github akitaonrails/ai-jail v2.4.1

4 hours ago

A fix release. mise is enabled by default and ai-jail already activates it
inside the sandbox, but under the default private home its paths were never
mounted, so the activation found nothing and every mise-managed tool — the
agent executable included — vanished from PATH. No .ai-jail config field
or CLI flag changed.

Fixed

  • mise toolchains now work out of the box. When mise is enabled, ai-jail
    maps the mise data dir (~/.local/share/mise, honoring MISE_DATA_DIR), the
    mise config dir (~/.config/mise, honoring MISE_CONFIG_DIR), and the
    mise binary's directory read-only automatically. Previously the default
    private home (which mounts only dotdirs) left ~/.local/share/mise and the
    mise binary under ~/.local/bin invisible, so activation was skipped and a
    mise-managed agent such as claude failed with
    executable ... not found in the host PATH. Running the agent unsandboxed, or
    adding the maps by hand, was the only workaround. (#113)

    Only existing directories are mapped, so a host without mise is unchanged, and
    the mise binary's directory is mapped only when it lives under the home tree
    (a system mise is already mounted). --no-mise and --lockdown opt out —
    both already disable mise activation, so neither maps these paths. The derived
    paths are injected at launch after the status/--init/bootstrap early returns,
    so they are never persisted into a saved .ai-jail nor shown as user maps in
    ai-jail status.

Checksums (SHA256)

36d3cc0777a014e6227f31ff9274906ab48ef2f5861775ba9f7452b86b751540  ai-jail-linux-x86_64.tar.gz
830786910c42e064c28c678e965d64cf0595f903a7981f4ebe52eb272ea5b3c1  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.