The graph's changed a teeny bit since that post, as we find more bugs and/or cursed configurations. A notable one I recall was container runtimes that bind-mount /etc/resolv.conf, and thus sometimes contains stuff that makes no sense, and also can't be atomically overwritten with mv(1)