/opt/cloudlinux/venv/lib/python3.11/site-packages
# -*- coding: utf-8 -*- # CLSETUP python lib # # Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2019 All Rights Reserved # # Licensed under CLOUD LINUX LICENSE AGREEMENT # http://cloudlinux.com/docs/LICENSE.TXT # Classes: # # Kernel # check min kernel for securelinks # Setup: # # setup apache gid for securelinks # setup nagios import grp import os import pwd import subprocess import sys import cldetectlib from cl_proc_hidepid import remount_proc from clcommon.sysctl import SYSCTL_CL_CONF_FILE, SysCtlConf # Kernel Version Class class KernelVersion: _SECURELINKS_MIN_KERNEL = ['1','1','95'] _system_kernel = '' _cl_kernel = True def __init__(self): with subprocess.Popen( ['uname', '-r'], stdout=subprocess.PIPE, stderr=subprocess.PIPE, ) as proc: out, _ = proc.communicate() if proc.returncode != 0: print('error: subprocess call error. Cant\'t get current kernel version') sys.exit(1) if out.find('lve') != -1: self._system_kernel = out.split('lve')[1].split('el')[0][:-1].strip().split('.') print(self._system_kernel) else: self._cl_kernel = False # Check if system kernel newer then securelinks min kernel def securelinks_kernel_requirement(self): if self._cl_kernel: return ( self._system_kernel >= self._SECURELINKS_MIN_KERNEL and os.path.isfile('/proc/sys/fs/symlinkown_gid') ) print('error: Feature is not supported on non CL kernel.') sys.exit(1) # return _SECURELINKS_MIN_KERNEL def get_securelinks_min_kernel(self): return 'lve' + '.'.join(self._SECURELINKS_MIN_KERNEL) sysctl = SysCtlConf(config_file=SYSCTL_CL_CONF_FILE) def set_securelinks_gid(apache_gid): """ Change /etc/sysctl.conf for apache gid :param apache_gid: id of apache's group :return: None """ symlink_command = 'fs.symlinkown_gid' sysctl.set(symlink_command, apache_gid) def _add_to_super_gid(user): """ Add user to the group specified by fs.proc_super_gid. If fs.proc_super_gid is 0 (means undefined) or group doesn't really exists then create "clsupergid" group, configure it as fs.proc_super_gid and add user to this group """ sgid_key = 'fs.proc_super_gid' try: # sysctl.get may return empty string in some cases like cldeploy # when CL kernel is not loaded yet and proc has no such param proc_super_gid = int(sysctl.get(sgid_key)) except ValueError: proc_super_gid = 0 try: # Check that group with this gid really exists, and if not, then reset # it to undefined so it will be replaced with clsupergid below grp.getgrgid(proc_super_gid).gr_name except KeyError: proc_super_gid = 0 if proc_super_gid == 0: # Create and configure group if it was undefined sgid_name = 'clsupergid' subprocess.run(f'groupadd -f {sgid_name}', shell=True, executable='/bin/bash', check=False) proc_super_gid = grp.getgrnam(sgid_name).gr_gid sysctl.set(sgid_key, proc_super_gid) # If user already in this group or it's primary group == proc_super_gid # this will do nothing subprocess.run(f'usermod -a -G {proc_super_gid} {user}', shell=True, executable='/bin/bash', check=False) def setup_nagios(do_remount_proc=True): """ Add nagios to configured fs.proc_super_gid group """ if not cldetectlib.get_nagios(): return # Nothing to do _add_to_super_gid('nagios') # CAG-796: use hidepid=2 when mounting /proc if do_remount_proc: remount_proc() def setup_mailman(): """ Detect "mailman" and add it to fs.proc_super_gid group """ if not os.path.isdir('/usr/local/cpanel/3rdparty/mailman'): return try: pwd.getpwnam('mailman') except KeyError: return _add_to_super_gid('mailman') def setup_supergids(): """ Configure "special" users to be in fs.proc_super_gid group, if it's necessary. If this GID was undefined(0) then create and setup special clsupergid group """ setup_nagios(do_remount_proc=False) setup_mailman() # CAG-796: use hidepid=2 when mounting /proc remount_proc()
.
Edit
..
Edit
GitPython-3.1.32.dist-info
Edit
Jinja2-3.0.3.dist-info
Edit
Mako-1.2.4.dist-info
Edit
MarkupSafe-2.1.3.dist-info
Edit
PyJWT-2.8.0.dist-info
Edit
PyMySQL-1.1.0.dist-info
Edit
PyVirtualDisplay-3.0.dist-info
Edit
PyYAML-6.0.1.dist-info
Edit
__pycache__
Edit
_cffi_backend.cpython-311-x86_64-linux-gnu.so
Edit
_distutils_hack
Edit
_pyrsistent_version.py
Edit
_pytest
Edit
_yaml
Edit
aiohttp
Edit
aiohttp-3.9.2.dist-info
Edit
aiohttp_jinja2
Edit
aiohttp_jinja2-1.5.dist-info
Edit
aiohttp_security
Edit
aiohttp_security-0.4.0.dist-info
Edit
aiohttp_session
Edit
aiohttp_session-2.9.0.dist-info
Edit
aiosignal
Edit
aiosignal-1.3.1.dist-info
Edit
alembic
Edit
alembic-1.11.1.dist-info
Edit
astroid
Edit
astroid-2.15.6.dist-info
Edit
attr
Edit
attrs
Edit
attrs-23.1.0.dist-info
Edit
backports
Edit
certifi
Edit
certifi-2023.7.22.dist-info
Edit
cffi
Edit
cffi-1.15.1.dist-info
Edit
chardet
Edit
chardet-5.2.0.dist-info
Edit
charset_normalizer
Edit
charset_normalizer-2.1.1.dist-info
Edit
cl_dom_collector
Edit
cl_proc_hidepid.py
Edit
cl_website_collector
Edit
clcagefslib
Edit
clcommon
Edit
clconfig
Edit
clconfigure
Edit
clcontrollib.py
Edit
cldashboard
Edit
cldetectlib.py
Edit
cldiaglib.py
Edit
clevents
Edit
clflags
Edit
clhooklib.py
Edit
cli_utils.py
Edit
cllicense
Edit
cllicenselib.py
Edit
cllimits
Edit
cllimits_validator
Edit
cllimitslib_v2
Edit
cllvectl
Edit
clpackages
Edit
clquota
Edit
clselect
Edit
clselector
Edit
clsentry
Edit
clsetuplib.py
Edit
clsudo.py
Edit
clsummary
Edit
clveconfig
Edit
clwizard
Edit
clwpos
Edit
configparser-5.0.2.dist-info
Edit
configparser.py
Edit
contextlib2
Edit
contextlib2-21.6.0.dist-info
Edit
coverage
Edit
coverage-7.2.7.dist-info
Edit
cryptography
Edit
cryptography-41.0.2.dist-info
Edit
ddt-1.4.4.dist-info
Edit
ddt.py
Edit
dill
Edit
dill-0.3.7.dist-info
Edit
distlib
Edit
distlib-0.3.8.dist-info
Edit
distutils-precedence.pth
Edit
docopt-0.6.2.dist-info
Edit
docopt.py
Edit
dodgy
Edit
dodgy-0.2.1.dist-info
Edit
filelock
Edit
filelock-3.13.1.dist-info
Edit
flake8
Edit
flake8-5.0.4.dist-info
Edit
flake8_polyfill
Edit
flake8_polyfill-1.0.2.dist-info
Edit
frozenlist
Edit
frozenlist-1.4.0.dist-info
Edit
future
Edit
future-0.18.3.dist-info
Edit
git
Edit
gitdb
Edit
gitdb-4.0.10.dist-info
Edit
guppy
Edit
guppy3-3.1.3.dist-info
Edit
idna
Edit
idna-3.4.dist-info
Edit
iniconfig
Edit
iniconfig-2.0.0.dist-info
Edit
isort
Edit
isort-5.12.0.dist-info
Edit
jinja2
Edit
jsonschema
Edit
jsonschema-3.2.0.dist-info
Edit
jwt
Edit
lazy_object_proxy
Edit
lazy_object_proxy-1.9.0.dist-info
Edit
libfuturize
Edit
libpasteurize
Edit
lve_stats-2.0.dist-info
Edit
lve_utils
Edit
lveapi.py
Edit
lvectllib.py
Edit
lvemanager
Edit
lvestat.py
Edit
lvestats
Edit
lxml
Edit
lxml-4.9.2.dist-info
Edit
mako
Edit
markupsafe
Edit
mccabe-0.7.0.dist-info
Edit
mccabe.py
Edit
mock
Edit
mock-5.1.0.dist-info
Edit
multidict
Edit
multidict-6.0.4.dist-info
Edit
numpy
Edit
numpy-1.25.1.dist-info
Edit
numpy.libs
Edit
packaging
Edit
packaging-23.1.dist-info
Edit
pam.py
Edit
past
Edit
pep8_naming-0.10.0.dist-info
Edit
pep8ext_naming.py
Edit
pip
Edit
pip-25.0.1.dist-info
Edit
pkg_resources
Edit
platformdirs
Edit
platformdirs-3.11.0.dist-info
Edit
pluggy
Edit
pluggy-1.2.0.dist-info
Edit
prettytable
Edit
prettytable-3.8.0.dist-info
Edit
prometheus_client
Edit
prometheus_client-0.8.0.dist-info
Edit
prospector
Edit
prospector-1.10.2.dist-info
Edit
psutil
Edit
psutil-5.9.5.dist-info
Edit
psycopg2
Edit
psycopg2_binary-2.9.6.dist-info
Edit
psycopg2_binary.libs
Edit
py.py
Edit
pycodestyle-2.9.1.dist-info
Edit
pycodestyle.py
Edit
pycparser
Edit
pycparser-2.21.dist-info
Edit
pydocstyle
Edit
pydocstyle-6.3.0.dist-info
Edit
pyfakefs
Edit
pyfakefs-5.2.3.dist-info
Edit
pyflakes
Edit
pyflakes-2.5.0.dist-info
Edit
pylint
Edit
pylint-2.17.4.dist-info
Edit
pylint_celery
Edit
pylint_celery-0.3.dist-info
Edit
pylint_django
Edit
pylint_django-2.5.3.dist-info
Edit
pylint_flask
Edit
pylint_flask-0.6.dist-info
Edit
pylint_plugin_utils
Edit
pylint_plugin_utils-0.7.dist-info
Edit
pylve-2.1-py3.11.egg-info
Edit
pylve.cpython-311-x86_64-linux-gnu.so
Edit
pymysql
Edit
pyparsing
Edit
pyparsing-3.0.9.dist-info
Edit
pyrsistent
Edit
pyrsistent-0.19.3.dist-info
Edit
pytest
Edit
pytest-7.4.0.dist-info
Edit
pytest_check
Edit
pytest_check-2.5.3.dist-info
Edit
pytest_snapshot
Edit
pytest_snapshot-0.9.0.dist-info
Edit
pytest_subprocess
Edit
pytest_subprocess-1.5.0.dist-info
Edit
pytest_tap
Edit
pytest_tap-3.5.dist-info
Edit
python_pam-1.8.4.dist-info
Edit
pyvirtualdisplay
Edit
raven
Edit
raven-6.10.0.dist-info
Edit
remove_ubc.py
Edit
requests
Edit
requests-2.31.0.dist-info
Edit
requirements_detector
Edit
requirements_detector-1.2.2.dist-info
Edit
schema-0.7.5.dist-info
Edit
schema.py
Edit
secureio.py
Edit
semver
Edit
semver-3.0.1.dist-info
Edit
sentry_sdk
Edit
sentry_sdk-1.29.2.dist-info
Edit
setoptconf
Edit
setoptconf_tmp-0.3.1.dist-info
Edit
setuptools
Edit
setuptools-78.1.0.dist-info
Edit
simple_rpm.so
Edit
simplejson
Edit
simplejson-3.19.1.dist-info
Edit
six-1.16.0.dist-info
Edit
six.py
Edit
smmap
Edit
smmap-5.0.0.dist-info
Edit
snowballstemmer
Edit
snowballstemmer-2.2.0.dist-info
Edit
sqlalchemy
Edit
sqlalchemy-1.3.24.dist-info
Edit
ssa
Edit
svgwrite
Edit
svgwrite-1.4.3.dist-info
Edit
tap
Edit
tap_py-3.2.1.dist-info
Edit
testfixtures
Edit
testfixtures-7.1.0.dist-info
Edit
toml
Edit
toml-0.10.2.dist-info
Edit
tomlkit
Edit
tomlkit-0.11.8.dist-info
Edit
typing_extensions-4.7.1.dist-info
Edit
typing_extensions.py
Edit
unshare-0.22.dist-info
Edit
unshare.cpython-311-x86_64-linux-gnu.so
Edit
urllib3
Edit
urllib3-2.0.4.dist-info
Edit
vendors_api
Edit
virtualenv
Edit
virtualenv-20.21.1.dist-info
Edit
wcwidth
Edit
wcwidth-0.2.6.dist-info
Edit
wmt
Edit
wrapt
Edit
wrapt-1.15.0.dist-info
Edit
xray
Edit
yaml
Edit
yarl
Edit
yarl-1.9.2.dist-info
Edit