v2.3.0
A focused audit-log usability and hardening release: readable local summaries,
shared safe-open checks, and bounded record processing.
Added
- Readable local audit summaries with
ai-jail --audit-show. Launches,
filtered-network decisions, and credential-substitution records are rendered
as concise local text. The command exits 0 after a successful display,
including an empty log; 1 for malformed records or an I/O/security error;
and 2 when the log does not exist. Verification likewise uses 0 for an
intact chain, 1 for a broken chain or read/security error, and 2 when the log
is missing. The display view summarizes recognized record
syntax but intentionally does not verify hash-chain integrity — use
--audit-verifyfor that separate check. Displayed launch records may
include command arguments, so avoid secrets in argv.
Security
- Audit display, verification, and writing now share safe-open hardening.
HOME is the trusted starting directory and may itself be a symlink, including
through symlinked ancestors. Once HOME is pinned as a directory descriptor,
no symlink is followed below it through
.local/share/ai-jail/history.jsonl. Readers reject special files,
foreign-owned logs, and logs with group or other permissions. The writer
rejects special or foreign-owned logs, while preserving compatibility by
tightening an existing user-owned regular log to mode 0600 through its opened
descriptor. Record handling is bounded for display, verification, and
append-time chain seeding,
so a malformed oversized record cannot cause unbounded memory growth. The
hash chain remains a tamper-evident internal-consistency check, not keyed
authenticity. - Audit-logging failures remain best-effort. Offline audit commands exit 1
when HOME is missing, empty, or invalid; a missing log below a valid HOME
still exits 2. Failures specific to optional launch logging, including an
unusable HOME at audit-log setup, disable logging with a warning but do not
prevent launch or override the child's status. Configuration and sandbox
validation errors remain fatal, and no fallback audit log is written under
/tmp.
Fixed
--audit-showremains a valid child argument after the command. As with
other command arguments,ai-jail COMMAND --audit-showpasses the flag to
the child; onlyai-jail --audit-showinvokes ai-jail's audit summary. This
preserves positional-command compatibility.
Checksums (SHA256)
e603b7d8ee582a29cf00631aecbff2cbe906e2e5a829e7ff654f875d88b7ae03 ai-jail-linux-x86_64.tar.gz
c6facf3905e930f952634e368aa2fbd2d470107b3c7731a388e3f608ffdf5d85 ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail