/
opt
/
cloudlinux
/
venv
/
lib
/
python3.11
/
site-packages
/
/opt/cloudlinux/venv/lib/python3.11/site-packages
mkdir
upload
Name
Size
Mode
Actions
aiohttp/
-
0755
rm
aiohttp-3.9.2.dist-info/
-
0755
rm
aiohttp_jinja2/
-
0755
rm
aiohttp_jinja2-1.5.dist-info/
-
0755
rm
aiohttp_security/
-
0755
rm
aiohttp_security-0.4.0.dist-info/
-
0755
rm
aiohttp_session/
-
0755
rm
aiohttp_session-2.9.0.dist-info/
-
0755
rm
aiosignal/
-
0755
rm
aiosignal-1.3.1.dist-info/
-
0755
rm
alembic/
-
0755
rm
alembic-1.11.1.dist-info/
-
0755
rm
astroid/
-
0755
rm
astroid-2.15.6.dist-info/
-
0755
rm
attr/
-
0755
rm
attrs/
-
0755
rm
attrs-23.1.0.dist-info/
-
0755
rm
backports/
-
0755
rm
certifi/
-
0755
rm
certifi-2023.7.22.dist-info/
-
0755
rm
cffi/
-
0755
rm
cffi-1.15.1.dist-info/
-
0755
rm
chardet/
-
0755
rm
chardet-5.2.0.dist-info/
-
0755
rm
charset_normalizer/
-
0755
rm
charset_normalizer-2.1.1.dist-info/
-
0755
rm
clcagefslib/
-
0755
rm
clcommon/
-
0755
rm
clconfig/
-
0755
rm
clconfigure/
-
0755
rm
cldashboard/
-
0755
rm
clevents/
-
0755
rm
clflags/
-
0755
rm
cllicense/
-
0755
rm
cllimits/
-
0755
rm
cllimitslib_v2/
-
0755
rm
cllimits_validator/
-
0755
rm
cllvectl/
-
0755
rm
clpackages/
-
0755
rm
clquota/
-
0755
rm
clselect/
-
0755
rm
clselector/
-
0755
rm
clsentry/
-
0755
rm
clsummary/
-
0755
rm
clveconfig/
-
0755
rm
clwizard/
-
0755
rm
clwpos/
-
0755
rm
cl_dom_collector/
-
0755
rm
cl_website_collector/
-
0755
rm
configparser-5.0.2.dist-info/
-
0755
rm
contextlib2/
-
0755
rm
contextlib2-21.6.0.dist-info/
-
0755
rm
coverage/
-
0755
rm
coverage-7.2.7.dist-info/
-
0755
rm
cryptography/
-
0755
rm
cryptography-41.0.2.dist-info/
-
0755
rm
ddt-1.4.4.dist-info/
-
0755
rm
dill/
-
0755
rm
dill-0.3.7.dist-info/
-
0755
rm
distlib/
-
0755
rm
distlib-0.3.8.dist-info/
-
0755
rm
docopt-0.6.2.dist-info/
-
0755
rm
dodgy/
-
0755
rm
dodgy-0.2.1.dist-info/
-
0755
rm
filelock/
-
0755
rm
filelock-3.13.1.dist-info/
-
0755
rm
flake8/
-
0755
rm
flake8-5.0.4.dist-info/
-
0755
rm
flake8_polyfill/
-
0755
rm
flake8_polyfill-1.0.2.dist-info/
-
0755
rm
frozenlist/
-
0755
rm
frozenlist-1.4.0.dist-info/
-
0755
rm
future/
-
0755
rm
future-0.18.3.dist-info/
-
0755
rm
git/
-
0755
rm
gitdb/
-
0755
rm
gitdb-4.0.10.dist-info/
-
0755
rm
GitPython-3.1.32.dist-info/
-
0755
rm
guppy/
-
0755
rm
guppy3-3.1.3.dist-info/
-
0755
rm
idna/
-
0755
rm
idna-3.4.dist-info/
-
0755
rm
iniconfig/
-
0755
rm
iniconfig-2.0.0.dist-info/
-
0755
rm
isort/
-
0755
rm
isort-5.12.0.dist-info/
-
0755
rm
jinja2/
-
0755
rm
Jinja2-3.0.3.dist-info/
-
0755
rm
jsonschema/
-
0755
rm
jsonschema-3.2.0.dist-info/
-
0755
rm
jwt/
-
0755
rm
lazy_object_proxy/
-
0755
rm
lazy_object_proxy-1.9.0.dist-info/
-
0755
rm
libfuturize/
-
0755
rm
libpasteurize/
-
0755
rm
lvemanager/
-
0755
rm
lvestats/
-
0755
rm
lve_stats-2.0.dist-info/
-
0755
rm
lve_utils/
-
0755
rm
lxml/
-
0755
rm
lxml-4.9.2.dist-info/
-
0755
rm
mako/
-
0755
rm
Mako-1.2.4.dist-info/
-
0755
rm
markupsafe/
-
0755
rm
MarkupSafe-2.1.3.dist-info/
-
0755
rm
mccabe-0.7.0.dist-info/
-
0755
rm
mock/
-
0755
rm
mock-5.1.0.dist-info/
-
0755
rm
multidict/
-
0755
rm
multidict-6.0.4.dist-info/
-
0755
rm
numpy/
-
0755
rm
numpy-1.25.1.dist-info/
-
0755
rm
numpy.libs/
-
0755
rm
packaging/
-
0755
rm
packaging-23.1.dist-info/
-
0755
rm
past/
-
0755
rm
pep8_naming-0.10.0.dist-info/
-
0755
rm
pip/
-
0755
rm
pip-24.3.1.dist-info/
-
0755
rm
pkg_resources/
-
0755
rm
platformdirs/
-
0755
rm
platformdirs-3.11.0.dist-info/
-
0755
rm
pluggy/
-
0755
rm
pluggy-1.2.0.dist-info/
-
0755
rm
prettytable/
-
0755
rm
prettytable-3.8.0.dist-info/
-
0755
rm
prometheus_client/
-
0755
rm
prometheus_client-0.8.0.dist-info/
-
0755
rm
prospector/
-
0755
rm
prospector-1.10.2.dist-info/
-
0755
rm
psutil/
-
0755
rm
psutil-5.9.5.dist-info/
-
0755
rm
psycopg2/
-
0755
rm
psycopg2_binary-2.9.6.dist-info/
-
0755
rm
psycopg2_binary.libs/
-
0755
rm
pycodestyle-2.9.1.dist-info/
-
0755
rm
pycparser/
-
0755
rm
pycparser-2.21.dist-info/
-
0755
rm
pydocstyle/
-
0755
rm
pydocstyle-6.3.0.dist-info/
-
0755
rm
pyfakefs/
-
0755
rm
pyfakefs-5.10.2.dist-info/
-
0755
rm
pyflakes/
-
0755
rm
pyflakes-2.5.0.dist-info/
-
0755
rm
PyJWT-2.8.0.dist-info/
-
0755
rm
pylint/
-
0755
rm
pylint-2.17.4.dist-info/
-
0755
rm
pylint_celery/
-
0755
rm
pylint_celery-0.3.dist-info/
-
0755
rm
pylint_django/
-
0755
rm
pylint_django-2.5.3.dist-info/
-
0755
rm
pylint_flask/
-
0755
rm
pylint_flask-0.6.dist-info/
-
0755
rm
pylint_plugin_utils/
-
0755
rm
pylint_plugin_utils-0.7.dist-info/
-
0755
rm
pylve-2.1-py3.11.egg-info/
-
0755
rm
pymysql/
-
0755
rm
PyMySQL-1.1.0.dist-info/
-
0755
rm
pyparsing/
-
0755
rm
pyparsing-3.0.9.dist-info/
-
0755
rm
pyrsistent/
-
0755
rm
pyrsistent-0.19.3.dist-info/
-
0755
rm
pytest/
-
0755
rm
pytest-7.4.0.dist-info/
-
0755
rm
pytest_check/
-
0755
rm
pytest_check-2.5.3.dist-info/
-
0755
rm
pytest_snapshot/
-
0755
rm
pytest_snapshot-0.9.0.dist-info/
-
0755
rm
pytest_subprocess/
-
0755
rm
pytest_subprocess-1.5.3.dist-info/
-
0755
rm
pytest_tap/
-
0755
rm
pytest_tap-3.5.dist-info/
-
0755
rm
python_pam-1.8.4.dist-info/
-
0755
rm
pyvirtualdisplay/
-
0755
rm
PyVirtualDisplay-3.0.dist-info/
-
0755
rm
PyYAML-6.0.1.dist-info/
-
0755
rm
raven/
-
0755
rm
raven-6.10.0.dist-info/
-
0755
rm
requests/
-
0755
rm
requests-2.31.0.dist-info/
-
0755
rm
requirements_detector/
-
0755
rm
requirements_detector-1.2.2.dist-info/
-
0755
rm
schema-0.7.5.dist-info/
-
0755
rm
semver/
-
0755
rm
semver-3.0.1.dist-info/
-
0755
rm
sentry_sdk/
-
0755
rm
sentry_sdk-1.29.2.dist-info/
-
0755
rm
setoptconf/
-
0755
rm
setoptconf_tmp-0.3.1.dist-info/
-
0755
rm
setuptools/
-
0755
rm
setuptools-81.0.0.dist-info/
-
0755
rm
simplejson/
-
0755
rm
simplejson-3.19.1.dist-info/
-
0755
rm
six-1.16.0.dist-info/
-
0755
rm
smmap/
-
0755
rm
smmap-5.0.0.dist-info/
-
0755
rm
snowballstemmer/
-
0755
rm
snowballstemmer-2.2.0.dist-info/
-
0755
rm
sqlalchemy/
-
0755
rm
sqlalchemy-1.3.24.dist-info/
-
0755
rm
ssa/
-
0755
rm
svgwrite/
-
0755
rm
svgwrite-1.4.3.dist-info/
-
0755
rm
tap/
-
0755
rm
tap_py-3.2.1.dist-info/
-
0755
rm
testfixtures/
-
0755
rm
testfixtures-7.1.0.dist-info/
-
0755
rm
toml/
-
0755
rm
toml-0.10.2.dist-info/
-
0755
rm
tomlkit/
-
0755
rm
tomlkit-0.11.8.dist-info/
-
0755
rm
typing_extensions-4.7.1.dist-info/
-
0755
rm
unshare-0.22.dist-info/
-
0755
rm
urllib3/
-
0755
rm
urllib3-2.0.4.dist-info/
-
0755
rm
vendors_api/
-
0755
rm
virtualenv/
-
0755
rm
virtualenv-20.21.1.dist-info/
-
0755
rm
wcwidth/
-
0755
rm
wcwidth-0.2.6.dist-info/
-
0755
rm
websiteisolation/
-
0755
rm
wmt/
-
0755
rm
wrapt/
-
0755
rm
wrapt-1.15.0.dist-info/
-
0755
rm
xray/
-
0755
rm
yaml/
-
0755
rm
yarl/
-
0755
rm
yarl-1.9.2.dist-info/
-
0755
rm
_distutils_hack/
-
0755
rm
_pytest/
-
0755
rm
_yaml/
-
0755
rm
__pycache__/
-
0755
rm
clcontrollib.py
53042
0644
edit
dl
rm
cldetectlib.py
18843
0644
edit
dl
rm
cldiaglib.py
49660
0644
edit
dl
rm
clhooklib.py
1296
0644
edit
dl
rm
cli_utils.py
1698
0644
edit
dl
rm
cllicenselib.py
11864
0644
edit
dl
rm
clsetuplib.py
5193
0644
edit
dl
rm
clsudo.py
23586
0644
edit
dl
rm
cl_proc_hidepid.py
4638
0644
edit
dl
rm
configparser.py
1546
0644
edit
dl
rm
ddt.py
12733
0644
edit
dl
rm
distutils-precedence.pth
151
0644
edit
dl
rm
docopt.py
19946
0644
edit
dl
rm
lveapi.py
23294
0644
edit
dl
rm
lvectllib.py
136479
0644
edit
dl
rm
lvestat.py
6997
0644
edit
dl
rm
mccabe.py
10654
0644
edit
dl
rm
pam.py
7556
0644
edit
dl
rm
pep8ext_naming.py
19052
0644
edit
dl
rm
py.py
263
0644
edit
dl
rm
pycodestyle.py
103501
0644
edit
dl
rm
pylve.cpython-311-x86_64-linux-gnu.so
29528
0755
edit
dl
rm
remove_ubc.py
5864
0755
edit
dl
rm
schema.py
30221
0644
edit
dl
rm
secureio.py
20037
0644
edit
dl
rm
simple_rpm.so
15544
0755
edit
dl
rm
six.py
34549
0644
edit
dl
rm
typing_extensions.py
111082
0644
edit
dl
rm
unshare.cpython-311-x86_64-linux-gnu.so
16704
0755
edit
dl
rm
_cffi_backend.cpython-311-x86_64-linux-gnu.so
274048
0755
edit
dl
rm
_lvdmap.cpython-311-x86_64-linux-gnu.so
18800
0755
edit
dl
rm
_pyrsistent_version.py
23
0644
edit
dl
rm
Edit:
/opt/cloudlinux/venv/lib/python3.11/site-packages/lveapi.py
(23294B)
#!/usr/bin/env python # -*- coding: utf-8 -*- # Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2019 All Rights Reserved # # Licensed under CLOUD LINUX LICENSE AGREEMENT # http://cloudlinux.com/docs/LICENSE.TXT import os import syslog import pwd from typing import Optional # NOQA from clcommon.clproc import ProcLve from clcommon import cpapi, ClPwd from clcommon.cpapi.cpapiexceptions import NotSupported from clveconfig import ve_config from lve_utils.pylve_wrapper import PyLveError, PyLve # noqa: F401 — re-exported for callers from websiteisolation import config as _ws_config from websiteisolation import id_registry as _ws_id_registry LVP_XML_TAG_NAME = "reseller" LVE_NO_UBC = 1 << 1 LVE_NO_MAXENTER = 1 << 2 class NameMapError(Exception): pass class NameMapConfigError(NameMapError): pass class NameMapNotInitialized(NameMapError): pass class NameMap: """ Container for backend storing resellers_name<=>resellers_id map As backend store use ve.cfg Usage: >>> name_map = NameMap() >>> name_map.link_xml_node() >>> name_map.id_list() [1001] """ def __init__(self, xml_tag_name=LVP_XML_TAG_NAME): self._xml_tag_name = xml_tag_name self._xml_node = None # Reseller name to id map (list of corteges) self._reseller_id_name_map = None def get_id(self, name): for name_, id_ in self.load_from_node(): if name_ == name: return id_ def get_name(self, id_): for name_, _id in self.load_from_node(): if id_ == _id: return name_ def id_list(self): return [id_ for _, id_ in self.load_from_node()] def link_xml_node(self, xml_node=None, use_cache=True): """ Initialize NameMap. If xml_node is none, config will be loaded automatically :param use_cache: Bool whether bypass ve.cfg xml cache :param xml_node: !! DEPRECATED PARAM !! this param is left only for compatibility with our old code """ if xml_node is None: # New mode, Load reseller_id, reseller_name pairs from ve.cfg to dictionary self._xml_node = None self._load_resellers_map_from_ve_cfg(use_cache) else: # For compatibility with our old code self._xml_node = xml_node self._reseller_id_name_map = None def _load_resellers_map_from_ve_cfg(self, use_cache): """ Fills self._reseller_id_name_map from ve.cfg file :return: """ self._reseller_id_name_map = [] ve_cfg, xml_node = self._try_get_xml_node(use_cache=use_cache) for el_ in xml_node: name = el_.getAttribute('user') id_ = int(el_.getAttribute('id')) if name and id_ and id_ not in self._reseller_id_name_map: self._reseller_id_name_map.append((id_, name)) # Force delete XML object to avoid high memory load del xml_node del ve_cfg def _try_get_xml_node(self, use_cache=True): try: ve_cfg, xml_node = ve_config.get_xml_config(use_cache=use_cache) except ve_config.BadVeConfigException as e: self._reseller_id_name_map = None raise NameMapConfigError("Error happened while loading data from ve.cfg") from e return ve_cfg, xml_node.getElementsByTagName(self._xml_tag_name) def load_from_node(self): """ Obtain data from xml node as (name, id_) list """ if self._xml_node is None and self._reseller_id_name_map is None: raise NameMapNotInitialized('Name map is not initialized. ' 'Use obj.link_xml_node() to get data from config') if self._xml_node: # For compatibility with our old code for el_ in self._xml_node.getElementsByTagName(self._xml_tag_name): name = el_.getAttribute('user') id_ = int(el_.getAttribute('id')) if name and id_: yield name, id_ if self._reseller_id_name_map: # New mode, use resellers map for id_, name in self._reseller_id_name_map: yield name, id_ class LvpMap: """ Container for storing information about lve:lvp mapping In which reseller container stored lve """ def __init__(self): self.name_map = NameMap() self._id_name_map = {} self._name_id_map = {} self._reseller_id_map_panel = None self._pwd = ClPwd() def _add_map(self, name, id_): self._id_name_map[id_] = name self._name_id_map[name] = id_ def pw_uid(self, name, default=None): try: return self._pwd.get_pw_by_name(name).pw_uid except ClPwd.NoSuchUserException: return default def _get_panel_reseller_id(self, reseller): # type: (str) -> Optional[int] uid = self.pw_uid(reseller) if uid is not None: return uid # in case when we cannot find reseller in passwd file # let's ask control panel for reseller's id if self._reseller_id_map_panel is None: self._reseller_id_map_panel = cpapi.get_reseller_id_pairs() return self._reseller_id_map_panel.get(reseller) def get_reseller_id(self, name): # type: (str) -> Optional[int] """ Convert reseller name to an LVE id. It supports resellers without a system account (for Plesk compatibility). """ uid = self.name_map.get_id(name) or self._name_id_map.get(name) if uid is not None: return uid try: uid = self._get_panel_reseller_id(name) except NotSupported: uid = None if uid is not None: self._add_map(name, uid) return uid def get_reseller_name(self, id_): """ Convert reseller id to reseller name It support resellers without system account (for Plesk