v2.8.0
A bare ai-jail claude (or codex/gemini/grok) now reaches its model API
out of the box, and Kiro CLI joins the recognized agents. macOS Codex and
Claude logins are fixed, and the PTY no longer stalls launchers that probe the
cursor position.
Backward compatible: every pre-2.8.0 .ai-jail keeps working.
Added
- Each known agent's own API host is default-allowed (#156). With no
network posture and no explicit--allow-hostlist, a bare launch of a known
API agent now receives filtered egress to that agent's own documented API
host —claude→api.anthropic.com,codex→api.openai.com,gemini→
generativelanguage.googleapis.com,grok→api.x.ai— so it reaches its
model API without opening the whole network. Deny-by-default still holds:
only the agent's single functional API host is added (never a telemetry
host), and an explicit--allow-hostset is used verbatim instead. Not
Linux-only — macOS filtered egress is a seatbelt loopback rule, so it applies
there too — and gated on the same unprivileged-netns probe as registry
egress, staying fully offline when that is unavailable.--no-network,
--network, a browser launch, and--lockdownall keep their existing
semantics. Reshaped from a Claude-only proposal; thanks @andrelramos. - Kiro CLI is recognized for agent-state (#155). Its login/session state
(~/.kiroplus~/.local/share/kiro-clion Linux,~/Library/Application Support/kiro-clion macOS) is mounted under private home on both backends,
andkiro-cliis listed among the positional presets. Thanks @JuanMCanchala.
Fixed
- macOS: Claude Code Keychain login and the Codex control socket (#154).
The seatbelt profile now preserves Claude Code's Keychain-stored auth and
allows the Codex app-server control socket, so both launch logged-in on
macOS. Thanks @andrelramos. - Cursor-position requests are answered from the vt100 screen (#159). A
launcher that emits a Device Status Report (cursor-position query) no longer
stalls waiting for a reply: ai-jail answers it from the virtual terminal's
own cursor when the child is on the primary screen. Thanks @enosteteo.
Internal
- Hardened the filtered-egress proxy against descriptor exhaustion and fixed a
lock race in its tests (#157, thanks @lucascouts). Widened a flaky
gh-token-lookup test timeout. - Assessed Microsoft LiteBox for a future Windows port (not a fit; a Windows
backend would use WSL2 or a native AppContainer/Job Objects sandbox).
Checksums (SHA256)
4965827929a1366f75747e87116cee6a5eb3fc13d310d180f3c923dca7df6a6c ai-jail-linux-x86_64.tar.gz
52fd5f693b049c1b1956a2030c4768d9ca6bcbe12df6547434df941c7ab9090b ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail