github akitaonrails/ai-jail v2.6.1

latest release: v2.6.2
2 hours ago

v2.6.1

A bug-fix release for the v2.6.0 agent-state default: two harnesses that
should have started pre-authenticated inside the jail did not — kimi
(wrong credential path) and any harness launched through an ai-memory run
wrapper carrying pre-harness flags. Both are fixed, and every other
supported harness's credential path was re-verified against the real tool.

Backward compatible: every pre-2.6.1 .ai-jail keeps working.

Fixed

  • kimi re-authenticated inside the jail (#150). v2.6.0 mapped kimi's
    agent-state to ~/.kimi-code, but kimi-cli actually stores its OAuth
    credentials and config in ~/.kimi (~/.kimi/credentials,
    ~/.kimi/config.toml). Because agent-state only binds paths that exist on
    the host, the wrong path meant nothing was mounted and kimi saw an empty
    home, so it asked you to log in every session. kimi now maps to ~/.kimi
    (with ~/.kimi-code kept as a legacy alias for any older install), on both
    the Linux (bwrap) and macOS (seatbelt) backends, and ~/.kimi is added to
    the built-in dotdir-deny list so it stays protected under
    --no-private-home unless agent-state re-exposes it.

  • Harnesses launched via ai-memory run with pre-harness flags
    re-authenticated (#151).
    managed_harness() parsed only ai-memory's
    value options, so a pre-harness wrapper flag it did not recognize — notably
    --jail=ssh,github,toolchains,mise, but also --yolo, --true-yolo,
    --fresh, --no-jail, --no-autowire, --force-unlock, and the value
    options --env/--env-file/--profile — made the effective harness fall
    back to ai-memory, so the real harness's agent-state (~/.claude, …) was
    never mounted and it asked you to log in. The parser now recognizes those
    pre-harness run flags (including --jail both bare and as --jail=TOGGLES)
    while still failing closed to the outer command on any unknown or
    incomplete pre-harness token.

  • CLI usability fixes (audit). --agent-state's help still claimed
    "default: off" even though it has been on by default since v2.6.0; it now
    reads "default: on; off under --lockdown; project .ai-jail can only
    disable." And --ro-map (a back-compat alias for --map) was listed in the
    sandbox-flag guard but had no parse arm, so it errored inconsistently —
    "unknown option" before the command and "would be passed to the child"
    after it. It now parses as a read-only map like --map. A new conformance
    test asserts every flag in the sandbox-flag guard is actually parseable (and
    that every boolean toggle has both --x/--no-x sides), so this class of
    drift fails CI instead of shipping. --allow-tcp-port's help also still
    advertised it as functional though it has been rejected at launch for a
    while (use --allow-host); the help now says so.

  • No more doomed mise auto-install spam under the read-only mise map.
    ai-jail maps mise's data dir read-only, so mise could never finish an
    auto-install of a declared-but-missing tool inside the jail — it only failed
    noisily (Read-only file system) on every shim call. When mise is enabled
    (and not under --lockdown), ai-jail now sets
    MISE_NOT_FOUND_AUTO_INSTALL=false in the sandbox so a missing tool fails
    once, cleanly; an explicit --env MISE_NOT_FOUND_AUTO_INSTALL=… still wins.

Verified

  • Re-confirmed, by running each tool in an isolated throwaway $HOME and
    observing the paths it actually creates, that the other supported harnesses
    map to their real credential/state directories: claude (~/.claude +
    ~/.claude.json), codex (~/.codex), opencode (~/.config/opencode +
    ~/.local/share/opencode), crush (~/.local/share/crush, within its
    mapped set), gemini (~/.gemini), and grok (~/.grok).

Checksums (SHA256)

73496bcecba0b0d74da147628e20087ee113bd934ff1989c89e0003e73596b96  ai-jail-linux-x86_64.tar.gz
74ecbf43d20a5426427d80fd24235997f4bd09a376ba0b985afb8b458701ba0c  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.