2026-05-03-allow-flag-cli-design.md

CLI –allow Flag Support for jail.sh and vibe.sh

Summary

Add --allow <dir> flag support to jail.sh and vibe.sh scripts to enable users to whitelist additional directories with read/write access in the firejail sandbox.

Current Behavior

Proposed Behavior

jail.sh

jail [--allow <dir>]... <command> [args...]

Examples: - jail opencode - Run opencode with default whitelist - jail --allow /tmp opencode - Add /tmp to whitelist - jail --allow /data --allow /home/projects bash - Add multiple directories, run bash - jail --allow /mnt opencode -s token123 - Combine with command args

vibe.sh

vibe [--allow <dir>]... [<session_token>]

Examples: - vibe - Run opencode with default whitelist - vibe --allow /tmp - Add /tmp to whitelist - vibe --allow /data --allow /projects token123 - Multiple dirs + session token

Design Decisions

  1. One directory per flag: Each --allow flag takes exactly one directory argument
  2. Flags before positional args: All --allow flags must come before the command (jail) or token (vibe)
  3. No read-only option: All allowed directories get read/write access
  4. getopts parsing: Use bash’s getopts for clean, POSIX-compliant argument parsing

Technical Details

jail.sh Changes

vibe.sh Changes

Edge Cases

Success Criteria