The login banner on subopi/pfvsvrpi systems was bleeding into the sudo
check output, making SUDOOK results look garbled and broken. Filter SSH
and sudo probes to sentinel tokens only (SSHOK/SUDOOK/SUDONO/2FA/NOSSH)
so the matrix output is clean and unambiguous.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
699 B
699 B
WORKING.md — Active Session Tracker
Agent work only. The human decides when it's done. A commit is blocked while any task below remains unchecked.
Current Tasks
(all done — session complete)
- Wire guest-agent-as-access ban: strip vm-guest from remote.sh, add check-rules.sh rule #11, codify in AGENTS.md [#403]
- Convert vm-validation.sh + perf-matrix.sh + deploy-tuned-guests.sh from guest-agent to SSH
- Rewrite bootstrap-all.sh for remaining 8 locked-out systems
- Ban harness question-tool in meta (TSYSGroupAIOS) + project AGENTS.md
- Update Redmine #403 + Discourse #298 audit log
- Final access probe: 63/67 SSH+sudo working; 3 blocked on unrelated work