HEX
Server: Apache
System: Linux www3.pit.tblive.com 5.14.0-687.38.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Aug 12 17:19:12 EDT 2026 x86_64
User: awaldron (1020)
PHP: 8.1.34
Disabled: exec,passthru,shell_exec,system
Upload Files
File: //opt/cloudlinux/venv/lib/python3.11/site-packages/clcagefslib/webisolation/crontab/constants.py
# -*- coding: utf-8 -*-
#
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2025 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENCE.TXT
#
"""Constants and regex patterns for crontab parsing."""

import re

# Path to the isolation wrapper script
ISOLATION_WRAPPER = "/usr/sbin/cagefs_enter_site"

# Environment variable that indicates website isolation is active
DOCUMENT_ROOT_ENV = "PROXYEXEC_DOCUMENT_ROOT"

# Pattern to match crontab schedule fields (5 fields for standard cron)
# Matches: minute hour day month weekday
CRON_SCHEDULE_PATTERN = re.compile(rb"^(\S+\s+\S+\s+\S+\s+\S+\s+\S+)\s+(.*)$")

# Pattern to match crontab(5) nickname schedules (`@hourly`, `@daily`,
# `@midnight`, `@reboot`, `@weekly`, `@monthly`, `@yearly`, `@annually`).
# crond recognises these as single-token schedules followed by a command;
# the standard 5-field pattern above never matches them, so they must be
# classified explicitly here to reach the wrap loop that prepends the
# cagefs_enter_site isolation prefix in per-docroot sections.
CRON_NICKNAME_PATTERN = re.compile(
    rb"^(@(?:reboot|yearly|annually|monthly|weekly|daily|midnight|hourly))\s+(.+)$"
)

# Pattern to match a crontab(5) environment-assignment line: `name = value`
# with optional whitespace around `=`. `name` is a POSIX-style identifier
# (matching cronie's env_get(): [A-Za-z_][A-Za-z0-9_]*). Anchored at start of
# the (stripped) line so leading whitespace is ignored at the call site.
#
# F-09 (CLOS-5947) DiD: vixie-cron's `load_env` (suexec_src/vixie-cron/env.c
# NAMEI state) also accepts `"NAME"=value` and `'NAME'=value` — the name may
# be single- or double-quoted. Without matching those, a docroot-scoped
# `"SHELL"=/path/attacker` would be parsed as a CommentLine, preserved by the
# processor's env-drop, and honoured by crond at run time — the wrapped jobs
# below it would spawn through the attacker's SHELL before the cagefs_enter
# isolation wrapper. Recognise all three forms here so the classifier drops
# them uniformly.
CRON_ENV_ASSIGNMENT_PATTERN = re.compile(
    rb"^(?:[A-Za-z_][A-Za-z0-9_]*|\"[A-Za-z_][A-Za-z0-9_]*\"|'[A-Za-z_][A-Za-z0-9_]*')\s*="
)

# Markers for website cron sections
WEBSITE_CRON_BEGIN_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+BEGIN\s+(.+)$")
WEBSITE_CRON_END_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+END\s*$")