Skip to content

v1.1.0

Latest

Choose a tag to compare

@LuD1161 LuD1161 released this 27 Jul 07:16

v1.1.0 summary

TL;DR

  • Display live AgentJail protection state when Codex sessions start and stop, including startup, resume, clear, and compact boundaries.
  • Distinguish full protection, shield-only operation, and unshielded sessions by probing both enforcement layers before attesting.
  • Launch Codex and Cursor through the same default OS sandbox as Claude Code, with PATH shims, hook installation, status reporting, and uninstall support for all three agents.
  • Preserve policy meaning across agent protocols by recording the canonical policy action separately from the effective action rendered to Claude, Codex, or Cursor.
  • Harden custom Rego rules so extensions can add candidates but cannot override the resolver, suppress locked rules, or mutate policy evaluation.
  • Fix daemon recovery and uninstall targeting so restart uses the installed supervisor and uninstall probes only the daemon belonging to the requested home.

Added

  • Codex lifecycle attestation (ADR 0113-cursor-status-line): matcher-free SessionStart and Stop hooks display sandbox + policy active, sandbox active, policy daemon offline, or OS sandbox inactive through Codex's supported systemMessage channel.
  • Codex and Cursor PATH shims: detected installations now receive the same automatic shield activation as Claude Code; macOS grants the agent-specific runtime paths from the shared sandbox contract.
  • Complete Codex hook integration: registers PreToolUse, PermissionRequest, and PostToolUse, normalizes their wire shapes, and preserves Codex-native approvals when Codex independently opens a permission request.
  • Complete Cursor hook integration: handles shell, MCP, and file-read hook events with typed normalization and binary allow/deny rendering.
  • Cursor status line (ADR 0113-cursor-status-line): installs an AgentJail protection badge while preserving and restoring a user's existing status command byte-for-byte.
  • Agent decision adapters (ADR 0115-agent-decision-adapters): decision records, logs, and UI state expose policy_action, effective_action, adapter provenance, and translation reason.
  • Cross-agent clean-VM conformance scenario covering installed Claude Code, Codex, and Cursor hook behavior.
  • Bounded decision snapshots: agentjail logs --latest N selects the newest matching SQLite decisions and prints them chronologically, including JSON output.

Changed

  • Codex asks fail closed at PreToolUse (ADR 0117-codex-ask-boundary): because Codex hooks cannot create an approval prompt, AgentJail records canonical ask and renders an explicit effective deny; an ask can never silently continue.
  • Policy inputs normalize at the adapter boundary so file paths, shell commands, MCP calls, session identity, and tool-call correlation have one canonical shape across supported agents.
  • Daemon restart uses the installed supervisor instead of treating restart as daemon process arguments and accidentally starting an unconfigured resolver-default daemon.

Fixed

  • Uninstall target-home isolation: daemon liveness checks now probe the socket under the requested home, rather than the process user's daemon, preventing false aborts that leave hooks and shell RC entries installed.
  • Fail-open recovery reporting: doctor recognizes a later recorded decision as proof that policy evaluation resumed instead of leaving a permanent outage warning.
  • Development deployment: refreshes all multicall role symlinks and the hook binary consistently.
  • Complete non-follow logs: agentjail logs --no-follow now traverses every matching SQLite page instead of stopping after the oldest 1,000 decisions.
  • Truthful sandbox outcomes: successful tool output that merely discusses EPERM or sandbox denials is no longer recorded as an OS-enforced block; Claude failures now use PostToolUseFailure, while Codex attribution requires structured failure evidence.
  • Inert commit-message paths: static, non-expanding git commit -m text no longer triggers the Bash sensitive-path rule, while expansions, other arguments, and chained commands remain protected.

Security

  • Custom rule surface validation (ADR 0116-custom-rule-surface): OPA AST validation accepts only partial candidate entries and rejects resolver/helper declarations, both at policy add and daemon load; invalid manually installed rules are quarantined without weakening the baseline.
  • Canonical/effective action separation prevents protocol limitations from being misreported as policy decisions and keeps final sandbox attribution independent.