docs: sync from coipond/coi-wiki (binary, pre_launch, protected branches, health --fix)
Mirror of coi-wiki c8a4cd8 (docs/binary-pre-launch-guard-health), flattened:
[tool] binary and pre_launch, [git] protected_branches, `coi health --fix`,
visudo-validated sudoers instructions, current reverse-shell detection
behavior, and the large-UID subuid/subgid fix.
Also renames Updating-COI.md -> Updating-Coi.md, matching coi-wiki and the
existing [Updating Coi](Updating-Coi) links, which pointed at a page that
didn't exist under that name here.
docs: update repo references mensfeld/coi -> coipond/coi (org transfer)
docs: align wiki to the Karafka writing style
Style-only pass across 39 pages: reduce decorative bold to scannable labels and
callouts, Title Case headings, expand contractions, present tense, US English,
cut filler and --- separators, tag code fences. Commands, code, config,
COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.
docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding
Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links
(install.sh raw URL, issues/releases/tree/wiki links) and one leftover
"code-on-incus" prose ref -> Coi.
docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command)
COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)".
Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers
(they document the actual on-disk marker text). Lowercase coi commands unchanged.
Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note
- macOS Setup Guide: OrbStack is now a first-class documented option
(setup steps, how COI handles the FUSE-backed macOS share via
raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage
notes); 'How It Works' rewritten around the v0.11.1 filesystem check
with the reactive fallback; Manual Override reframed as rarely
needed; Colima instructions now install Incus from Zabbly (Ubuntu's
6.0 is below the required 6.1).
- Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping
mechanism descriptions updated (auto-selected shift vs raw.idmap),
disable_shift comment rewritten, Colima-only framing widened to
Colima/Lima/OrbStack.
- System Health Check/Troubleshooting/Best Practices/Getting Started/
Linux Setup Guide: dir-pool driver warning documented (detection,
cost, fix), example output shows the new 'pool (driver)' label,
manual-setup example no longer recommends a dir pool, Zabbly note
reframed around the automatic raw.idmap recovery, #673 version/update
known-issue note added.
- Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited
sandbox-context injection documented incl. auto-healing of bloated
files; tool interface snippets synced (AlwaysSetupConfig, full effort
level list).
- nftables internals: NFT monitoring is disabled by default.
- Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count
fix; IPv6 host-side blocking wording.
Add nftables Monitoring Internals page (ported from repo docs/NFT-MONITORING.md)
Moves the nftables monitoring technical deep-dive out of the code repo and into
the wiki as a dedicated internals page, cross-linked from Security-Monitoring
and the sidebar. Fixed a stale detail from the original: LOG rules are inserted
at the top of the ip filter FORWARD chain (priority 0 + nft insert), not placed
via a per-rule priority -5/-10 (nftables has no per-rule priority).