audit(multidrive): §8 Outcome — FIXED via sudoers completeness pass; controller-swap surfaced

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EPZ4GJ8L5Jqf8UiPwbn1kt
This commit is contained in:
2026-06-29 16:06:41 +02:00
parent 66a001de0b
commit c6bae9515a
@@ -182,3 +182,30 @@ drop any submount.
*No secrets recorded (the per-guest token used for the read-only `/disks` check is stored
out-of-band; never printed).*
---
## 8. Outcome — FIXED 2026-06-29 (supervised sudoers completeness pass)
A full audit of every privileged command vs the allowlist (felhom-agent `55888e5`; full table in
`felhom-agent/REPORT.md`) closed the gaps. **Sudoers-only, no binary change, no agent restart.**
Grants added: `lxc-info -n [0-9]* -p -H` (the root-cause fix) + `mount --make-private
/mnt/felhom-drives` → FELHOM_INTERMEDIARY; `systemctl restart dnsmasq` → FELHOM_DNSMASQ; `pct set
[0-9]* -onboot 1` → FELHOM_PROVISION; `pct reboot [0-9]*` → FELHOM_GUESTHOOK. Deployed via the
install-script mechanism (`visudo -cf``install -m 0440 -o root -g root` → re-validate `/etc/sudoers`).
**Validation (all pass):** `sudo -n lxc-info -n 9201 -p -H` now returns PID `2137736`; agent `/disks`
reports `bound_under_parent=true` for **both** felhom-usb + felhom-flash; the controller gate logged
`drive RETURNED … re-attached + restarted` for both and **nextcloud auto-restarted** (held healthy,
zero `drive ABSENT` after); the real UI (`/settings`) shows **both drives Aktív concurrently**. Symptom
gone.
**Surfaced, NOT fixed (operator decision):** `GuestExec`'s general `pct exec <vmid> -- …`
(controller-swap / managed auto-update) needs arbitrary root-in-guest — **not granted; controller-swap
is broken under the non-root agent** until a narrow trust path is decided. **Deferred:** `sensors -j`
(no caller + lm-sensors not installed). **Left as-is:** the §4 host-side doubling (re-isolating the
live parent would orphan the working guest slave — fixed grant takes effect on the next clean host
boot). The §7 "guest_attached / pct config" note is **resolved**: `GuestConfig` is a Proxmox **API**
call, not a sudo CLI command, so `guest_attached=false` is not a sudoers gap (and is benign in the
intermediary model).