- runner: export sbin-inclusive PATH (util-linux tools live in /usr/sbin)
- 001: read /proc/swaps instead of swapon(8)
- 005: resolve /dev/disk/by-uuid symlink instead of findfs(8); report ?
(exit 2) when the UUID cannot be resolved
status convention: print one line, exit 0 OK / 1 DRIFT / 2 unknown (e.g.
needs root). sysmig status now shows [applied ✓/✗/?] per migration and
exits 1 on drift. DB checks fall back to peer auth when non-root.