fix(sandbox): build real arm64 sandbox images and ship arm64 Cube variants - #3897
Merged
Merged
Conversation
…iants The global `ARG TARGETPLATFORM=linux/amd64` in Dockerfile.sandbox overrode the per-platform value BuildKit injects, so the multi-platform CI build ran every platform on the amd64 rootfs and only relabeled the arm64 config. The published arm64 entries of main, latest and main-desktop are byte-for-byte the amd64 layers. The stage-level `ARG TARGETARCH=amd64` had the same effect, so the cube "amd64 only" guard could never fire. - Declare TARGETPLATFORM without a default and fall back to linux/amd64 in FROM only when it is empty (legacy builder). - Fail the runtime stage when the rootfs architecture differs from TARGETARCH. - cubesandbox-base:2026.16 publishes linux/arm64 as well, and Cube runs on arm64 bare-metal KVM (PVM stays x86_64-only). Follow TARGETPLATFORM for cube-base, replace the amd64-only guard with an envd-vs-rootfs check, and build cube / desktop-cube for linux/amd64,linux/arm64 in CI and build_images.sh.
nullptr-error
force-pushed
the
fix/sandbox-multiarch
branch
from
September 30, 2026 02:51
3685a25 to
0de6d00
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The arm64 entries of
wechatopenai/weknora-sandbox:main,latestandmain-desktopcontain an amd64 rootfs. Registry manifests show the arm64 and amd64 entries share all 16 layer digests; only the config'sarchitecturefield differs. Inside the arm64 image,uname -misx86_64,dpkg --print-architectureisamd64, and python3 is an x86-64 ELF. Real arm64 hosts without x86 binfmt fail withexec format error, and Apple Silicon runs the image entirely under emulation.Root cause:
docker/Dockerfile.sandboxdeclaredARG TARGETPLATFORM=linux/amd64before the firstFROM. A declared default overrides the value BuildKit injects per platform, so withplatforms: linux/amd64,linux/arm64both platforms pulled amd64 bases and ran everyRUNon amd64, and BuildKit still labeled the second configarm64. The stage-levelARG TARGETARCH=amd64incube/desktop-cubehad the same effect, so their amd64-only guard never fired.Changes:
TARGETPLATFORMwithout a default;FROM --platform=${TARGETPLATFORM:-linux/amd64}falls back to amd64 only when it is empty (legacy builder, which also rejects an empty--platform).runtimestage now fails the build ifdpkg --print-architecturediffers fromTARGETARCH, so a relabeled image can no longer be published silently.ghcr.io/tencentcloud/cubesandbox-base:2026.16publishes a reallinux/arm64image (distinct layers, aarch64envd), and Cube supports arm64 bare-metal KVM since v0.5.0; PVM remains x86_64-only.cube-basenow followsTARGETPLATFORM, the amd64-only guard is replaced by an envd-vs-rootfs architecture check, andcube/desktop-cubeare built forlinux/amd64,linux/arm64in CI and inscripts/build_images.sh.Type of Change
Related Issue
N/A
Testing
Run on Apple Silicon (colima, BuildKit v0.32.2):
ARG TARGETPLATFORM=linux/amd64,docker buildx build --platform linux/arm64produces anx86_64/amd64rootfs; without the default it producesaarch64/arm64.sandbox,desktop,cube,desktop-cubeeach built forlinux/amd64,linux/arm64with a docker-container builder (same driver assetup-buildx-action).sandbox,desktopandcube(multi-platform) to a local registry, then ran every platform entry by digest: layer sets differ between platforms, and amd64 → x86_64 / amd64 / x86-64 python3 ELF, arm64 → aarch64 / arm64 / aarch64 python3 ELF.cube/desktop-cubeper platform: amd64 hasenvdx86-64, arm64 hasenvdARM aarch64;cube-entrypoint.shpresent and executable.runtimebuild fail withruntime rootfs is amd64 but TARGETARCH=arm64; pinningcube-baseback to amd64 makes an arm64cubebuild fail withenvd is x86-64 but rootfs is arm64.DOCKER_BUILDKIT=0) still builds with the amd64 fallback, and honours--build-arg TARGETPLATFORM.docker buildx build --check: only the 4 intentionalRedundantTargetPlatformwarnings remain.Not tested: building a Cube template from the arm64 image on an arm64 Cube cluster (none available).
Note: the
cube/desktop-cubearm64 builds run under QEMU on the amd64ubuntu-latestrunner, sobuild-sandboxwill take noticeably longer.Checklist
git diff --check origin/main...HEADpasseswebsite-docs/, Swagger annotations, etc.)