v2.6.2
A small hardening release from a defaults and flag-interaction audit, plus
the real fix for the --env-on-argv exposure (#147).
Backward compatible: every pre-2.6.2 .ai-jail keeps working.
Fixed
--envvalues no longer land on bwrap's argv (#147). Previously the
sandbox launcher's--setenv NAME VALUEpairs — carrying every--envand
--env-from-filevalue — sat on bwrap's command line, readable by any
same-user process via/proc/<pid>/cmdline. ai-jail now passes all bwrap
options through an anonymous in-memory file (bwrap --args FD) on Linux, so
the values never appear on argv; only--args <fd>and the---separated
command remain there (the command is not secret).--secretis still the
right tool for a value that must also stay out of the sandbox's own
environment. macOS (seatbelt) was never affected.--dry-runstill prints
the full command for inspection.--lockdownnow always isolates the network namespace, even with
--network. The--unshare-netdecision keyed only on whether network
was enabled, so the contradictory--lockdown --networkleft the net
namespace shared. On kernels without Landlock V4 net enforcement (ABI < 6.7)
that was a fail-open: lockdown is the maximum-isolation posture, so it now
forces--unshare-netregardless of--network. Filtered egress is
unaffected (it already runs with--no-network), and lockdown with
--allow-hoststill tunnels through the egress proxy as before.
Audit notes
- Reviewed every capability default, lockdown gate, and flag interaction
against the documented security model. All 25 defaults match the spec and
are test-locked; the monotonic project-config merge, the network-flag
conflict guards (--network⊗--allow-host,--browser⊗--allow-host,
--secretrequires filtered egress,--allow-tcp-portrejected), and the
lockdown gating at the mount sites are all correct. - Confirmed that
--no-networkcombined with--allow-hostis not a
contradiction: it composes to filtered egress (strict offline is
--no-networkwith no allow-hosts). This is load-bearing — the Landlock
wrapper itself re-execs with--no-network --allow-host— and is now
covered by a regression test so it can't silently change. - Added regression tests for the lockdown network-isolation fix and for the
browser profile's collateral defaults (no_toolchains,agent_stateoff).
Checksums (SHA256)
541ea6a743f710fcc7fd6bbd7542f619f8911d149616dec2dbabcba8ddbb9f00 ai-jail-linux-x86_64.tar.gz
59fca1a95db912d41b5a1ac3e0055f82850f92b046d799626ce2480413a9bfa6 ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail