v2.6.0
A developer-friendliness release: AI harnesses now start pre-authenticated
by default, so a plain ai-jail <harness> no longer makes the agent log in
again inside the jail. This leans into ai-jail's purpose — an accident-guard for
a trusted-but-fallible agent, not a hard-security boundary (use a disposable VM
for hostile code) — and the docs now say so clearly, with the full list of what
is on by default and how to tighten it down to full --lockdown.
Backward compatible: every pre-2.6.0 .ai-jail keeps working. The one behavior
change is the new default below, which is additive (more works out of the box)
and monotonic (an untrusted project .ai-jail can only disable it).
Changed
-
Agent/harness auth is ON by default (
agent_state, previously opt-in).
A plainai-jail <harness>now mounts that harness's own credential/state dir
read-write so it starts pre-authenticated — OAuth tokens persist and refresh,
and the harness does not re-login each session. Covers claude (~/.claude+
~/.claude.json), codex (~/.codex), opencode, crush, kimi (~/.kimi-code),
gemini (~/.gemini), grok, pi, and others.--no-agent-staterestores the
isolated, logged-out run;--lockdownalways disables it (the lockdown gate is
folded into the capability so every mount, the Landlock wrapper, and the audit
record stay isolated); browser profiles disable it. Still monotonic — an
untrusted project.ai-jailmay only disable it.This reverses the former opt-in #84 stance in favor of the "YOLO mode that
won't wreck anything outside the project" goal. Read-only still does not stop a
compromised agent from reading its own token, so this is a deliberate
convenience default, not a security boundary.
Added
- Pre-authenticate API-key harnesses too: when agent state is on, the invoked
harness's well-known API-key env var is copied from the host when set —
ANTHROPIC_API_KEY(claude),OPENAI_API_KEY(codex),
GEMINI_API_KEY/GOOGLE_API_KEY(gemini/antigravity),XAI_API_KEY(grok),
MOONSHOT_API_KEY(kimi). Never persisted to a saved.ai-jail; an explicit
--envfor the same name wins.
Fixed
- macOS launch regression (#148). v2.5.0 emitted the toolchain cache maps
(which useSOURCE:DESTINATION) on macOS, where seatbelt cannot express
alternate destinations — so every default macOS launch failed with "alternate
map destinations are not supported." The toolchain cache and its default
registry egress are now correctly Linux-only; macOS returns to its pre-2.5.0
behavior. (--no-toolchainswas the workaround.) - A global read-only
--mapof the project directory no longer forces the
project read-only (#149). A map whose destination is the project dir itself
is now emitted before the project's own read-write bind, so the working
directory stays writable; maps of paths inside the project (e.g.--map .git)
still take precedence as before. --env/--env-from-filenow document that their values land on the
launcher's argv (/proc/<pid>/cmdline, readable by same-user processes, #147);
use--secret KEY=hostfor a secret that must stay off argv. A
descriptor-based fix to keep all such values off argv is tracked as a
follow-up.- crush agent-state now includes
~/.config/crushand
~/.local/share/crush(its real config and provider data);~/.crushalone
was empty, so crush still re-authenticated. - antigravity is now recognized and mapped to
~/.gemini(its OAuth lives
under~/.gemini/antigravity-cliand it shares~/.gemini's Google OAuth).
Docs
- Reframed the purpose across README,
docs/SECURITY.md, andCLAUDE.md:
ai-jail prevents accidents by a trusted agent (a mistypedrmthat would hit
files outside the project), it is not a defense against a motivated attacker or
a substitute for a VM. Added a clear "on by default" list and a "turn it down /
lockdown levels" progression from the friendly default to full--lockdown.
Checksums (SHA256)
edb3aa4e036887186382da181055a5ee1a613d61473ab7dceb95757dca06237b ai-jail-linux-x86_64.tar.gz
6b760233bf3b3303bd86f109cc10e841cbe844d02dbc9cf8a48ead993cf43b91 ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail