Microsandbox Dependencies: Complete Guide to External Rust Crates and Libraries

Microsandbox is a multi-language sandboxing platform built in Rust that depends on approximately 60 external crates declared in the workspace's top-level Cargo.toml, organized into categories including networking, filesystem isolation, database persistence, and CLI tooling.

This guide examines the full dependency tree of the superradcompany/microsandbox repository, showing exactly which external libraries power each subsystem and how they're structured across the workspace. Whether you're auditing the supply chain, planning feature additions, or debugging build issues, understanding these dependencies reveals how microsandbox achieves its sandboxing capabilities.

How Dependencies Are Organized in Microsandbox

Microsandbox uses Cargo workspace inheritance to centralize version management. All external crates are declared once in the root Cargo.toml at Cargo.toml#L96-L100 and referenced via workspace = true in subcrate manifests.

This pattern eliminates version drift across the six main crates:

Crate Path Primary Responsibility
microsandbox-runtime crates/runtime/Cargo.toml Core sandbox process, VM entry points
microsandbox-cli crates/cli/Cargo.toml The msb command-line interface
microsandbox-network crates/network/Cargo.toml Network stack and policies
microsandbox-db crates/db/Cargo.toml SeaORM/SQLite persistence
microsandbox-filesystem crates/filesystem/Cargo.toml Filesystem isolation primitives
microsandbox-agent-client packages/agent-client/rust/Cargo.toml In-guest agent communication

Core Systems Programming Dependencies

Microsandbox relies on capability-based security and low-level OS primitives for sandbox isolation.

Capability and Filesystem Isolation


# From https://github.com/superradcompany/microsandbox/blob/main/Cargo.toml

cap-primitives = "4.0.2"
cap-std = "4.0.2"
nix = "0.31"
xattr = "1.3"
  • cap-std and cap-primitives — Provide capability-based filesystem APIs that restrict sandboxed processes to explicitly granted directories. This replaces raw std::fs calls with sandbox-aware alternatives.

  • nix — Unix system call wrappers for process management, signals, and file descriptors.

  • xattr — Extended attribute manipulation for Linux filesystem security labels.

Cross-Platform Support

windows-sys = "0.59"  # Windows API bindings

libc = "0.2"          # C standard library bindings

The windows-sys crate enables Windows sandboxing support, while libc provides the foundation for Unix-specific operations.

Networking Stack Dependencies

Microsandbox implements a custom network virtualization layer combining userspace TCP/IP with Tokio's async runtime.

Async Runtime and Core Networking

tokio = { version = "1.52", features = [
    "fs","io-util","io-std","macros","net","process",
    "rt","rt-multi-thread","signal","sync","time"
] }
tokio-util = { version = "0.7", features = ["io"] }
futures = "0.3"
futures-util = "0.3"

tokio with rt-multi-thread and full I/O features powers the entire async architecture. The futures ecosystem provides stream combinators and async utilities.

Sandboxed Network Stack

smoltcp = { version = "0.13", default-features = false }
socket2 = "0.6"
hickory-net = "0.26.1"
hickory-proto = "0.26.1"
resolv-conf = "0.7"
  • smoltcp — A standalone TCP/IP stack that runs in userspace, enabling network isolation without host network access.

  • hickory-net and hickory-proto — DNS resolution with custom resolver configuration.

  • socket2 — Low-level socket options for SO_BINDTODEVICE and other sandboxing controls.

TLS and Secure Connections

rustls = { version = "0.23", default-features = false, features = [
    "logging","ring","std","tls12"
] }
tokio-rustls = "0.26"
rustls-pki-types = "1.9"
rustls-native-certs = "0.8"
rustls-platform-verifier = "0.7"
tokio-tungstenite = { version = "0.30.0", features = ["rustls-tls-webpki-roots"] }

rustls with ring provides TLS 1.2/1.3 without OpenSSL dependencies. The rustls-platform-verifier crate ensures certificate validation matches host OS behavior. tokio-tungstenite adds WebSocket support for agent communication.

HTTP Client

reqwest = { version = "0.13", features = ["json", "stream"] }
ureq = { version = "3", features = ["platform-verifier"] }

reqwest is the primary async HTTP client for OCI registry operations. ureq provides a synchronous fallback for simple requests.

Database and Persistence Dependencies

Microsandbox uses SQLite with SeaORM for metadata, logs, and metrics storage.

sea-orm = { version = "2.0.0", default-features = false, features = [
    "macros","runtime-tokio-rustls","sqlite-use-returning-for-3_35",
    "sqlx-sqlite","with-chrono"
] }
sea-orm-migration = { version = "2.0.0", default-features = false, features = [
    "runtime-tokio-rustls","sqlx-sqlite"
] }
sqlx = { version = "0.9", default-features = false, features = [
    "runtime-tokio","tls-rustls","sqlite"
] }
  • sea-orm — Type-safe ORM with migration support. Disabled default features minimize binary size.

  • sqlx — Compile-time checked SQL queries underlying SeaORM.

The sqlite-use-returning-for-3_35 feature enables modern SQLite RETURNING clauses.

CLI and User Experience Dependencies

The msb command-line tool prioritizes ergonomic output with progress indication and color support.

clap = { version = "4.6", features = ["color", "derive"] }
clap_complete = "4.6"
console = "0.16"
indicatif = "0.18"
crossterm = { version = "0.29.0", features = ["events"] }
Crate Function
clap Derive-based argument parsing with colored help
clap_complete Shell completion generation (bash, zsh, fish)
indicatif Progress bars for long-running operations
crossterm Cross-platform terminal control

Serialization and Data Format Dependencies

Microsandbox handles multiple serialization formats for configuration, network protocols, and TypeScript bindings.

serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
serde_bytes = "0.11"
serde-saphyr = { version = "1.0.1", default-features = false, features = ["deserialize"] }
ciborium = "0.2"
ts-rs = "12.0.1"
  • serde-saphyr — YAML 1.2 deserialization for sandbox configuration files.

  • ciborium — CBOR (Concise Binary Object Representation) for compact agent protocol messages.

  • ts-rs — Generates TypeScript definitions from Rust structs for the frontend interface.

Cryptography and Security Dependencies

blake3 = "1.8"
sha2 = "0.11.0"
zeroize = { version = "1.8", features = ["derive", "serde"] }
  • blake3 — Fast, parallelizable hashing for filesystem layers and content addressing.

  • zeroize — Secure memory clearing for cryptographic material, with derive macros and serde support.

Container and OCI Dependencies

oci-client = "0.17"
oci-spec = "0.10.0"
astral-tokio-tar = "0.6"
tar = "0.4"
flate2 = { version = "1.0", features = ["zlib-rs"] }
async-compression = "0.4"
  • oci-client and oci-spec — Pull and parse OCI/Docker images from registries.

  • astral-tokio-tar — Async tar extraction optimized for large container layers.

  • flate2 with zlib-rs — Pure-Rust zlib compression, faster than C zlib in many cases.

Adding New Dependencies: A Practical Example

To extend microsandbox with zstd log compression, modify the workspace configuration:


# In https://github.com/superradcompany/microsandbox/blob/main/Cargo.toml

# Add to the workspace dependencies section:

zstd = "0.13"

# In crates/runtime/Cargo.toml

[features]
default = ["prebuilt", "net"]
log-compression = ["dep:zstd"]

[dependencies]
zstd = { workspace = true, optional = true }

Then gate the implementation in crates/runtime/src/lib.rs:

#[cfg(feature = "log-compression")]
use zstd::stream::Encoder;

pub fn compress_logs(data: &[u8]) -> Vec<u8> {
    #[cfg(feature = "log-compression")]
    {
        let mut encoder = Encoder::new(Vec::new(), 3).unwrap();
        encoder.write_all(data).unwrap();
        encoder.finish().unwrap()
    }
    #[cfg(not(feature = "log-compression"))]
    {
        data.to_vec()
    }
}

This pattern keeps the feature optional while leveraging centralized version management.

Summary

  • Centralized management: All microsandbox dependencies are declared in the root Cargo.toml and inherited via workspace = true across six subcrates.

  • Key architectural pillars: Capability-based security (cap-std), userspace networking (smoltcp + tokio), and SQLite persistence (sea-orm).

  • Security-first choices: rustls over OpenSSL, zeroize for secrets, blake3 for content hashing.

  • Minimal feature flags: Default features are frequently disabled to control binary size and compilation time.

  • Practical extensibility: New dependencies follow the workspace + optional feature pattern demonstrated with the zstd example.

Frequently Asked Questions

What version of Tokio does microsandbox use?

Microsandbox uses Tokio 1.52 with an extensive feature set including rt-multi-thread, full networking, process spawning, and signal handling. This is declared in the workspace Cargo.toml and inherited by all crates requiring async runtime capabilities.

Does microsandbox depend on OpenSSL?

No. Microsandbox uses rustls with the ring cryptographic provider for all TLS operations. This eliminates OpenSSL as a system dependency, simplifying cross-compilation and reducing the attack surface. The rustls-platform-verifier crate ensures certificate validation matches host OS behavior without native code.

How are database migrations handled in microsandbox?

Database schema changes use sea-orm-migration with SQLite as the backend. Migrations run automatically on sandbox startup, and the sqlite-use-returning-for-3_35 feature enables modern SQL patterns. The persistence layer is isolated in the microsandbox-db crate per its [Cargo.toml](https://github.com/superradcompany/microsandbox/blob/main/crates/db/Cargo.toml).

Can I build microsandbox without networking support?

Yes. The microsandbox-runtime crate exposes a net feature flag that can be disabled: default = ["prebuilt"] instead of default = ["prebuilt", "net"]. This removes dependencies on smoltcp, tokio-tungstenite, and the TLS stack, producing a smaller binary for offline-only sandboxing use cases.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →