When to use this profile
Rust compilation often dominates an agent's action time. Prepare dependencies and distinguish incremental development tests from the clean build that validates a final patch. Cache only trusted build inputs within the task's isolation scope. Proc macros and build scripts execute during compilation, so compilation belongs inside the sandbox boundary too.
Prepare a repeatable environment
- Preserve Cargo.lock and pin the toolchain with rust-toolchain.toml.
- Install required native libraries and linkers during image preparation.
- Fetch crates before disabling network access; document any git-based dependencies.
cargo test --locked --jobs 2Return results the agent can use
- Cargo test results and compiler diagnostics.
- The source diff, including intentional lockfile changes.
- Binary artifacts with the target triple and build profile recorded.
Run locked tests on a small fixture, then add a compile error and confirm diagnostics reach the agent. Measure a clean build before using the recipe for large workspaces.
Resources and boundaries
Start with 4 vCPU and 8 GB of RAM, then measure peak memory and task duration on a representative fixture. These are workload planning values, not a benchmark or a provisioned configuration. Use the sandbox cost calculator to estimate running time and retained snapshots.
- Parallel compiler processes and linkers can consume more memory than the program itself.
- Build scripts and proc macros run arbitrary code and can read task credentials.
- Keep caches scoped so another tenant cannot replace a dependency or build artifact.
Keep model inference separate from this execution profile. A hosted model or gpuOS can decide the next action while the CPU environment runs it. The quickstart describes the account workflow and the proposed runtime contract.