The busybox skeleton had no /etc/shadow, so Settings/Security's root
password check (grep root: /etc/shadow, mkpasswd -m md5 with the same
salt) rejected the documented default password every time; the flow that
covers it could only record the rejection. The guest now carries
/etc/passwd, /etc/shadow (the overlay's root line, md5-crypt of the
default password with salt wardenrs, verified equal to openssl passwd -1)
and /etc/group.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3G6m9Aw5RyVY4ZowtKzEj