HEX
Server: Apache
System: Linux www3.pit.tblive.com 5.14.0-687.38.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Aug 12 17:19:12 EDT 2026 x86_64
User: awaldron (1020)
PHP: 8.1.34
Disabled: exec,passthru,shell_exec,system
Upload Files
File: //opt/cloudlinux/venv/lib64/python3.11/site-packages/ssa/internal/__pycache__/utils.cpython-311.pyc
�

?Ocj�D�
�L�dZddlZddlZddlZddlZddlZddlZddlZddlm	cm
Zddlm
Z
ddlmZddlmZmZddlmZddlmZmZmZmZmZmZmZddlmZmZdd	lmZddl Z dd
l!m"Z"ddl#m$Z$ddl%m&Z&dd
l'm(Z(m)Z)m*Z*m+Z+ddl,m-Z-m.Z.ddl/m0Z0ddl1m2Z2ddl,m3Z3ddl4m5Z5ddl6m7Z7ej8d��Z9e
dddg��Z:de;de;fd�Z<de;de:fd�Z=dee;fd�Z>dee;fd�Z?dFd�Z@dGd!e;d"eAde;fd#�ZBd$e;de;fd%�ZCdHd'e;d(eDdefd)�ZEde;fd*�ZFdId,e;de;fd-�ZGde;fd.�ZHd/eDdeIfd0�ZJd1e;dee;fd2�ZKdeAfd3�ZLdeAfd4�ZMdeAfd5�ZNd6eAddfd7�ZOdeAfd8�ZPde;fd9�ZQd:e;d;ee;efdeAfd<�ZRd=�ZSedJd>eDddfd?���ZTe	dKdBeDdCeDd>eDddfdD���ZUdAZVdE�ZWdS)Lz>
This module contains helpful utility functions for SSA Agent
�N)�
namedtuple)�contextmanager)�date�	timedelta)�LooseVersion)�socket�fromfd�AF_UNIX�SOCK_STREAM�AF_INET�AF_INET6�
SOCK_DGRAM)�Optional�Union)�urlparse)�AtexitIntegration)�LoggingIntegration)�Feature)�is_panel_feature_supported�get_cp_description�is_throttling_supported�is_wp2_environment)�get_kmodlve_module_version�get_username)�get_cl_edition_readable)�get_hostname)�get_rhn_systemid_value�)�
sentry_dsn)�SSAError�utils�URL�domain_name�uri_path�url�returnc�R�t|��j�dd��S)u�
    The domain string the request processor stores as RequestResult.domain.
    This is the single source of truth for a URL's domain attribution: it
    operates on the raw netloc and removes every 'www.' substring, exactly as
    the stored metric is keyed. The authorizer MUST derive its decision from
    this same value (see SimpleAgent._authorize_sender) — any divergence
    re-opens cross-tenant metric spoofing.
    zwww.�)r�netloc�replace)r%s �I/opt/cloudlinux/venv/lib64/python3.11/site-packages/ssa/internal/utils.py�canonical_stored_domainr,1s#���C�=�=��'�'���3�3�3�c��t|��}|jr
d|j��nd}|jr|j�|��nd}tt	|��|��S)z�
    Split URL into domain_name and uripath including query string
    :param url: URL of format protocol://domain/path;parameters?query#fragment
    :return: namedtuple URL(domain_name, uripath)
    �?r(�/)r�query�pathr"r,)r%�	fragments�qs�uris    r+�	url_splitr6=sb����
�
�I�"+�/�	9�	�Y�_�	�	�	�r�B�%.�^�
<�Y�^�
!�R�
!�
!�
!��C��&�s�+�+�S�1�1�1r-c� �td��S)z"Get version of alt-php-ssa packagez/usr/share/clos_ssa/version��pkg_version�r-r+�ssa_versionr;Js���4�5�5�5r-c� �td��S)z#Get version of alt-php-xray packagez/usr/share/alt-php-xray/versionr8r:r-r+�xray_versionr=Os���8�9�9�9r-c�2���dtdtdtfd�}d���fd���fd�}dd	�}t��pd
}ttjtj���}t
|���}tjt||d
||g���tj
��5}dtd��p%���pt��p
t��i|_	||��n#t$rYnwxYwddd��dS#1swxYwYdS)u�
    Initialize Sentry client
    shutdown_timeout=0 disables Atexit integration as stated in docs:
