github akitaonrails/ai-jail v2.6.2

one hour ago

v2.6.2

A small hardening release from a defaults and flag-interaction audit, plus
the real fix for the --env-on-argv exposure (#147).

Backward compatible: every pre-2.6.2 .ai-jail keeps working.

Fixed

  • --env values no longer land on bwrap's argv (#147). Previously the
    sandbox launcher's --setenv NAME VALUE pairs — carrying every --env and
    --env-from-file value — sat on bwrap's command line, readable by any
    same-user process via /proc/<pid>/cmdline. ai-jail now passes all bwrap
    options through an anonymous in-memory file (bwrap --args FD) on Linux, so
    the values never appear on argv; only --args <fd> and the ---separated
    command remain there (the command is not secret). --secret is still the
    right tool for a value that must also stay out of the sandbox's own
    environment. macOS (seatbelt) was never affected. --dry-run still prints
    the full command for inspection.
  • --lockdown now always isolates the network namespace, even with
    --network.
    The --unshare-net decision keyed only on whether network
    was enabled, so the contradictory --lockdown --network left the net
    namespace shared. On kernels without Landlock V4 net enforcement (ABI < 6.7)
    that was a fail-open: lockdown is the maximum-isolation posture, so it now
    forces --unshare-net regardless of --network. Filtered egress is
    unaffected (it already runs with --no-network), and lockdown with
    --allow-host still tunnels through the egress proxy as before.

Audit notes

  • Reviewed every capability default, lockdown gate, and flag interaction
    against the documented security model. All 25 defaults match the spec and
    are test-locked; the monotonic project-config merge, the network-flag
    conflict guards (--network⊗--allow-host, --browser⊗--allow-host,
    --secret requires filtered egress, --allow-tcp-port rejected), and the
    lockdown gating at the mount sites are all correct.
  • Confirmed that --no-network combined with --allow-host is not a
    contradiction: it composes to filtered egress (strict offline is
    --no-network with no allow-hosts). This is load-bearing — the Landlock
    wrapper itself re-execs with --no-network --allow-host — and is now
    covered by a regression test so it can't silently change.
  • Added regression tests for the lockdown network-isolation fix and for the
    browser profile's collateral defaults (no_toolchains, agent_state off).

Checksums (SHA256)

541ea6a743f710fcc7fd6bbd7542f619f8911d149616dec2dbabcba8ddbb9f00  ai-jail-linux-x86_64.tar.gz
59fca1a95db912d41b5a1ac3e0055f82850f92b046d799626ce2480413a9bfa6  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.