Toolkit
Every script here comes from a specific, dated incident documented on this site — diagnosed on real hardware, fixed, and then generalized into a script that’s safe to hand to a stranger: no silent writes, backups before anything destructive, dry-run modes where it matters.
What’s in it
fix-partuuid-after-clone.sh— detects and fixes the staleroot=PARTUUID=reference thatrpi-cloneand similar tools leave behind after cloning an SD card to a USB SSD/NVMe. From The rpi-clone PARTUUID trap.check-undervoltage.sh— one-shot Raspberry Pi power health check, with or withoutvcgencmdinstalled, plain-English explanations instead of a hex code. From Undervoltage doesn’t look like a power problem.check-journald-persistence.sh— detects the vendor drop-in that keeps Trixie’s journal in RAM, and fixes it properly — including the flush step most published fixes leave out. From Trixie throws away your logs on reboot.-
check-swap-mechanism.sh— reports which swap subsystem actually governs the machine, and finds disk consumed by swap thatswapon,freeand/proc/swapsall decline to mention. From Your Pi’s 2 GB swap file isn’t swap. check-memory-cgroup.sh— answers whether a memory limit set on this machine will actually be enforced. On stock Raspberry Pi OS it will not, anddocker run --memorysays nothing about it. From Your Pi accepts every memory limit you set.check-sysctl-persistence.sh— finds sysctl settings that apply now and disappear at the next reboot, and checks for the compatibility symlink that decides which way it goes. From sysctl -p says it worked.check-wifi-autoconnect-block.sh— tells you whether NetworkManager will bring WiFi back on its own after one failed WPA handshake. On Trixie it will not: the profile is blocked from autoconnect and a headless Pi stays offline until someone runsnmcli connection up. Reports exposure and, on request, installs the 30-second timer that does it for you. From One failed WPA handshake and a headless Pi on Trixie stays off WiFi.check-nmcli-provisioning.sh— flags thenmcliabbreviation that NetworkManager 1.52 made ambiguous, and WiFi profiles left with no key management that look configured and can never associate. From A new NetworkManager property broke a decade of scripts.check-cloudinit-ssh-import.sh— catches a cloud-initssh_import_idthat will never be read, before you flash the card and find out the headless way. From cloud-init calls your user-data valid.check-llama-cache-ram.sh— tells you whether a runningllama-serveruses--cache-ram -1, documented as “no limit”: it keeps less than the default on dense models and has no memory bound on hybrid ones. From llama-server’s--cache-ram -1is not “no limit”.check-decision-temperatures.sh— lists calibration temperatures in Laya checkpoints and edgejev builds that make a decision model’s confidence meaningless — the English checkpoint’s 0.1 for 11+-option questions, which laya clamps at load time but ports inherit from the file. From The Laya checkpoint still ships a 0.1 temperature.check-ollama-gpu-overhead.sh— checks whether the VRAM you reserved withOLLAMA_GPU_OVERHEADis actually left free. Ollama 0.34.x prints the reservation in its log, but the llama-server runner that places the layers never receives it; the script measures free VRAM with a model loaded and prints theLLAMA_ARG_FIT_TARGETto set instead. From Ollama 0.34 logs your OLLAMA_GPU_OVERHEAD reservation as applied.check-ollama-v1-sampling.sh— lists the Ollama models whosetemperature,top_por penalties the OpenAI-compatible API replaces when a client leaves them out, whileollama showkeeps printing the model’s values;--probemeasures it on your server. From Ollama’s OpenAI-compatible API replaces your model’s temperature and top_p with 1.0.check-eog-text-tokens.sh— finds end-of-generation tokens that plain text can produce, for a model in your own llama.cpp build: entries the build forced into its stop list because of how they are spelled. On PLaMo-2 and PLaMo-3 that is the closing strikethrough tag, and output stops at it withfinish_reason: "stop". From llama.cpp picks stop tokens partly by their spelling.check-embd-determinism.sh— tells you whether decoding throughllama_batch.embdgives the same logits every time on your build and model, and when it does not, confirms whether the cause is the known heap over-read: on M-RoPE models the batch code reads four positions per token from an array the header told you to size at one. From llama.cpp reads past your pos array on every embedding batch for an M-RoPE model.check-tool-param-names.sh— finds tool parameters namedtype,description,required,propertiesornullable, which Ollama’s gemma4 renderer never shows the model while still marking them required — so the model omits the argument or makes one up. Checks a tools file statically, or probes a live server. From Ollama’s gemma4 renderer never shows the model a tool parameter named type.check-responses-state.sh— tells you whether a Responses-API server honoursprevious_response_idor accepts it, returns 200, and forgets the conversation. Ollama does the second. From Ollama’s Responses API accepts previous_response_id and starts every turn from nothing.check-docker-log-integrity.sh— tells you whetherdocker logsis returning everything on disk, or stopping at a NUL byte with exit 0 and hiding the rest. From docker logs stops at a NUL byte and exits 0.check-podman-compat-update-restart.sh— lists the running Podman containers that have no restart policy and probes whether