compatibilyty) """ # add attribute fo in memory cache support name = self.name_map.get_name(id_) or self._id_name_map.get(id_) if name is not None: return name try: name = pwd.getpwuid(id_).pw_name if cpapi.is_reseller(name): self._add_map(name, id_) else: name = None except KeyError: name = None return name def lve_lvp_pairs(self): """ This method loops over all user:reseller pairs in control panel and returns appropriate lve_id:lvp_id pairs. THIS METHOD WON'T CHECK IF 'RESELLER LIMITS' IS ENABLED IN ve.cfg """ resellers = set(cpapi.resellers()) reseller_uids = {} for reseller in resellers: try: reseller_uids[reseller] = self.get_reseller_id(reseller) except NotSupported: syslog.syslog( syslog.LOG_WARNING, f"Reseller {reseller} still exists in control panel, " "but absent in /etc/passwd file") for cplogin, reseller in cpapi.cpinfo(keyls=('cplogin', 'reseller')): lve_id = self.pw_uid(cplogin) # for some reasons (process of destroying user died # or admin called 'pure' userdel), user may still exist in control panel # but absent in /etc/passwd file; we can do nothing with that, # so just skip and write a warning to syslog if lve_id is None: syslog.syslog( syslog.LOG_WARNING, f"user {cplogin} still exists in control panel, " "but absent in /etc/passwd file") continue lvp_id = reseller_uids.get(reseller, 0) yield lve_id, lvp_id @staticmethod def resellers(): for reseller_name in cpapi.resellers(): yield reseller_name @staticmethod def reseller_uids(name): """ Obtain from control panel resellers uids """ uids = [] reseller_users = cpapi.reseller_users(name) for user in reseller_users: try: id_ = pwd.getpwnam(user).pw_uid uids.append(id_) except KeyError: syslog.syslog( syslog.LOG_WARNING, f"user {user} still exists in control panel, " "but absent in /etc/passwd file") return uids def lvp_lve_id_list(self, lvp_id): reseller_name = self.get_reseller_name(lvp_id) return self.reseller_uids(reseller_name) class Lve: def __init__(self, proc=None, py=None, map=None): self.proc = proc or ProcLve() self.py = py or PyLve() self.map = map or LvpMap() self._mapped_domain_users: set = set() # CLOS-6868: memoised {lve_id: lvp_id}. Derived from ve.cfg plus the # panel's user list, neither of which changes while a single lvectl # command runs, so one build per process is enough. Before this, # lve2lvp() rescanned the whole generator per account, which made # `apply all` quadratic in account count — 7,738 rebuilds on a # 3,868-account host, each re-deriving the list from cpinfo and passwd. self._lve_lvp_map_cache: dict | None = None def lve_lvp_map(self) -> dict: """{lve_id: lvp_id} from ve.cfg, built once per instance. Callers that need a single lookup must use this rather than scanning `lve_id_lvp_id_pairs()`; the scan is O(accounts) and doing it per account is what made `apply all` quadratic. """ if self._lve_lvp_map_cache is None: enabled_lvp_id = set(self.map.name_map.id_list()) # A user whose reseller is NOT enabled in ve.cfg still appears, with # lvp_id 0 — dropping those rows would silently change which # accounts `apply all` treats as host-level. self._lve_lvp_map_cache = { lve_id: (lvp_id if lvp_id in enabled_lvp_id else 0) for lve_id, lvp_id in self.map.lve_lvp_pairs() } return self._lve_lvp_map_cache def invalidate_lve_lvp_map(self) -> None: """Drop the memoised map after ve.cfg or the panel user list changes.""" self._lve_lvp_map_cache = None def lve_id_lvp_id_pairs(self): """ Obtain {lve id}:{lvp id} pairs iterator based on ve.cfg config (detect enabled resellers containers) This method (unlike LvpMap.lve_lvp_pairs) will check if reseller is enabled in ve.cfg and return lvp_id=0 for users of reseller with disabled reseller limits """ yield from self.lve_lvp_map().items() def lve2lvp(self, lve_id): """ Obtain lvp id based on ve.cfg config (detect enabled resellers containers) """ return self.lve_lvp_map().get(lve_id, 0) def lve_destroy(self, lve_id, *args, **kwargs): """ safe destroy lve container with preserving lvp mapping """ if os.path.exists(self.proc.proc_lve_map()): lvp_id = self.proc.map().get(lve_id, 0) else: lvp_id = 0 self.py.lve_destroy(lve_id, *args, **kwargs) if lvp_id != 0: try: pwd.getpwuid(lve_id) self.py.lve_lvp_map(lvp_id, lve_id) except KeyError: pass def _build_domain_map(self, lve_id): """Resolve all domain→docroot→domain_id mappings once. Returns a list of (domain_id, limits_dict) tuples. Callers pass this to _map_domain_lves / apply_domain_lve_limits to avoid redundant resolve_docroot + assign_domain_id calls. Uses cpapi.userdomains() to fetch all domain→docroot pairs in a single file read instead of calling resolve_docroot per domain, which would re-parse the entire userdatadomains file each time. """ config = _ws_config.load_config(lve_id) try: username = pwd.getpwuid(lve_id).pw_name docroot_by_domain = dict(cpapi.userdomains(username) or []) except KeyError: docroot_by_domain = {} entries = [] for d in config.domains: if not d.name: continue try: docroot = docroot_by_domain.get(d.name) if docroot is None: continue # Only map domains the administrator explicitly enabled (the # registry entry is allocated via enable_domain_lve). Do NOT # allocate here: domains.json is user-writable, so allocating on # mere presence would let an account self-register domains and # bypass the admin-only enable step. domain_id = _ws_id_registry.get_domain_id(lve_id, docroot) if domain_id is None: continue entries.append((domain_id, d.limits.to_dict())) except (ValueError, TypeError, OverflowError) as exc: # Malformed tenant data (e.g. a non-str/unhashable domain name) # must not abort the root apply-all batch — log and skip the # offending domain so other domains and tenants still apply. syslog.syslog( syslog.LOG_WARNING, f"Skipping malformed domain entry for user {lve_id} " f"(name={d.name!r}): {exc}") continue return entries def _map_domain_lves(self, lve_id, proc_map, domain_map): """Place every domain LVE that belongs to *lve_id* under its user LVP. Uses lve_lvp_move for domain LVEs that already exist in the kernel, and falls back to lve_lvp_map for those that do not yet exist (so the kernel will place them under the correct LVP when lve_setup creates them later). *proc_map* is an lve_id→lvp_id dict (from /proc/lve/map) used to skip mappings that are already correct. Updated in-place so callers see the new state. *domain_map* is a precomputed list from _build_domain_map(). """ for domain_id, _limits in domain_map: if proc_map.get(domain_id) == lve_id: continue if domain_id in proc_map: # Domain LVE exists in the kernel — move it. self.py.lve_lvp_move(lve_id, domain_id) else: # Domain LVE does not exist yet — pre-register mapping. self.py.lve_lvp_map(lve_id, domain_id) proc_map[domain_id] = lve_id self._mapped_domain_users.add(lve_id) def apply_domain_lve_limits(self, lve_id, domain_map): """Apply per-domain limits from domains.json to each domain LVE. Must be called after lve_set_default() resets all LVEs inside the user LVP to the user's defaults. Each domain LVE is set to its stored limits, or the user's current cpu when unconfigured (cpu=0). CLOS-4024: the kernel rejects lve_lvp_setup when any child has cpu=0 inside a finite-cpu parent, so we never write cpu=0 to the kernel. CLOS-4060: domains with no custom limits are skipped — lve_set_default already reset their existing LVEs to user defaults, and non-existing ones will be lazily created by lve_enter under the user's LVP. *domain_map* is a precomputed list from _build_domain_map(). """ custom_limits = [(d, l) for d, l in domain_map if l] if not custom_limits: return try: parent_ls_cpu = self.py.lve_info(lve_id).ls_cpu except OSError: # fallback to 100% of all available CPU # fallback to 1 cpu core when we cannot identify # number of cores and cpu_count returns None parent_ls_cpu = (os.cpu_count() or 1) * 10000 for domain_id, limits in custom_limits: settings = self.py.liblve_settings() try: # CLOS-4024: the kernel rejects lve_lvp_setup with EINVAL when # any child LVE has cpu=0 inside a finite-cpu parent. Always # set a non-zero cpu on domain LVEs: use the stored value if # present, otherwise inherit the parent's current cpu limit. if 'cpu' in limits: settings.ls_cpu = int(limits['cpu']) or parent_ls_cpu else: settings.ls_cpu = parent_ls_cpu if 'pmem' in limits: pmem_bytes = int(limits['pmem']) settings.ls_memory_phy = pmem_bytes // 4096 if pmem_bytes else 0 if 'io' in limits: settings.ls_io = int(limits['io']) if 'nproc' in limits: settings.ls_nproc = int(limits['nproc']) if 'iops' in limits: settings.ls_iops = int(limits['iops']) if 'ep' in limits: settings.ls_enters = int(limits['ep']) if 'vmem' in limits: vmem_bytes = int(limits['vmem']) settings.ls_memory = vmem_bytes // 4096 if vmem_bytes else 0 except (ValueError, TypeError, OverflowError) as exc: # Malformed tenant data (e.g. a non-numeric or out-of-C-long # limit value) must not abort the root apply-all batch — log # and skip this domain so other domains and tenants still # apply. Real kernel/lve errors from lve_setup below are NOT # caught here and still propagate to the outer handler. syslog.syslog( syslog.LOG_WARNING, f"Skipping malformed limits for domain LVE {domain_id} " f"(user {lve_id}): {exc}") continue self.py.lve_setup( domain_id, settings, err_msg=f'Can`t setup domain LVE {domain_id}; error code {{code}}', ) def _sync_map(self): """ Load lve_id:lvp_id map to kmod-lve. For users with per-domain isolation configured, builds a nested LVP hierarchy instead of a flat reseller mapping: lvp<0> [lvp<reseller_id>] ← reseller LVP (if enabled) lvp<user_id> ← user-level LVP with isolation lve<user_id> ← user LVE lve<domain_id> ... ← domain LVEs lvp<0> [lvp<reseller_id>] ← reseller LVP (without isolation) lve<user_id> ← user LVE (flat, existing behaviour) """ # load mapping information from kernel (/proc/lve/map) proc_map_dict = self.proc.map() # loop over user_id:reseller_id pairs # lve_id_lvp_id_pairs includes all control panel users # and checks for enabled resellers in ve.cfg # so user of reseller without reseller limits # will be listed in response like 'tuple(user_id, 0)' if self.py.domains_supported(): # CLOS-4542: only users with at least one registered domain are # domain-isolated. A bare marker (allow-domain-limits with no # enabled domain — the state cagefsctl --isolates-allow-all leaves # every user in) must NOT get a per-user LVP here: lve_apply treats # it as non-isolated (lvectllib._is_domain_isolated_user requires # >= 1 domain) and never caps lvp<uid>, so nesting lve<uid> under a # freshly-created uncapped lvp<uid> on a cold (post-reboot) rebuild # would collapse the user to the kernel-default LVP. Mirror the # _is_domain_isolated_user predicate so the two paths agree. isolated_users = { uid for uid in _ws_config.find_all_lve_ids_with_config() if _ws_id_registry.get_all_entries(uid) } else: isolated_users = set() for lve_id, lvp_id in self.lve_id_lvp_id_pairs(): if lve_id in isolated_users: # User has per-domain isolation: build nested LVP hierarchy. # Ensure the parent (reseller) LVP exists first. if lvp_id != 0 and not self.proc.exist_lvp(lvp_id=lvp_id): self.py.lve_lvp_create(lvp_id) # Create user LVP nested under the reseller (or at root # when there is no reseller). lve_apply_all() already # creates the nested LVP for reseller users; this handles # the non-reseller case and the standalone sync-map call. if not self.proc.exist_lvp(lvp_id=lve_id): if lvp_id: self.py.lve_lvp_create2(lve_id, lvp_id) else: self.py.lve_lvp_create(lve_id) # Move the user LVE under the user LVP (both share lve_id). if proc_map_dict.get(lve_id, 0) != lve_id: self.py.lve_lvp_move(lve_id, lve_id) proc_map_dict[lve_id] = lve_id if lve_id not in self._mapped_domain_users: domain_map = self._build_domain_map(lve_id) self._map_domain_lves(lve_id, proc_map=proc_map_dict, domain_map=domain_map) else: # Standard behaviour: move user LVE under reseller/root LVP. if proc_map_dict.get(lve_id, 0) != lvp_id: # change map if needed only if not self.proc.exist_lvp(lvp_id=lvp_id): self.py.lve_lvp_create(lvp_id) self.py.lve_lvp_move(lvp_id, lve_id) proc_map_dict[lve_id] = lvp_id def sync_map(self): """ wrapped _sync_map function for prevent error if some cpapi not supported """ try: self._sync_map() except NotSupported: pass def is_panel_supported(self): """ Check if current panel supported for reseller's limits; :rtype: bool """ try: return cpapi.is_reseller_limits_supported() except NotSupported: return False def reseller_limit_supported(self): """ Check present all needed (kmod-lve, liblve, /proc/lve, panel) for manipulate resellers limits """ return all((self.py.resellers_supported(), self.proc.resellers_supported(), self.is_panel_supported())) def is_lve10(self): """ Check present all needed (kmod-lve, liblve, /proc/lve) for manipulate resellers limits """ return all((self.py.resellers_supported(), self.proc.resellers_supported()))
Save
cmd:
run