forked from heavy-duty/rig
Round-2 convergence (codex + claude-bot): sshd enforces the group directives against the candidate's ACTUAL membership, and the gate read only the *Users pair — an admin outside 'AllowGroups sudo' still reached ADMIN_OK=1, and root closed on a false proof. The gate now resolves id -Gn and judges both group directives with the *Users discipline: DenyGroups flags on a held-group literal or ANY pattern/host-qualified token; AllowGroups, when set, passes only on a literal token naming a held group (a pattern that would admit proves nothing — over-refusing stays the safe error). id failing yields no groups, which makes a set AllowGroups flag: fail closed there too. Both requested regressions ride the sourced lib (unmet AllowGroups, DenyGroups naming a held group) plus the pattern/pass cases, and grep guards pin the shipped gate to the verdicts and to real membership. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cli.sh | ||
| db-integration.sh | ||