    'it’s easier to disable it by setting the shutdown_timeout to 0'
    https://docs.sentry.io/platforms/python/default-integrations/#atexit
    On the other hand, docs say, that
    'Setting this value too low will most likely cause problems
    for sending events from command line applications'
    https://docs.sentry.io/error-reporting/configuration/?platform=python#shutdown-timeout
    �event�hintr&c�@�|d�ddi��|S)z�
        Add extra data into sentry event
        :param event: original event
        :param hint: additional data caught
        :return: updated event
        �extrazssa.versionz
0.4-31.el9)�update)r?r@s  r+�add_infozsentry_init.<locals>.add_info`s&��	�g����}�l�;�<�<�<��r-c��	t|t��5}|�|df��|���dcddd��S#1swxYwYdS#t$rt
�d��YdSwxYw)aI
        address_family - we can choose constants represent the address
                           (and protocol) families
                           (AF_INET for ipv4 and AF_INET6 for ipv6)
        private_ip - specify some private ip address. For instance:
                     ipv4 -> 10.255.255.255 or ipv6 -> fc00::
        rrNzCannot retrieve IP address)rr�connect�getsockname�	Exception�logger�info)�address_family�
private_ip�ss   r+�
try_get_ipzsentry_init.<locals>.try_get_ipjs���	6���
�3�3�
*�q��	�	�:�q�/�*�*�*��}�}���q�)�
*�
*�
*�
*�
*�
*�
*�
*�
*�
*�
*�
*����
*�
*�
*�
*�
*�
*���	6�	6�	6��K�K�4�5�5�5�5�5�5�	6���s4�A"�1A�A"�A�A"�A�A"�"$B
�	B
c�`��tdftdff}|D]\}}�||��}|r|cS�dS)zq
        We are trying to get an IPv4 or IPv6 address.
        In case of failure we'll return 127.0.0.1
        z10.255.255.255zfc00::z	127.0.0.1)rr
)�
ipversions�addr_fam�priv_ip�iprNs    �r+�get_ipzsentry_init.<locals>.get_ipysZ���
�/�0�8�X�2F�F�
�!+�	�	��H�g���H�g�.�.�B��
��	�	�	�
��{r-c���t��}|r|�d��nd}|r|�d��nd}t��rdnd}dt��pdfd|fd|fd|fd	t	j��fd
t
d��fdt��fd
t
d��fd���fdt��ff
}|D]}|j	|��
dS)N�version�name�WP2zalt-php-xray�UNKNOWNzControl Panel NamezControl Panel VersionzControl Panel Product�kernelzCloudLinux version�
os_releasezCloudlinux edition�Architecture�architecture�
ip_address�username)
r�getrr=�platform�releaserrr�set_tag)�sentry_scope�cp_description�
cp_version�cp_name�
cp_product�tags�tagrTs       �r+�set_tagszsentry_init.<locals>.set_tags�s���+�-�-��6D�N�^�'�'�	�2�2�2�$�
�0>�H�.�$�$�V�,�,�,�D��0�2�2�<�U�U��
��\�^�^�8�y�9�
!�7�+�
$�j�1�
$�j�1�
�x�'�)�)�*�
!�#9�,�#G�#G�H�
!�#:�#<�#<�=�
�3�N�C�C�D�
�6�6�8�8�$�
����(�
���	'�	'�C� �L� �#�&�&�&�	'�	'r-Nc��dS�Nr:)�pending�timeouts  r+�nopezsentry_init.<locals>.nope�s���r-zalt-php-ssa@0.4-31.el9)�level�event_level)�callbacki')�dsn�before_sendrb�max_value_length�integrations�id�	system_id�r&N)�dictr;r�logging�INFO�WARNINGr�
sentry_sdk�initr�configure_scoperrr�userrH)	rDrkrp�ssa_ver�sentry_logging�
silent_atexit�scoperTrNs	       @@r+�sentry_initr�Ts��������D��T�����
6�
6�
6�
�
�
�
�
�'�'�'�'�'�.
�
�
�
��m�m�7�7�G�'�g�l���X�X�X�N�%�t�4�4�4�M��O�����$�m�4�����
�	#�	%�	%����2�;�?�?�o�6�6�8�8�o�|�~�~�o�am�ao�ao�p��
�	��H�U�O�O�O�O���	�	�	��D�	����	��������������������s6�%=D�#C/�.D�/
C<�9D�;C<�<D�D�DF�fname�as_errorc�L�	tj|tjdd���	tj|d��n#t
$rYnwxYw|S#t$rL}t�|rtj	ntjdt|����Yd}~dSd}~wwxYw)zz
    Try to configure logging into given fname
    If as_error True, log the exception as ERROR, otherwise -- as INFO
    z%(asctime)s %(message)sz%m/%d/%Y %I:%M:%S %p)�filenamerq�format�datefmti�z$No logging configuration applied: %sN)r|�basicConfigr}�os�chmod�PermissionError�OSErrorrI�log�ERROR�str)r�r��es   r+�set_logging_into_filer��s���

p����'�,�7P�Zp�	
�	
�	
�	
�	��H�U�E�"�"�"�"���	�	�	��D�	��������p�p�p��
�
�H�>�7�=�=�'�,�@f�hk�lm�hn�hn�o�o�o�o�o�o�o�o�o�����p���s8�"A
�;�A
�
A�A
�A�A
�
B#�AB�B#�lognamec�H�t��t|����	tjtj�|����n@#t$r3}t�dt|����Yd}~dSd}~wwxYwt|d���}|S)zP
    Configure logging
    :param logname: path to log
    :return: logpath
    NzFailed to create logdir %sr(T)r�)
r�r�r��makedirsr2�dirnamerHrI�warningr�)r�r�s  r+�configure_loggingr��s����M�M�M��W�%�%�-�	��K������0�0�1�1�1�1���	�	�	��N�N�7��Q���@�@�@��2�2�2�2�2�����	����(��$�?�?�?���Ns�1A�
B�(B	�	B��
sock_location�backlogc�t�ttj�dd����}|dkrTt	t
��}|�|��tj|d��|�|��n0tdt
t��}|�|��|S)a	
    Create socket in given sock_location with restricted permissions
    or reuse existing one
    :param sock_location: socket address
    :param backlog: maximum number of queued connections (default 2048 for high-traffic servers)
    :return: socket object
    �
LISTEN_FDSri��)�intr��environr`rr
�bindr��listenr	r)r�r�r��sockobjs    r+�
create_socketr��s����R�Z�^�^�L�!�4�4�5�5�J��Q�����/�/�����]�#�#�#�	����&�&�&����w�������G�[�1�1�����w�����Nr-c�t�tj��td���z
}|�d��S)zC
    Returns date of previous day in a format "day.month.year"
    r)�days�%d.%m.%Y)r�todayr�strftime)�	yesterdays r+�previous_day_dater��s3���
���y�a�0�0�0�0�I����j�)�)�)r-r��datestrc�l�tj�||��}|�d��S)z+
    Convert date to format YYYY-mm-dd
    z%Y-%m-%d)�datetime�strptimer�)r��	formatstr�_dates   r+�format_dater��s.��
��&�&�w�	�:�:�E��>�>�*�%�%�%r-c���	tjd��}|���}|�d��j}tj��5}|�d|��ddd��n#1swxYwY|�d��S#ttj
f$r3}t�dt|����Yd}~dSd}~wwxYw)ze
    Obtain system ID from /etc/sysconfig/rhn/systemid
    :return: system ID without ID- prefix
    z/etc/sysconfig/rhn/systemidz(.//member[name='system_id']/value/stringryNzID-z Failed to retrieve system_id: %s)�ET�parse�getroot�find�textrr�rc�lstripr��
ParseErrorrIr�r�)�tree�root�whole_idr�r�s     r+�read_sys_idr��s��
C��x�5�6�6���|�|�~�~���9�9�G�H�H�M��
�
'�
)�
)�	1�U��M�M�+�x�0�0�0�	1�	1�	1�	1�	1�	1�	1�	1�	1�	1�	1����	1�	1�	1�	1����u�%�%�%���R�]�#�C�C�C����9�3�q�6�6�B�B�B�B�B�B�B�B�B�����C���s<�AB�A:�.B�:A>�>B�A>�B�C#�0(C�C#�durationc�B�tt|dzd����S)zQ
    Cast duration from microseconds to seconds leaving 2 digits after point
    i@Bz0.2f)�floatr�)r�s r+�
duration_castr�s!�����7�*�F�3�3�4�4�4r-�filepathc�&�	t|��5}|������}ddd��n#1swxYwYn#t$rYdSwxYwd�|�d��dd���pdS)zDGet version of package from file. alt-php-ssa/alt-php-xray supportedN�.�z0.0-0)�open�read�stripr��join�split)r��v_filerVs   r+r9r9s����
�(�^�^�	,�v��k�k�m�m�)�)�+�+�G�	,�	,�	,�	,�	,�	,�	,�	,�	,�	,�	,����	,�	,�	,�	,���������������8�8�G�M�M�#�&�&�r��r�*�+�+�6�w�6s3�A�'A�A�A�A�A�A�
A�Ac��t��}|�dS	t|��td��kS#ttf$rYdSwxYw)zb
    Check version of alt-php-xray package.
    Autotracing in X-Ray is supported since 0.4-1
    NFz0.4-1)r=r�	TypeError�AttributeError)�version_numbers r+�is_xray_version_supportedr� s_��
"�^�^�N����u���N�+�+�|�G�/D�/D�D�D���~�&�����u�u����s�4�A	�A	c���d}ttt��5}	|�|��n##tt
f$rYddd��dSwxYw	ddd��n#1swxYwYdS)z Check if User Agent is listeningz$/opt/alt/php-xray/run/xray-user.sockNFT)rr
rrF�ConnectionErrorr�)�user_agent_sockrMs  r+�is_xray_user_agent_activer�/s���<�O�	���	%�	%���	�
�I�I�o�&�&�&�&����)�	�	�	��	��������	����
'�������������������
�4s1�A%�5�A%�A�A%�A�A%�%A)�,A)c��d}tj�|��sdS	tj|d��5}t|�����dkcddd��S#1swxYwYdS#tj$rYdSwxYw)z@Check if there are no active X-Ray tasks (== empty task storage)z/usr/share/alt-php-xray/tasksT�crNF)r�r2�isfile�dbmr��len�keys�error)�xray_tasks_storage�
xray_taskss  r+�no_xray_active_tasksr�:s���8��
�7�>�>�,�-�-���t��
�X�(�#�
.�
.�	/�*��z���(�(�)�)�Q�.�	/�	/�	/�	/�	/�	/�	/�	/�	/�	/�	/�	/����	/�	/�	/�	/�	/�	/���9�����u�u����s4�A9�%A,�A9�,A0�0A9�3A0�4A9�9B�B�enabledc��ttj��sdSt�d|��	tddd���5}|�|rdnd��t�d	��ddd��dS#1swxYwYdS#t$r4}t�d
|t|����Yd}~dSd}~wwxYw)zb
    Switch on/off throttle statistics gathering by kmodlve
    :param enabled: True or False
    NzSwitching schedstats: %sz!/proc/sys/kernel/sched_schedstats�wbr)�mode�	buffering�1�0zDone OKz(Failed to set sched_schedstats to %s: %s)	rr�LVErIrJr��writer�r�)r��fr�s   r+�switch_schedstatsr�Js/��
&�g�k�2�2����
�K�K�*�G�4�4�4�Q�
�5�D�A�
N�
N�
N�	#�RS�
�G�G�G�-�D�D��.�.�.��K�K�	�"�"�"�	#�	#�	#�	#�	#�	#�	#�	#�	#�	#�	#�	#����	#�	#�	#�	#�	#�	#���Q�Q�Q����>���Q���P�P�P�P�P�P�P�P�P�����Q���s;�B�
4B�>B�B�B�B�B�
C�")C�Cc��td��}td��}t��}|rt||��Stt��|��S)z�
    Check kmodlve module version or kernel version in order to determine
    if it provides the detection of IO throttling
    z2.0-23z1.5.58)rr�compare_versions_ge�extract_kernel_version)�kmod_min_version�kernel_min_version�kmod_currents   r+�$is_io_throttling_detection_availabler�\s]��
$�H�-�-��%�h�/�/��-�/�/�L��C�"�<�1A�B�B�B��5�7�7�9K�L�L�Lr-c���tjd��}tj��}	|�|���d��}n#t$rYdSwxYw|S)zO
    Get kernel version in the form of "major-minor" from current platform
    zlve([0-9]+(\.[0-9]+)+)\.elrz0.0.0)�re�compilerarb�search�groupr�)�patternrb�version_nums   r+r�r�isp���j�6�7�7�G��� � �G���n�n�W�-�-�3�3�A�6�6���������w�w������s�(A�
A �A �
first_version�second_versionc�r�	t|��|kS#t$rtd|�d|�d����wxYw)zE
    Comparing two versions using the greater or equal operator.
    zAUnable to compare required versions: unexpected versions format "z" and "�")rr�r )r�r�s  r+r�r�vs_��
��M�*�*�n�<�<���
�
�
��w�P]�w�w�ft�w�w�w�
�
�	
�
���s��!6c�>�t��sdSt��S)zR
    General check of kernel support (IO throttling availability is required)
    T)rr�r:r-r+�is_kernel_version_supportedr�s#��#�$�$���t�/�1�1�1r-�maskc#�K�tj|��}	dV�tj|��dS#tj|��wxYw)z,
    Context manager for dropping umask
    N)r��umask)r�prevs  r+�umask_0r�sF����
�8�D�>�>�D��
����
������������������s	�2�Ar�T�
target_uid�
target_gidc#�pK�tj��}tj��}	tj|��}n#t$rd}YnwxYw|�|�|}n|j}|�|�|}n|j}|�tj|��}d}	||ks||krltj��}		tj	tj|��j|��n+#ttf$rtjg��YnwxYw||krmtj|��t �d|��|r<tj��|kr%|	�tj|	��t'd���||kr�tj|��t �d|��|rVtj��|kr?||krtj|��|	�tj|	��t'd���	dV�||kr/tj|��t �d|��||kr/tj|��t �d|��|	�tj|	��|�tj|��dSdS#||kr/tj|��t �d|��||kr/tj|��t �d|��|	�tj|	��|�tj|��wwxYw)aH
    Context manager to drop privileges during some operation
    and then restore them back.
    If target_uid or target_gid are given, use input values.
    Otherwise, stat target_uid and target_gid from given target_path.
    If no target_path given, use current directory.
    Use mask if given.
    :param target_uid: uid to set
    :param target_gid: gid to set
    :param target_path: directory or file to stat for privileges,
                       default -- current directory
    :param mask: umask to use
    :param with_check: check the result of switching privileges
    NzDropped GID privs to %sz6Unable to execute required operation: permission issuezDropped UID privs to %szRestored UID privs to %szRestored GID privs to %s)r��getuid�getgid�statr��st_uid�st_gidr�	getgroups�
initgroups�pwd�getpwuid�pw_name�KeyError�	setgroups�setegidrI�debug�getegidr �seteuid�geteuid)
r	r
�target_pathr�
with_check�prev_uid�prev_gid�	stat_infor�saved_groupss
          r+�set_privilegesr#�sY����$�y�{�{�H��y�{�{�H���G�K�(�(�	�	�������	�	�	���������!�J�J�"�)�J�����!�J�J�"�)�J����x��~�~���L��:����Z�!7�!7��|�~�~��	��M�#�,�z�2�2�:�J�G�G�G�G���'�"�	�	�	��L�������	�����:���
�
�:�������.�
�;�;�;��	U�"�*�,�,�*�4�4��'���\�*�*�*��S�T�T�T��:���
�
�:�������.�
�;�;�;��	U�"�*�,�,�*�4�4��:�%�%��
�8�$�$�$��'���\�*�*�*��S�T�T�T�
�
�����z�!�!��J�x� � � ��L�L�3�X�>�>�>��z�!�!��J�x� � � ��L�L�3�X�>�>�>��#��L��&�&�&����H�T�N�N�N�N�N�����z�!�!��J�x� � � ��L�L�3�X�>�>�>��z�!�!��J�x� � � ��L�L�3�X�>�>�>��#��L��&�&�&����H�T�N�N�N�N����s.�?�A�
A�%,C�%C:�9C:�>J�BL5c�2�Gd�d��}||��S)Nc��eZdZdZd�Zd�ZdS)�singleton.<locals>.__Singletonzm
        A singleton wrapper class. Its instances would be created
        for each decorated class.
