9VjddlZddlZddlZddlZddlmZddlmZddlmZddl m Z ddl m Z m Z dZdZd Zd efd Zd ed efd ZdedededefdZd ed efdZd ed efdZdZdZd ed efdZdZdS)N)Path)ClPwd)drop_privileges)get_user_var_cagefs_path)apply_metadata_nofollow write_via_tmpl%#Ds_ lcNt|}tj|dS)Nz/.cagefs/isolates.mounts)rpathlibr)user cagefs_dirs Wopt/cloudlinux/venv/lib/python3.11/site-packages/clcagefslib/webisolation/jail_utils.pyget_jail_config_pathrs()$//J <:??? @ @@ document_rootc|dpd}t}|dD]}||z}|tzdz}|dS)z Generates unique id for an isolate website using FNV-1a 64-bit hash. FNV-1a has excellent avalanche properties and distribution. Must match the docroot_hash() function in jail C code. /zutf-8l016x)rstrip_FNV_OFFSET_BASISencode _FNV_PRIME)r hash_valuechars r get_website_idrsh"((--4M"J$$W--DDd  :-1CC   rr ct|}t|}tt |dz }||z }|ddd|ddt t|dddtd}|d }t|||t |d |j d|d }t|||t |d ddd S)z Create website token directory structure and files in /var/cagefs. Creates: - /var/cagefs//.cagefs/website// - token directory .cagefs/websiteTi)exist_okparentsmodei)rrr z/.cagefs.tokenz/.cagefs.websitei$N) rget_pw_by_namerrrmkdirrstr_generate_passwordrpw_uid) r rpw website_idwebsite_base_dir website_dirtokentoken_file_pathdocroot_file_paths r create_website_token_directoryr.0s+    % %B ..J4T::;;>OO"Z/KD$UCCCt%000C ,,eQ::: r " "E %444O+666OUBIqAAA'888+0-@@@-ua;;;;;r parent_fdnamerreturnc tj|||n#t$rYnwxYwtj|tjtjztjztjz|S)uCreate or open ``name`` under ``parent_fd`` rejecting any symlink. mkdirat(name, parent_fd) followed by openat(name, parent_fd, O_NOFOLLOW | O_DIRECTORY) — the open raises ELOOP if the path was pre-planted as a symlink and ENOTDIR if it is a non-directory inode. EEXIST on the mkdir is benign (idempotent re-run); other errors propagate. Returns an fd opened on the real directory inode that the caller is responsible for closing. )rdir_fd)r3)osr#FileExistsErroropenO_RDONLY O_NOFOLLOW O_DIRECTORY O_CLOEXEC)r/r0rs r _mkdir_nofollow_underr;_sz  D33333      7  bm#bn4r|C   s  ''c&t|}t|jsdSt j|jt jt jzt j z} t|5t|dd} t|dd} t|t|d}t j |t j |n#t j |wxYw t j |n#t j |wxYw dddn #1swxYwYt j |dS#t j |wxYw)z Create overlay storage directory in user's home. Creates: - /.cagefs/websites// - storage base for overlays Drops privileges to user before creating to ensure proper ownership. N.cagefsiwebsites)rr"rpw_direxistsr4r6r7r9r:rr;rclose)r rr'home_fd cagefs_fd websites_fdleaf_fds r create_overlay_storage_directoryrFts    % %B  ?? ! ! # #gbir~!= !LMMG T " " $ $-gy%HHI $3Iz5QQ *3#^M%B%BEGHW%%%H[))))BH[)))))######### $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ s` E:E+D3=2D/D3DD3E3E  E E:EE: E!E::Fctt|dz }|t|z }|rt j|dSdS)z= Remove website token directory structure and files. rN)rrrr@shutilrmtreer rr)r*s r remove_website_token_directoryrKsg4T::;;>OO"^M%B%BBK# k"""""##rc\tjdt|S)z5 Returns path: websites/ r>)r4pathjoinr)docroots r website_suffix_with_hashrPs" 7<< N7$;$; < </.cagefs/websites/ r=)r4rMrNrP)homedirrOs r full_website_pathrSs% 7<<,DW,M,M N NNrctt|dz }|t|z }|dz ddS)z, Removes cached namespace from disk rz .cagefs.mntT) missing_okN)rrrunlinkrJs r invalidate_ns_cacherWsU4T::;;>OO"^M%B%BBK= ((D(99999rc|dks|dkrtddttj|}dfd|D}|S)z Generate a random password/token using the same algorithm as the C function. Uses cryptographically secure random bytes and converts them to alphanumeric characters. rr!zInvalid buffer length requested>0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzc3.K|]}|zVdS)N).0bcharset charset_sizes r z%_generate_password..s-EE1WQ-.EEEEEEr) ValueErrorlensecrets token_bytesrN)length random_bytesresultr_r`s @@r r%r%sx {{fsll:;;;NGw<rns  ******333333AAAAAAAA)  AAA  #    $,<,