/
usr
/
local
/
cpanel
/
scripts
/
/usr/local/cpanel/scripts
mkdir
upload
Name
Size
Mode
Actions
cpan_sandbox/
-
0755
rm
php_sandbox/
-
0755
rm
activesync-invite-reply
1734
0755
edit
dl
rm
adddns
2418
0755
edit
dl
rm
addpop
6228
0755
edit
dl
rm
addsystemuser
3345
0755
edit
dl
rm
adduser
92
0755
edit
dl
rm
add_dns
2418
0755
edit
dl
rm
agent360.sh
16410
0700
edit
dl
rm
apachelimits
4410
0755
edit
dl
rm
archive_sync_zones
3122
0755
edit
dl
rm
auto-adjust-mysql-limits
1854
0755
edit
dl
rm
autorepair
1274
0755
edit
dl
rm
backups_clean_metadata_for_missing_backups
1612
0755
edit
dl
rm
backups_create_metadata
16126
0755
edit
dl
rm
backups_list_user_files
4671
0755
edit
dl
rm
backup_jobs_helper
11139
0755
edit
dl
rm
balance_linked_node_quotas
2643
0755
edit
dl
rm
biglogcheck
1729
0755
edit
dl
rm
builddovecotconf
9869
0755
edit
dl
rm
buildeximconf
7167
0755
edit
dl
rm
buildhttpdconf
2664
0755
edit
dl
rm
buildpureftproot
539
0755
edit
dl
rm
build_bandwidthdb_root_cache_in_background
1561
0755
edit
dl
rm
build_cpnat
3494
0755
edit
dl
rm
build_mail_sni
3966
0755
edit
dl
rm
build_maxemails_config
1169
0755
edit
dl
rm
call_pkgacct
2306
0755
edit
dl
rm
ccs-check
5031
0755
edit
dl
rm
checkalldomainsmxs
2462
0755
edit
dl
rm
checkbashshell
1205
0755
edit
dl
rm
checkccompiler
1253
0755
edit
dl
rm
checkexim.pl
3172
0755
edit
dl
rm
checklink
1323
0755
edit
dl
rm
checkusers
856
0755
edit
dl
rm
check_cpanel_pkgs
10856
0755
edit
dl
rm
check_domain_tls_service_domains.pl
6841
0755
edit
dl
rm
check_immutable_files
5621
0755
edit
dl
rm
check_mail_spamassassin_compiledregexps_body_0
187
0755
edit
dl
rm
check_maxmem_against_domains_count
3652
0755
edit
dl
rm
check_mount_procfs
2072
0755
edit
dl
rm
check_mysql
5697
0755
edit
dl
rm
check_plugin_pkgs
2512
0755
edit
dl
rm
check_security_advice_changes
8477
0755
edit
dl
rm
check_unmonitored_enabled_services
4666
0755
edit
dl
rm
check_unreliable_resolvers
3672
0755
edit
dl
rm
check_users_my_cnf
6191
0755
edit
dl
rm
check_valid_server_hostname
7840
0755
edit
dl
rm
chkpaths
141
0755
edit
dl
rm
chpass
416
0755
edit
dl
rm
ckillall
1139
0755
edit
dl
rm
cleandns
13429
0755
edit
dl
rm
cleandns8
417
0755
edit
dl
rm
cleanmsglog
735
0755
edit
dl
rm
cleanphpsessions
932
0755
edit
dl
rm
cleanphpsessions.php
658
0644
edit
dl
rm
cleanquotas
1651
0755
edit
dl
rm
cleansessions
6032
0755
edit
dl
rm
cleanupinterchange
2706
0755
edit
dl
rm
cleanupmysqlprivs
773
0755
edit
dl
rm
clean_dead_mailman_locks
2141
0755
edit
dl
rm
clean_up_temp_wheel_users
2498
0755
edit
dl
rm
clean_user_php_sessions
4875
0755
edit
dl
rm
clear_orphaned_virtfs_mounts
3645
0755
edit
dl
rm
comet_license_registration_sync
1711
0755
edit
dl
rm
comet_protected_item_maintenance
21281
0755
edit
dl
rm
comparecdb
1561
0755
edit
dl
rm
compilers
2932
0755
edit
dl
rm
compilerscheck
999
0755
edit
dl
rm
configure_firewall_for_cpanel
520
0755
edit
dl
rm
configure_rh_firewall_for_cpanel
520
0755
edit
dl
rm
configure_rh_ipv6_firewall_for_cpanel
520
0755
edit
dl
rm
convert2dovecot
682
0755
edit
dl
rm
convert_accesshash_to_token
4171
0755
edit
dl
rm
convert_and_migrate_from_legacy_backup
2017
0755
edit
dl
rm
convert_maildir_to_mdbox
1703
0755
edit
dl
rm
convert_mdbox_to_maildir
1698
0755
edit
dl
rm
convert_roundcube_mysql2sqlite
26748
0755
edit
dl
rm
convert_to_dovecot_delivery
4438
0755
edit
dl
rm
convert_whmxfer_to_sqlite
1499
0755
edit
dl
rm
copy_user_mail_as_root
1281
0755
edit
dl
rm
copy_user_mail_as_user
1375
0755
edit
dl
rm
cpanelsync
28991
0755
edit
dl
rm
cpanelsync_postprocessor
1657
0755
edit
dl
rm
cpanel_initial_install
69583
0755
edit
dl
rm
cpanpingtest
965
0755
edit
dl
rm
cpan_config
2870
0755
edit
dl
rm
cpbackup
45861
0755
edit
dl
rm
cpbackup_transport_file
5781
0755
edit
dl
rm
cpdig
2882
0755
edit
dl
rm
cpfetch
1258
0755
edit
dl
rm
cphulkdblacklist
433
0755
edit
dl
rm
cphulkdwhitelist
1336
0755
edit
dl
rm
cpservice
2934
0755
edit
dl
rm
cpuser_port_authority
19755
0755
edit
dl
rm
cpuser_service_manager
11113
0755
edit
dl
rm
createacct
31904760
0700
edit
dl
rm
create_default_featurelist
11903
0700
edit
dl
rm
custom_backup_destination.pl.sample
5182
0755
edit
dl
rm
custom_backup_destination.pl.skeleton
2906
0755
edit
dl
rm
dcpumon-wrapper
850
0755
edit
dl
rm
delpop
6350
0755
edit
dl
rm
detect_env_capabilities
508
0755
edit
dl
rm
disablefileprotect
2241
0755
edit
dl
rm
disable_prelink
2841
0755
edit
dl
rm
distro_changed_hook
1185
0755
edit
dl
rm
dnscluster
4546
0755
edit
dl
rm
dnsqueuecron
1316
0755
edit
dl
rm
dnssec-cluster-keys
3840
0755
edit
dl
rm
dovecot_maintenance
7842
0755
edit
dl
rm
dovecot_set_defaults.pl
984
0755
edit
dl
rm
dumpcdb
866
0755
edit
dl
rm
dumpinodes
687
0755
edit
dl
rm
dumpquotas
616
0755
edit
dl
rm
dumpstor
913
0755
edit
dl
rm
ea4_fresh_install
2699
0755
edit
dl
rm
editquota
3512
0755
edit
dl
rm
edit_cpanelsync_exclude_list
2641
0755
edit
dl
rm
elevate-cpanel
424577
0700
edit
dl
rm
email_archive_maintenance
6300
0755
edit
dl
rm
email_hold_maintenance
1495
0755
edit
dl
rm
enablefileprotect
2149
0755
edit
dl
rm
enable_spf_dkim_globally
9039
0755
edit
dl
rm
ensure_autoenabled_features
3322632
0700
edit
dl
rm
ensure_conf_dir_crt_key
4940
0755
edit
dl
rm
ensure_cpuser_file_ip
2610
0755
edit
dl
rm
ensure_crontab_permissions
1101
0755
edit
dl
rm
ensure_dovecot_memory_limits_meet_minimum
3208
0755
edit
dl
rm
ensure_hostname_resolves
2572
0755
edit
dl
rm
ensure_includes
601
0755
edit
dl
rm
ensure_vhost_includes
13851
0755
edit
dl
rm
eximconfgen
1350
0755
edit
dl
rm
eximstats_spam_check
867
0755
edit
dl
rm
exim_tidydb
3036
0755
edit
dl
rm
expunge_expired_certificates_from_sslstorage
3648
0755
edit
dl
rm
expunge_expired_pkgacct_sessions
852
0755
edit
dl
rm
expunge_expired_transfer_sessions
1089
0755
edit
dl
rm
fastmail
5281
0755
edit
dl
rm
featuremod
1970
0755
edit
dl
rm
fetchfile
422
0755
edit
dl
rm
find_and_fix_rpm_issues
7157
0755
edit
dl
rm
find_outdated_services
6625
0755
edit
dl
rm
find_pids_with_inotify_watch_on_path
3745
0755
edit
dl
rm
fix-cpanel-perl
29112
0755
edit
dl
rm
fix-listen-on-localhost
4036
0755
edit
dl
rm
fix-web-vhost-configuration
6296
0755
edit
dl
rm
fixetchosts
4424
0755
edit
dl
rm
fixheaders
572
0755
edit
dl
rm
fixmailinglistperms
1008
0755
edit
dl
rm
fixmailman
2144
0755
edit
dl
rm
fixnamedviews
1247
0755
edit
dl
rm
fixndc
413
0755
edit
dl
rm
fixquotas
18834
0755
edit
dl
rm
fixrelayd
1784
0755
edit
dl
rm
fixrndc
16780
0755
edit
dl
rm
fixtar
503
0755
edit
dl
rm
fixtlsversions
4816
0755
edit
dl
rm
fixvaliases
2047
0755
edit
dl
rm
fixwebalizer
966
0755
edit
dl
rm
fix_dns_zone_ttls
1369
0755
edit
dl
rm
fix_innodb_tables
4149
0755
edit
dl
rm
fix_reseller_acls
10958
0755
edit
dl
rm
forcelocaldomain
895
0755
edit
dl
rm
ftpfetch
2251
0755
edit
dl
rm
ftpquotacheck
8511
0755
edit
dl
rm
ftpsfetch
2416
0755
edit
dl
rm
ftpupdate
261
0755
edit
dl
rm
gather_update_logs_setupcrontab
5582
0700
edit
dl
rm
gather_update_log_stats
4354
0700
edit
dl
rm
gemwrapper
1783
0755
edit
dl
rm
gencrt
6410
0755
edit
dl
rm
generate_account_suspension_include
5840
0755
edit
dl
rm
generate_google_drive_credentials
1135
0755
edit
dl
rm
generate_google_drive_oauth_uri
984
0755
edit
dl
rm
generate_maildirsize
14908
0755
edit
dl
rm
gensysinfo
1185
0755
edit
dl
rm
getremotecpmove
23084
0755
edit
dl
rm
get_locale_from_legacy_name_info
2041
0755
edit
dl
rm
grpck
1218
0755
edit
dl
rm
hackcheck
3092
0755
edit
dl
rm
hook
1487
0755
edit
dl
rm
httpspamdetect
2891
0755
edit
dl
rm
hulk-unban-ip
4301456
0700
edit
dl
rm
import_exim_data
8593
0755
edit
dl
rm
increase_filesystem_limits
891
0755
edit
dl
rm
initacls
5107
0755
edit
dl
rm
initfpsuexec
444
0755
edit
dl
rm
initialize_360monitoring
2824
0700
edit
dl
rm
initquotas
19811
0755
edit
dl
rm
initsuexec
4123
0755
edit
dl
rm
installpkg
575
0755
edit
dl
rm
installpostgres
6715
0755
edit
dl
rm
installsqlite3
1866
0755
edit
dl
rm
install_cpanel_analytics
1973
0755
edit
dl
rm
install_dovecot_fts
1605
0755
edit
dl
rm
install_plugin
2869
0755
edit
dl
rm
install_tuxcare_els_php
1889
0755
edit
dl
rm
ipcheck
4020
0755
edit
dl
rm
ipusage
7624
0755
edit
dl
rm
isdedicatedip
602
0755
edit
dl
rm
is_update_available
3343
0755
edit
dl
rm
jetbackup-check
3776
0755
edit
dl
rm
killdns
422
0755
edit
dl
rm
killdns-dnsadmin
1180
0755
edit
dl
rm
killmysqluserprivs
433
0755
edit
dl
rm
killmysqlwildcard
1180
0755
edit
dl
rm
killpvhost
853
0755
edit
dl
rm
killspamkeys
937
0755
edit
dl
rm
linksubemailtomainacct
3248
0755
edit
dl
rm
link_3rdparty_binaries
1271
0755
edit
dl
rm
listcheck
538
0755
edit
dl
rm
listsubdomains
1074
0755
edit
dl
rm
litespeed-check
3952
0755
edit
dl
rm
locale_export
5331
0755
edit
dl
rm
locale_import
4803
0755
edit
dl
rm
locale_info
4086
0755
edit
dl
rm
logo.dat
205
0644
edit
dl
rm
log_retention
21793
0755
edit
dl
rm
magicloader
1985
0755
edit
dl
rm
maildir_converter
6222
0755
edit
dl
rm
mailperm
16923
0755
edit
dl
rm
mailscannerupdate
2478
0755
edit
dl
rm
mainipcheck
10236
0755
edit
dl
rm
maintenance
53445
0755
edit
dl
rm
make_config
407
0644
edit
dl
rm
make_hostname_unowned
1189
0755
edit
dl
rm
manage_extra_marketing
13068
0700
edit
dl
rm
manage_greylisting
16719
0755
edit
dl
rm
manage_mysql_profiles
16727
0755
edit
dl
rm
mass_change_php_setting
10904
0755
edit
dl
rm
migrate_ccs_to_cpdavd
48186
0755
edit
dl
rm
migrate_local_ini_to_php_ini
7587
0755
edit
dl
rm
migrate_whmtheme_file_to_userdata
3025
0755
edit
dl
rm
MirrorSearch_pingtest
2437
0755
edit
dl
rm
mkwwwacctconf
2385
0755
edit
dl
rm
modify_accounts
4169
0755
edit
dl
rm
modify_featurelist
11597
0700
edit
dl
rm
modify_packages
3726
0755
edit
dl
rm
modsec_vendor
16008
0755
edit
dl
rm
mysqlconnectioncheck
6877
0755
edit
dl
rm
mysqlpasswd
4235
0755
edit
dl
rm
named.ca
1603
0644
edit
dl
rm
named.rfc1912.zones
774
0644
edit
dl
rm
notify_expiring_certificates
9592
0755
edit
dl
rm
notify_expiring_certificates_on_linked_nodes
1361
0755
edit
dl
rm
oopscheck
1142
0755
edit
dl
rm
optimize_eximstats
3975
0755
edit
dl
rm
panel_ini
4210
0755
edit
dl
rm
patchfdsetsize
2784
0755
edit
dl
rm
patch_mail_spamassassin_compiledregexps_body_0
2452
0755
edit
dl
rm
pedquota
2310
0755
edit
dl
rm
perform_sqlite_auto_rebuild_db_maintenance
2031
0755
edit
dl
rm
perlinstaller
528
0755
edit
dl
rm
perlmods
1204
0755
edit
dl
rm
phpini_tidy
687
0755
edit
dl
rm
php_fpm_config
9968
0755
edit
dl
rm
pkgacct
92065
0755
edit
dl
rm
post_snapshot
2144
0755
edit
dl
rm
post_sync_cleanup
5973
0755
edit
dl
rm
primary_virtual_host_migration
2502
0755
edit
dl
rm
process_cpmove
4419
0755
edit
dl
rm
process_pending_cpanel_php_pear_registration
2793
0755
edit
dl
rm
proxydomains
9822
0755
edit
dl
rm
ptycheck
724
0755
edit
dl
rm
purge_modsec_log
1563
0755
edit
dl
rm
purge_old_config_caches
2125
0755
edit
dl
rm
pwck
708
0755
edit
dl
rm
quickdnslookup
1159
0755
edit
dl
rm
quickwhoisips
2348
0755
edit
dl
rm
quotacheck
22900
0755
edit
dl
rm
quota_auto_fix
1440
0755
edit
dl
rm
rawchpass
460
0755
edit
dl
rm
