Releases: ruifm/aibox
Release list
v0.3.0
aibox 0.3.0
Mounts and sockets
Use repeatable --ro-mount PATH and --rw-mount PATH for selected existing
files, directories, or Unix sockets outside the workspace. Aibox resolves each
path and mounts it at the same absolute path. It rejects missing paths and
mounts that overlap the workspace, protected sandbox paths, or other mounts.
The default mount policy is unchanged.
Two boxes can share one selected socket without sharing its parent directory.
The box that creates the socket needs a writable mount of a dedicated directory;
clients can mount only the socket. Socket mount mode does not limit service
requests.
Desktop access
--keyring permits access to the host Secret Service through a filtered D-Bus
proxy. It can read or change all secrets that the same host account may access.
--wayland shares one Wayland socket for clipboard use; it also permits other
Wayland operations. --browser sends URL requests to the host OpenURI portal
and permits introspection on that portal object.
The flags are independent and opt-in. The host D-Bus socket stays hidden.
The OpenURI portal does not accept file:// URLs and reports its final result
after the request call. A successful helper exit confirms only that the request
was sent. Browser login callbacks use the shared host network; remote sessions
may need loopback forwarding.
Startup and compatibility
Startup errors now name inaccessible required policy and certificate paths and
give focused hints for common Bubblewrap failures under systemd. Application
exit codes are unchanged. The Nix package adds the desktop proxy and client
tools. Direct-script installs need xdg-dbus-proxy and gdbus for keyring or
browser access; Wayland clipboard commands need wl-clipboard.
No existing flag was removed. No new host mounts or desktop services are enabled
without an explicit flag.
v0.2.0
aibox 0.2.0
Configuration
NixOS system agent, Nix, and certificate mounts now include their matching
/etc/static subdirectories. Remove downstream source patches for
/etc/static/codex. The complete host /etc/static directory is not mounted.
Use repeatable --require-config PATH to stop startup when a required system
policy file is missing or unreadable inside the sandbox. The option accepts
files below the existing fixed system agent directories and adds no mounts.
Environment
--hostname NAME sets the display hostname. The default remains aibox.
Replace hostname-based detection with [ "${AIBOX:-}" = 1 ]. The marker selects
script behavior; it does not prove isolation or grant authority.
XDG_RUNTIME_DIR now points to private mode-0700 tmpfs storage at
/run/aibox/runtime. It was previously unset. Remove wrappers that create a
runtime directory only for sandbox use. Each new sandbox starts with empty
runtime storage; persistent agent mounts are unchanged.
Explicit SSL_CERT_FILE and NIX_SSL_CERT_FILE values must name readable regular
files inside the sandbox. Empty values now stop startup. Unset variables retain
the client's defaults. Use a Nix store certificate bundle in service environments.
Services and Installation
The NixOS service example is tested with real Bubblewrap, NixOS policy links,
two accounts, restart checks, and a local TLS server. It uses
ProtectHostname=private and disables ProtectKernelLogs and
ProtectKernelTunables to permit sandbox setup.
Versioned GitHub releases are published after CI passes for the version tag.
Use github:ruifm/aibox/v0.2.0 for installation or a flake input, and retain
the exact revision and NAR hash in the flake lock. Session startup does not
check for or install updates.