== R-861 real-sudo proof, sudo 1.9.16p2 (debian:trixie throwaway container on DooPlex, 2026-10-05T09:58:38Z); 'sudo -l -U felhom-agent <argv>' per case

-- NEW sudoers (agent v0.146.0): every capability must be ALLOW, every attack DENY
ok   ALLOW '/usr/bin/lxc-info' '-n' '9201' '-p' '-H'
ok   ALLOW '/usr/bin/mount' '--bind' '/mnt/felhom-drives' '/mnt/felhom-drives'
ok   ALLOW '/usr/bin/mount' '--make-shared' '/mnt/felhom-drives'
ok   ALLOW '/usr/bin/mount' '--make-private' '/mnt/felhom-drives'
ok   ALLOW '/usr/bin/mount' '--bind' '/mnt/felhom-usb/felhom-data' '/mnt/felhom-drives/felhom-usb'
ok   ALLOW '/usr/bin/umount' '/mnt/felhom-drives/felhom-usb'
ok   ALLOW '/usr/bin/mkdir' '-p' '/mnt/felhom-drives'
ok   ALLOW '/usr/bin/mkdir' '-p' '/mnt/felhom-drives/felhom-usb'
ok   ALLOW '/usr/bin/mkdir' '-p' '/mnt/felhom-usb/felhom-data'
ok   ALLOW '/usr/bin/chown' '100000:100000' '/mnt/felhom-usb/felhom-data'
ok   ALLOW '/usr/bin/systemctl' 'enable' 'felhom-shared-parent.service'
ok   ALLOW '/usr/sbin/pct' 'set' '9201' '-mp8' '/mnt/felhom-drives,mp=/mnt/felhom-drives'
ok   ALLOW '/usr/sbin/blkid' '-p' '-o' 'export' '/dev/sda'
ok   ALLOW '/usr/bin/lsblk' '-J' '-o' 'NAME,FSTYPE,PTTYPE,MOUNTPOINT' '/dev/sda'
ok   ALLOW '/usr/local/sbin/felhom-mkfs-guarded' '/dev/sda' 'ext4'
ok   ALLOW '/usr/local/sbin/felhom-mkfs-guarded' '/dev/sda' 'xfs'
ok   ALLOW '/usr/sbin/smartctl' '-a' '-j' '/dev/sda'
ok   ALLOW '/usr/sbin/lvs' '--reportformat' 'json' '--units' 'b' '-o' 'lv_name,data_percent,metadata_percent' '--' 'pve/data'
ok   ALLOW '/usr/local/sbin/felhom-priv-apply' 'unit' 'mnt-felhom\x2dx.mount'
ok   ALLOW '/usr/bin/systemctl' 'daemon-reload'
ok   ALLOW '/usr/bin/systemctl' 'enable' '--now' '--' 'mnt-felhom\x2dx.mount'
ok   ALLOW '/usr/bin/systemctl' 'disable' '--' 'mnt-felhom\x2dx.mount'
ok   ALLOW '/usr/bin/systemctl' 'stop' '--' 'mnt-felhom\x2dx.mount'
ok   ALLOW '/usr/bin/systemctl' 'reset-failed' '--' 'mnt-felhom\x2ddrives-media.automount'
ok   ALLOW '/usr/bin/rmdir' '/mnt/felhom-drives/media'
ok   ALLOW '/usr/bin/systemctl' 'start' 'networking.service'
ok   ALLOW '/usr/bin/chown' '-R' '100000:100000' '/var/lib/felhom-agent/guests/9201'
ok   ALLOW '/usr/sbin/pct' 'set' '9201' '-mp0' '/var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1'
ok   ALLOW '/usr/sbin/pct' 'set' '9201' '-onboot' '1'
ok   ALLOW '/usr/sbin/pct' 'set' '9201' '--hookscript' 'local:snippets/felhom-guest-hook.sh'
ok   ALLOW '/usr/sbin/pct' 'set' '9201' '--delete' 'mp0'
ok   ALLOW '/usr/sbin/pct' 'reboot' '9201'
ok   ALLOW '/usr/bin/apt-get' 'install' '-y' '-q' 'dnsmasq'
ok   ALLOW '/usr/local/sbin/felhom-priv-apply' 'dnsmasq' '/tmp/felhom-resolver-123456789.conf' 'felhom-x.conf'
ok   ALLOW '/usr/bin/systemctl' 'enable' '--now' 'dnsmasq'
ok   ALLOW '/usr/local/sbin/felhom-os-apply' '--plan' '/var/lib/felhom-agent/os/plan-x.json'
ok   ALLOW '/usr/bin/systemctl' 'reload' 'dnsmasq'
ok   ALLOW '/usr/bin/systemctl' 'restart' 'dnsmasq'
ok   ALLOW '/usr/bin/rm' '-f' '/etc/dnsmasq.d/felhom-x.conf'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'ip' '-4' '-o' 'addr' 'show' 'dev' 'eth0'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'docker' 'exec' 'felhom-controller' 'cat' '/opt/docker/felhom-controller/controller.yaml'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'ip' 'route' 'show' 'default'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'cat' '/etc/network/interfaces'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'pgrep' '-x' 'dhclient'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'dhclient' '-pf' '/run/dhclient.eth0.pid' '-lf' '/var/lib/dhcp/dhclient.eth0.leases' 'eth0'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'cat' '/etc/felhom-controller-image'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'docker' 'image' 'inspect' 'gitea.dooplex.hu/admin/felhom-controller:0.0.0'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'docker' 'inspect' '-f' '{{.State.Running}}' 'felhom-controller'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'systemctl' 'restart' 'felhom-controller-bootstrap.service'
ok   ALLOW '/usr/sbin/pct' 'exec' '9201' '--' 'tee' '/etc/felhom-controller-image'
ok   ALLOW '/usr/sbin/pct' 'unlock' '9201'
ok   ALLOW '/usr/bin/apt-get' 'install' '-y' '-q' 'wireguard-tools'
ok   ALLOW '/usr/local/sbin/felhom-priv-apply' 'wg'
ok   ALLOW '/usr/bin/systemctl' 'enable' '--now' 'wg-quick@wg-felhom'
ok   ALLOW '/usr/bin/systemctl' 'restart' 'wg-quick@wg-felhom'
ok   ALLOW '/usr/bin/systemctl' 'disable' '--now' 'wg-quick@wg-felhom'
ok   ALLOW '/usr/bin/wg' 'show' 'wg-felhom' 'latest-handshakes'
ok   ALLOW '/usr/local/sbin/felhom-pbs-apply' 'create' 'felhom-pbs' '10.77.0.1' 'felhom-offsite' 'ns0' 'felhom@pbs!ns0' '00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00' '/etc/pve/priv/storage'
ok   ALLOW '/usr/local/sbin/felhom-pbs-apply' 'reconcile' 'felhom-pbs' '10.77.0.1' 'ns0' 'felhom@pbs!ns0' '00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00' '/etc/pve/priv/storage'
ok   ALLOW '/usr/local/sbin/felhom-pbs-apply' 'grant' 'felhom-pbs'
ok   ALLOW '/usr/local/sbin/felhom-pbs-apply' 'read' 'felhom-pbs' '/etc/pve/priv/storage'
ok   ALLOW '/usr/local/bin/felhom-agent' '--config' '/etc/felhom-agent/agent.json' '--selftest=escrow-create' '--upload' '--output=json'
ok   ALLOW '/usr/local/sbin/felhom-selfupdate-guarded' 'commit'
ok   ALLOW '/usr/local/sbin/felhom-selfupdate-guarded' 'rollback'
ok   DENY /usr/sbin/pct set 9201 --dev0 /dev/sda -onboot 1
ok   DENY /usr/sbin/pct set 9201 --dev0 /dev/sda -mp8 /mnt/felhom-drives
ok   DENY /usr/sbin/pct set 9201 --delete mp0 --dev0 /dev/sda
ok   DENY /usr/sbin/pct set 9201 -mp0 /var/lib/felhom-agent/guests/9201/bootstrap,mp=/x --dev0 /dev/sda
ok   DENY /usr/bin/mount --bind /mnt/../var/lib/felhom-agent/x/felhom-data /mnt/felhom-drives/x
ok   DENY /usr/bin/mount --bind /mnt/a/felhom-data /mnt/felhom-drives/../../etc/sudoers.d
ok   DENY /usr/bin/umount /mnt/felhom-drives/x /
ok   DENY /usr/bin/chown 100000:100000 /mnt/a/felhom-data /etc/shadow
ok   DENY /usr/bin/mkdir -p /mnt/felhom-drives/x /etc/systemd/system/evil.mount
ok   DENY /usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/units/x.mount /etc/systemd/system/etc-sudoers.d.mount
ok   DENY /usr/bin/install -m 0755 -- /tmp/felhom-guest-hook-1.sh /var/lib/vz/snippets/felhom-guest-hook.sh
ok   DENY /usr/bin/install -m 0755 -- /tmp/felhom-shared-parent-1.sh /usr/local/sbin/felhom-shared-parent.sh
ok   DENY /usr/bin/install -m 0644 /tmp/felhom-resolver-1.conf /etc/dnsmasq.d/felhom-x.conf
ok   DENY /usr/bin/install -o root -g root -m 0600 -- /var/lib/felhom-agent/wg/wg-felhom.conf /etc/wireguard/wg-felhom.conf
ok   DENY /usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/felhom-sshd/sshd_config /etc/felhom-sshd/sshd_config
ok   DENY /usr/local/sbin/felhom-selfupdate-guarded apply /var/lib/felhom-agent/selfupdate/felhom-agent-9.9.9 0000000000000000000000000000000000000000000000000000000000000000
ok   DENY /usr/bin/systemctl enable --now -- mnt-hdd_1.mount evil.service
ok   DENY /usr/bin/systemctl enable --now -- etc-sudoers.d.mount
ok   DENY /usr/bin/rm -f /etc/systemd/system/mnt-felhomx /etc/passwd
ok   DENY /usr/bin/rm -f /etc/dnsmasq.d/felhom-x.conf /etc/shadow
ok   DENY /usr/bin/rmdir /mnt/felhom-drives/x /etc
ok   DENY /usr/sbin/nft add element inet felhom_oob operator_ips { 10.77.0.250 } ';' flush ruleset
ok   DENY /usr/sbin/smartctl -a -j /dev/sda -s off
ok   DENY /usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data --config x
ok   DENY /usr/sbin/pct exec 9201 --keep-env -- docker inspect -f x felhom-controller
ok   DENY /usr/sbin/pct unlock 9201 --whatever
ok   DENY /usr/local/sbin/felhom-priv-apply unit ../../etc/x.mount
ok   DENY /usr/local/sbin/felhom-priv-apply dnsmasq /etc/shadow felhom-x.conf
ok   DENY /usr/local/sbin/felhom-priv-apply wg /etc/shadow
rc=0

-- OLD sudoers (agent v0.145.0), the same attacks (this side is the red-proof: 'FAIL want=ALLOW got=DENY' means the OLD file already refused that one; 'ok ALLOW' means the old file let it through)
ok   ALLOW /usr/sbin/pct set 9201 --dev0 /dev/sda -onboot 1
ok   ALLOW /usr/sbin/pct set 9201 --dev0 /dev/sda -mp8 /mnt/felhom-drives
ok   ALLOW /usr/sbin/pct set 9201 --delete mp0 --dev0 /dev/sda
ok   ALLOW /usr/sbin/pct set 9201 -mp0 /var/lib/felhom-agent/guests/9201/bootstrap,mp=/x --dev0 /dev/sda
ok   ALLOW /usr/bin/mount --bind /mnt/../var/lib/felhom-agent/x/felhom-data /mnt/felhom-drives/x
ok   ALLOW /usr/bin/mount --bind /mnt/a/felhom-data /mnt/felhom-drives/../../etc/sudoers.d
ok   ALLOW /usr/bin/umount /mnt/felhom-drives/x /
FAIL want=ALLOW got=DENY :: /usr/bin/chown 100000:100000 /mnt/a/felhom-data /etc/shadow
ok   ALLOW /usr/bin/mkdir -p /mnt/felhom-drives/x /etc/systemd/system/evil.mount
ok   ALLOW /usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/units/x.mount /etc/systemd/system/etc-sudoers.d.mount
ok   ALLOW /usr/bin/install -m 0755 -- /tmp/felhom-guest-hook-1.sh /var/lib/vz/snippets/felhom-guest-hook.sh
ok   ALLOW /usr/bin/install -m 0755 -- /tmp/felhom-shared-parent-1.sh /usr/local/sbin/felhom-shared-parent.sh
ok   ALLOW /usr/bin/install -m 0644 /tmp/felhom-resolver-1.conf /etc/dnsmasq.d/felhom-x.conf
ok   ALLOW /usr/bin/install -o root -g root -m 0600 -- /var/lib/felhom-agent/wg/wg-felhom.conf /etc/wireguard/wg-felhom.conf
ok   ALLOW /usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/felhom-sshd/sshd_config /etc/felhom-sshd/sshd_config
ok   ALLOW /usr/local/sbin/felhom-selfupdate-guarded apply /var/lib/felhom-agent/selfupdate/felhom-agent-9.9.9 0000000000000000000000000000000000000000000000000000000000000000
FAIL want=ALLOW got=DENY :: /usr/bin/systemctl enable --now -- mnt-hdd_1.mount evil.service
ok   ALLOW /usr/bin/systemctl enable --now -- etc-sudoers.d.mount
ok   ALLOW /usr/bin/rm -f /etc/systemd/system/mnt-felhomx /etc/passwd
FAIL want=ALLOW got=DENY :: /usr/bin/rm -f /etc/dnsmasq.d/felhom-x.conf /etc/shadow
ok   ALLOW /usr/bin/rmdir /mnt/felhom-drives/x /etc
ok   ALLOW /usr/sbin/nft add element inet felhom_oob operator_ips { 10.77.0.250 } ';' flush ruleset
ok   ALLOW /usr/sbin/smartctl -a -j /dev/sda -s off
ok   ALLOW /usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data --config x
ok   ALLOW /usr/sbin/pct exec 9201 --keep-env -- docker inspect -f x felhom-controller
ok   ALLOW /usr/sbin/pct unlock 9201 --whatever
FAIL want=ALLOW got=DENY :: /usr/local/sbin/felhom-priv-apply unit ../../etc/x.mount
FAIL want=ALLOW got=DENY :: /usr/local/sbin/felhom-priv-apply dnsmasq /etc/shadow felhom-x.conf
FAIL want=ALLOW got=DENY :: /usr/local/sbin/felhom-priv-apply wg /etc/shadow
rc=1
