Rename MultiUseSandbox to Sandbox - #1866
Conversation
The "multi use" qualifier once distinguished this type from SingleUseSandbox, which no longer exists. Sandbox is the plain name for an initialized sandbox. MultiUseSandbox remains as a deprecated alias, so existing callers keep compiling and get a warning pointing at the new name. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Jorge Prendes <jorge.prendes@gmail.com>
The initialized module holds the initialized sandbox type. Sandbox, SandboxStatus and PtRootFinder are reached through hyperlight_host::Sandbox or hyperlight_host::sandbox. The module is private because every public item in it is already re-exported one level up. sandbox::initialized_multi_use stays as a deprecated facade so existing callers keep compiling. Keeping the type in a deprecated module is not an option. Module deprecation is inherited by the items defined inside it and follows them through re-exports, which would warn on every use of the canonical hyperlight_host::Sandbox path. The log tracing test pointed at sandbox/initialized.rs, a file that did not exist, so it took the "not found" path instead of testing an invalid binary as intended. It now reads the crate manifest, which always exists and is never a valid guest binary. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Jorge Prendes <jorge.prendes@gmail.com>
fc66057 to
97ea8d9
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The legacy public module path lacks a downstream compile test for the stated compatibility guarantee.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Renames the initialized sandbox type to Sandbox while preserving deprecated compatibility aliases and paths.
Changes:
- Introduces
Sandboxand deprecatedMultiUseSandboxaliases. - Moves implementation into private
sandbox::initialized. - Updates consumers, documentation, tests, and isolated-test paths.
| File | Description |
|---|---|
src/hyperlight_host/tests/wit_test.rs |
Uses Sandbox. |
src/hyperlight_host/tests/snapshot_goldens/fixtures.rs |
Updates golden fixtures. |
src/hyperlight_host/tests/snapshot_goldens/checks.rs |
Updates golden checks. |
src/hyperlight_host/tests/integration_test.rs |
Updates integration tests. |
src/hyperlight_host/tests/common/mod.rs |
Updates test helpers. |
src/hyperlight_host/src/sandbox/uninitialized.rs |
Returns Sandbox and fixes invalid-binary test. |
src/hyperlight_host/src/sandbox/uninitialized_evolve.rs |
Constructs Sandbox. |
src/hyperlight_host/src/sandbox/snapshot/mod.rs |
Updates API documentation. |
src/hyperlight_host/src/sandbox/snapshot/file/mod.rs |
Updates snapshot example. |
src/hyperlight_host/src/sandbox/snapshot/file_tests.rs |
Migrates snapshot tests. |
src/hyperlight_host/src/sandbox/mod.rs |
Adds exports and compatibility facade. |
src/hyperlight_host/src/sandbox/initialized.rs |
Renames the primary type. |
src/hyperlight_host/src/sandbox/host_funcs.rs |
Updates constructor documentation. |
src/hyperlight_host/src/sandbox/file_mapping.rs |
Updates API link. |
src/hyperlight_host/src/sandbox/config.rs |
Updates snapshot links. |
src/hyperlight_host/src/sandbox/builder.rs |
Uses the primary type directly. |
src/hyperlight_host/src/mem/memory_region.rs |
Updates mapping documentation. |
src/hyperlight_host/src/lib.rs |
Exports Sandbox and deprecated alias. |
src/hyperlight_host/src/func/host_functions.rs |
Implements registration for Sandbox. |
src/hyperlight_host/src/error.rs |
Updates recovery links. |
src/hyperlight_host/examples/func_ctx/main.rs |
Updates example terminology. |
src/hyperlight_host/examples/crashdump/main.rs |
Updates crashdump documentation. |
src/hyperlight_host/benches/benchmarks.rs |
Migrates benchmarks. |
src/hyperlight_component_util/src/host.rs |
Emits the public Sandbox path. |
Justfile |
Updates isolated-test module paths. |
fuzz/fuzz_targets/host_print.rs |
Migrates fuzz state type. |
fuzz/fuzz_targets/host_call.rs |
Migrates fuzz state type. |
fuzz/fuzz_targets/guest_trace.rs |
Migrates fuzz state type. |
fuzz/fuzz_targets/guest_call.rs |
Migrates fuzz state type. |
docs/virtio-host-guest-communication.md |
Updates sandbox terminology. |
docs/msr.md |
Updates restore API name. |
docs/hyperlight-metrics-logs-and-traces.md |
Updates log-level API name. |
docs/how-to-debug-a-hyperlight-guest.md |
Updates debugging guidance. |
docs/cancellation.md |
Updates call-path terminology. |
CHANGELOG.md |
Documents the rename and compatibility paths. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This comment has been minimized.
This comment has been minimized.
Preserving hyperlight_host::sandbox::initialized_multi_use is a compatibility guarantee, so it needs a guard. An integration test compiles as a separate crate, which is the only way to prove the path is reachable from outside hyperlight_host. The in-crate test it replaces resolved the aliases through crate paths, which says nothing about what downstream users can reach. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Jorge Prendes <jorge.prendes@gmail.com>
This comment has been minimized.
This comment has been minimized.
simongdavies
left a comment
There was a problem hiding this comment.
a couple of minor things, otherwise LGTM
The name says what the function does. It takes an UninitializedSandbox and returns a Sandbox. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Jorge Prendes <jorge.prendes@gmail.com>
The mu prefix stood for "multi use", which the type name no longer carries. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Jorge Prendes <jorge.prendes@gmail.com>
Benchmark ResultsMeasured commit: kvm / amd (Linux) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
kvm / intel (Linux) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
mshv3 / amd (Linux) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
mshv3 / intel (Linux) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
hyperv-ws2025 / amd (Windows) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
hyperv-ws2025 / intel (Windows) (➖ stable)No benchmark improved or regressed. Benchmark Resultsfunction_call_codec
payload_allocation
sandboxes
slot_pool
snapshot_files
virtq_readonly
virtq_readwrite
Reported by |

SingleUseSandboxwas removed long ago, so the "multi use" qualifierdistinguishes nothing.
Sandboxis the plain name for an initialized sandbox.Two commits:
MultiUseSandboxstays as a deprecated alias.sandbox::initialized_multi_useinto the privatesandbox::initializedmodule.sandbox::initialized_multi_usestays as adeprecated public facade.
Backwards compatibility
Nothing breaks. Both old paths still resolve, and both warn:
hyperlight_host::MultiUseSandboxhyperlight_host::sandbox::initialized_multi_usehyperlight-wasmimportsMultiUseSandboxfrom the crate root inwasm_sandbox.rsandloaded_wasm_sandbox.rs, and never uses the modulepath. It keeps building, with a deprecation warning.
Why the module is private
Every public item in it is already re-exported one level up, so the module
path adds no API surface.
Deprecating the module in place, rather than moving the type out of it, does
not work. Module deprecation is inherited by the items defined inside it and
follows them through re-exports, so
hyperlight_host::Sandboxwould warn onevery use.
#[allow(deprecated)]on the re-export only silences the definingcrate, not downstream callers.
Also
::hyperlight_host::sandbox::Sandboxrather thanan internal module path.
test_log_tracepointed atsandbox/initialized.rs, a file that did notexist, so it exercised the "not found" path instead of an invalid binary as
its comment claims. It now reads the crate manifest, which always exists and
is never a valid guest binary.