        c�"�||_d|_dSrm)�_wrapped�	_instance)�self�_clss  r+�__init__z'singleton.<locals>.__Singleton.__init__s�� �D�M�!�D�N�N�Nr-c�P�|j�ts|j|i|��|_|jS)z,Returns a single instance of decorated class)r)�IS_SINGLETON_ENABLEDr()r*�args�kwargss   r+�__call__z'singleton.<locals>.__Singleton.__call__s0���~�%�-A�%�!.����!?��!?�!?����>�!r-N)�__name__�
__module__�__qualname__�__doc__r,r1r:r-r+�__Singletonr&�s<������	�	�
	"�	"�	"�	"�	"�	"�	"�	"r-r6r:)�some_clsr6s  r+�	singletonr8�s<��"�"�"�"�"�"�"�"� �;�x� � � r-rz)F)r�)r�)r)NNr�NT)Xr5r�r�r|r�rarr��xml.etree.ElementTree�etree�ElementTreer��collectionsr�
contextlibrrr�distutils.versionrrr	r
rrr
r�typingrr�urllib.parserr�sentry_sdk.integrations.atexitr�sentry_sdk.integrations.loggingr�clcommon.constr�clcommon.cpapirrrr�clcommon.utilsrr�clcommon.lib.cleditionr�clcommon.lib.networkrr�	constantsr�
exceptionsr �	getLoggerrIr"r�r,r6r;r=r��boolr�r�r�r�r�r�r�r�r�r9r�r�r�r�r�r�r�rrr#r.r8r:r-r+�<module>rLs���������
�
�
�
�����	�	�	�	�����
�
�
�
�	�	�	�	�"�"�"�"�"�"�"�"�"�"�"�"�"�"�"�%�%�%�%�%�%�$�$�$�$�$�$�$�$�*�*�*�*�*�*�V�V�V�V�V�V�V�V�V�V�V�V�V�V�V�V�V�V�"�"�"�"�"�"�"�"�!�!�!�!�!�!�����<�<�<�<�<�<�>�>�>�>�>�>�"�"�"�"�"�"�v�v�v�v�v�v�v�v�v�v�v�v�C�C�C�C�C�C�C�C�:�:�:�:�:�:�-�-�-�-�-�-�1�1�1�1�1�1�!�!�!�!�!�!� � � � � � �	��	�7�	#�	#���j���
�3�4�4��	4��	4��	4�	4�	4�	4�
2�3�
2�3�
2�
2�
2�
2�6�X�c�]�6�6�6�6�
:�h�s�m�:�:�:�:�
[�[�[�[�|p�p��p��p��p�p�p�p�$�s��s�����"����s��f�����2*�3�*�*�*�*�&�&��&�s�&�&�&�&�
C�S�
C�
C�
C�
C� 5�C�5�E�5�5�5�5�7�#�7�(�3�-�7�7�7�7��4������4�����
�d�
�
�
�
� Q�t�Q��Q�Q�Q�Q�$
M�d�
M�
M�
M�
M�
��
�
�
�
�	
�s�	
�E�#�|�BS�<T�	
�Y]�	
�	
�	
�	
�2�2�2����#��d��������bf�S�S��S�(+�S�KN�S�	�S�S�S���S�t��!�!�!�!�!r-