HEX
Server: Apache
System: Linux www3.pit.tblive.com 5.14.0-687.38.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Aug 12 17:19:12 EDT 2026 x86_64
User: awaldron (1020)
PHP: 8.1.34
Disabled: exec,passthru,shell_exec,system
Upload Files
File: //opt/cloudlinux/venv/lib64/python3.11/site-packages/__pycache__/clsetuplib.cpython-311.pyc
�

�x`�j���ddlZddlZddlZddlZddlZddlZddlmZddlm	Z	m
Z
Gd�d��Ze
e	���Zd�Z
d�Zd
d
�Zd�Zd�ZdS)�N)�remount_proc)�SYSCTL_CL_CONF_FILE�
SysCtlConfc�0�eZdZgd�ZdZdZd�Zd�Zd�ZdS)�
KernelVersion)�1r�95�Tc�R�tjddgtjtj���5}|���\}}|jdkr#td��t
jd��|�d��dkr{|�	d��d�	d	��ddd��
���	d
��|_t|j��nd|_ddd��dS#1swxYwYdS)Nz/usr/bin/unamez-r)�stdout�stderrrz?error: subprocess call error. Cant't get current kernel version��lve����el�.F)
�
subprocess�Popen�PIPE�communicate�
returncode�print�sys�exit�find�split�strip�_system_kernel�
_cl_kernel)�self�proc�out�_s    �py/clsetuplib.py�__init__zKernelVersion.__init__&sN��
�
�
�t�$��?��?�
�
�
�
	(���%�%�'�'�F�C����!�#�#��X�Y�Y�Y��������x�x����"�$�$�&)�i�i��&6�&6�q�&9�&?�&?��&E�&E�a�&H��"��&M�&S�&S�&U�&U�&[�&[�\_�&`�&`��#��d�)�*�*�*�*�"'���
	(�
	(�
	(�
	(�
	(�
	(�
	(�
	(�
	(�
	(�
	(�
	(����
	(�
	(�
	(�
	(�
	(�
	(s�C!D�D �#D c��|jr/|j|jkotj�d��St
d��tjd��dS)Nz/proc/sys/fs/symlinkown_gidz1error: Feature is not supported on non CL kernel.r)	rr�_SECURELINKS_MIN_KERNEL�os�path�isfilerrr�r s r$�securelinks_kernel_requirementz,KernelVersion.securelinks_kernel_requirement7sY���?�	��#�t�'C�C�B��G�N�N�#@�A�A�
�	�A�B�B�B���������c�<�dd�|j��zS)Nrr)�joinr'r+s r$�get_securelinks_min_kernelz(KernelVersion.get_securelinks_min_kernelBs���s�x�x�� <�=�=�=�=r-N)	�__name__�
__module__�__qualname__r'rrr%r,r0�r-r$rr!sU������,�n�n���N��J�(�(�(�"���>�>�>�>�>r-r)�config_filec�@�d}t�||��dS)zn
    Change /etc/sysctl.conf for apache gid
    :param apache_gid: id of apache's group
    :return: None
    zfs.symlinkown_gidN)�sysctl�set)�
apache_gid�symlink_commands  r$�set_securelinks_gidr;Is#��*�O�
�J�J��
�+�+�+�+�+r-c���d}	tt�|����}n#t$rd}YnwxYw	t	j|��jn#t$rd}YnwxYw|dkrOd}tj	dd|gd���t	j
|��j}t�||��tj	dd	d
t|��|gd���dS)a�
    Add user to the group specified by fs.proc_super_gid.
    If fs.proc_super_gid is 0 (means undefined) or group doesn't really exists
    then create "clsupergid" group, configure it as fs.proc_super_gid and
    add user to this group

    CLOS-4594/F-54: this creates-or-reuses the proc-super group, whose members get
    the hidepid /proc bypass. lve-utils cannot validate the group's members here
    (clsupergid is intentionally populated with regular-uid panel admins, which are
    indistinguishable from tenants by uid alone). Membership integrity -- evicting any
    tenant that slipped into a reused pre-existing group -- is owned by lvemanager, which
    knows the authoritative cpapi admin/user sets: see cpanel-lvemanager
    commons/lib/lvemanager/sudoers.py::_remove_tenants_from_group. NOTE: that eviction runs
    only on hosts lvemanager manages; on an lve-utils-only host it does not run, so a
    pre-existing externally-populated group is not reconciled (pre-seeding it requires root).
    zfs.proc_super_gidr�
clsupergidz/usr/sbin/groupaddz-fF)�checkz/usr/sbin/usermodz-az-GN)�intr7�get�
ValueError�grp�getgrgid�gr_name�KeyErrorr�run�getgrnam�gr_gidr8�str)�user�sgid_key�proc_super_gid�	sgid_names    r$�_add_to_super_gidrNTs,��"#�H���V�Z�Z��1�1�2�2�����������������	��^�$�$�,�,�,������������������ �	���,�d�I�>�"�	$�	$�	$�	$���i�0�0�7���
�
�8�^�,�,�,��N�'��t�S��5H�5H�$�O�� � � � � � s�',�;�;�A�A(�'A(Tc�r�tj��sdStd��|rt��dSdS)z:
    Add nagios to configured fs.proc_super_gid group
    N�nagios)�cldetectlib�
get_nagiosrNr��do_remount_procs r$�setup_nagiosrU�sI���!�#�#�����h�������������r-c��tj�d��sdS	tjd��n#t
$rYdSwxYwt
d��dS)z@
    Detect "mailman" and add it to fs.proc_super_gid group
    z"/usr/local/cpanel/3rdparty/mailmanN�mailman)r(r)�isdir�pwd�getpwnamrErNr4r-r$�
setup_mailmanr[�sp���7�=�=�=�>�>�������Y������������������i� � � � � s�8�
A�Ac�^�td���t��t��dS)z�
    Configure "special" users to be in fs.proc_super_gid group, if it's
    necessary.
    If this GID was undefined(0) then create and setup special clsupergid group
    FrSN)rUr[rr4r-r$�setup_supergidsr]�s-����'�'�'�'��O�O�O��N�N�N�N�Nr-)T)rBr(rYrrrQ�cl_proc_hidepidr�clcommon.sysctlrrrr7r;rNrUr[r]r4r-r$�<module>r`s��*�
�
�
�	�	�	�	�
�
�
�
�����
�
�
�
�����(�(�(�(�(�(�;�;�;�;�;�;�;�;�">�">�">�">�">�">�">�">�J
�� 3�	4�	4�	4��,�,�,�* �* �* �Z����!�!�!�
�
�
�
�
r-