Files
hailongzhao 176aa0d02b fix(sandbox): build real arm64 sandbox images and ship arm64 Cube variants
The global `ARG TARGETPLATFORM=linux/amd64` in Dockerfile.sandbox overrode
the per-platform value BuildKit injects, so the multi-platform CI build ran
every platform on the amd64 rootfs and only relabeled the arm64 config.
The published arm64 entries of main, latest and main-desktop are byte-for-byte
the amd64 layers. The stage-level `ARG TARGETARCH=amd64` had the same effect,
so the cube "amd64 only" guard could never fire.

- Declare TARGETPLATFORM without a default and fall back to linux/amd64 in
  FROM only when it is empty (legacy builder).
- Fail the runtime stage when the rootfs architecture differs from
  TARGETARCH.
- cubesandbox-base:2026.16 publishes linux/arm64 as well, and Cube runs on
  arm64 bare-metal KVM (PVM stays x86_64-only). Follow TARGETPLATFORM for
  cube-base, replace the amd64-only guard with an envd-vs-rootfs check, and
  build cube / desktop-cube for linux/amd64,linux/arm64 in CI and
  build_images.sh.
2026-09-30 13:34:01 +08:00
..