Server IP : 103.119.228.120 / Your IP : 3.15.228.32 Web Server : Apache System : Linux v8.techscape8.com 3.10.0-1160.119.1.el7.tuxcare.els2.x86_64 #1 SMP Mon Jul 15 12:09:18 UTC 2024 x86_64 User : nobody ( 99) PHP Version : 5.6.40 Disable Function : shell_exec,symlink,system,exec,proc_get_status,proc_nice,proc_terminate,define_syslog_variables,syslog,openlog,closelog,escapeshellcmd,passthru,ocinum cols,ini_alter,leak,listen,chgrp,apache_note,apache_setenv,debugger_on,debugger_off,ftp_exec,dl,dll,myshellexec,proc_open,socket_bind,proc_close,escapeshellarg,parse_ini_filepopen,fpassthru,exec,passthru,escapeshellarg,escapeshellcmd,proc_close,proc_open,ini_alter,popen,show_source,proc_nice,proc_terminate,proc_get_status,proc_close,pfsockopen,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,dl,symlink,shell_exec,system,dl,passthru,escapeshellarg,escapeshellcmd,myshellexec,c99_buff_prepare,c99_sess_put,fpassthru,getdisfunc,fx29exec,fx29exec2,is_windows,disp_freespace,fx29sh_getupdate,fx29_buff_prepare,fx29_sess_put,fx29shexit,fx29fsearch,fx29ftpbrutecheck,fx29sh_tools,fx29sh_about,milw0rm,imagez,sh_name,myshellexec,checkproxyhost,dosyayicek,c99_buff_prepare,c99_sess_put,c99getsource,c99sh_getupdate,c99fsearch,c99shexit,view_perms,posix_getpwuid,posix_getgrgid,posix_kill,parse_perms,parsesort,view_perms_color,set_encoder_input,ls_setcheckboxall,ls_reverse_all,rsg_read,rsg_glob,selfURL,dispsecinfo,unix2DosTime,addFile,system,get_users,view_size,DirFiles,DirFilesWide,DirPrintHTMLHeaders,GetFilesTotal,GetTitles,GetTimeTotal,GetMatchesCount,GetFileMatchesCount,GetResultFiles,fs_copy_dir,fs_copy_obj,fs_move_dir,fs_move_obj,fs_rmdir,SearchText,getmicrotime MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /scripts/ |
Upload File : |
#!/usr/local/cpanel/3rdparty/bin/perl # cpanel - scripts/initacls Copyright 2022 cPanel, L.L.C. # All rights reserved. # copyright@cpanel.net http://cpanel.net # This code is subject to the cPanel license. Unauthorized copying is prohibited package Cpanel::Script::Initacls; use cPstrict; use Cpanel::Binaries (); use Cpanel::SafeRun::Simple (); use Cpanel::SafeRun::Errors (); use Cpanel::Config::CpConfGuard (); use Cpanel::Logger (); use Cpanel::OSSys (); use Cpanel::SafeFile (); use Cpanel::TempFile (); our $aclsonfs = 0; our $fstab = "/etc/fstab"; our $fileprotect_touch = '/var/cpanel/fileprotect'; my $logger; exit main() unless caller(); sub main { $logger = Cpanel::Logger->new(); my ( $system, undef, $release ) = Cpanel::OSSys::uname(); my $mount_bin = Cpanel::Binaries::path('mount'); my $mount = Cpanel::SafeRun::Simple::saferun($mount_bin); chomp($mount); if ( $mount =~ /acl/ ) { $aclsonfs = 1; } unless ( -x Cpanel::Binaries::path('setfacl') ) { acldeath("Unable to locate setfacl: your distribution may not support acls\n"); } $release =~ /^(\d+\.\d+)/; my $nversion = $1; if ( $system =~ /linux/i && $nversion < 2.6 ) { acldeath("You must be running at least a 2.6 kernel to use this script."); } setuplinuxfstab(); acltestandsetup(); return 0; } sub setuplinuxfstab () { my $mount_bin = Cpanel::Binaries::path('mount'); #Check if the system is XFS (we only support XFS and ext3/4 as of this writing) my $is_xfs = Cpanel::SafeRun::Errors::saferunallerrors( $mount_bin, '-l' ); chomp $is_xfs; if ( $is_xfs =~ m/on \/ type xfs/i ) { print "XFS requires no mount alterations to enable ACLs, skipping...\n"; return 1; } if ( !$aclsonfs ) { my $acltest = Cpanel::SafeRun::Errors::saferunallerrors( $mount_bin, "-o", "remount,acl", "/" ); chomp($acltest); if ( $acltest ne "" ) { acldeath("System error: $acltest when testing for acl support. Your kernel may not support POSIX acls\n"); } } my $modtab = 0; my (@FSTAB); my (@REMOUNT); local $| = 1; my $fstablock = Cpanel::SafeFile::safeopen( \*FT, "+<", $fstab ); if ( !$fstablock ) { $logger->die("Could not edit $fstab"); } while (<FT>) { chomp(); if ( !/^[\s\t]*[\#\;]+/ ) { my (@FSLINE) = split( /[\s\t]+/, $_ ); my @OPTS = $FSLINE[3] ? split( /\,/, $FSLINE[3] ) : (); if ( ( $FSLINE[2] && $FSLINE[2] =~ /^ext\d+$/ ) && !grep( /^acl$/, @OPTS ) ) { push( @OPTS, 'acl' ); $FSLINE[3] = join( ",", @OPTS ); push( @FSTAB, join( "\t", @FSLINE ) ); push( @REMOUNT, $FSLINE[0] ); $modtab = 1; } else { push( @FSTAB, $_ ); } } else { push( @FSTAB, $_ ); } } if ($modtab) { seek( FT, 0, 0 ); print FT join( "\n", @FSTAB ) . "\n"; truncate( FT, tell(FT) ); } foreach (@REMOUNT) { my $res = Cpanel::SafeRun::Errors::saferunallerrors( $mount_bin, '-o', 'remount', $_ ); chomp $res; acldeath("System error: $res could not remount $_ with ACLs enabled!") if $res; } return Cpanel::SafeFile::safeclose( \*FT, $fstablock ); } sub acltestandsetup () { my $cfiler = Cpanel::TempFile->new(); my $randfile = $cfiler->file(); open( my $ACLTESTFILE, ">", $randfile ) or die("Couldn't open ACL test file $randfile for writing!"); close($ACLTESTFILE); my $acltest = Cpanel::SafeRun::Errors::saferunallerrors( Cpanel::Binaries::path('setfacl'), "-m", "user:nobody:r", "--", $randfile ); my $acltest2 = Cpanel::SafeRun::Errors::saferunnoerror( Cpanel::Binaries::path('getfacl'), $randfile ); chomp($acltest); if ( $acltest ne "" ) { acldeath("System error: setfacl: $acltest when testing for acl support. Your kernel may not support POSIX acls.\n"); } chomp($acltest2); if ( $acltest2 !~ /nobody/i ) { acldeath("System error: setfacl did not set the permissions that were requested. Your kernel may not support POSIX acls.\n"); } print "ACLS are now on\n"; return setacls(1); } sub acldeath ($err) { print "ACLS are now off\n"; setacls(0); return die($err); } sub setacls ($val) { my $cpconf_guard = Cpanel::Config::CpConfGuard->new(); $cpconf_guard->{'data'}->{'acls'} = $val; $cpconf_guard->save(); print "Updating Permissions....."; if ( -e $fileprotect_touch ) { Cpanel::SafeRun::Errors::saferunnoerror('/usr/local/cpanel/scripts/enablefileprotect'); } else { Cpanel::SafeRun::Errors::saferunnoerror('/usr/local/cpanel/scripts/disablefileprotect'); } print "Done\n"; return 1; }