v2.6.1
A bug-fix release for the v2.6.0 agent-state default: two harnesses that
should have started pre-authenticated inside the jail did not — kimi
(wrong credential path) and any harness launched through an ai-memory run
wrapper carrying pre-harness flags. Both are fixed, and every other
supported harness's credential path was re-verified against the real tool.
Backward compatible: every pre-2.6.1 .ai-jail keeps working.
Fixed
-
kimi re-authenticated inside the jail (#150). v2.6.0 mapped kimi's
agent-state to~/.kimi-code, but kimi-cli actually stores its OAuth
credentials and config in~/.kimi(~/.kimi/credentials,
~/.kimi/config.toml). Because agent-state only binds paths that exist on
the host, the wrong path meant nothing was mounted and kimi saw an empty
home, so it asked you to log in every session. kimi now maps to~/.kimi
(with~/.kimi-codekept as a legacy alias for any older install), on both
the Linux (bwrap) and macOS (seatbelt) backends, and~/.kimiis added to
the built-in dotdir-deny list so it stays protected under
--no-private-homeunless agent-state re-exposes it. -
Harnesses launched via
ai-memory runwith pre-harness flags
re-authenticated (#151).managed_harness()parsed only ai-memory's
value options, so a pre-harness wrapper flag it did not recognize — notably
--jail=ssh,github,toolchains,mise, but also--yolo,--true-yolo,
--fresh,--no-jail,--no-autowire,--force-unlock, and the value
options--env/--env-file/--profile— made the effective harness fall
back toai-memory, so the real harness's agent-state (~/.claude, …) was
never mounted and it asked you to log in. The parser now recognizes those
pre-harness run flags (including--jailboth bare and as--jail=TOGGLES)
while still failing closed to the outer command on any unknown or
incomplete pre-harness token. -
CLI usability fixes (audit).
--agent-state's help still claimed
"default: off" even though it has been on by default since v2.6.0; it now
reads "default: on; off under--lockdown; project.ai-jailcan only
disable." And--ro-map(a back-compat alias for--map) was listed in the
sandbox-flag guard but had no parse arm, so it errored inconsistently —
"unknown option" before the command and "would be passed to the child"
after it. It now parses as a read-only map like--map. A new conformance
test asserts every flag in the sandbox-flag guard is actually parseable (and
that every boolean toggle has both--x/--no-xsides), so this class of
drift fails CI instead of shipping.--allow-tcp-port's help also still
advertised it as functional though it has been rejected at launch for a
while (use--allow-host); the help now says so. -
No more doomed mise auto-install spam under the read-only mise map.
ai-jail maps mise's data dir read-only, so mise could never finish an
auto-install of a declared-but-missing tool inside the jail — it only failed
noisily (Read-only file system) on every shim call. When mise is enabled
(and not under--lockdown), ai-jail now sets
MISE_NOT_FOUND_AUTO_INSTALL=falsein the sandbox so a missing tool fails
once, cleanly; an explicit--env MISE_NOT_FOUND_AUTO_INSTALL=…still wins.
Verified
- Re-confirmed, by running each tool in an isolated throwaway
$HOMEand
observing the paths it actually creates, that the other supported harnesses
map to their real credential/state directories: claude (~/.claude+
~/.claude.json), codex (~/.codex), opencode (~/.config/opencode+
~/.local/share/opencode), crush (~/.local/share/crush, within its
mapped set), gemini (~/.gemini), and grok (~/.grok).
Checksums (SHA256)
73496bcecba0b0d74da147628e20087ee113bd934ff1989c89e0003e73596b96 ai-jail-linux-x86_64.tar.gz
74ecbf43d20a5426427d80fd24235997f4bd09a376ba0b985afb8b458701ba0c ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail