/opt/cloudlinux/venv/lib/python3.11/site-packages/xray/manager/__pycache__
NameSizeModeActions
base.cpython-311.pyc477470644editdlrm
cpanel.cpython-311.pyc88670644editdlrm
custom.cpython-311.pyc108470644editdlrm
directadmin.cpython-311.pyc183710644editdlrm
plesk.cpython-311.pyc93350644editdlrm
__init__.cpython-311.pyc17920644editdlrm
Edit: /opt/cloudlinux/venv/lib/python3.11/site-packages/xray/manager/__pycache__/custom.cpython-311.pyc (10847B)
§ ð ˜j"'ãó®—dZddlZddlmZddlmZddlmZddlm Z ddl m Z dd l mZdd lmZmZdd lmZdd lmZmZd dlmZGd„de¦«ZdS)zZ This module contains classes implementing X-Ray Manager behaviour for custom integration éN)ÚChainMap)ÚClassVar)Ú PublicApi)Úgettext)Ú phpinfo_utilsé)Úis_allowed_ini_path)ÚXRayManagerErrorÚXRayMissingDomain)Ú DomainInfo)Úuser_mode_verificationÚwith_fpm_reload_restrictedé)Ú BaseManagercó‡—eZdZUdZdddddddddddddddœZeeed<ˆfd„Zde fd„Z e d„¦«Z defd „Z eed edefd „¦«¦«Zd edefd „Zdededzfd„Zdededefd„Zd edefd„Zd edefˆfd„ ZˆxZS)Ú CustomManagerz0 Manager supporting integration scripts N)Ú54Ú55Ú56Ú70Ú71Ú72Ú73Ú74Ú80Ú81Ú82Ú83Ú84Ú85ÚVERSIONS_CUSTOMcóØ•—t¦«j|i|¤Žt¦«|_|jr| ¦«|_dSttd¦«¦«‚)Nz.X-Ray is not supported by control panel vendor) ÚsuperÚ__init__rÚapiÚis_xray_integratedÚget_all_domainsÚ all_domainsr Ú_)ÚselfÚargsÚkwargsÚ __class__s €úJ/opt/cloudlinux/venv/lib64/python3.11/site-packages/xray/manager/custom.pyr$zCustomManager.__init__1sgø€Ø�‰ŒÔ˜$Ð) &Ð)Ð)Ð)å‘;”;ˆŒØ Ô "ð XØ#×3Ò3Ñ5Ô5ˆDÔ Ð Ð å"¥1Ð%UÑ#VÔ#VÑWÔWÐ WóÚreturncó6—t|j|j¦«S)za Get supported PHP versions :return: dict with custom supported versions )rÚVERSIONSr!©r*s r.Úsupported_versionsz CustomManager.supported_versions:s€õ ˜œ  tÔ';Ñ<Ô<Ѐð ”×#Ò#Ñ%Ô%ˆØÔ.ˆØ Ð Ø�4à�|Š|˜F EÑ*Ô*Ð*r/có8—|j d¬¦«S)z9 Collect domains from integration script T)Úwith_php)r%Údomainsr3s r.r'zCustomManager.get_all_domainsMs€ðŒx×Ò¨ÐÑ.Ô.Ð.r/Ú domain_namecój— |j|}n;#t$r.|j dd|i¬¦«t |¦«‚wxYw|jr]t j|j||j j ¬¦«}t||  d¦«|j d|j|j¬¦«S| |j j|j¦«}t||j|j j |j j|j j|¬¦«}|j d ||j|j¦«|S) z< Retrieve PHP setting for given domain_name z#Domain does not exist on the serverr?)Úextra)ÚdomainÚtrusted_php_versionÚT)ÚnameÚpanel_php_versionÚphp_ini_scan_dirÚis_selector_appliedÚuserÚ panel_fpm)rErIrFrJÚ is_nativeÚini_pathz@Retrieved domain info: domain %s owned by %s uses php version %s)r(ÚKeyErrorÚloggerÚwarningr Ú phpinfo_moderÚget_php_configurationÚownerÚphpÚversionr Úget_full_php_versionÚabsolute_ini_scan_dirÚ is_php_fpmÚ_validate_ini_pathrLÚfpmrKÚinforIrF)r*r?Ú domain_confÚconfigrLÚ domain_infos r.Úget_domain_infozCustomManager.get_domain_infoSsi€ð  1ØÔ*¨;Ô7ˆKˆKøÝð 1ð 1ð 1Ø ŒK× Ò Ð EÈmÐ]hÐMiÐ Ñ jÔ jÐ jÝ# KÑ0Ô0Ð 0ð 1øøøð Ô ð! Ý"Ô8ØÔ!Ø"ð%0¤OÔ$;ð ñ ô ˆFõØ Ø"(×"=Ò"=¸bÑ"AÔ"AØ!'Ô!=ð%)Ø Ô&Ø Ô+ð ñ ô ð ð×.Ò.¨{¬Ô/GÈÔIZÑ[Ô[ˆHÝ$Ø Ø Ô&Ø"-¤/Ô"9Ø%œ/Ô-Ø%œ/Ô3Ø!ð ñôˆKð Œ ×ÒØ NØ Ø Ô Ø Ô )ñ  ô ð ð Ðs ‚ �8Ar]có —|jo|j S)zß Check if selector is enabled specifically for custom panels Required to be implemented by child classes :param domain_info: a DomainInfo object :return: True if yes, False otherwise )rKrJ©r*r]s r.Úpanel_specific_selector_enabledz-CustomManager.panel_specific_selector_enabledŠs€ðÔ$ÐB¨[Ô-BÐ)BÐBr/Údom_infocó—|jS)z+ Retrieve FPM service name )rJ)r*rbs r.Úfpm_service_namezCustomManager.fpm_service_name“s €ðÔ!Ð!r/rLrRcóì—|s|Stj |¦«}t|¦«s:|j d|¦«t td¦«|z¦«‚tj ||¦«stj ||¦«r|Stj tj |¦«stj |¦«r:|j d|¦«t td¦«|z¦«‚ tj|¦«j}n#t $r|cYSwxYw|dkr|S|j d||¦«t td¦«|z¦«‚)uÞOwner-bind the vendor-supplied ini_path before it steers a root write. In non-phpinfo mode the custom integration reports ini_path verbatim and the only downstream guard is the broad is_allowed_ini_path prefix allowlist, which admits serverwide (/etc/php.d) and per-tenant (/var/cagefs/..., the per-domain ini roots) trees. Without owner-binding an allowlisted-but-foreign path would let the root xray.ini write land in another tenant's jail. Accept the path only when it is the owner's own subtree or an operator-controlled root-owned INI directory; reject a path that resolves outside the allowlist, into a foreign tenant's per-user tree, or onto a dir owned by a different unprivileged user. Returns the CANONICAL (realpath'd) directory, not the raw vendor string. The write-time owner binding (Task._ini_dir_validator / unified_write) classifies ini_location as per-tenant vs global from this value and then re-checks the PINNED inode against it, so it must be canonical here — a raw symlink path would misclassify and either over-reject a legitimate own-subtree symlink or fail to bind a per-tenant location. z.Rejected custom ini_path outside allowlist: %sz&ini_location outside allowed paths: %sz6Rejected custom ini_path bound to a foreign tenant: %srz7Rejected custom ini_path owned by uid %s (not root): %s)ÚosÚpathÚrealpathr rNrOr r)rÚ_is_own_cagefs_subtreeÚ_is_own_per_domain_ini_dirÚ _is_withinÚ _CAGEFS_ROOTÚ_is_under_per_domain_ini_rootÚstatÚst_uidÚOSError)r*rLrRÚresolvedros r.rXz CustomManager._validate_ini_path™s˜€ð(ð ØˆOÝ”7×#Ò# HÑ-Ô-ˆÝ" 8Ñ,Ô,ð [Ø ŒK× Ò Ð PÐRZÑ [Ô [Ð [Ý"¥1Ð%MÑ#NÔ#NÐQYÑ#YÑZÔZÐ Zõ Ô /°°xÑ @Ô @ð ÅMÔDlØ �8ñE ôE ð ðˆOõ Ô #Ý Ô &¨ñ ô ð [å Ô 8¸Ñ BÔ Bð [ð ŒK× Ò Ð XÐZbÑ cÔ cÐ cÝ"¥1Ð%MÑ#NÔ#NÐQYÑ#YÑZÔZÐ Zð  Ý”W˜XÑ&Ô&Ô-ˆFˆFøÝð ð ð ØˆOˆOˆOð øøøà �QŠ;ˆ;؈OØ Œ ×ÒÐUÐW]Ð_gÑhÔhÐhÝ�qÐ!IÑJÔJÈXÑUÑVÔVÐVsÄD!Ä! D0Ä/D0có—|jS)zL Path to additional .ini files specific custom panel getter )rLr`s r.Ú _ini_pathzCustomManager._ini_pathÏs €ðÔ#Ð#r/cój•—|jr|jSt¦« |¦«}| d¦«rm|j d¦«sS|j}d|j›�|_ |jp|}n#t $rYnwxYw||_|j d|¦«|S)aû Resolve a path to directory for additional ini file. It depends on version set for domain and on selector NOTE: This method is overrided to manage php.d.location=selector resolving. In custom integration we do not know if PHP version is alt or not, it is set as just two digits. Thus, we only could rely on resolved path -- if it is '/opt/alt'. :param domain_info: a DomainInfo object :return: path to directory for ini files z/opt/altzalt-phpzIni path re-resolved as %s) rGr#Ú get_ini_pathÚ startswithrFÚphpd_location_ini_pathÚ ValueErrorrNrZ)r*r]rLÚsaved_panel_phpr-s €r.ruzCustomManager.get_ini_pathÕsÚø€ð Ô 'ð 0ØÔ/Ð /õ‘7”7×'Ò'¨ Ñ4Ô4ˆØ × Ò ˜zÑ *Ô *ð E°;Ô3P×3[Ò3[Ð\eÑ3fÔ3fð EØ)Ô;ˆOØ,U°kÔ6SÐ,UÐ,UˆKÔ )ð Ø&Ô=ÐIÀ��øÝð ð ð à�ð øøøð-<ˆKÔ )Ø ŒK× Ò Ð9¸8Ñ DÔ DÐ D؈sÁ7 B B B)Ú__name__Ú __module__Ú __qualname__Ú__doc__r!rÚdictÚ__annotations__r$rr4Úpropertyr&r'rr Ústrr r^ÚboolrardrXrsruÚ __classcell__)r-s@r.rrsïø€€€€€€ððð ØØØØØØØØØØØØØð'ð'€O�X˜d”^ððñð"XðXðXðXðXð= Hð=ð=ð=ð=ðð +ð +ñ„Xð +ð/ ð/ð/ð/ð/ð  Øð3¨3ð3°:ð3ð3ð3ñÔñ Ôð3ðjC¸:ðCÈ$ðCðCðCðCð"¨ð"¸¸d¹ ð"ð"ð"ð"ð 4W¨3ð4W°sð4W¸sð4Wð4Wð4Wð4Wðl$ Zð$°Cð$ð$ð$ð$ð ¨ ð°sððððððððððr/r)r}rfÚ collectionsrÚtypingrÚclcommon.cpapi.plugins.vendorsrr6rr)Ú xray.internalrÚinternal.constantsr Úinternal.exceptionsr r Úinternal.typesr Úinternal.user_plugin_utilsr rÚbaserr©r/r.úrŽsðð ðð  € € € Ø Ð Ð Ð Ð Ð ØÐÐÐÐÐà4Ð4Ð4Ð4Ð4Ð4àÐÐÐÐÐØ'Ð'Ð'Ð'Ð'Ð'à4Ð4Ð4Ð4Ð4Ð4ØEÐEÐEÐEÐEÐEÐEÐEØ'Ð'Ð'Ð'Ð'Ð'Ø[Ð[Ð[Ð[Ð[Ð[Ð[Ð[ØÐÐÐÐÐðVðVðVðVðV�KñVôVðVðVðVr/