rclone: rclone v1.75.1 (lab; the provider runs its own version)
T1 DELETE snapshots/<existing>         -> 403 Forbidden 
T2 POST over existing snapshots/<id>   -> 403 Forbidden 
T3 POST over existing config           -> 403 Forbidden 
T4 DELETE data/<existing pack>         -> 403 Forbidden 
T5 POST ../.ssh/authorized_keys        -> 400 Bad Request 
T6 POST %2e%2e/.ssh/authorized_keys    -> 400 Bad Request 
T7 POST data/..%2f..%2f.ssh/x          -> 400 Bad Request 
T8 POST a NEW keys/aaaa                -> 200 
T9 POST arbitrary top-level foo        -> 200 
T10 DELETE the new keys/aaaa           -> 403 Forbidden 
T11 POST a NEW locks/bbbb then DELETE  -> 200  / 200 
after: snapshot present: yes; config unchanged: yes; authorized_keys unchanged: yes; stray files:
/home/sub:
spike-repo

/home/sub/.ssh:
authorized_keys
/home/sub/spike-repo:
config
data
foo
index
keys
locks
snapshots

/home/sub/spike-repo/keys:
aaaa
f651e7eec6b06d2594a748cb05cfaca39f7488092af5c4da5c332a7c3a7a8e5e

/home/sub/spike-repo/locks:
