A fix release. mise is enabled by default and ai-jail already activates it
inside the sandbox, but under the default private home its paths were never
mounted, so the activation found nothing and every mise-managed tool — the
agent executable included — vanished from PATH. No .ai-jail config field
or CLI flag changed.
Fixed
-
mise toolchains now work out of the box. When mise is enabled, ai-jail
maps the mise data dir (~/.local/share/mise, honoringMISE_DATA_DIR), the
mise config dir (~/.config/mise, honoringMISE_CONFIG_DIR), and the
misebinary's directory read-only automatically. Previously the default
private home (which mounts only dotdirs) left~/.local/share/miseand the
misebinary under~/.local/bininvisible, so activation was skipped and a
mise-managed agent such asclaudefailed with
executable ... not found in the host PATH. Running the agent unsandboxed, or
adding the maps by hand, was the only workaround. (#113)Only existing directories are mapped, so a host without mise is unchanged, and
themisebinary's directory is mapped only when it lives under the home tree
(a systemmiseis already mounted).--no-miseand--lockdownopt out —
both already disable mise activation, so neither maps these paths. The derived
paths are injected at launch after the status/--init/bootstrap early returns,
so they are never persisted into a saved.ai-jailnor shown as user maps in
ai-jail status.
Checksums (SHA256)
36d3cc0777a014e6227f31ff9274906ab48ef2f5861775ba9f7452b86b751540 ai-jail-linux-x86_64.tar.gz
830786910c42e064c28c678e965d64cf0595f903a7981f4ebe52eb272ea5b3c1 ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail