+30,
-13
1@@ -11,7 +11,8 @@
2 let
3 pkgs = nixpkgs.legacyPackages.${system};
4
5- # jail package - wraps jail.sh with firejail dependency
6+ # jail package - wraps jail.sh
7+ # NOTE: Requires system-installed firejail and opencode
8 jail = pkgs.stdenvNoCC.mkDerivation {
9 pname = "jail";
10 version = "0.1.0";
11@@ -20,8 +21,6 @@
12
13 nativeBuildInputs = [ pkgs.makeWrapper ];
14
15- buildInputs = [ pkgs.firejail ];
16-
17 installPhase = ''
18 runHook preInstall
19
20@@ -29,15 +28,16 @@
21 cp jail.sh $out/bin/jail
22 chmod +x $out/bin/jail
23
24- # Wrap jail to ensure firejail is in PATH
25+ # Wrap jail to ensure git, coreutils, and which are in PATH
26+ # firejail and opencode must be installed system-wide
27 wrapProgram $out/bin/jail \
28- --prefix PATH : ${pkgs.lib.makeBinPath [ pkgs.firejail pkgs.git pkgs.coreutils pkgs.which ]}
29+ --prefix PATH : ${pkgs.lib.makeBinPath [ pkgs.git pkgs.coreutils pkgs.which ]}
30
31 runHook postInstall
32 '';
33
34 meta = with pkgs.lib; {
35- description = "Run OpenCode in a sandboxed firejail environment";
36+ description = "Run OpenCode in a sandboxed firejail environment (requires system firejail and opencode)";
37 homepage = "https://kilimanjaro.io/vibe";
38 license = licenses.mit;
39 platforms = platforms.linux;
40@@ -45,6 +45,7 @@
41 };
42
43 # vibe package - wraps jail opencode
44+ # NOTE: Requires system-installed firejail and opencode
45 vibe = pkgs.stdenvNoCC.mkDerivation {
46 pname = "vibe";
47 version = "0.1.0";
48@@ -53,7 +54,7 @@
49
50 nativeBuildInputs = [ pkgs.makeWrapper ];
51
52- buildInputs = [ jail pkgs.opencode ];
53+ buildInputs = [ jail ];
54
55 installPhase = ''
56 runHook preInstall
57@@ -62,15 +63,16 @@
58 cp vibe.sh $out/bin/vibe
59 chmod +x $out/bin/vibe
60
61- # Wrap vibe to ensure jail and opencode are in PATH
62+ # Wrap vibe to ensure jail is in PATH
63+ # firejail and opencode must be installed system-wide
64 wrapProgram $out/bin/vibe \
65- --prefix PATH : ${pkgs.lib.makeBinPath [ jail pkgs.opencode ]}
66+ --prefix PATH : ${pkgs.lib.makeBinPath [ jail ]}
67
68 runHook postInstall
69 '';
70
71 meta = with pkgs.lib; {
72- description = "Run OpenCode in a sandboxed environment with optional session token";
73+ description = "Run OpenCode in a sandboxed environment with optional session token (requires system firejail and opencode)";
74 homepage = "https://kilimanjaro.io/vibe";
75 license = licenses.mit;
76 platforms = platforms.linux;
77@@ -87,8 +89,8 @@
78 name = "vibe-dev";
79
80 buildInputs = with pkgs; [
81- opencode
82- firejail
83+ jail
84+ vibe
85 git
86 bash
87 jq
88@@ -98,9 +100,24 @@
89
90 shellHook = ''
91 echo "Vibe development shell"
92- echo "Available tools: opencode, firejail, git, jq, curl"
93+ echo "NOTE: firejail and opencode must be installed system-wide"
94+ echo "Available tools: git, jq, curl, which"
95 echo "Run 'jail' to start the sandbox wrapper"
96 echo "Run 'vibe' to start OpenCode in sandbox (optional: vibe <token>)"
97+
98+ # Check for system dependencies
99+ if ! command -v firejail &> /dev/null; then
100+ echo ""
101+ echo "WARNING: firejail not found in PATH"
102+ echo "Install with: sudo pacman -S firejail (Arch)"
103+ echo " sudo apt install firejail (Debian/Ubuntu)"
104+ fi
105+
106+ if ! command -v opencode &> /dev/null; then
107+ echo ""
108+ echo "WARNING: opencode not found in PATH"
109+ echo "Please install opencode using your package manager"
110+ fi
111 '';
112 };
113 });
M
jail.sh
+24,
-1
1@@ -3,9 +3,28 @@
2 # opencode-sandbox - Run OpenCode in a sandboxed firejail environment
3 # This script runs in firejail with filesystem isolation
4 # while maintaining access to current directory and configuration
5+#
6+# NOTE: This script requires system-installed firejail and opencode.
