fix bun crashes with additional access to device environment
1 files changed,  +15, -3
M jail.sh
+15, -3
 1@@ -42,9 +42,6 @@ FIREJAIL_ARGS=(
 2     # Use noprofile to avoid default restrictions that might block large directories
 3     --noprofile
 4 
 5-    # Terminal handling - required for interactive TUI applications like opencode
 6-    --tty                      # Allocate a pseudo-terminal for TUI apps
 7-
 8     # Security restrictions
 9     # NOTE: --private-tmp removed to allow opencode access to system /tmp
10     # for test scratch space and shared temporary files
11@@ -70,6 +67,21 @@ FIREJAIL_ARGS=(
12     --read-write="$HOME/.agents" # skills
13     --whitelist="$HOME/.ssh" # to troubleshoot Nix depoyment
14     --read-only="$HOME/.ssh"
15+
16+    # Terminal access - required for interactive TUI applications
17+    --whitelist=/dev/tty        # Allow access to controlling terminal
18+    --read-write=/dev/tty
19+
20+    # Device access required for Bun/JavaScriptCore
21+    --whitelist=/dev/shm        # Shared memory required by JSC
22+    --read-write=/dev/shm
23+    --whitelist=/dev/urandom    # Randomness required for crypto/timing
24+    --read-only=/dev/urandom
25+    --whitelist=/dev/random     # Randomness fallback
26+    --read-only=/dev/random
27+    --whitelist=/dev/null       # Standard I/O
28+    --whitelist=/dev/zero       # Memory allocation helpers
29+    --whitelist=/dev/full
30 )
31 
32 # Blacklist specific tools resident in /usr/bin environment that you absolutely don't want