffic by redirecting port 443 to an internal proxy that presents a locally signed certificate and relays plaintext to the container. The system also includes a scanning mechanism that retries port detection for up to two minutes after a container starts to accommodate slow server bindings.

guest/arcbox-agent/src/domains · high confidence

Docker API compatibility layer with smart proxy and host networking reconciliation

ArcBox now provides a Docker Engine API compatibility layer that routes requests to a guest dockerd via a smart proxy. The server strips Docker API version prefixes (e.g., /v1.51/) to support any version, handles container lifecycle operations locally, and proxies the rest. On macOS, bind-mount paths are automatically rewritten to resolve symlinks (e.g., /tmp → /private/tmp) so they land on the VirtioFS share. A background reconciler periodically checks the guest's running container set and tears down host port-forwarding and DNS entries for containers that have stopped without an explicit API call, preventing resource leaks. Workload routing is centralized: arm64 workloads run natively, while amd64 workloads are routed to the HV utility VM via FEX translation, with VZ/Rosetta removed from the runtime path.

app/arcbox-docker/src · high confidence

E2B-compatible sandbox API surface for Python and TypeScript

The \arcbox.e2b\ (Python) and \@arcbox/sandbox/e2b\ (TypeScript) modules now provide an API surface compatible with the E2B SDK, allowing users to swap imports from \e2b\ to \arcbox.e2b\ while keeping their code. This surface exposes synchronous and asynchronous versions of \Sandbox\, \Commands\, \Filesystem\, \Git\, and \Pty\, backed by the local ArcBox daemon. Features include sandbox lifecycle management (create, connect, list, pause, kill), file operations, command execution with output streaming, and git operations. Unsupported E2B features like fork, volumes, signed URLs, metrics, MCP, and template build DSL raise \UnsupportedException\. Cloud-specific arguments (e.g., \api\_key\) are accepted but ignored, as authentication is handled by the local daemon via socket permissions.

sdk/python/src/arcbox/e2b, sdk/typescript/src/e2b · high confidence

Embedded Claude Code sandbox template and improved CLI error handling

The CLI now includes a built-in sandbox image template for Claude Code, allowing users to launch the agent without manually providing a Dockerfile. This template is built on Node.js 22 and includes necessary tools like git and ripgrep. Additionally, the CLI now provides actionable error messages for machine, sandbox, and snapshot operations, guiding users on how to resolve common issues like missing resources or unavailable services.

app/arcbox-cli/src · high confidence

Enhanced machine exec with flow control, debug shells, and TCP relay

The machine exec subsystem now supports flow-controlled sessions, ensuring output and stdin are managed within host-defined windows to prevent connection stalls. It introduces a debug shell capability that enters a container's namespaces (network, IPC, UTS, PID) and mounts fresh procfs/sysfs views using the agent's local busybox, allowing debugging of shell-less images without external dependencies. Additionally, exec requests can now be run as sshd-style login sessions, and the agent can relay TCP connections initiated from inside the machine, carrying both directions of data and half-closes through the same flow-controlled session loop.

_guest/arcbox-agent/src/agent/linux/machine\exec · high confidence

Explicit guest egress proxy policy and host environment detection

The \arcbox-fakeip\ crate now provides the core logic for explicit guest egress proxy configuration, replacing the previous behavior where the guest unconditionally inherited the host's system proxy. It introduces a \ProxyPolicy\ enum allowing operators to choose between \system\ (follow host settings), \none\ (direct connection), or a \custom\ proxy URL (HTTP CONNECT or SOCKS5). The crate includes \proxy\_detect\ to identify the host's current proxy/VPN environment (including Fake-IP ranges on macOS) and \dns\_log\ to map resolved IP addresses back to domain names, enabling the TCP bridge to tunnel by hostname rather than virtual IP.

common/arcbox-fakeip · high confidence

Extracted lock-free datapath primitives into a shared crate

The \arcbox-datapath\ crate has been introduced to provide reusable, high-performance networking primitives extracted from \arcbox-net\. This new library exposes a lock-free SPSC ring buffer (\LockFreeRing\) for zero-lock packet passing, a pre-allocated \PacketPool\ with O(1) allocation to avoid system malloc overhead, and a \FrameBuf\ type that manages buffer ownership via the pool or heap fallback. It also includes cache-line-aligned \DatapathStats\ for tracking TX/RX/NAT metrics without false sharing, along with utility functions for cache padding and software prefetching. This change centralizes these low-level components for reuse across host-side proxies and VM datapaths.

common/arcbox-datapath · high confidence

Extracted standalone NAT engine into arcbox-conntrack crate

The NAT engine has been extracted from \arcbox-net\ into a new, reusable \arcbox-conntrack\ crate, enabling non-VM consumers to utilize the same high-performance NAT datapath. This crate provides stateful connection tracking using Swiss Tables for O(1) lookups, zero-copy in-place packet translation for SNAT and DNAT with incremental checksums, and a \HostNetIO\ trait to abstract host-side network I/O mechanisms such as utun or TAP devices.

common/arcbox-conntrack · high confidence

Generated Python protobuf types for sandbox v1 API

The SDK now includes generated Python protocol buffer code for the \arcbox/sandbox/v1\ API, enabling type-safe interaction with sandbox services. This adds wire types for core sandbox operations (create, inspect, list, pause, resume, stop, remove), process management (start, attach, signal, wait, list executions), and filesystem access (read, write, stat, list, watch). It also introduces specific capabilities such as exposing and listing sandbox ports, watching sandbox lifecycle events (including a new monotonic sequence number on events), and handling nested virtualization support.

_sdk/python/src/arcbox/\gen · high confidence

Generated Rust bindings for the new Sandbox API and core protocol types

The generated protocol buffer code now includes the full Rust types for the new Sandbox API (arcbox.sandbox.v1), exposing capabilities for sandbox lifecycle management (create, stop, remove), resource limits, network configuration, and execution control. Additionally, the core arcbox.v1 module has been regenerated to include updated common types such as Mount, PortBinding, and ResourceLimits, along with network management services (create, list, inspect) and Kubernetes support, ensuring the client and server implementations have the latest contract definitions for these areas.

rpc/arcbox-protocol/src/generated · high confidence

Generated TypeScript SDK types for the sandbox v1 API

The TypeScript SDK now includes generated protocol-buffer types for the sandbox v1 API, covering the control plane (sandbox lifecycle, port exposure, events), data plane (filesystem and process operations), and supporting services (templates, snapshots). These generated files provide the message schemas, enums, and service definitions that the SDK uses to communicate with the sandbox daemon.

sdk/typescript/src/gen · high confidence

Guest agent boot readiness, container filesystem browsing, and sandbox lifecycle testing

The guest agent now reliably signals when the guest OS has finished booting by installing a distro-agnostic sentinel hook (systemd, OpenRC, or sysvinit) that writes a boot-ID-matched file to /run, allowing the host to gate machine readiness until the guest is truly ready. Additionally, the agent can now resolve container filesystem layer paths via the containerd snapshots service and export running container rootfses over NFSv4, enabling users to browse live container contents at \~/ArcBox. To support these capabilities, the agent's VMM configuration has been split into runtime and adapter halves, and new end-to-end smoke tests have been added to verify sandbox creation, network isolation, and execution flows.

guest/arcbox-agent/src · high confidence

Hypervisor defaults, nested virtualization support, and snapshotting capabilities

The hypervisor now automatically sizes VMs based on the host: vCPU count defaults to the host's logical core count and memory defaults to half of host RAM (clamped to 512 MB–16 GB and aligned to 1 MiB), with Linux builds respecting cgroup memory limits. A new capability probe detects nested virtualization support, and the VM configuration now includes a \nested\_virt\ flag to enable it when required. Additionally, the hypervisor interface now supports VM and vCPU snapshots, dirty page tracking for memory, and device state serialization.

virt/arcbox-hypervisor/src · high confidence

Initial release of the @arcbox/sandbox TypeScript SDK

The TypeScript SDK for ArcBox sandboxes is now available as the \@arcbox/sandbox\ npm package, enabling developers to programmatically manage isolated microVMs via the local daemon's Unix socket. The SDK provides a comprehensive API for sandbox lifecycle management (create, connect, kill, pause, info), command execution with foreground results and background streaming handles, file system operations, and event listening. It includes an E2B-compatible surface (\@arcbox/sandbox/e2b\) to allow existing E2B code to run against the local ArcBox daemon with minimal changes, handling behavioral differences such as port exposure requirements and timeout semantics. The package is built with Bunchee, uses Biome for formatting, and requires Node.js 22 or later.

sdk/typescript · high confidence

Initial release of the ArcBox gRPC protocol definitions

This change introduces the complete set of Protocol Buffer definitions for the ArcBox daemon and agent communication. It establishes the public API surface via \api.proto\ (covering Network, System, and Setup status services) and the internal guest agent contract via \agent.proto\ (providing health checks, runtime management, and resource monitoring streams). The schema also defines core domain services for managing container lifecycles (\container.proto\), image operations (\image.proto\), Kubernetes clusters (\kubernetes.proto\), and Linux virtual machines (\machine.proto\). Additionally, it adds a dedicated \macos.proto\ service for managing macOS guest VMs on Apple Silicon, a \stats.proto\ service for streaming machine resource samples, and \common.proto\ for shared types. The \buf.yaml\ configuration splits these into a public sandbox module and an internal daemon module, enforcing a breaking-change gate for the public contract.

rpc/arcbox-protocol/proto · high confidence

Initial repository scaffolding and developer guidelines

The repository now includes foundational configuration and documentation files to support development workflows. A \.envrc\ file configures the \devenv\ tool for reproducible development environments, and a \.pre-commit-config.yaml\ file enforces code quality by running \cargo fmt\ and \cargo clippy\ with strict warning checks before commits. Additionally, \AGENTS.md\ provides comprehensive guidelines for coding agents and contributors, covering project structure, code standards, architecture principles, and release procedures, while \CONTRIBUTING.md\ offers a guide for building from source, including prerequisites and code signing instructions for macOS. A \.release-please-manifest.json\ file establishes the versioning structure for the main project and its SDK components.

(repo-wide) · high confidence

Introduce ArcBox DHCP server with IP pool management and lease handling

Adds a new lightweight DHCP server implementation for ArcBox, including an IP address pool allocator, packet parsing for DHCP messages (RFC 2131), and a server that manages the DISCOVER/OFFER/REQUEST/ACK flow. The server supports IP reservations by MAC address, tracks active leases with configurable durations (default 24 hours), and quarantines declined IPs for 5 minutes to prevent immediate re-allocation of conflicting addresses while preserving reservations on release.

virt/arcbox-dhcp · high confidence

Introduce ArcBox Docker context management

Users can now manage Docker CLI contexts for ArcBox integration. The new \DockerContextManager\ in the context module allows creating, enabling, and disabling an 'arcbox' Docker context that points to the ArcBox socket, while preserving other Docker configuration fields. It also supports setting ArcBox as the default context and restoring the previous default when disabling or removing the context, with comprehensive tests verifying idempotency, status reporting, and config preservation.

app/arcbox-docker/src/context · high confidence

Introduce ArcBox host tool management library

Added a new Rust library (\app/arcbox-docker-tools\) that handles the download, installation, and management of host-side binaries for ArcBox on macOS. The library parses pinned versions and SHA-256 checksums from \assets.lock\ for tools such as Docker CLI, \kubectl\, and \pstramp\, and installs them to \\~/.arcbox/runtime/bin/\. It supports installation from local app bundles or CDN downloads, verifies checksums, and handles architecture-specific artifacts for \arm64\ and \x86\_64\.

app/arcbox-docker-tools · high confidence

Introduce ArcBoxVZShim Swift package for Virtualization framework access

Added the ArcBoxVZShim Swift package, which provides a C ABI boundary for the Rust backend to interact with macOS Virtualization framework objects. This shim exposes functions to configure VM settings (CPU, memory, boot loaders, platforms), construct device configurations (storage, network, serial, socket, entropy, graphics, directory shares, VirtioFS), manage VM lifecycle (start, stop, pause, resume), handle macOS restore images and IPSW installation, and perform vsock connections.

virt/arcbox-vz/shim · high confidence

Introduce Firecracker VM driver adapter

Added the \arcbox-fc-driver\ crate, implementing the \VmDriver\ port for Firecracker. This adapter manages the Firecracker and jailer processes, handles VM lifecycle operations (boot, restore, checkpoint, shutdown), and supports staging files into the jailer's chroot. It includes robust orphan recovery via \Adopt\, which discovers and reconnects to existing Firecracker processes by PID and command-line identity, providing a killable handle even when the API socket is unreachable. The driver enforces path safety within the jail, supports vsock communication, and restricts checkpoint capabilities to jailed VMs to ensure correct disk path handling during restore.

