1 files changed,
+15,
-3
M
jail.sh
M
jail.sh
+15,
-3
1@@ -42,9 +42,6 @@ FIREJAIL_ARGS=(
2 # Use noprofile to avoid default restrictions that might block large directories
3 --noprofile
4
5- # Terminal handling - required for interactive TUI applications like opencode
6- --tty # Allocate a pseudo-terminal for TUI apps
7-
8 # Security restrictions
9 # NOTE: --private-tmp removed to allow opencode access to system /tmp
10 # for test scratch space and shared temporary files
11@@ -70,6 +67,21 @@ FIREJAIL_ARGS=(
12 --read-write="$HOME/.agents" # skills
13 --whitelist="$HOME/.ssh" # to troubleshoot Nix depoyment
14 --read-only="$HOME/.ssh"
15+
16+ # Terminal access - required for interactive TUI applications
17+ --whitelist=/dev/tty # Allow access to controlling terminal
18+ --read-write=/dev/tty
19+
20+ # Device access required for Bun/JavaScriptCore
21+ --whitelist=/dev/shm # Shared memory required by JSC
22+ --read-write=/dev/shm
23+ --whitelist=/dev/urandom # Randomness required for crypto/timing
24+ --read-only=/dev/urandom
25+ --whitelist=/dev/random # Randomness fallback
26+ --read-only=/dev/random
27+ --whitelist=/dev/null # Standard I/O
28+ --whitelist=/dev/zero # Memory allocation helpers
29+ --whitelist=/dev/full
30 )
31
32 # Blacklist specific tools resident in /usr/bin environment that you absolutely don't want