Skip to content

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 18:20
· 11 commits to main since this release
v0.2.0
28ac4da

aibox 0.2.0

Configuration

NixOS system agent, Nix, and certificate mounts now include their matching
/etc/static subdirectories. Remove downstream source patches for
/etc/static/codex. The complete host /etc/static directory is not mounted.

Use repeatable --require-config PATH to stop startup when a required system
policy file is missing or unreadable inside the sandbox. The option accepts
files below the existing fixed system agent directories and adds no mounts.

Environment

--hostname NAME sets the display hostname. The default remains aibox.
Replace hostname-based detection with [ "${AIBOX:-}" = 1 ]. The marker selects
script behavior; it does not prove isolation or grant authority.

XDG_RUNTIME_DIR now points to private mode-0700 tmpfs storage at
/run/aibox/runtime. It was previously unset. Remove wrappers that create a
runtime directory only for sandbox use. Each new sandbox starts with empty
runtime storage; persistent agent mounts are unchanged.

Explicit SSL_CERT_FILE and NIX_SSL_CERT_FILE values must name readable regular
files inside the sandbox. Empty values now stop startup. Unset variables retain
the client's defaults. Use a Nix store certificate bundle in service environments.

Services and Installation

The NixOS service example is tested with real Bubblewrap, NixOS policy links,
two accounts, restart checks, and a local TLS server. It uses
ProtectHostname=private and disables ProtectKernelLogs and
ProtectKernelTunables to permit sandbox setup.

Versioned GitHub releases are published after CI passes for the version tag.
Use github:ruifm/aibox/v0.2.0 for installation or a flake input, and retain
the exact revision and NAR hash in the flake lock. Session startup does not
check for or install updates.