github akitaonrails/ai-jail v2.3.0

2 hours ago

v2.3.0

A focused audit-log usability and hardening release: readable local summaries,
shared safe-open checks, and bounded record processing.

Added

  • Readable local audit summaries with ai-jail --audit-show. Launches,
    filtered-network decisions, and credential-substitution records are rendered
    as concise local text. The command exits 0 after a successful display,
    including an empty log; 1 for malformed records or an I/O/security error;
    and 2 when the log does not exist. Verification likewise uses 0 for an
    intact chain, 1 for a broken chain or read/security error, and 2 when the log
    is missing. The display view summarizes recognized record
    syntax but intentionally does not verify hash-chain integrity — use
    --audit-verify for that separate check. Displayed launch records may
    include command arguments, so avoid secrets in argv.

Security

  • Audit display, verification, and writing now share safe-open hardening.
    HOME is the trusted starting directory and may itself be a symlink, including
    through symlinked ancestors. Once HOME is pinned as a directory descriptor,
    no symlink is followed below it through
    .local/share/ai-jail/history.jsonl. Readers reject special files,
    foreign-owned logs, and logs with group or other permissions. The writer
    rejects special or foreign-owned logs, while preserving compatibility by
    tightening an existing user-owned regular log to mode 0600 through its opened
    descriptor. Record handling is bounded for display, verification, and
    append-time chain seeding,
    so a malformed oversized record cannot cause unbounded memory growth. The
    hash chain remains a tamper-evident internal-consistency check, not keyed
    authenticity.
  • Audit-logging failures remain best-effort. Offline audit commands exit 1
    when HOME is missing, empty, or invalid; a missing log below a valid HOME
    still exits 2. Failures specific to optional launch logging, including an
    unusable HOME at audit-log setup, disable logging with a warning but do not
    prevent launch or override the child's status. Configuration and sandbox
    validation errors remain fatal, and no fallback audit log is written under
    /tmp.

Fixed

  • --audit-show remains a valid child argument after the command. As with
    other command arguments, ai-jail COMMAND --audit-show passes the flag to
    the child; only ai-jail --audit-show invokes ai-jail's audit summary. This
    preserves positional-command compatibility.

Checksums (SHA256)

e603b7d8ee582a29cf00631aecbff2cbe906e2e5a829e7ff654f875d88b7ae03  ai-jail-linux-x86_64.tar.gz
c6facf3905e930f952634e368aa2fbd2d470107b3c7731a388e3f608ffdf5d85  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.