virt/arcbox-fc-driver · high confidence

Introduce OCI runtime specification support and container runtime primitives

The \runtime/arcbox-oci\ crate now provides a complete implementation of the OCI Runtime Specification (version 1.2.0), enabling the platform to manage container bundles. This includes parsing and validating \config.json\ files, handling OCI bundle directories (root filesystems and configuration), and defining Linux-specific container settings such as namespaces, cgroup resource limits (CPU, memory, block I/O, PIDs), seccomp profiles, and device mappings. Additionally, the \runtime/arcbox-container\ crate introduces core container domain types, including container state management (created, running, exited, etc.), configuration structures for ports and volumes, and an exec manager for running commands inside containers via a guest VM agent.

runtime/arcbox-oci · high confidence

Introduce Python SDK for ArcBox sandboxes

The \sdk/python\ directory now contains the initial release of the ArcBox Python SDK (v0.1.2), providing both synchronous (\Sandbox\) and asynchronous (\AsyncSandbox\) interfaces to manage isolated microVMs via the local daemon's Unix socket. The SDK supports core operations including creating and connecting to sandboxes, running commands with output streaming, and managing files. It also includes an E2B-compatible surface (\arcbox.e2b\) to allow existing E2B code to run against the local ArcBox daemon with minimal changes. The package is built with \uv\, uses \httpx\ for transport, and enforces strict typing with \pyright\ and linting with \ruff\.

sdk/python · high confidence

Introduce Python SDK with typed error handling and connection resolution

The Python SDK now provides a structured error hierarchy and robust connection management. Users benefit from specific, typed exceptions (such as ConnectionFailedError, RequestTimeoutError, and SandboxNotFoundError) that replace generic transport errors, making debugging and error handling more precise. The SDK automatically resolves connection targets by prioritizing explicit options, then environment variables (ARCBOX\_API\_URL, ARCBOX\_SOCKET), and finally defaulting to the local Unix socket, ensuring seamless local development while supporting remote configurations.

sdk/python/src/arcbox · high confidence

Introduce TypeScript SDK for ArcBox sandbox management

The \@arcbox/sandbox\ TypeScript SDK is now available, providing a programmatic interface to manage isolated microVM sandboxes via the local ArcBox daemon. Users can create, connect to, and list sandboxes, run commands with support for PTY, stdin, and output re-attachment, and manage the sandbox filesystem (read, write, watch). The SDK also exposes port management (expose, unexpose, wait for port), template catalog operations (build, list, get), and snapshot/restore capabilities. Connection resolution supports both local Unix sockets and remote API URLs, with configurable timeouts and API key authentication.

sdk/typescript/src · high confidence

Introduce arcbox-hv crate for Apple Hypervisor.framework bindings

The new \arcbox-hv\ crate provides safe Rust bindings for Apple's Hypervisor.framework on ARM64 macOS, enabling the construction of custom virtual machines. It exposes core VMM capabilities including VM lifecycle management (\HvVm\), vCPU execution and register access (\HvVcpu\), guest physical memory mapping, and ARM64 VM exit parsing. It also includes optional GICv3 interrupt controller support (gated behind the \gic\ feature for macOS 15+), typed error handling for framework return codes, and strict thread-safety constraints to comply with the framework's requirements.

virt/arcbox-hv · high confidence

Introduce arcbox-transport crate for host/guest communication

The new \arcbox-transport\ crate provides the foundational transport abstractions for ArcBox host/guest communication, introducing \UnixTransport\ for Unix domain sockets and \VsockTransport\ for virtio-vsock endpoints. It includes platform-specific implementations for Linux (using \AF\_VSOCK\ sockets) and macOS (integrating with \Virtualization.framework\), along with a \BlockingVsockTransport\ for the hypervisor agent control plane. The crate also implements in-band half-close and flow-control mechanisms via \HalfCloseStream\ to ensure reliable Docker attach sessions and prevent connection stalls on macOS.

rpc/arcbox-transport · high confidence

Introduce arcbox-vmnet crate for macOS virtual networking

The new \arcbox-vmnet\ crate provides safe Rust bindings to Apple's \vmnet.framework\, enabling VMs on macOS to connect via shared (NAT), host-only, or bridged modes. It includes a high-level \Vmnet\ interface for configuration and lifecycle management, low-level FFI bindings, and an event-driven \VmnetRelay\ that bridges \vmnet\ to a socketpair consumed by \VZFileHandleNetworkDeviceAttachment\. The relay uses an event callback to drain packets to the guest without a polling thread, improving efficiency. The crate also exposes a structured \VmnetError\ type for configuration and I/O failures, and includes integration tests for the public API.

virt/arcbox-vmnet · high confidence

Introduce async Python SDK with generated sync surface

The Python SDK now provides a native async interface (arcbox.\_async) built on an httpx-based Connect-over-httpx transport, exposing sandbox lifecycle management (create, connect, list), command execution with PTY and stdin re-attach, file operations with directory watching, port exposure and readiness waiting, and a template catalog client. A synchronous surface (arcbox.\_sync) is automatically generated from this async core to maintain parity, ensuring both programming models share the same underlying behavior and error handling.

_sdk/python/src/arcbox/\async · high confidence

Introduce cross-platform fleet agent with Docker and VM job execution backends

The fleet agent now supports executing jobs on Linux via Docker containers and on macOS via disposable VMs, replacing the previous host-runner-only model. It manages a live registry of available backends (Docker, VM, WSL interop) to advertise capabilities to the gateway and route jobs accordingly. The agent handles credential persistence using the OS keychain on macOS or secure files on Linux, manages a durable gRPC connection to the gateway with automatic reconnection and self-update on version mismatch, and ensures jobs are isolated in containers or VMs with output captured to individual log files.

fleet/arcbox-fleet-agent/src · high confidence

Introduce fleet v1 protocol for agent enrollment, attachment, and job offer handling

This change adds the \fleet.proto\ definition for the \arcbox.fleet.v1\ service, establishing the contract for BYOC edge machine management. It defines the \FleetGatewayService\ with RPCs for \Enroll\ (exchanging a token for a credential, including version gating via \AgentUpdate\), \Attach\ (a bidirectional stream for heartbeats and telemetry), and \Unenroll\ (terminal removal). The protocol supports cross-platform capabilities (\darwin\/\linux\ on \arm64\/\amd64\ via host, Docker, or VM backends) and introduces an offer/reject mechanism where agents report \RunnerAccepted\ or \RunnerRejected\ verdicts for job assignments.

fleet/arcbox-fleet-proto/proto · high confidence

Introduce local Docker runtime migration from Docker Desktop and OrbStack to ArcBox

The \app/arcbox-migration\ crate now provides a complete local migration flow that discovers and imports Docker objects (images, volumes, networks, and containers) from supported source runtimes—Docker Desktop and OrbStack—into the ArcBox target environment. The implementation includes a \MigrationPlanner\ to inspect source and target daemons and build a normalized \MigrationPlan\, and a \MigrationExecutor\ to carry out the import and recreation steps (including handling image ID reassignment, volume blockers, and container replacement). Users can now migrate their existing local Docker workloads into ArcBox via the CLI.

app/arcbox-migration · high confidence

Introduce local control-plane API for fleet agent management

This change adds the \control.proto\ definition for a new local control-plane API served by the fleet agent on a Unix socket, enabling direct management of the agent via the CLI and desktop app. The API introduces \FleetLifecycleService\ for core operations including enrollment, draining/resuming job acceptance, unenrolling, and in-place process restarts, alongside status reporting via \GetStatus\ and \GetAgentInfo\. It also defines \FleetStateService\ to stream live state snapshots (such as connection status and backend capabilities) to clients, allowing them to react to changes like credential rejection or self-update transitions without maintaining local state.

fleet/arcbox-fleet-control-proto/proto · high confidence

Introduce local control-plane protocol for fleet agent communication

Added a new internal proto crate (\arcbox-fleet-control-proto\) that defines the local control-plane API used by the fleet agent. This crate generates Rust client and server stubs (via tonic/prost) for the \arcbox.fleet.control.v1\ package, enabling the \arcbox-fleet-agent\ CLI and desktop app to communicate with the agent service over a local Unix socket (\\~/.arcbox/fleet/agent.sock\). The protocol contract is locked to the \WIRE\_JSON\ breaking-change policy to ensure binary and JSON compatibility between independently updating desktop and agent components, while allowing safe source-level refactors.

fleet/arcbox-fleet-control-proto · high confidence

Introduce macOS guest support with copy-on-write image cloning and NAT networking

Added a new macOS guest subsystem for Apple Silicon hosts, enabling the creation of disposable macOS VMs via copy-on-write cloning of base system images. The system supports pulling pre-built macOS images from a remote CDN (darwin.arcboxcdn.com) using a chunked, integrity-verified streaming restore, as well as installing from local or latest Apple IPSW files (behind the macos-ipsw-install feature flag). Guests are configured with NAT networking, and their IP addresses are discovered via the host's DHCP lease table using pinned MAC addresses. The lifecycle enforces a maximum of two concurrently running macOS guests per host, with serialization of start/stop/remove operations to prevent race conditions.

app/arcbox-core/src/macos · high confidence

Introduce native Rust SDK for ArcBox sandboxes

The \sdk/rust\ directory now contains the initial release of the native Rust SDK (\arcbox\), providing a complete interface for managing isolated microVM sandboxes via the local daemon's Unix socket. This SDK introduces a new client entry point (\ArcBox\) and sandbox handle (\Sandbox\) that support full lifecycle management (create, connect, list, info, kill, pause, and set\_lifecycle), command execution (foreground \run\ and background \spawn\ with offset-idempotent stdin and output re-attachment), file operations (streamed read/write, stat, list, mkdir, remove, rename, and watch), port management (wait\_for\_port, expose, unexpose, list), and snapshot capabilities (checkpoint, restore, list, delete). It also exposes a typed event stream for sandbox lifecycle changes. The SDK uses the Connect protocol over HTTP/2, maps daemon errors to a structured \Error\ type with actionable suggestions, and resolves connection settings via environment variables (\ARCBOX\_SOCKET\, \ARCBOX\_DATA\_DIR\, \ARCBOX\_PROFILE\) or explicit configuration.

sdk/rust · high confidence

Introduce safe Rust bindings for Apple Virtualization.framework

The \virt/arcbox-vz/src\ module now provides a new, async-first Rust API for managing macOS virtual machines via Apple's Virtualization.framework. This change introduces a Swift-based C ABI shim (\ArcBoxVZShim\) to handle framework interaction, exposing safe Rust types for VM lifecycle management (start, stop, pause, resume), configuration (CPU, memory, boot loaders, platforms), and device setup (network, storage, graphics, VirtioFS, vsock). It also adds support for macOS-specific features, including restore image handling, the macOS installer, and vsock communication with guests.

virt/arcbox-vz/src · high confidence

Introduce shared asset download and verification library

The \common/arcbox-asset\ crate now provides a unified library for downloading, verifying, and caching binary assets. It ensures data integrity by streaming downloads with incremental SHA-256 verification and writes files atomically using unique temporary paths to prevent corruption during concurrent operations. The library exposes architecture detection (mapping \aarch64\ to \arm64\) and progress reporting, serving as the foundation for asset preparation in \arcbox-boot\ and \arcbox-docker-tools\.

common/arcbox-asset · high confidence

Introduce shared constants crate for ArcBox configuration

A new \common/arcbox-constants\ library centralizes configuration values previously scattered across the codebase. It defines kernel command-line keys for boot parameters (such as Docker vsock ports, network CIDRs, and debug console paths), validates container network address pools, and specifies guest device paths (e.g., \/dev/vda\, \/dev/vdb\). The crate also standardizes runtime paths for Docker and containerd, SSH relay ports, and the privileged helper binary location. Additionally, it introduces the \ArcboxProfile\ enum to distinguish between production and development environments, sets the agent RPC protocol version to 6, and enforces a minimum helper version of 1.1.0 to ensure wire compatibility.

common/arcbox-constants · high confidence

Introduce shared error handling types for ArcBox

The \common/arcbox-error\ crate now provides a unified \CommonError\ enum and associated result type, allowing other ArcBox components to handle standard scenarios like I/O failures, configuration issues, resource not found, and timeouts consistently. This centralization reduces code duplication and ensures that error messages and handling patterns remain uniform across the system.

common/arcbox-error · high confidence

Introduce standalone vm-agent crate and shared wire protocol

The \arcbox-vm-agent\ crate is extracted from \arcbox-vm\ to provide a standalone guest-side daemon (PID 1 in the sandbox microVM) that handles exec sessions, file I/O, and filesystem watching over vsock. This change introduces the \arcbox-vm-proto\ crate, which defines the shared wire vocabulary (frame formats, opcodes, and data types) for the exec, file, and boot channels, ensuring both the host manager and guest agent use the same contract. The agent now includes pure, host-testable helpers for parsing inotify events (with rename pairing), resolving Docker-style user specifications, and checking TCP listen tables, while the binary itself handles Linux-specific syscalls like vsock, pty, and clock synchronization via \ptp\_kvm\.

virt/arcbox-vm-agent · high confidence

Introduce the VM driver port crate for VMM abstraction

The \virt/arcbox-vm-driver/src\ directory now contains the new \arcbox-vm-driver\ crate, which defines the standard interface (port) between the ArcBox orchestrator and underlying Virtual Machine Monitors (VMMs). This crate introduces \VmDriver\ and \VmHandle\ traits to manage VM lifecycle (boot, restore, shutdown) and exposes optional capabilities—such as vsock communication, checkpointing, file staging, and network attachment—through capability accessors. It also defines the serializable \VmSpec\ for VM configuration and the \GuestNetwork\ trait for managing host-side network resources like TAP interfaces and IP leases, effectively decoupling the orchestrator from specific VMM implementations like Firecracker or Virtualization.framework.

virt/arcbox-vm-driver/src · high confidence

Introduce unified logging infrastructure with size-based rotation and structured output

The \common/arcbox-logging\ crate now provides a centralized logging system that writes machine-parseable JSON logs to rotating files (defaulting to 10 MB per file, keeping 5 backups) and optional human-readable logs to stderr when running in the foreground. It initializes the \tracing\ subscriber with configurable filters, supports Sentry integration via a feature flag, and ensures log data is flushed on shutdown via a returned \LogGuard\.

common/arcbox-logging · high confidence

Introduces a local certificate authority for container TLS

The \arcbox-local-ca\ crate now provides the infrastructure to generate a local Certificate Authority (CA) and mint short-lived TLS certificates for container domains. The CA is created once in the data directory with name constraints limiting it to the \arcbox.local\ domain, and a \LeafMinter\ component dynamically signs certificates on demand for specific server names, caching them for up to 30 days to support secure HTTPS access to containers via \https://\<name\>.arcbox.local\.

common/arcbox-local-ca · high confidence

Introduces generated Rust client stubs for the Fleet gateway protocol

The \arcbox-fleet-proto\ crate now provides the generated Rust code for the Fleet gateway contract, exposing the \FleetGatewayService\ with \Enroll\ and \Attach\ RPCs to agents. This change establishes the vendored protocol definition and build infrastructure (using \tonic-prost-build\) required for agents to communicate with the gateway, while intentionally excluding the internal dispatch service which remains in the platform's unpublished module.

fleet/arcbox-fleet-proto · high confidence

Introduction of ArcBox Protocol definition crate

The \rpc/arcbox-protocol\ crate has been added to provide the canonical Protocol Buffer message and service definitions for ArcBox. This new component generates Rust types from a comprehensive set of \.proto\ files covering common types, machine and container lifecycles, image management, agent health, API operations, Kubernetes support, and sandbox-specific resources (processes, filesystems, snapshots, templates, and errors). The crate enforces a strict separation between the protocol layer and data serialization by excluding serde derives from the generated code, ensuring that persisted JSON formats remain decoupled from the protobuf schema evolution.

rpc/arcbox-protocol · high confidence

Kubernetes LoadBalancer port forwarding and guest runtime validation

The runtime now validates that all required guest binaries (agent and runtime assets) are present and executable before starting the System VM, failing fast with clear instructions if they are missing. It also introduces host-side listeners that automatically forward ports from Kubernetes Services of type LoadBalancer, allowing users to access cluster services directly from the host. Additionally, operators can now configure the guest Docker daemon via \config.toml\ overrides, which are staged and merged into the guest's \daemon.json\ at boot.

app/arcbox-core/src/runtime · high confidence

Linux guest agent implementation with Btrfs storage, Kubernetes, and exec support

The Linux guest agent now handles vsock RPCs to manage the guest environment, including starting and stopping a single-node Kubernetes cluster, executing commands in the guest or inside containers, and reclaiming disk space via FITRIM. It formats the data disk as Btrfs with dedicated subvolumes for Docker, containerd, and sandboxes, and mounts a separate ext4 volume for fsync-heavy metadata to improve performance.

guest/arcbox-agent/src/agent/linux · high confidence

Local gRPC control-plane API for agent management

The agent now exposes a local Unix-socket gRPC server (agent.sock) that allows the CLI and desktop app to manage the agent's lifecycle and configuration while it runs. This new API supports enrolling, draining, resuming, and unenrolling the machine, as well as updating settings like gateway, runner images, and VM mode. It also provides a streaming state watch for real-time status updates and a dedicated service to prepare and pull runner images (Linux and macOS) with progress reporting. This replaces the previous fixed, credential-required-at-startup enrollment process with a flexible state machine.

fleet/arcbox-fleet-agent/src/control · high confidence

New CLI commands for diagnostics, debugging, and disk management

The \abctl\ CLI now includes several new commands to improve operational visibility and maintenance. The \abctl doctor\ command runs end-to-end health checks on the daemon, Docker context, and shell integration, reporting pass/fail status with repair instructions. The \abctl debug \<container\>\ command opens an interactive shell inside a target container's namespaces, using the guest agent's busybox to ensure compatibility even with shell-less images. Disk management is enhanced with \abctl disk usage\ to inspect the Docker data disk's logical vs. physical allocation, and \abctl disk compact\ to manually trigger a trim of free blocks for immediate space reclamation.

app/arcbox-cli/src/commands · high confidence

New HV backend for macOS with manual vCPU execution and full VirtIO emulation

The macOS virtual machine manager now supports a custom Hypervisor.framework backend (darwin\_hv) as an alternative to the VZ framework managed-execution path. This backend provides manual vCPU execution, giving the VMM full control over VirtIO device emulation, including the ability to negotiate TCP Segmentation Offload (TSO) and handle VirtIO-net headers in userspace. The implementation includes a complete lifecycle for vCPU threads (with PSCI CPU\_ON/OFF support), a PL011 UART emulator for early boot console logging, a PL031 RTC for guest timekeeping, and an HVC fast-path for block I/O that allows direct pread/pwrite/fsync operations against backing files, including support for punching DISCARD ranges to shrink sparse images. Network connectivity is established via socketpairs bridging to the existing NetworkDatapath, and guest RAM is managed with stage-2 mapping refreshes to handle page reclamation.

_virt/arcbox-vmm/src/vmm/darwin\hv · high confidence

New PTY primitives crate for interactive sessions

A new \arcbox-pty\ crate has been added to provide shared primitives for interactive machine sessions. It implements Linux-specific PTY allocation, window resizing, and a secure privilege-dropping sequence (setsid, TIOCSCTTY, fd duplication, and credential drop) to establish a controlling terminal for child processes. This enables consistent, secure interactive exec capabilities across the sandbox microVM agent and the machine-level agent.

common/arcbox-pty · high confidence

New SSH server for direct machine access

The daemon now includes an SSH server that allows you to connect directly to your machines using standard SSH clients. It generates and manages its own host and client keys, and writes an OpenSSH client configuration file to simplify authentication and host key pinning. The server supports shell and command execution sessions, SFTP file transfers, and TCP port forwarding (local tunnels), while correctly handling terminal sizes, environment variables, and process signals.

app/arcbox-ssh/src · high confidence

New VMM boot examples for HV and default backends

Added two new example programs in the \virt/arcbox-vmm/examples\ directory: \hv\_boot\_test.rs\ and \vmm\_boot.rs\. The \hv\_boot\_test\ example demonstrates an end-to-end boot sequence using the custom Hypervisor.framework backend (\VmBackend::Hv\), including loading a kernel and rootfs block device, monitoring serial output, and performing a clean shutdown. The \vmm\_boot\ example provides a simpler demonstration of the VMM layer using the default backend, loading a kernel and optional initrd, and monitoring VM state. These examples serve as reference implementations for configuring and running the VMM with different backends and boot configurations.

virt/arcbox-vmm/examples · high confidence

New VMM module with dual macOS backend support (HV and VZ)

The \virt/arcbox-vmm\ module introduces a new Virtual Machine Monitor implementation that supports both Apple's Virtualization.framework (VZ) and Hypervisor.framework (HV) backends on macOS, alongside a KVM-based path for Linux. Users can now select the backend via the \VmBackend\ configuration enum, enabling features like Rosetta 2 translation (VZ), nested virtualization (VZ), and a custom HV path with manual vCPU execution. The module also adds support for VirtioFS shared directories, memory balloon devices, vsock communication, and a debug console socket for the HV backend.

virt/arcbox-vmm/src/vmm · high confidence

New \`check-layers\` cargo command enforces workspace dependency rules

Developers can now run \cargo xtask check-layers\ to validate that the workspace's direct dependency edges comply with architectural layer rules (e.g., ensuring the engine and computer layers remain daemon-free and do not depend on app-layer crates). The command reads the \cargo metadata\ graph, checks it against a defined set of rules and grandfathered exceptions, and fails the build if any violations or stale exceptions are detected, helping to maintain strict separation between architectural layers.

xtask/src · high confidence

New arcbox-grpc crate for gRPC service bindings

The \rpc/arcbox-grpc\ crate has been introduced to provide tonic-generated gRPC client and server implementations for ArcBox services. It exposes clients and servers for Machine, Macos, Agent, Migration, Volume, Icon, and System services, alongside a split control-plane/data-plane set for Sandbox operations (Sandbox, Template, Process, Filesystem, and Snapshot services). The crate re-exports these services and the underlying \arcbox\_protocol\ and \tonic\ dependencies for convenient consumption by other parts of the system.

rpc/arcbox-grpc · high confidence

New arcbox-packet crate with SIMD-optimized checksums and Ethernet frame construction

The \common/arcbox-packet\ crate has been introduced to provide zero-copy packet primitives and high-performance network utilities extracted from the \arcbox-net\ stack. This new module delivers a \checksum\ implementation that automatically uses SIMD (NEON on AArch64, SSSE3 on x86\_64) for payloads exceeding 64 bytes, significantly accelerating Internet checksum calculations for IP, TCP, and UDP. It also includes a comprehensive \ethernet\ module for constructing and parsing L2 frames, featuring an ARP responder for gateway replies, and dedicated builders for TCP (ACK, data, GSO partial checksum) and UDP frames (including automatic IPv4 fragmentation for payloads exceeding the link MTU). A \packet\ module provides zero-copy packet structures and pre-parsed metadata for fast-path processing, while an example benchmark (\checksum\_bench\) is included to validate the performance gains of the SIMD path over scalar implementations.

common/arcbox-packet · high confidence

New atomic file write primitive with differentiated durability errors

The \common/arcbox-atomic-file\ crate introduces a durable atomic write function that replaces a destination file via a temporary sibling, \fsync\, and directory \fsync\. This ensures readers never see truncated content and provides two distinct error types: \NotCommitted\ (the write failed before replacement) and \DurabilityUncertain\ (the new content is visible but its survival across a power loss is unconfirmed), allowing callers to handle these scenarios differently.

common/arcbox-atomic-file · high confidence

New batch datagram I/O API for reduced syscall overhead

The \arcbox-xnu-net\ crate now exposes \BatchDgram\ and \AsyncBatchDgram\ to send and receive multiple datagrams in a single system call, reducing overhead for high-throughput workloads like L2 Ethernet frames over \AF\_UNIX SOCK\_DGRAM\. On macOS, this uses \recvmsg\_x\/\sendmsg\_x\, and on Linux, \recvmmsg\/\sendmmsg\. The API automatically clamps batch sizes to the live kernel limits (e.g., \kern.ipc.maxrecvmsgx\ on macOS) and handles non-blocking readiness via \WouldBlock\ retries. An async variant is available behind the \tokio\ feature, integrating with \tokio::io::AsyncFd\ for readiness-based polling.

common/arcbox-xnu-net · high confidence

New boot asset management commands for caching and status

The CLI now includes a new \boot\ command group with subcommands to manage boot assets: \prefetch\ downloads and caches boot assets and runtime binaries (with optional force re-download and version selection), \status\ reports the integrity and completeness of cached assets including manifest and binary verification, \clear\ removes cached boot assets, and \list\ shows available cached versions. These commands provide users with explicit control over the boot asset lifecycle, allowing them to pre-fetch assets for offline use, verify cache integrity, and manage storage.

app/arcbox-cli/src/commands/boot · high confidence

New configuration API for Linux and macOS virtual machines

The \virt/arcbox-vz\ configuration module now exposes a structured API for defining virtual machine settings, introducing dedicated types for boot loaders (\LinuxBootLoader\, \MacOSBootLoader\) and platform configurations (\GenericPlatform\, \MacPlatform\). Users can now configure macOS guests by specifying hardware models, machine identifiers, and auxiliary storage, while Linux guests can be set up with direct kernel booting and initrd support. The \VirtualMachineConfiguration\ builder allows setting CPU/memory limits, attaching various devices (storage, network, graphics, serial, etc.), and validating the setup before launching the virtual machine.

virt/arcbox-vz/src/configuration · high confidence

New dedicated I/O workers and DAX mapper for the HV backend

The VMM now uses dedicated background threads for block, network, vsock, and console I/O instead of processing them on the vCPU run loop, which prevents host-to-guest data paths from stalling while the guest is idle. It also introduces a Hypervisor.framework-backed DAX mapper that maps host file pages into the guest's DAX window, enabling VirtioFS direct access. Additionally, the builder now defaults vCPU count and memory size to the hypervisor's platform defaults, and exposes per-vCPU exit counters and VM debug snapshots for observability.

virt/arcbox-vmm/src · high confidence

New device configuration types for macOS Virtualization

The device module now exposes configuration structs for several virtual hardware components, allowing users to attach a memory balloon device, an entropy (random number) generator, a VirtioFS filesystem share, a macOS graphics display, a serial console port, a vsock socket, and a block storage disk image to the virtual machine.

virt/arcbox-vz/src/device · high confidence

New host-socket egress proxy for UDP and ICMP traffic

The proxy now routes guest UDP and ICMP packets directly through host sockets instead of relying on kernel routing or NAT interfaces. This new egress module handles ICMP echo requests and replies (including macOS-specific identifier restoration) and manages per-flow UDP connections, which can optionally be routed through a SOCKS5 proxy. This change bypasses kernel routing issues, VPN interference, and pf configuration problems for outbound guest traffic.

common/arcbox-proxy/src/egress · high confidence

New local development and installation tooling for the ArcBox daemon

Developers and users now have dedicated scripts to streamline daemon management and installation. A new \dev-daemon.sh\ harness allows developers to build, run, and verify the daemon directly against the current code checkout, including a cold-boot reliability loop and automatic crash symbolication, ensuring the correct binary is tested. A \dev.arcbox.daemon.plist\ provides a launchd configuration for running the daemon as a user agent with a 45-second shutdown timeout to preserve the full VM stop budget. Additionally, a new \install.sh\ script enables one-line installation of the \abctl\ CLI and \arcbox-daemon\ binaries with automatic version resolution, architecture detection, and codesigning for macOS 12+, while a \docker-cli-e2e.sh\ script facilitates end-to-end testing of Docker CLI compatibility against the daemon.

scripts · high confidence

New macOS and Linux virtualization examples for arcbox-vz

Added a suite of diagnostic and demonstration examples for the arcbox-vz crate. For macOS, the new examples cover the full lifecycle: \macos\_validate\ (Gate A) verifies VM configuration validity, \macos\_probe\ tests fast boot from metadata, \macos\_install\ (Gate B) performs a full OS installation from an IPSW, \macos\_clone\_boot\ verifies copy-on-write disk cloning, and \macos\_latest\_url\ retrieves the latest restore image URL. For Linux, \simple\_vm\ demonstrates basic kernel booting, \virtiofs\ shows directory sharing between host and guest, and \vsock\_echo\ tests socket communication with a guest service.

virt/arcbox-vz/examples · high confidence

New modular VirtIO console device with multiple I/O backends

The \virt/arcbox-virtio-console\ crate now provides a fully implemented VirtIO console device (\VirtioConsole\) that supports multiple I/O backends via a unified \ConsoleIo\ trait. Users can connect the guest console to standard I/O (\StdioConsole\), a testable buffer (\BufferConsole\), a real terminal via pseudo-terminals on Unix (\PtyConsole\), or a Unix socket for remote access (\SocketConsole\). The device handles multiport configuration, manages TX/RX queues, and ensures thread-safe PTY allocation to prevent race conditions on macOS.

virt/arcbox-virtio-console · high confidence

New modular network stack with cross-platform backends and DNS/mDNS features

The \arcbox-net\ crate has been restructured into a modular network stack that provides NAT, bridge, and host-only networking modes. It introduces platform-specific network backends: a TAP device implementation for Linux and a vmnet wrapper for macOS, both conforming to a unified \NetworkBackend\ trait. The stack now includes a built-in DNS forwarder that supports local hostname resolution, configurable upstream servers, and a shared hosts table, along with an mDNS responder for multicast-based discovery. Networking capabilities are further extended with a DHCP server, a NAT engine for address translation, a TCP/UDP port forwarding service, and a unified timer wheel for efficient flow timeout management.

virt/arcbox-net/src · high confidence

New proxy crate with SOCKS5/HTTP CONNECT egress and L2 inbound relay

The \arcbox-proxy\ crate introduces dedicated modules for host-level proxying and inbound traffic handling. It adds SOCKS5 and HTTP CONNECT clients to tunnel TCP and UDP traffic through upstream proxies, ensuring hostnames are resolved by the proxy to support fake-IP environments. Additionally, it implements an inbound relay that forwards host-to-guest connections by injecting crafted L2 Ethernet frames directly into the guest's network interface, bypassing kernel routing.

common/arcbox-proxy/src · high confidence

New sandbox API protocol definitions

The sandbox control and data planes are now defined in the \arcbox/sandbox/v1\ proto package, introducing a structured API for managing sandbox lifecycles, executing processes, and handling filesystem operations. The \sandbox.proto\ file establishes the control plane, defining the sandbox state machine (STARTING, READY, RUNNING, PAUSED, etc.) and lifecycle RPCs such as Create, Pause, Resume, and SetLifecycle. The \process.proto\ file introduces the data plane for addressable, resumable executions, allowing clients to start, attach to, and manage process I/O (stdin/stdout) with offset-based reconnection support. The \filesystem.proto\ file adds a data-plane service for file transfers and path operations (ReadFile, WriteFile, Stat, ListDir, etc.) within the sandbox. Additionally, \errors.proto\ provides a centralized error registry with machine-readable codes and actionable suggestions, while \template.proto\ defines a first-class template catalog for versioned, reproducible sandbox bases. The \snapshot.proto\ file supports checkpoint and restore functionality for cold-start optimization.

rpc/arcbox-protocol/proto/arcbox · high confidence

New shared DNS packet parsing and response building library

The \common/arcbox-dns\ crate introduces a platform-independent, no-std-compatible library for parsing DNS queries and constructing responses, designed for use by both host-side and VMM-side DNS forwarders. It provides utilities to parse raw DNS query bytes into structured \DnsQuery\ objects and includes functions to build specific response packets, such as A/AAAA records with configurable TTLs, NXDOMAIN responses, and SERVFAIL responses. The library also defines a shared local-hosts table type and standard DNS constants (port 53, default TTL 300s), along with comprehensive integration tests validating query parsing, response construction, and error handling for unsupported types or truncated packets.

common/arcbox-dns · high confidence

New shell integration setup and management commands

The CLI now includes a \setup\ command group that allows users to install, uninstall, and check the status of shell integration. This feature automatically configures the user's shell environment by creating a symlink for the \abctl\ binary, injecting profile initialization scripts for Zsh, Bash, and Fish, and generating shell completion files. It also handles the registration of Docker CLI plugins and cleans up stale links from previous versions during installation.

app/arcbox-cli/src/commands/setup · high confidence

New snapshot engine crate for checkpoint and template management

The \engine/arcbox-snapshot\ crate introduces the core engine-layer logic for managing VM snapshots and sandbox templates. It provides a snapshot catalog for storing and retrieving checkpoint metadata (including full and diff types, geometry, and labels), a copy-on-write (CoW) rootfs manager that uses device-mapper snapshots to share read-only template images across sandboxes efficiently, and a versioned template catalog for building, publishing, and resolving sandbox base images with optional pre-warmed snapshots. The implementation includes robust error handling, durable file operations, and support for both busybox and util-linux block-device tooling.

engine/arcbox-snapshot/src · high confidence

New snapshot manager for VMs and containers

The snapshot subsystem has been restructured into a dedicated module with a new SnapshotManager that handles lifecycle operations (create, list, delete, prune) for both virtual machines and containers. The manager persists metadata to disk and supports optional LZ4 compression for memory dumps. VM snapshots now require an explicit context (vCPU, device, and memory state) to capture real state, while container snapshots use CRIU on Linux when the \criu\ feature is enabled, falling back to a placeholder checkpoint otherwise.

virt/arcbox-vmm/src/snapshot · high confidence

New splicetcp crate for userspace TCP termination and frame classification

The \common/splicetcp\ crate introduces a modular, userspace TCP termination shim and frame plane for the ArcBox datapath. It provides a \FrameClassifier\ to demultiplex inbound Ethernet frames (ARP, TCP, UDP, ICMP, DHCP, DNS) and a \TcpBridge\ for fast-path data plane handling without a full userspace TCP stack. The crate includes a \FragmentReassembler\ to handle guest-originated IPv4 fragments, an \EgressResolver\ trait with a \DefaultEgress\ implementation for system-proxy-aware outbound connections, and a \FlowObserver\ seam for per-flow byte accounting. Ingest is handled via pluggable \FrameSource\ implementations (including batched reads via \recvmsg\_x\ on macOS) and egress via \FrameSink\ traits, with an L3-to-L2 shim to support \utun\ interfaces.

common/splicetcp/src · high confidence

New virtio-net backend crate for NAT and TSO network paths

A new \arcbox-net-virtio\ crate has been introduced to provide the concrete implementations of the \NetBackend\ trait for the ArcBox virtualization environment. This crate decouples the device-model dependency from the core networking layer by hosting two specific backends: a NAT backend (\NatNetBackend\) that routes guest traffic through the connection tracking engine for address translation, and a TSO backend (\TsoNetBackend\) that offloads large TCP segments directly to host TCP streams for high-throughput forwarding while falling back to a slow path for other protocols.

virt/arcbox-net-virtio · high confidence

Privileged helper daemon for host mutations

A new privileged helper daemon (arcbox-helper) is introduced to manage sensitive host-level operations, including network routing, DNS resolver installation, /etc/hosts alias management, and symlink creation for Docker CLI tools. The helper runs as a root launchd daemon with socket activation and enforces strict peer authentication (code signature and Team ID verification) before processing any requests. It exposes a structured RPC interface via tarpc with bincode serialization, ensuring wire compatibility through append-only error variants and version checks. The daemon supports an idle-exit mode to automatically shut down after 30 seconds of inactivity, reducing its persistent footprint while remaining available for on-demand operations.

app/arcbox-helper/src · high confidence

Replaces smoltcp-based TCP stack with a custom TCP bridge shim

The \splicetcp\ component now uses a hand-rolled TCP bridge (\TcpBridge\) instead of the previous \smoltcp\-based implementation. This new shim handles TCP frame parsing, handshake synthesis (SYN/SYN-ACK/ACK), and fast-path data forwarding between the guest and host. It introduces specific behaviors for upload and download flows, including lossless uploads by ACKing only bytes successfully written to the host socket, and download-side congestion control by honoring the guest's advertised receive window and buffering for retransmission. The bridge also includes validation for IPv4 IHL and TCP data offsets, bounds for out-of-order segments, and timeouts for dead and half-closed flows to prevent resource leaks.

_common/splicetcp/src/tcp\bridge · high confidence

Sandbox agent protocol v1 with addressable executions, file I/O, and template catalog support

The guest agent's sandbox module has been rewritten to implement the \sandbox.v1\ protocol, introducing addressable executions (start, attach, stdin, wait) and streaming file I/O (read, write, stat, list, mkdir) that allow direct interaction with sandbox contents. It also adds a template catalog system supporting builds from Docker references, inline Dockerfiles, or existing snapshots, along with lifecycle event streaming and checkpoint/restore operations. All guest-to-host streams are now flow-controlled via a host-managed window to prevent backpressure issues over vsock.

guest/arcbox-agent/src/sandbox · high confidence

Sandbox lifecycle protocols and host-seam abstraction introduced

The \arcbox-computer\ crate now provides the core domain logic for sandbox management, introducing a \SandboxHost\ trait that abstracts host-side services (DNS, port binding, state generation) from the protocol implementations. This enables transparent resume for paused sandboxes (auto-resuming on data-plane errors), durable network cleanup via a background watch stream, and robust port-exposure handling with rollback on race conditions. It also adds a \NestedVirtCapability\ check to fail fast with actionable reasons if nested virtualization is unsupported, and per-sandbox operation locks to serialize concurrent lifecycle mutations.

computer/arcbox-computer · high confidence

VirtIO block device now supports DISCARD and WRITE\_ZEROES operations

The VirtIO block device implementation in this crate now handles DISCARD and WRITE\_ZEROES requests from the guest. This is enabled by new wire types in \request.rs\ (including \BlockRequestType::Discard\ and \WRITE\_ZEROES\_FLAG\_UNMAP\), a shared \punch.rs\ module that implements sparse-file zeroing and hole-punching for Linux and macOS, and a new \AsyncBlockBackend\ trait in \backend.rs\ that allows backends like \DirectIoBackend\ and \MmapBackend\ to support these operations. Users can now benefit from space reclamation and efficient zeroing in their virtual disks.

virt/arcbox-virtio-blk/src · high confidence

VirtIO-FS device implementation with FUSE protocol support

The \virt/arcbox-virtio-fs/src/device\ module now provides the core VirtIO-FS device implementation, enabling high-performance file sharing between the host and guest via the FUSE protocol. This change introduces the \VirtioFs\ struct and its configuration (\FsConfig\), handling the full device lifecycle including activation, reset, and configuration space reads (tag, queue count). It implements the \VirtioDevice\ trait to manage virtqueues, processing FUSE requests such as INIT and DESTROY handshakes, and delegating standard file operations to a pluggable \FuseRequestHandler\. The implementation supports multiple request queues and includes logic to parallelize normal FUSE requests when safe, while ensuring sequential processing for control operations to maintain ring ordering.

virt/arcbox-virtio-fs/src/device · high confidence

VirtioFS server refactored with DAX support and adaptive caching

The \virt/arcbox-fs/src\ module has been restructured into a new modular architecture (cache, dispatcher, error, fuse, passthrough, server) to support end-to-end VirtioFS DAX (Direct Access) and improved performance. The server now exposes a \DaxMapper\ trait and integrates a \FuseDispatcher\ that handles FUSE protocol version 7.38, including \SetupMapping\ and \RemoveMapping\ opcodes for zero-copy guest memory mapping. Caching behavior has been enhanced with configurable \CacheProfile\ presets (Static, Dynamic, Custom) for entry/attribute timeouts and a new \NegativeCache\ with adaptive TTL rules for stable paths like \node\_modules\ and \.git\. Additionally, the FUSE dispatcher now uses \read\_unaligned\ for safe parsing of unaligned VirtIO queue memory, and the \PassthroughFs\ backend includes TOCTOU-safe inode open checks to harden against hostile guests.

virt/arcbox-fs/src · high confidence

macOS bundle entitlements split and helper daemon configuration

The macOS application bundle now uses separate entitlement files for development and release builds to support the hardened runtime and local development environments. The release entitlements include \com.apple.vm.networking\ for direct VMnet bridge access, while the new development entitlements disable library validation to accommodate non-Apple-signed dependencies (like nix-store libiconv) and omit the restricted networking entitlement to allow ad-hoc signing for CI tests. Additionally, the bundle includes a new launchd plist for the desktop helper service, configuring it with an idle-exit flag, a specific socket path, and a 45-second exit timeout to ensure graceful shutdown.

bundle · high confidence

Removals

Removal of VirtIO device implementations

The \arcbox-virtio\ crate has been removed, eliminating the block, network, console, filesystem, and vsock device emulation layers from the virtual machine environment. Users will no longer have access to these specific VirtIO-based hardware interfaces for guest I/O operations.

crates/arcbox-virtio · high confidence

Removed Darwin and Linux hypervisor platform implementations

The \arcbox-hypervisor\ crate has removed its platform-specific virtual machine implementations for macOS (Darwin) and Linux. The deleted files include the Darwin FFI bindings for the Virtualization.framework, the Darwin memory, vCPU, and VM modules, as well as the Linux KVM VM implementation. Additionally, the crate's common types file, which defined CPU architectures, platform capabilities, register states, and VirtIO device configurations, has been removed. This change eliminates the existing code responsible for managing virtual machines and their hardware abstractions on these two operating systems.

crates/arcbox-hypervisor · high confidence

Security

Hardened peer authentication and strict input validation for the helper server

The ArcBox helper server now enforces strict security boundaries for privileged operations. In release builds, it requires peer authentication via macOS code-signing verification (checking Team ID and allowed bundle identifiers) before accepting connections on the Unix socket, while debug builds skip this check for local development. Additionally, all RPC mutations now perform strict dynamic validation at the server boundary, ensuring that mutation functions only receive strongly typed, validated inputs rather than raw strings, and the server supports launchd socket activation for improved lifecycle management.

app/arcbox-helper/src/server · high confidence

Architecture

Extracted arcbox-engine as a standalone, daemon-free VM management crate

The engine layer has been extracted from arcbox-core into a new, standalone \arcbox-engine\ crate. This new crate provides the core VM and machine management capabilities—including the guest-agent RPC client (\AgentClient\), VM lifecycle handling (\VmManager\), machine state persistence, and an event bus—while remaining platform-neutral and free of daemon or CLI dependencies. It exposes a clean API for creating, configuring, and managing VMs (including backend selection between VZ and HV, Rosetta support, and nested virtualization) and persists machine configurations atomically to disk, ensuring that interrupted states are detected and recovered upon restart.

engine/arcbox-engine/src · high confidence

Refactored passthrough FUSE filesystem into modular components

The passthrough FUSE server implementation has been restructured into distinct modules (directories, file\_handles, inode\_ops, metadata, node\_ops, types, and tests) to improve maintainability and code organization. This refactoring preserves all existing functionality—including file/directory operations, extended attributes, and inode caching—while separating concerns for better readability and future extensibility.

virt/arcbox-fs/src/passthrough · high confidence

Removal of legacy VMM, device, and IRQ modules

The \arcbox-vmm\ crate has removed its previous implementation files (\vmm.rs\, \device.rs\, and \irq.rs\), which previously contained the main Virtual Machine Monitor logic, VirtIO MMIO device management, and a basic IRQ chip abstraction. This deletion indicates a structural refactoring where these components are being replaced or moved to other locations within the codebase.

crates/arcbox-vmm · high confidence

Unified VirtIO queue infrastructure and memory accessors

The \arcbox-virtio-core\ crate now provides the foundational types for all VirtIO devices, replacing fragmented per-device implementations. It introduces \GuestMemWriter\ for safe, GPA-based access to guest RAM, and a unified \SplitQueue\ abstraction that handles descriptor chain iteration, used-ring publishing, and notification suppression (including EVENT\_IDX support) in a single, cycle-safe location. The \VirtQueue\ implementation has been enhanced with batched used-ring updates and explicit EVENT\_IDX feature negotiation, while error handling now integrates with the central \arcbox-error\ crate.

virt/arcbox-virtio-core · high confidence

VirtioNet device refactored into modular components with hot-path optimizations

The \VirtioNet\ device implementation has been split into separate modules (\mod.rs\, \hot\_path.rs\, \tx\_rx.rs\, \virtio\_device.rs\, and \tests.rs\) to improve code organization and performance. The new \hot\_path.rs\ introduces a zero-allocation RX scratch buffer and optimized TX/RX queue draining logic that reduces CPU overhead during high-throughput network operations. The refactoring also ensures proper offload feature negotiation (checksum, TSO) is passed to the backend upon activation, preventing silent packet loss or incomplete offloads. Comprehensive unit tests have been added to verify device creation, feature negotiation, configuration reading, and link status toggling.

virt/arcbox-virtio-net/src/device · high confidence

Behavioural changes

API error classification and Connect transport integration

The API layer now routes all errors through a unified \ApiError\ type that maps internal failures (common, core, and agent-reported errors) to specific Connect error codes. This ensures that clients using Connect, gRPC, or gRPC-Web receive consistent, structured error responses, including detailed registry codes for agent errors like execution not found, sandbox state issues, or file limits.

app/arcbox-api/src · high confidence

Adaptive RX interrupt coalescing for VirtIO-net injection

The RX injection engine now uses an adaptive gather-window policy to dynamically adjust interrupt coalescing based on traffic patterns. Instead of a fixed delay, the system expands the coalescing window (up to 800 µs) under high frame-rate multi-flow loads to reduce guest IRQ overhead, and shrinks it (down to 100 µs) during idle or single-stream periods to lower latency. This change is implemented in the \arcbox-net-inject\ crate, which introduces a dedicated \CoalescePolicy\ module, an \RxInjectThread\ that drives both channel-based and inline fast-path connections, and an \InlineConn\ subsystem for zero-copy TCP data delivery directly into guest memory.

virt/arcbox-net-inject · high confidence

ArcBox Helper introduces structured mutations for CLI, DNS, hosts, routes, and Docker socket management

The ArcBox Helper server now exposes a new set of mutation handlers that manage system-level configurations with strict ownership and validation. CLI tool symlinks in /usr/local/bin are now managed via strong types, ensuring targets are valid, non-symlink files owned by ArcBox, and preventing conflicts with foreign binaries. DNS resolver files in /etc/resolver are installed and uninstalled using a marker-based approach that preserves existing foreign-managed entries. The /etc/hosts file is updated to include an alias for the guest-data NFS mount, with uninstall logic that removes only the managed line while preserving user-added entries. Network routes are managed via the PF\_ROUTE socket, with ownership checks to avoid conflicting with existing routes. Docker socket symlinks at /var/run/docker.sock are managed with specific error handling for occupied sockets, ensuring only ArcBox-owned targets are linked and foreign sockets are preserved.

app/arcbox-helper/src/server/mutations · high confidence

Computer lifecycle restructured as a hierarchical state machine

The computer runtime's lifecycle management has been refactored from a flat, imperative flow into a hierarchical state machine using the \statig\ library. This change introduces a formal transition table (\machine.rs\) that explicitly defines states (such as \provisioning\, \staging\, \booting\, \gating\, \running\, \paused\, and \failed\) and the events that drive transitions between them. The logic is now separated into declarative effects (\effect.rs\) that describe requested actions (like spawning a boot task or persisting a record) and an actor (\actor.rs\) that executes these effects and manages the mailbox. This structure enforces crash safety by clearly distinguishing between durable phases (persisted to the record store) and transient runtime states, and it simplifies complex flows like warm restores and handovers by modeling them as specific state transitions with defined side effects.

computer/arcbox-computer-runtime/src/lifecycle · high confidence

Daemon self-provisioning and unified API transport

The daemon now provisions itself, allowing the desktop app to act as a pure display layer while the daemon manages its own lifecycle. It serves the sandbox and system APIs over a unified Connect stack that supports gRPC, gRPC-Web, and Connect protocols simultaneously on a single Unix socket, replacing the previous Tonic-based gRPC server. This change includes a new build script to embed the git build SHA for identity verification, a typed startup pipeline with strict lock acquisition, and background services for disk space reclamation, DNS resolution, and Kubernetes load balancer reconciliation.

app/arcbox-daemon · high confidence

Darwin VM console pipe handling and lifecycle cleanup

The Darwin hypervisor now provides non-blocking duplicates of the VM's console pipe readers via a new \SerialReaders\ struct, allowing external consumers to read guest output without blocking the VM thread. Additionally, the VM's \Drop\ implementation has been updated to explicitly close the host-side serial file descriptors and release guest pipe ends, ensuring that resources are properly cleaned up even if the VM never starts or is dropped unexpectedly.

virt/arcbox-hypervisor/src/darwin/vm · high confidence

Extracted boot asset and machine image management into a new engine crate

The boot asset and machine image management logic has been extracted from \arcbox-core\ into a new, standalone \arcbox-image\ crate. This new module provides the daemon with the ability to manage the compile-time-pinned boot asset chain (kernel, EROFS rootfs, and runtime binaries like Docker and K3s) and the published Linux machine image registry. It introduces a \BootAssetProvider\ for downloading and verifying boot assets against a pinned manifest, a \MachineImageManager\ for pulling and caching distro rootfs images from the CDN, and shared remote image fetching primitives, all while remaining platform-neutral and daemon-free.

engine/arcbox-image · high confidence

Flow-controlled machine exec sessions with guaranteed drain

The engine now manages machine execution sessions as flow-controlled TCP connections, ensuring that input and output are properly back-pressured and that sessions are always fully drained before closing. This change introduces a dedicated module for handling these sessions, replacing the previous ad-hoc implementation. Users benefit from more reliable execution of commands within machines, as the system now correctly handles stdin/stdout streams and signals, preventing data loss or connection hangs during long-running or high-throughput operations.

_engine/arcbox-engine/src/agent\_client/machine\exec · high confidence

Guest agent communication is abstracted behind a portable port

The runtime now exposes a \GuestAgent\ and \GuestFiles\ interface that decouples host-side operations (command execution, file I/O, clock sync, network reconfiguration, and port waiting) from the underlying transport. The default implementation uses a vsock-based protocol (\vm\_proto\) to reach the in-VM agent, but the new factory pattern allows alternative transports to be injected via \NodeEnvironment::agent\. This change also introduces a structured readiness model (\Readiness\) supporting dial-out, polling, and probe strategies, ensuring the boot flow can correctly wait for the guest agent regardless of how it is reached.

computer/arcbox-computer-runtime/src · high confidence

Guest agent now adapts behavior based on machine type and improves exec reliability

The guest agent now distinguishes between System VMs and Distro Machines by detecting the \arcbox.machine\_rootfs\ kernel command-line parameter. For Distro Machines, the agent restricts its operation to serving RPC requests only, avoiding conflicts with the machine's own init system and DNS configuration. Additionally, command execution errors are now more precise: missing executables return a 404 status, while other spawn failures return 500. Login sessions for exec requests now follow sshd conventions, setting appropriate PATHs and environment variables based on the user's UID (root vs. standard user). The runtime ensure logic is now non-blocking to prevent RPC timeouts during container startup.

guest/arcbox-agent/src/agent · high confidence

Idle balloon shrinking logic extracted and gated by backend reclaim capability

The idle balloon shrinking policy and its message-driven controller have been extracted into the \arcbox-engine\ module. This change introduces a staged descent mechanism that probes guest memory usage and shrinks the balloon in steps, but it is strictly gated by a \reclaim\_capable\ check. Currently, this gate prevents shrinking on macOS backends (VZ and HV) because they do not return memory to the host in a way that reduces the host's physical footprint, ensuring the daemon does not attempt ineffective or harmful memory reclamation.

_engine/arcbox-engine/src/vm\lifecycle/balloon · high confidence

Improved Docker build reliability and network DNS consistency

The Docker API handlers now enforce stricter runtime checks and maintain accurate host DNS records. For \POST /build\ requests, the system verifies that the FEX translator is available in the HV guest before proceeding; if FEX is missing, the build fails immediately with a clear error rather than silently falling back to incompatible runtimes or failing later with cryptic errors. Additionally, when containers are connected to or disconnected from networks, the host's DNS entries are automatically refreshed to reflect the container's current IP and aliases, preventing stale resolution issues.

app/arcbox-docker/src/handlers · high confidence

Improved KVM stability and ARM64 boot support in the Linux hypervisor

The Linux hypervisor implementation now correctly initializes ARM64 vCPUs for Linux boot by setting the program counter, x0, and PSTATE registers, replacing the previous placeholder. To prevent undefined behavior during I/O exits, memory reads from the KVM run region now use unaligned access methods. The hypervisor also exposes new KVM ioctls and structures for interrupt injection, GSI routing, and dirty page logging, and enables dirty page tracking in the memory subsystem to support snapshotting. Additionally, nested virtualization capability detection is now delegated to a shared host capability check rather than reading sysfs directly.

virt/arcbox-hypervisor/src/linux · high confidence

Improved network reliability and configuration management on macOS

The core layer now uses direct kernel ioctls via the \ifbridge\ crate to discover VM bridge interfaces, replacing fragile text parsing of \ifconfig\ output. This change, along with the introduction of a route reconciler that retries transient failures and falls back to split container routes, makes container networking more robust. Additionally, the daemon now persists VM resource changes (CPU and memory) directly to the user's \\~/.config/arcbox/config.toml\ while preserving existing comments and formatting.

app/arcbox-core/src · high confidence

Introduce ArcBox Connect RPC surface with precompiled descriptor generation

The \rpc/arcbox-connect\ crate now provides the public Connect RPC surface for the ArcBox sandbox API, serving \arcbox.sandbox.v1\ and \arcbox.v1\ via Connect (supporting HTTP/JSON, binary protobuf, gRPC, and gRPC-Web) while ensuring musl compatibility for the guest agent. Code generation is handled by a new build script that uses a committed precompiled descriptor set (\arcbox\_connect.protoset\) and source hashing to guarantee that generated buffa message types remain synchronized with \.proto\ definitions without requiring \protoc\ at build time. This crate's generated types are now the single runtime representation for the daemon, \abctl\, and the host-guest vsock wire, while the previous prost-based types in \arcbox-protocol\ are restricted to test support only.

rpc/arcbox-connect · high confidence

Introduce PF\_ROUTE-based routing socket API for macOS

The \arcbox-route\ crate now implements direct kernel syscalls via the BSD \PF\_ROUTE\ socket to manage the macOS routing table, replacing the previous approach of shelling out to \/sbin/route\. This change provides a safe Rust interface for adding, removing, and querying IPv4 subnet routes, utilizing a validated \Ipv4Net\ type to ensure correct prefix and host-bit handling. By communicating directly with the kernel, the system avoids the overhead and potential alignment issues of external process execution, offering a more robust and consistent method for low-level network configuration on Darwin.

common/arcbox-route · high confidence

Introduce committed protobuf descriptor set for build consistency

The build process now relies on a committed descriptor set (arcbox\_connect.protoset) and a source list (protos.txt) to ensure that the code generator uses a consistent view of the protocol definitions. A new refresh script (refresh.sh) allows developers to regenerate this descriptor and its SHA-256 hash after modifying proto files, preventing build failures caused by stale or mismatched descriptors across different environments.

rpc/arcbox-connect/descriptor · high confidence

Introduce guest Docker backend with vsock readiness validation

The container backend layer now includes a dedicated GuestDockerBackend that ensures the guest's Docker daemon is ready before container operations. This implementation validates the guest's vsock endpoint port against the configured expected port, rejecting mismatches or invalid formats, and supports a test mode that skips VM checks for mock-based testing.

_app/arcbox-core/src/container\backend · high confidence

Introduces flow-controlled exec and sandbox streaming sessions

The engine now manages machine exec sessions and guest-to-host sandbox streams with explicit flow control to prevent backpressure stalls. New modules in the agent client handle these connections by queuing output frames and granting windows back to the agent only as the host consumer processes them, ensuring that slow consumers do not block the VM's vsock connection. This change also includes a platform-specific transport layer that uses a blocking I/O path on macOS to avoid reactor stalls with socketpair file descriptors, while maintaining an async path for Linux and macOS VZ backends.

_engine/arcbox-engine/src/agent\client · high confidence

Lifecycle tasks moved into dedicated modules

The boot, checkpoint, pause, release, restore, and resume sub-tasks have been extracted from the \sandbox\ module into new files under \lifecycle/tasks\. This refactoring isolates the specific lifecycle operations (such as VM startup, snapshotting, pausing, and cleanup) into their own modules, while the manager and actor wiring remain in the surrounding lifecycle code.

computer/arcbox-computer-runtime/src/lifecycle/tasks · high confidence

Linux KVM hypervisor VM implementation refactored into modular components

The Linux KVM virtual machine implementation has been restructured into distinct modules to improve maintainability and fix compilation issues. The \KvmVm\ struct now explicitly manages memory slot tracking and dirty page logging, enabling features like live migration and snapshotting by allowing users to enable/disable dirty tracking and retrieve modified page bitmaps. Interrupt handling is now separated into its own module, providing methods to set IRQ line levels, trigger edge-triggered interrupts, and register/unregister IRQFDs for efficient event injection. VirtIO device integration is handled via a dedicated module that allocates MMIO regions and IRQs, sets up IOEVENTFDs for queue notifications, and serializes device configurations for snapshots. The VM lifecycle is managed through a new \Drop\ implementation that ensures clean shutdown by stopping the VM and releasing VirtIO resources (IRQFDs, IOEVENTFDs, and file descriptors). Tests have been added to verify VM creation, vCPU lifecycle, device addition, and dirty bitmap parsing.

virt/arcbox-hypervisor/src/linux/vm · high confidence

Live sandbox CoW state survives startup sweep

The snapshot subsystem now correctly re-registers and preserves the copy-on-write resources (dm-snapshot devices, loop devices, and COW files) for sandboxes that are still running when the host restarts. Previously, a startup sweep might have incorrectly treated these active resources as stale orphans, potentially detaching shared loop devices or removing overlay files, which could lead to data loss or VM crashes. This change ensures that live sandboxes are adopted and their disk state is maintained across agent restarts.

_engine/arcbox-snapshot/src/snapshot\cow · high confidence

Migrate ArcBox API services to Connect RPC

The daemon's API surface has been migrated from the tonic gRPC implementation to the Connect RPC protocol, serving Connect (HTTP POST with JSON or binary protobuf), gRPC, and gRPC-Web on a single endpoint. This change introduces new service implementations for sandbox lifecycle and data-plane operations (control, filesystem, process, and snapshot), as well as daemon-internal services including machine management, macOS guest management, Kubernetes cluster lifecycle, migration, system stats, and image icon lookups. The migration preserves existing behaviors such as transparent sandbox auto-resume on paused states and deferred runtime readiness checks, while unifying the wire representation through buffa-generated types.

app/arcbox-api/src/connect · high confidence

New Linux network stack implementation for virtualization

The Linux networking layer in \virt/arcbox-net\ has been restructured and implemented from scratch to support VM networking. This change introduces dedicated modules for managing Linux bridge interfaces (\bridge.rs\), TAP devices (\tap.rs\), low-level netlink socket operations (\netlink.rs\), and firewall rules using iptables or nftables (\firewall.rs\). These components replace previous implementations, providing the core infrastructure for creating virtual networks, attaching VM interfaces, and configuring NAT/port forwarding on Linux hosts.

virt/arcbox-net/src/linux · high confidence

New macOS networking implementation using Virtualization and vmnet frameworks

The Darwin networking module has been rewritten to leverage Apple's Virtualization.framework and vmnet.framework, replacing the previous utun-based L3 tunnel approach with a high-performance datapath. This change introduces support for NAT, Host-Only, and Bridged network modes, allowing VMs to share the host's connection or appear as separate devices on the network. The implementation includes a new NAT engine with zero-copy packet handling, lock-free queues, and a custom utun device for host-side packet I/O, significantly improving network performance and stability on macOS.

virt/arcbox-net/src/darwin · high confidence

New modular IRQ chip with interrupt coalescing support

The \virt/arcbox-vmm/src/irq\ module has been refactored into a structured IRQ chip abstraction (\IrqChip\) that manages interrupt routing, GSI mapping, and trigger modes (edge vs. level). A key addition is timer-based interrupt coalescing, which accumulates pending interrupts within a configurable window to reduce VM wakeups, with specific presets for virtio-net, virtio-blk, virtio-fs, and virtio-vsock devices. The module also exposes statistics for monitoring triggered and coalesced interrupts.

virt/arcbox-vmm/src/irq · high confidence

Passive observation streams no longer prevent System VM idle reclaim

The proxy now classifies Docker API requests to distinguish between active operations (like pulls or builds) and passive observation streams (such as GET /events, log follow, and stats streaming). Previously, any open stream kept the System VM out of idle memory reclaim indefinitely; now, passive streams are transparent to the idle clock, allowing the VM to idle and reclaim memory even while clients are watching it.

app/arcbox-docker/src/proxy · high confidence

Refactored FUSE dispatcher into modular components with DAX security hardening

The FUSE dispatcher in \virt/arcbox-fs/src/dispatcher\ has been split into separate modules (dax.rs, directories.rs, file\_ops.rs, lookup\_attrs.rs, mapping\_xattr.rs, nodes.rs, types.rs) to improve code organization. This change introduces a new DAX-specific extension trait (\DaxFsExt\) that adds a TOCTOU (Time-of-Check-Time-of-Use) security guard to the \FUSE\_SETUPMAPPING\ operation. When the guest kernel requests a DAX mapping without an open file handle (using the \FUSE\_NO\_FH\ sentinel), the dispatcher now opens a temporary file descriptor and verifies that the inode number of the opened file matches the originally registered inode. If a rename or swap occurred between the initial lookup and the mapping request, the operation is rejected with \EIO\, preventing potential security issues from hostile guests manipulating file paths. The refactoring also includes implementations for standard FUSE operations like \opendir\, \readdir\, \read\, \write\, \getattr\, \setattr\, and extended attributes, along with comprehensive unit tests for the dispatcher logic.

virt/arcbox-fs/src/dispatcher · high confidence

Refactored VirtIO block device into modular components

The VirtIO block device implementation in \virt/arcbox-virtio-blk/src/device\ has been split into separate modules (\io.rs\, \virtio\_device.rs\, \mod.rs\, and \tests.rs\) to improve code organization. This refactoring isolates I/O handling (reads, writes, flushes, discard, write zeroes) from device lifecycle management (activation, feature negotiation, queue processing). The core \VirtioBlock\ struct and its \VirtioDevice\ trait implementation remain, but the internal logic is now distributed across these new files, with comprehensive unit tests added to verify device creation, I/O operations, and safety against cyclic descriptor chains.

virt/arcbox-virtio-blk/src/device · high confidence

Refactored computer lifecycle into a per-computer actor with strict handover ownership

The computer lifecycle management has been restructured to use a dedicated per-computer actor that serializes all state transitions and commands. This change introduces a strict ownership model for handovers: the actor now refuses any command other than Detach when a computer is in the Detached state, preventing the successor process from interacting with a VM that has already been handed over. Additionally, the handover process (Detach) now drops the guest agent reference before initiating the port call to the successor, ensuring that the current process cannot execute operations on a VM it no longer owns. The actor also manages in-flight sub-tasks with preemption capabilities, allowing force-removes to cancel ongoing boots or checkpoints, and handles stalled teardowns with exponential backoff retries.

computer/arcbox-computer-runtime/src/lifecycle/actor · high confidence

Refactored container lifecycle handlers with precise kill-signal teardown logic

The container handler module has been restructured to centralize routing and improve lifecycle management. Container creation now resolves macOS symlinks in bind-mount paths and strictly enforces the AMD64 runtime requirement, failing closed if the FEX translator is unavailable. Starting a container automatically configures host-side port forwarding and DNS registration. Stopping a container tears down this networking state. A key behavioral change is in the kill handler: host networking is now only torn down when the container is actually terminated (SIGKILL or default kill signal), preventing premature removal of port forwarding and DNS records for non-fatal signals like SIGHUP or SIGTERM.

app/arcbox-docker/src/handlers/container · high confidence

Refactored device manager with new modular submodules and debug capabilities

The device management layer has been restructured into distinct submodules to improve maintainability and add diagnostic features. A new \checksum.rs\ module now handles guest-side TCP/UDP checksum offload finalization for virtio-net traffic. A \debug.rs\ module provides a \virtio\_debug\ snapshot capability that reads live virtqueue ring indices, interrupt status, and EVENT\_IDX slots from guest memory to aid in diagnosing wedged queues or suppressed interrupts. The \mmio\_state.rs\ submodule centralizes the virtio-mmio 1.1 register layout and per-device state, increasing the maximum supported virtqueues from 8 to 64 to prevent silent drops on multi-vCPU block devices. The \dispatch.rs\ module handles MMIO read/write routing, including config space forwarding and device activation/reset logic. The \net\_worker.rs\ module manages the lifecycle of the network RX worker thread, spawning it upon device activation. The \poll.rs\ module provides thin shims for polling bridge network RX, vsock RX injection, and console input injection. Finally, \tree.rs\ generates deterministic device tree entries for Linux FDT discovery, ensuring consistent block device naming.

virt/arcbox-vmm/src/device · high confidence

Restructured computer lifecycle flows into dedicated boot, restore, and teardown modules

The runtime's lifecycle logic has been reorganized into three new, distinct flow modules: \boot.rs\ handles cold-start sequences including the readiness gate and initial command execution; \restore.rs\ manages checkpoint restoration and VM resumption; and \teardown.rs\ centralizes checkpoint capture, graceful shutdown, and resource release. This change separates the concerns of starting, restoring, and stopping virtual machines, improving code maintainability and clarity for the computer runtime.

computer/arcbox-computer-runtime/src/lifecycle/flows · high confidence

Reworked VirtIO crate structure with back-compat re-exports

The \arcbox-virtio\ crate has been reorganized to serve as a unified facade for per-device sub-crates (blk, net, console, fs, vsock, rng, balloon). The library now re-exports types and modules from these underlying crates and \arcbox-virtio-core\ to maintain backward compatibility for existing imports, while the integration tests have been restructured into modular blocks to align with the new layout.

virt/arcbox-virtio · high confidence

Sandbox guest networking now uses eBPF TCX for identity-invariant NAT with an nftables backend option

The sandbox's guest network implementation has been refactored into a dedicated crate that supports two host-side NAT datapaths for the identity-invariant link (where every guest uses the fixed 169.254.100.2 address). The default datapath is now eBPF TCX programs that perform stateless, O(1) source/destination rewriting, replacing the previous iptables/fwmark policy-routing chain; if the eBPF object cannot be loaded, the system automatically falls back to the legacy netfilter rule set. Additionally, a new nftables PacketFilter backend has been added alongside the existing iptables-legacy backend, allowing the netfilter rules to be rendered using nftables on stock distributions while remaining mutually invisible to the iptables path.

virt/arcbox-tap-net · high confidence

Sandbox runtime restructured into lifecycle, boot, and checkpoint modules

The sandbox runtime code has been reorganized into distinct modules (\boot\, \checkpoint\, \cleanup\, \events\, \execution\, \files\, \lifecycle\, \pause\, \policy\) to separate concerns such as readiness probing, snapshot management, file operations, and lifecycle state machines. This refactoring introduces monotonic sequence numbers for sandbox events to detect delivery gaps, implements a readiness probe mechanism for templates, and clarifies the pause/resume workflow by separating internal checkpoint management from user-facing operations.

computer/arcbox-computer-runtime/src/sandbox · medium confidence

The .claude/skills location is now a symbolic link pointing to ../.agents/skills, centralizing skill definitions in the .agents directory while maintaining the previous access path for the Claude tooling.

.claude · high confidence

Standardized ArcBox RPC protocol module structure

The \arcbox-protocol\ crate now provides a unified, re-exported module structure for all RPC message types and services. Users and internal consumers can access types via canonical paths (e.g., \arcbox\_protocol::v1::TypeName\) or convenient top-level re-exports, while maintaining backward compatibility through specific submodules like \common\, \machine\, \container\, \image\, \agent\, \kubernetes\, and \api\. This change consolidates definitions for container lifecycle, image management, VM operations, guest agent interactions, and system/migration services into a single, consistent interface.

rpc/arcbox-protocol/src · high confidence

Strict input validation for privileged operations

The validation module in app/arcbox-helper/src/validate has been refactored to enforce strict, type-safe validation of all external inputs before they reach privileged code. New typed validators ensure that bridge interfaces match the bridge\<N\> pattern, CLI tool names are restricted to an allow list, CLI symlink targets are confined to specific application bundle paths, DNS ports are unprivileged (\>=1024), domain names comply with RFC standards, socket targets are restricted to the .arcbox directory, and subnets are limited to private IPv4 ranges with no host bits. This change hardens the application against injection and path traversal attacks by rejecting invalid inputs at the type level.

app/arcbox-helper/src/validate · high confidence

VM lifecycle management refactored into an actor-based state machine

The VM lifecycle management in the engine has been restructured from a monolithic implementation into a modular, actor-based architecture. The new design uses a \statig\ hierarchical state machine to manage transitions (e.g., NotExist → Creating → Running → Idle) and a dedicated lifecycle actor to handle asynchronous I/O operations like booting, stopping, and health monitoring. This separation ensures that the state machine remains pure and testable, while the actor manages concurrent tasks, channels, and hypervisor interactions. Key components include a boot/stop sub-task system for non-blocking I/O, a health monitor for tracking VM stability, and a recovery policy with exponential backoff for handling failures. The change improves resilience by allowing force-stops to preempt in-flight operations and provides better observability through structured events and state publishing.

_engine/arcbox-engine/src/vm\lifecycle · high confidence

VZ backend now uses a SwiftPM-compiled Swift shim instead of hand-written ObjC interop

The Virtualization.framework backend has replaced its previous hand-written Objective-C runtime interop with a new Swift package (ArcBoxVZShim) built via SwiftPM's native build system. This change introduces a strict C ABI boundary between Rust and Swift, enforced at link time to prevent symbol drift, and ensures the Swift concurrency runtime loads correctly by adding the necessary rpath. For users, this provides a more robust and maintainable foundation for macOS virtualization, eliminating the previous ObjC dependency and ensuring correct runtime linking on macOS 13+.

virt/arcbox-vz · high confidence

VirtIO RNG device now fails securely on entropy source errors

The virtio-rng implementation in the new arcbox-virtio-rng crate has been refactored to use the unified SplitQueue for processing guest requests. Crucially, the device no longer falls back to zero-filling buffers when the underlying getrandom call fails; instead, it stops filling the current chain and returns a short read, preventing the guest from receiving invalid entropy that was previously masked by zero-padding.

virt/arcbox-virtio-rng · high confidence

VirtIO-FS device refactored into modular components with FUSE 7.38 support

The \arcbox-virtio-fs\ crate has been restructured from a monolithic library into distinct modules (\device\, \handler\, \protocol\, \request\, \session\) to improve code organization and maintainability. This change introduces a \FuseRequestHandler\ trait that allows downstream implementations (like \arcbox-fs\) to process FUSE requests, decoupling the virtio device logic from filesystem semantics. The protocol support has been updated to FUSE kernel version 7.38, and the session initialization logic now dynamically negotiates the DAX map alignment based on the host's page size (16 KiB on Apple Silicon, 4 KiB on x86) to ensure correct memory mapping.

virt/arcbox-virtio-fs/src · high confidence

Virtio-net device refactored into modular components with TAP offload support

The virtio-net implementation has been restructured from a monolithic source file into distinct modules (config, header, backend, device, tap) to improve maintainability. This change introduces a \NetBackend\ trait that abstracts network I/O, enabling both a Linux-specific \TapBackend\ and a cross-platform \LoopbackBackend\ for testing. A key behavioral update is the addition of host-side TAP offload configuration (checksum, TSO, UFO) that is applied after feature negotiation, ensuring the host kernel matches the guest's negotiated capabilities. The module also includes updated network configuration structures and wire-format header definitions.

virt/arcbox-virtio-net/src · high confidence

Virtio-vsock refactored into modular components with improved write reliability

The virtio-vsock implementation has been split from a monolithic structure into distinct modules (addr, backend, connection, device, protocol, etc.) to improve maintainability. This change introduces a robust partial-write handling mechanism in the TX path that retries writes with backoff, preventing silent data truncation when the host socket buffer is full. Additionally, the device now properly handles OP\_SHUTDOWN half-close flags per the vsock specification, allowing connections to be preserved when only one direction is closed, and proactively sends CREDIT\_REQUEST messages when the window is half-full to prevent flow-control stalls.

virt/arcbox-virtio-vsock/src · high confidence

macOS hypervisor backend refactored to use arcbox-vz and software dirty page tracking

The Darwin hypervisor implementation has been restructured to rely on the \arcbox-vz\ crate for Virtualization.framework bindings, replacing the previous direct FFI approach. This change introduces a new \DarwinMemory\ module that implements software-based dirty page tracking using FNV-1a checksums, enabling incremental snapshot support on macOS where hardware dirty tracking is unavailable. Additionally, the \DarwinVcpu\ implementation is simplified to act as a stub for managed execution, removing dead state-poll machinery, while the hypervisor now correctly detects nested virtualization support and validates memory configurations against host limits.

virt/arcbox-hypervisor/src/darwin · high confidence

Fixes

Fix VM console stalls by draining all machine serial pipes

The engine now actively drains serial console and agent-log pipes for every running VM, not just the default System VM. Previously, if a guest's console output filled the pipe, the guest's virtio-console queue would block, causing vCPUs to spin at 100% and halting vsock communication. This change introduces a readiness-driven drain that reads from these pipes as soon as data is available, preventing backpressure and ensuring guest stability. It also includes tests to verify correct machine lifecycle event publishing and CID assignment.

engine/arcbox-engine/src/machine · high confidence

Fixes for migration execution and idempotency

The migration module now includes a DTO layer to safely project internal migration plans to wire formats, ensuring that invalid states from the wire are not passed to the planner. Additionally, the migration runner has been updated to support dry-run modes and to handle re-attachment idempotently, allowing clients to resume or inspect migration progress without losing events or causing duplicate executions.

app/arcbox-core/src/migration · high confidence

Improved DNS reliability with raw response caching and dynamic upstream following

The DNS forwarder now caches complete raw wire-format responses instead of parsed structures, preserving DNS compression pointers, EDNS, and DNSSEC data while correctly adjusting TTLs on cache hits. Additionally, the forwarder now monitors the host's resolver configuration file (e.g., /etc/resolv.conf) for changes, automatically switching upstream DNS servers when network conditions change (such as Wi-Fi switches or VPN connections) to prevent queries from being sent to stale or invalid resolvers.

virt/arcbox-net/src/dns · high confidence

Refactored Darwin network datapath loop for lossless delivery and performance

The Darwin network datapath loop has been refactored into modular components to improve reliability and throughput. Guest-bound frames are now classified as either Reliable (TCP-shim frames) or Lossy (datagrams), ensuring that Reliable frames are never dropped even when the socketpair buffer overflows, thereby preventing permanent TCP connection stalls. To reduce system call overhead, frame writes are batched using \sendmsg\_x\, significantly lowering latency on high-speed links. The refactored loop also includes explicit handling for \EINTR\ interruptions during writes and IPv4 fragmentation for UDP datagrams exceeding the link MTU.

_virt/arcbox-net/src/darwin/datapath\loop · high confidence

Refactored vsock connection manager with improved credit flow control

The vsock connection manager has been split into dedicated modules (connection, host\_connections, ops) to improve code organization and maintainability. This refactoring introduces a bitmask-based priority queue for RX operations, ensuring that credit requests and connection setup take precedence over data transfers. Credit flow control is now more proactive: the host sends credit updates every 4 KB of forwarded data and requests credit refreshes when the guest's available buffer drops below half its advertised size, preventing host-to-guest data stalls. Additionally, the manager now correctly handles half-close scenarios by shutting down the write side of the internal socketpair when the guest signals it will no longer send data, preventing hangs in scenarios like Docker container attach sessions.

virt/arcbox-virtio-vsock/src/manager · high confidence

Refactored vsock device internals and added comprehensive tests

The vsock device implementation has been restructured to improve maintainability and correctness. The RX injection logic was extracted into a dedicated \rx\_injection.rs\ module, introducing a \poll\_rx\_injection\ method that batches host-to-guest data delivery and optimizes interrupt handling by respecting the \VIRTIO\_F\_EVENT\_IDX\ feature to reduce unnecessary vCPU exits. The \virtio\_device.rs\ module now explicitly implements the \VirtioDevice\ trait, managing the creation and reset of RX, TX, and Event virtqueues, and handling TX packet forwarding. Additionally, a new \tests.rs\ file was added to provide unit test coverage for device configuration, feature negotiation, queue activation, and basic connect/send/recv operations.

virt/arcbox-virtio-vsock/src/device · high confidence

Test coverage

Added FEX64 validation harness for AMD64 container support; Added HV backend end-to-end test suite; Added HV cold-boot repro harness example; Added HV wake-path benchmark probes; Added VirtioFS benchmark suite for performance tracking; Added build script for cross-compiling Linux kernel for ARM64; Added comprehensive tests for the computer lifecycle state machine and actor; Added contract tests for the VM driver port; Added end-to-end tests for the local control-plane API; Added integration and end-to-end tests for the guest agent; Added integration and manager tests for sandbox lifecycle and block device operations; Added integration tests for OCI runtime specification handling; Added integration tests for SSH server functionality; Added integration tests for TAP network lifecycle and nftables rendering; Added integration tests for arcbox-helper RPC and E2E scenarios; Added integration tests for container image icon resolution; Added integration tests for macOS hypervisor features; Added integration tests for network datapath, DNS, and NAT components; Added shared test infrastructure for arcbox-helper integration tests; Added test helper to detect root privileges; Added test helpers for network datapath validation; Added test support fixtures for sandbox manager flows; Added test support infrastructure for Docker API integration tests; Added unit and integration tests for the TypeScript SDK; Contract test suite for VM driver lifecycle and capabilities; Expanded Docker API test coverage for routing, proxying, and handler behavior; Expanded e2e test coverage for daemon lifecycle, Docker builds, and network performance; Initial test suite for the Python SDK; New e2e test harness and scenario modules; New testkit for VM driver adapters.

Dependencies

Rust dependency and workspace manifest updates

Updated Cargo.toml manifests across the ArcBox Rust workspace, including the addition of new crates (arcbox-api, arcbox-cli, arcbox-ssh, arcbox-migration, arcbox-connect, arcbox-grpc, arcbox-protocol, arcbox-container, arcbox-oci, arcbox-dhcp, arcbox-fc-driver, arcbox-hv, arcbox-xnu-net, arcbox-route, arcbox-pty, arcbox-conntrack, arcbox-datapath, arcbox-packet, arcbox-proxy, arcbox-fakeip, arcbox-local-ca, arcbox-logging, arcbox-constants, arcbox-error, arcbox-atomic-file, arcbox-asset, arcbox-dns, arcbox-computer, arcbox-computer-runtime, arcbox-engine, arcbox-image, arcbox-snapshot, arcbox-docker, arcbox-docker-tools, arcbox-helper, arcbox-fleet-agent, arcbox-fleet-proto, arcbox-fleet-control-proto) and updates to existing ones. Key dependency changes include upgrading connectrpc (arcbox-connectrpc) to 0.9.0-arcbox.1, buffa to 0.9.1, russh to 0.62.1, reqwest to 0.12.28 (and 0.13.4 in fleet-agent), and adding new dependencies like statig, oci2rootfs, arcbox-ext4, and security-framework. The Python SDK (pyproject.toml) and TypeScript SDK (package.json) manifests were also updated, with the Python SDK requiring httpx\>=0.28.1, msgspec\>=0.21.1, protobuf\>=7.35.1, and the TypeScript SDK using @connectrpc/connect ^2.1.2 and requiring Node \>=22.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 70 → 66 (-3.9)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 78 → 78 (+0.0)
  • Architecture 99 → 96 (-3.4)
  • Maturity 77 → 80 (+3.5)
  • Readiness 64 → 56 (-7.9)
  • Security 67 → 74 (+7.1)
  • Domain Modelling 88 → 91 (+3.0)
  • Event Sourcing 100 → 100 (+0.0)
  • Performance 69 (new)

Resolved (76)

  • AgentClient::machine_exec (cognitive 16) (engine/arcbox-engine/src/agent_client.rs)
  • AgentClient::machine_exec_session (cognitive 26) (engine/arcbox-engine/src/agent_client.rs)
  • AgentClient::machine_exec_session (cyclomatic 16) (engine/arcbox-engine/src/agent_client.rs)
  • AgentClient::sandbox_exec_attach (cognitive 16) (engine/arcbox-engine/src/agent_client.rs)
  • AgentClient::sandbox_read_file (cognitive 16) (engine/arcbox-engine/src/agent_client.rs)
  • AgentClient::sandbox_watch_dir (cognitive 17) (engine/arcbox-engine/src/agent_client.rs)
  • Boundary-crossing change coupling: config.rs ↔ mod.rs (app/arcbox-core/src/config.rs)
  • Change coupling: mod.rs ↔ rpc.rs (guest/arcbox-agent/src/agent/mod.rs)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (rpc/arcbox-transport/README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (engine/arcbox-engine/src/agent_client.rs)
  • Duplicated block (10 lines × 2) (guest/arcbox-agent/src/agent/linux/machine_exec.rs)
  • Duplicated block (10 lines × 2) (virt/arcbox-vmm/src/blk_worker.rs)
  • Duplicated block (12 lines × 2) (guest/arcbox-agent/src/agent/linux/proxy.rs)
  • Duplicated block (13 lines × 2) (guest/arcbox-agent/src/agent/linux/machine_exec.rs)
  • Duplicated block (14 lines × 2) (virt/arcbox-virtio-console/src/device.rs)
  • …and 56 more

New (80)

  • ClassTooLong: MachineServiceImpl (app/arcbox-api/src/connect/machine.rs)
  • Documentation: no architecture or design documentation (docs/README.md)
  • Duplicated block (12–13 lines × 2) (guest/arcbox-agent/src/agent/linux/port_forward.rs)
  • Duplicated block (13 lines × 2) (guest/arcbox-agent/src/agent/linux/port_forward.rs)
  • Duplicated block (14 lines × 3) (virt/arcbox-virtio-balloon/src/lib.rs)
  • Duplicated block (16–18 lines × 3) (virt/arcbox-virtio-vsock/src/device/rx_injection.rs)
  • Duplicated block (16–19 lines × 2) (virt/arcbox-virtio-vsock/src/device/rx_injection.rs)
  • Duplicated block (6 lines × 2) (guest/arcbox-agent/src/docker_events.rs)
  • Duplicated block (7 lines × 2) (app/arcbox-daemon/src/nfs_mount.rs)
  • Duplicated block (7 lines × 2) (engine/arcbox-engine/src/agent_client/machine_exec.rs)
  • Duplicated block (7 lines × 2) (guest/arcbox-agent/src/agent/linux/port_forward.rs)
  • Duplicated block (8 lines × 2) (guest/arcbox-agent/src/agent/linux/machine_exec.rs)
  • Duplicated block (8 lines × 2) (virt/arcbox-vmm/src/blk_worker.rs)
  • Edited copy of a member (23 corresponding lines) (virt/arcbox-virtio-vsock/src/device/rx_injection.rs)
  • FunctionTooLong: arcbox_agent::main (guest/arcbox-agent/src/main.rs)
  • Further sole-owners (lower concentration)
  • High CVE: [GHSA redacted] (sdk/typescript/package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 60 more

Changes since last survey

  • 141 commits — 117 feature/other, 24 fixes

By area

  • guest/arcbox-agent — 33 commits
  • engine/arcbox-engine — 16 commits
  • app/arcbox-ssh — 12 commits
  • app/arcbox-core — 9 commits
  • (root) — 7 commits
  • tests/e2e — 7 commits
  • app/arcbox-daemon — 6 commits
  • virt/arcbox-virtio-vsock — 5 commits
  • app/arcbox-cli — 4 commits
  • rpc/arcbox-protocol — 4 commits
  • virt/arcbox-vz — 4 commits
  • .github/workflows — 3 commits
  • app/AGENTS.md — 3 commits
  • common/arcbox-constants — 3 commits
  • rpc/arcbox-transport — 3 commits
  • virt/arcbox-hypervisor — 3 commits
  • virt/arcbox-vmm — 3 commits
  • app/arcbox-api — 2 commits
  • guest/AGENTS.md — 2 commits
  • virt/arcbox-virtio-balloon — 2 commits

Notable commits

  • fix: fix(agent): give sysvinit machines a boot-completion hook
  • fix: fix(agent): keep the boot-done hook out of systemd's preset policy
  • fix: fix(agent): put every busybox applet on a debug shell's PATH
  • fix: fix(agent): read machine addresses off the interfaces, not hostname
  • fix: fix(agent): report Kubernetes ready only once its kubeconfig exists
  • fix: fix(agent): serve only RPC inside distro machines
  • fix: fix(agent): trim data disks with FITRIM instead of a missing fstrim
  • fix: fix(config): read the documented ~/.config/arcbox/config.toml
  • fix: fix(daemon): boot on the HV backend without asking it for sandbox cleanup
  • fix: fix(dns): follow the host resolver across network changes
  • fix: fix(docker): carry attach half-close in-band over the vsock channel
  • fix: fix(engine): end a machine exec session when its consumer goes away
  • fix: fix(engine): keep kernel NIC names in distro machines
  • fix: fix(machine): cap the machine kernel console at loglevel=4
  • fix: fix(machine): drain every VM's console pipes, not only the System VM's
  • fix: fix(machine): keep the serial drain's fast poll while any bytes arrive
  • fix: fix(ssh): never hold the connection for input while output needs it
  • fix: fix(transport): fail a writer whose peer left while it waited for window
  • fix: fix(vsock): keep a host->guest packet inside one 4 KiB guest RX buffer
  • fix: fix(vsock): park a host->guest write while the guest's window is full
  • …and 121 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

arcboxlabs/arcbox was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cc9a27525943cba88eb244ee8c7ae12bc9612ac1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.