9Mj-ddlZddlZddlmZmZejdZdZdede fdZ d Z d Z d Z d Zd ZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZ dZ!dZ"dZ#d Z$ej%&d!rd"nd#Z'd$Z(erd%Z)d&Z*d'Z+erd(Z(d)Z,nd*Z,d+Z-n d,Z)d-Z*d'Z+d.Z,d.Z-d/e*d0e+d1e)Z.d2d3gZ/dZ0d4Z1d5Z2dS)6N)staging local_apiz^[a-zA-Z0-9_\-]+$) z /opt/alt/phpz /var/cagefs/z/opt/cpanel/ea-phpz/opt/plesk/php/z/usr/local/phpz/usr/share/cagefs/z/usr/share/cagefs-skeleton/z/etc/cl.php.d/z /etc/php.d/z/etc/php.scan.d/z /etc/users/pathreturnc ^tj|}tD]}tj|}|dr,||ks"||tjzrdSc||sy|t|d}|dt|t| dz }|r8|t|t|dzdtjfvrdSdS)uTBoundary-aware allowlist check for a PHP ini_scan_dir / ini_location. A plain ``startswith`` against ALLOWED_INI_PREFIXES is unsafe: a sibling such as ``/opt/alt/phpevil`` string-prefix-matches the bare ``/opt/alt/php`` entry and escapes the intended tree. Canonicalize the candidate and require a real directory boundary against each prefix: * Prefixes that name a full directory (trailing separator) match only when the candidate is that directory or descends below it. * The bare component prefixes (``/opt/alt/php``, ``/opt/cpanel/ea-php``, ``/usr/local/php``) are followed by a PHP version component; the candidate must continue with a run of version digits (e.g. ``/opt/alt/php80``) that then either ends or descends at a separator — never a letter or other separator-extending name. /TN 0123456789rF) osrrealpathALLOWED_INI_PREFIXESnormpathendswith startswithseplenlstrip)rresolvedprefix normalizedrestdigitss N/opt/cloudlinux/venv/lib64/python3.11/site-packages/xray/internal/constants.pyis_allowed_ini_pathrs! w%%H&W%%f-- ??3   :%%)<)r\s "*122 %c%d%%%%N65J994:A@L1 - 76 . 8 1 AC3    :>>+66BF  7992I .E *Fy{{/% . 7I .E *F)J1 4 4 4 4 4 4 4 (*<=r