github docker/sbx-releases v0.46.0

latest release: v0.47.0-rc1
7 hours ago

What's new

Breaking changes

  • Secret commands configured with sbx secret set --command, sbx secret set-custom --command, or secrets.<name>.command in an environment file execute from a fresh temporary directory on the host. Relative paths such as ./credential-helper no longer resolve from the project directory or the directory where you ran sbx. Store helpers and their dependencies outside writable sandbox mounts. Run helpers by name from an absolute directory on the host's PATH, use absolute paths, or explicitly change to their private directory in the command. For existing environments that declare secret commands, the next sbx env run asks you to approve a one-time plan change for the working directory. The execution change takes effect after upgrading and restarting the daemon, even before you approve that plan.

Cloud sandboxes

  • sbx --cloud create --on-timeout restart accepts restart as the timeout action. When the sandbox reaches its time limit, it stops and immediately restarts instead of remaining stopped.
  • sbx --cloud create passes --kit-arg and --kit-args-file values to kits supplied with --kit.

Kits and skills

  • Kits can install files in the agent's skills directory when shared skills are read-only. The shared skills store remains read-only, while kit installation and startup commands can write their own skills without a read-only filesystem error.
  • Kits added through the runtime API retain their network rules and applicable agent instructions when another kit addition recreates the sandbox container.
  • sbx kit add warns if it cannot save the updated sandbox record. The warning explains which kit settings could be lost and whether a daemon restart or another container replacement would cause the loss.

Agents and models

  • The local model server starts and stops with the Docker Sandboxes daemon and downloads its llama.cpp runtime when the daemon starts. The macOS and Windows bundles include llmman v0.1.418, which manages the runtime download instead of relying on a separately bundled llama-server.
  • Image paste in WSL2 falls back to the Windows clipboard when Linux clipboard tools return no image. Requires clipboard.imagePaste to be enabled.

Sandbox lifecycle and workspaces

  • Fixed a shutdown bug affecting templates that use dash as /bin/sh, including the built-in Ubuntu-based templates. The shutdown handler forwards SIGTERM correctly, giving sandbox processes a chance to exit gracefully instead of waiting five seconds for a forced shutdown.
  • On Linux arm64 hosts, the default CPU allocation is capped at 16 CPUs per sandbox. This fixes startup failures with VM did not connect within 15s when several sandboxes start together on hosts with many CPU cores. Use --cpus to request a larger allocation.
  • sbx umount can remove a saved mount from a stopped sandbox using the original host path even after that directory has been deleted.
  • On macOS, mounting, unmounting, and restoring saved mounts consistently recognize host paths whose capitalization differs.
  • If the runtime fails to mount the workspace, sandbox startup reports the mount failure and points to the daemon log for the cause instead of reporting a generic container startup error.
  • Starting a second daemon against a state directory already in use fails with an error instead of disrupting the running daemon.
  • sbx reset stops background feature-flag updates and log writes before deleting local state, preventing leftover files and recreated directories. On Windows, it also closes daemon log files before deleting them to avoid cleanup retries caused by open file handles.

Authentication and credentials

  • Removing secrets in bulk revokes credentials from running sandboxes. Failed revocations can be retried even after the stored secrets have been deleted.

Networking and policy

  • Sandboxes created with the balanced network policy preset can download Playwright browser binaries from cdn.playwright.dev over HTTPS. Existing sandboxes keep their saved policies. To use the updated preset, create a new sandbox with the balanced network policy.

CLI and diagnostics

  • sbx env reports unrecognized environment-file keys with the file, line, and column where they were declared, including when multiple files are merged.
  • Canceling a batch sbx rm or sbx stop stops processing the remaining sandboxes instead of printing a cancellation error for each one.
  • sbx diagnose --upload returns a non-zero exit status if the requested diagnostics upload fails, so scripts can detect the failure.
  • sbx diagnose reports the socket-path length limit used by the container runtime as runtime_socket_limit_bytes and clarifies the meaning of the reported socket-path values.

Packaging and installation

  • Windows MSI installations include llmman and the guest kernel, fixing local model serving with sbx run --model and sandbox launches that failed with No kernel specified.
  • Uninstalling Docker Sandboxes through the Windows MSI stops the daemon.
  • Fixed the Linux static tarball failing to start on distributions with older glibc versions. The tarball is built against glibc 2.34.

Don't miss a new sbx-releases release

NewReleases is sending notifications on new releases.