github akitaonrails/ai-jail v2.8.0

3 hours ago

v2.8.0

A bare ai-jail claude (or codex/gemini/grok) now reaches its model API
out of the box, and Kiro CLI joins the recognized agents. macOS Codex and
Claude logins are fixed, and the PTY no longer stalls launchers that probe the
cursor position.

Backward compatible: every pre-2.8.0 .ai-jail keeps working.

Added

  • Each known agent's own API host is default-allowed (#156). With no
    network posture and no explicit --allow-host list, a bare launch of a known
    API agent now receives filtered egress to that agent's own documented API
    host — claude → api.anthropic.com, codex → api.openai.com, gemini →
    generativelanguage.googleapis.com, grok → api.x.ai — so it reaches its
    model API without opening the whole network. Deny-by-default still holds:
    only the agent's single functional API host is added (never a telemetry
    host), and an explicit --allow-host set is used verbatim instead. Not
    Linux-only — macOS filtered egress is a seatbelt loopback rule, so it applies
    there too — and gated on the same unprivileged-netns probe as registry
    egress, staying fully offline when that is unavailable. --no-network,
    --network, a browser launch, and --lockdown all keep their existing
    semantics. Reshaped from a Claude-only proposal; thanks @andrelramos.
  • Kiro CLI is recognized for agent-state (#155). Its login/session state
    (~/.kiro plus ~/.local/share/kiro-cli on Linux, ~/Library/Application Support/kiro-cli on macOS) is mounted under private home on both backends,
    and kiro-cli is listed among the positional presets. Thanks @JuanMCanchala.

Fixed

  • macOS: Claude Code Keychain login and the Codex control socket (#154).
    The seatbelt profile now preserves Claude Code's Keychain-stored auth and
    allows the Codex app-server control socket, so both launch logged-in on
    macOS. Thanks @andrelramos.
  • Cursor-position requests are answered from the vt100 screen (#159). A
    launcher that emits a Device Status Report (cursor-position query) no longer
    stalls waiting for a reply: ai-jail answers it from the virtual terminal's
    own cursor when the child is on the primary screen. Thanks @enosteteo.

Internal

  • Hardened the filtered-egress proxy against descriptor exhaustion and fixed a
    lock race in its tests (#157, thanks @lucascouts). Widened a flaky
    gh-token-lookup test timeout.
  • Assessed Microsoft LiteBox for a future Windows port (not a fit; a Windows
    backend would use WSL2 or a native AppContainer/Job Objects sandbox).

Checksums (SHA256)

4965827929a1366f75747e87116cee6a5eb3fc13d310d180f3c923dca7df6a6c  ai-jail-linux-x86_64.tar.gz
52fd5f693b049c1b1956a2030c4768d9ca6bcbe12df6547434df941c7ab9090b  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.