`sshd -t` folds two questions into one exit code — is the merged config parseable, and is the privilege-separation directory there. Both call sites ran it as `sshd -t 2>/dev/null` and read any non-zero exit as the first question's answer, discarding the line that named the second. Bootstrap aborted with "sshd rejects the merged config", a verdict sshd never reached, and sent the operator to audit /etc/ssh files that were never broken. /run is a tmpfs and /run/sshd is ssh.service's RuntimeDirectory, so it is legitimately absent under socket activation on a box whose SSH door is serving connections normally. Classification is now a pure, sourceable sshd_privsep_gap: the status is the verdict, the text only classifies a failure, so a passing sshd -t is never diverted. sshd_config_ok repairs the gap with an idempotent install -d and retests once. A genuine parse refusal still refuses and the rollback is untouched. Refusals now carry sshd's own stderr. users-close-root had the identical three lines and now reaches the shared judgement through lib/sshd.sh instead of keeping a second copy of it. Fixes #92 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cli.sh | ||
| db-integration.sh | ||
| labels-reconcile.sh | ||
| release.sh | ||