== RED-PROOF F1 (mount units): felhom-priv-apply stops checking Where
test_U3_bind_over_sudoers_dir (__main__.Refuses.test_U3_bind_over_sudoers_dir) ... ok
test_U3_name_must_match_where (__main__.Refuses.test_U3_name_must_match_where) ... ok
test_U3_network_outside_drives (__main__.Refuses.test_U3_network_outside_drives) ... ok
test_U3_traversal_in_where (__main__.Refuses.test_U3_traversal_in_where) ... ok
OK

== RED-PROOF F2 (WireGuard): felhom-priv-apply allows any key
FAIL: test_W1_postup (__main__.Refuses.test_W1_postup)
FAILED (failures=1)

== RED-PROOF F3 (self-update, root side): felhom-os-apply agent_update skips the signature
FAILED (errors=1)

== RED-PROOF F4 (self-update, agent side): the agent calls felhom-selfupdate-guarded apply itself again
--- FAIL: TestExecutor_HappyPath (0.00s)
    executor_test.go:111: execute: agent_update: the root wrapper did not apply it: <nil> (report: ; stderr: )
FAIL

== RED-PROOF F5 (guest hook): SnippetReady accepts any content
--- FAIL: TestSnippetReady (0.00s)
    install_test.go:43: a hook with other content read as ready
FAIL

== RED-PROOF F6 (shared parent): the agent installs the boot script from /tmp again when it differs
--- FAIL: TestSharedParentBoot_NeverInstalls (0.00s)
    intermediary_install_test.go:54: both missing: the agent ran [[install -m 0755 -- /tmp/felhom-shared-parent-x.sh /tmp/TestSharedParentBoot_NeverInstalls2355530825/001/felhom-shared-parent.sh]] — it must install nothing (R-861)
    intermediary_install_test.go:54: script differs: the agent ran [[install -m 0755 -- /tmp/felhom-shared-parent-x.sh /tmp/TestSharedParentBoot_NeverInstalls2355530825/002/felhom-shared-parent.sh]] — it must install nothing (R-861)
    intermediary_install_test.go:54: unit missing: the agent ran [[install -m 0755 -- /tmp/felhom-shared-parent-x.sh /tmp/TestSharedParentBoot_NeverInstalls2355530825/003/felhom-shared-parent.sh]] — it must install nothing (R-861)

== RED-PROOF F7 (escrow, root read): a staged file is read with os.ReadFile (follows a symlink)
--- FAIL: TestAttach_RefusesASymlink (0.00s)
    r861_staged_read_test.go:24: a symlinked staged file was read: ok=true err=<nil> value-set=true
FAIL

== RED-PROOF F8 (network shares): nosuid,nodev dropped from the NFS options
--- FAIL: TestPrivApply_AcceptsTheRenderedUnits (0.35s)
    r861_privapply_contract_test.go:31: media .mount: REFUSED [U5] mnt-felhom\x2ddrives-media.mount: a network share must carry nosuid,nodev
FAIL

== RED-PROOF F9 (the exact patterns): the v0.145.0 sudoers under the injection test
injections the old file allows (Go matcher): 23

== restored — the same tests green
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/selfupdate	(cached)
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/guesthook	(cached)
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/localapi	(cached)
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/escrow	(cached)
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/storage	0.474s
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/capability	0.177s
OK
OK

== RED-PROOF F1 (re-run): the first run did NOT convict — the name check (escape(Where)==name) masked it. The test now uses the
   pair that only the Where rule stops: name mnt-..-etc.mount + Where=/mnt/../etc (= /etc). Mutation: stop checking Where
FAIL: test_U3_traversal_in_where (__main__.Refuses.test_U3_traversal_in_where)
FAILED (failures=1)

== RED-PROOF F3 (re-run, clean assertion): felhom-os-apply skips the signature
FAIL: test_a_bad_signature_never_reaches_the_wrapper (__main__.AgentUpdate.test_a_bad_signature_never_reaches_the_wrapper)
AssertionError: None is not true : a job whose signature does not verify was NOT refused: {'agent_update': {'sha256': 'd76b02acf626ce399da7e0a9e17b35563227a4831e14f5edca4ab7cf89eb2c79', 'version': '0.146.0', 'wrapper': '', 'wrapper_rc': 0}, 'layer': 'host', 'mode': 'agent_update', 'pass_seconds': 0.0, 'refused': None, 'release_id': 'agent-0.146.0', 'vmid': 0}
FAILED (failures=1)

== restored
OK
OK

=== Review findings 2026-10-05 (background security review of commit 6ab1e7c) — fixed in v0.146.1, each red-proved
== RED-PROOF S1 (TOCTOU): the wrapper gets the agent's path again (hash, then copy by path)
FAIL: test_signed_update_flips_and_burns_the_nonce (__main__.AgentUpdate.test_signed_update_flips_and_burns_the_nonce)
FAILED (failures=1)
== RED-PROOF S1b: the A/B wrapper accepts the agent's staging dir again
FAIL: test_the_agents_staging_dir_is_refused (__main__.SelfupdateWrapperConfinement.test_the_agents_staging_dir_is_refused)
FAILED (failures=1)
== RED-PROOF S2 (allowlist escape): [Unit] accepts Wants=/Requires=/Before= again
FAIL: test_U2_wants_starts_another_unit (__main__.Refuses.test_U2_wants_starts_another_unit)
FAILED (failures=1)
== RED-PROOF S3 (path traversal): open the whole path with O_NOFOLLOW only
--- FAIL: TestAttach_RefusesASymlinkedDirectory (0.00s)
    r861_staged_read_test.go:54: a key behind a symlinked directory was read: ok=true err=<nil>
FAIL
== restored
OK
OK
ok  	gitea.dooplex.hu/admin/felhom-agent/internal/escrow	0.008s
