You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Runtime host grants (ADR 0044) - agentjail allow host and grants approve/deny for interactive egress approval.
Shared sandbox contract for darwin/linux parity, plus macOS code signing and notarization in the release pipeline.
Added
Session-aware network proxy - control-plane server with session registry,
per-token data plane, and lease reaper; shield registers a per-session
allowlist with netproxy over the control plane instead of a global allowlist
Per-folder project policy overlays - direnv-style trust gate discovers
per-folder overlays; agentjail trust/untrust/trust list CLI commands;
shield applies the trusted overlay to the session allowlist additively
Runtime host grants - agentjail allow host and grants approve/deny (--persist) CLI for interactive egress approval, backed
by a shared runtime host-grant validator and session identity fields
macOS code signing and notarization wired into the release pipeline
Dev-deploy script to build and swap local binaries during development
Netproxy decision logging to a file for observability, including target
host on non-CONNECT rejects
Changed
Domain-driven interface-first architecture (ADR 0035) - extracted
hookwatch, credential, sandbox, envaudit, and policyeval into internal
packages; policyctl domain service replaces 12 copy-pasted audit ceremonies
Shared sandbox contract for darwin/linux parity - hybrid allowed_hosts model with non-removable essential hosts and
user-configurable extended hosts; EffectiveAllowedHosts enforces the split
Netproxy egress enforcement is now opt-in via --netproxy; host
resolution and upstream connectivity checks are bounded and parallelized
agentjail run/claude resolves the real binary past the shim; status
line now shows the build git hash and a "secured by agentjail" indicator
Security
Policy denies agent-issued grant verbs - approve/deny/persist/ trust cannot be invoked by the agent itself, only by the human operator
Narrowed agent grant on ~/.agentjail to daemon.sock only; reads of
the agentjail state dir are allowed while writes stay locked
macOS keychain access hardened for Claude Code as part of darwin/linux
sandbox parity, alongside Phase 3 grant-boundary regression guards