forked from heavy-duty/rig
`sshd -t` folds two questions into one exit code — is the merged config parseable, and is the privilege-separation directory there. Both call sites ran it as `sshd -t 2>/dev/null` and read any non-zero exit as the first question's answer, discarding the line that named the second. Bootstrap aborted with "sshd rejects the merged config", a verdict sshd never reached, and sent the operator to audit /etc/ssh files that were never broken. /run is a tmpfs and /run/sshd is ssh.service's RuntimeDirectory, so it is legitimately absent under socket activation on a box whose SSH door is serving connections normally. Classification is now a pure, sourceable sshd_privsep_gap: the status is the verdict, the text only classifies a failure, so a passing sshd -t is never diverted. sshd_config_ok repairs the gap with an idempotent install -d and retests once. A genuine parse refusal still refuses and the rollback is untouched. Refusals now carry sshd's own stderr. users-close-root had the identical three lines and now reaches the shared judgement through lib/sshd.sh instead of keeping a second copy of it. Fixes #92 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| lib | ||
| bootstrap-tenant.sh | ||
| bootstrap.sh | ||
| coolify-backup-install.sh | ||
| coolify-install.sh | ||
| db.sh | ||
| manifest.sh | ||
| platform.sh | ||
| runner-install.sh | ||
| runner-remove.sh | ||
| runner-repoint.sh | ||
| runner-status.sh | ||
| users-apply.sh | ||
| users-close-root.sh | ||
| users-status.sh | ||