this Podman’s Docker-compatibleupdateendpoint resets the policy tonowhen the body omits it — it does on 5.4.2, even for{}, while Docker keeps it. From Podman’s compat API resets the restart policy on any update that omits it.check-podman-subpath-cp.sh— lists the Podman containers for which apodman cpwhile stopped will read and write the volume root instead of thesubpath=they mount — a different file out, another container’s file overwritten in. From podman cp on a stopped container ignores the volume’s subpath.check-podman-export-idmap.sh— lists the Podman containers with their own user-namespace mapping, such as rootless--userns=keep-idones, whosepodman exportandpodman cparchives carry every file owner shifted, and checks an export without writing it. From Rootless podman export of a keep-id container shifts every file owner.check-llama-response-format.sh— tells you whichresponse_formatforms a runningllama-serveractually enforces. The one its README shows is accepted and ignored. From llama-server ignores the response_format its own README shows.check-cloudinit-instance-id.sh— answers whether auser-datayou place on a disk will be acted on at all. On a plain image write it will not be, and cloud-init logs the skip asSUCCESS. From cloud-init never reads the instance-id Raspberry Pi OS sets.check-iptables-backend.sh— tells you whether legacy iptables can work on this kernel at all, before you install something that assumes it. From iptables says your kernel needs upgrading.check-network-config-location.sh— finds where your WiFi credentials are actually stored, and warns when the directory every guide names is empty so your backup silently captures nothing. From tar backed up your WiFi config and exited 0.check-container-firewall-bypass.sh— finds container ports that are reachable from your network while your firewall reports them as denied. Docker’s chains are evaluated before UFW’s, so both are true at once. From UFW says the port is closed.
Also relevant if you’re building your own delivery pipeline: Stripe retries a failed webhook for three days — the idempotency bug this toolkit’s own delivery Worker hit and fixed.
New scripts are added as new incidents happen — this is a living collection, not a one-time release.
Pick the checks you need — $5 each
Each pack answers one question and contains only the scripts for it. Buy the one that matches what you are about to do; you are not paying for checks that do not apply to your machine.
Exposure & firewall — $5
Is anything reachable from your network that your firewall says is blocked?
Two checks. Container ports that answer from the LAN while ufw reports them denied, and whether the iptables your tools call has any kernel support left.
Buy Exposure & firewall →Backup & restore integrity — $5
Is your backup actually a backup, and will the clone boot?
Four checks. Where your network config really persists before you archive it, the stale PARTUUID that stops a successful-looking clone from booting, the podman cp that copies a different file out of a stopped container, and the podman export that writes every owner in the archive shifted.
Buy Backup & restore integrity →Persistence across reboot — $5
Will the settings you just applied still be there after a reboot?
Five checks. sysctl, the journal, swap, Docker container logs after a power loss, and whether your Podman containers still have the restart policy you gave them — each a case where the command succeeds, the value reads back, and the next boot disagrees.
Buy Persistence across reboot →Provisioning verification — $5
Did the machine actually get configured the way you told it to?
Four checks. The cloud-init key that is valid, schema-checked, and silently ignored — in both directions — whether your user-data will be acted on at all or parsed and skipped, the network profile a provisioning run really produced, and whether the WiFi you just set up will come back by itself after one failed handshake.
Buy Provisioning verification →Local LLM artifacts — $5
Is the model, adapter, or build you just installed the thing it says it is?
Twelve checks. An Ollama quantisation that pulls and runs and returns no working code, a LoRA adapter accepted and applied to zero layers, a build that reports a commit hash from a repository it has never heard of, a response_format the server accepts and then ignores, a previous_response_id that is accepted and dropped, a tool parameter the gemma4 renderer never shows the model, an embedding batch whose positions the library reads past the end of, a prompt cache whose "no limit" setting keeps less than the default, and a decision model whose confidence is sharpened tenfold by a temperature its own library clamps at load time, a VRAM reservation Ollama prints in its log and never passes to the runner that places the layers, model sampling settings the OpenAI-compatible API quietly replaces with 1.0, and an end-of-generation token chosen by its spelling that stops a model mid-sentence with a normal finish.
Buy Local LLM artifacts →Every script in every pack is also in the complete toolkit below, so there is no reason to buy both.
Get everything — $15
Every script in the toolkit, including the ones that are not in any pack. Buying the 5 packs separately is $25, so this is the cheaper route if you want more than two of them. One-time purchase: the download link is emailed to you immediately, and every script added later is part of the same purchase.
Buy the toolkit →