2f97ce31dd
Validates a second sshd (own port/config/host-key/AuthorizedKeysFile/unit) as Felhom's OOB entry point, coexisting with the customer's stock sshd on :22: robust port probe-and-claim (skip/idempotent/loud-exhaustion), four-axis coexistence independence, tunnel-scoped nft, reload-gate robustness, operator identity isolated via AuthorizedKeysFile location, clean uninstall. #1 TASK constraint (caught live): a second sshd unit must NEVER declare RuntimeDirectory=sshd — it removes the SHARED /run/sshd privsep dir on stop and takes the stock sshd down (LAN SSH lockout; recovered via PVE console + mkdir /run/sshd). Use a tmpfiles.d entry instead. All spike artifacts removed; baseline re-verified. Docs-only; no code/hub/agent/manifest change. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6