7+# Install them via your package manager (e.g., pacman, apt, dnf).
8
9 set -euo pipefail
10
11+# Check for required system dependencies
12+if ! command -v firejail &> /dev/null; then
13+ echo "Error: firejail is not installed or not in PATH" >&2
14+ echo "Please install firejail using your system package manager:" >&2
15+ echo " Arch Linux: sudo pacman -S firejail" >&2
16+ echo " Ubuntu/Debian: sudo apt install firejail" >&2
17+ echo " Fedora: sudo dnf install firejail" >&2
18+ exit 1
19+fi
20+
21+if ! command -v opencode &> /dev/null; then
22+ echo "Error: opencode is not installed or not in PATH" >&2
23+ echo "Please install opencode using your system package manager" >&2
24+ exit 1
25+fi
26+
27 # Enable OpenCode experimental support for oxfmt when listed as a package dependency
28 export OPENCODE_EXPERIMENTAL_OXFMT="true"
29 export EDITOR="echo"
30@@ -23,8 +42,12 @@ FIREJAIL_ARGS=(
31 # Use noprofile to avoid default restrictions that might block large directories
32 --noprofile
33
34+ # Terminal handling - required for interactive TUI applications like opencode
35+ --tty # Allocate a pseudo-terminal for TUI apps
36+
37 # Security restrictions
38- --private-tmp # Private /tmp directory
39+ # NOTE: --private-tmp removed to allow opencode access to system /tmp
40+ # for test scratch space and shared temporary files
41 --noroot # Disable su/sudo inside sandbox
42 --caps.drop=all # Drop all capabilities
43 --nonewprivs # Prevent privilege escalation
M
vibe.sh
+25,
-0
1@@ -2,9 +2,34 @@
2
3 # vibe - Run OpenCode in a sandboxed firejail environment
4 # Usage: vibe [<token>] or vibe -s <token>
5+#
6+# NOTE: This script requires system-installed jail (from this package),
7+# firejail, and opencode. Install firejail and opencode via your package manager.
8
9 set -euo pipefail
10
11+# Check for required dependencies
12+if ! command -v jail &> /dev/null; then
13+ echo "Error: jail is not installed or not in PATH" >&2
14+ echo "Please install the jail package from this flake" >&2
15+ exit 1
16+fi
17+
18+if ! command -v firejail &> /dev/null; then
19+ echo "Error: firejail is not installed or not in PATH" >&2
20+ echo "Please install firejail using your system package manager:" >&2
21+ echo " Arch Linux: sudo pacman -S firejail" >&2
22+ echo " Ubuntu/Debian: sudo apt install firejail" >&2
23+ echo " Fedora: sudo dnf install firejail" >&2
24+ exit 1
25+fi
26+
27+if ! command -v opencode &> /dev/null; then
28+ echo "Error: opencode is not installed or not in PATH" >&2
29+ echo "Please install opencode using your system package manager" >&2
30+ exit 1
31+fi
32+
33 # Handle different argument patterns:
34 # - vibe (no args) -> jail opencode
35 # - vibe <token> -> jail opencode -s <token>