rdate
4913
0755
edit
dl
rm
realadduser
5743
0755
edit
dl
rm
realchpass
3336
0755
edit
dl
rm
realperlinstaller
5805
0755
edit
dl
rm
realrawchpass
425
0755
edit
dl
rm
rebuilddnsconfig
26110
0755
edit
dl
rm
rebuildhttpdconf
2664
0755
edit
dl
rm
rebuildinstalledssldb
2917
0755
edit
dl
rm
rebuildippool
509
0755
edit
dl
rm
rebuilduserssldb
948
0755
edit
dl
rm
rebuild_bandwidthdb_root_cache
1487
0755
edit
dl
rm
rebuild_dbmap
5937
0755
edit
dl
rm
rebuild_provider_openid_connect_links_db
1039
0755
edit
dl
rm
rebuild_whm_chrome
2277
0755
edit
dl
rm
refresh-dkim-validity-cache
6110
0755
edit
dl
rm
regenerate_tokens
2228
0755
edit
dl
rm
remote_log_transfer
11875
0755
edit
dl
rm
removeacct
29654400
0700
edit
dl
rm
remove_dovecot_index_files
6028
0755
edit
dl
rm
rescan_user_dovecot_fts
3048
0755
edit
dl
rm
resetmailmanurls
2077
0755
edit
dl
rm
resetquotas
4723
0755
edit
dl
rm
reset_mail_quotas_to_sane_values
6982
0755
edit
dl
rm
restartsrv
3266
0755
edit
dl
rm
restartsrv_apache
422
0755
edit
dl
rm
restartsrv_apache_php_fpm
11368960
0755
edit
dl
rm
restartsrv_base
11368960
0755
edit
dl
rm
restartsrv_bind
11368960
0755
edit
dl
rm
restartsrv_chkservd
427
0755
edit
dl
rm
restartsrv_clamd
11368960
0755
edit
dl
rm
restartsrv_cpanellogd
11368960
0755
edit
dl
rm
restartsrv_cpanel_php_fpm
11368960
0755
edit
dl
rm
restartsrv_cpdavd
11368960
0755
edit
dl
rm
restartsrv_cpgreylistd
11368960
0755
edit
dl
rm
restartsrv_cphulkd
11368960
0755
edit
dl
rm
restartsrv_cpipv6
11368960
0755
edit
dl
rm
restartsrv_cpsrvd
11368960
0755
edit
dl
rm
restartsrv_crond
11368960
0755
edit
dl
rm
restartsrv_dnsadmin
11368960
0755
edit
dl
rm
restartsrv_dovecot
11368960
0755
edit
dl
rm
restartsrv_exim
11368960
0755
edit
dl
rm
restartsrv_eximstats
504
0755
edit
dl
rm
restartsrv_ftpd
426
0755
edit
dl
rm
restartsrv_ftpserver
911
0755
edit
dl
rm
restartsrv_httpd
11368960
0755
edit
dl
rm
restartsrv_imap
437
0755
edit
dl
rm
restartsrv_inetd
2525
0755
edit
dl
rm
restartsrv_ipaliases
11368960
0755
edit
dl
rm
restartsrv_lmtp
437
0755
edit
dl
rm
restartsrv_mailman
11368960
0755
edit
dl
rm
restartsrv_mysql
11368960
0755
edit
dl
rm
restartsrv_named
579
0755
edit
dl
rm
restartsrv_nscd
11368960
0755
edit
dl
rm
restartsrv_p0f
11368960
0755
edit
dl
rm
restartsrv_pdns
11368960
0755
edit
dl
rm
restartsrv_pop3
437
0755
edit
dl
rm
restartsrv_postgres
427
0755
edit
dl
rm
restartsrv_postgresql
11368960
0755
edit
dl
rm
restartsrv_powerdns
442
0755
edit
dl
rm
restartsrv_proftpd
11368960
0755
edit
dl
rm
restartsrv_pureftpd
11368960
0755
edit
dl
rm
restartsrv_queueprocd
11368960
0755
edit
dl
rm
restartsrv_rsyslog
11368960
0755
edit
dl
rm
restartsrv_rsyslogd
437
0755
edit
dl
rm
restartsrv_spamd
11368960
0755
edit
dl
rm
restartsrv_sshd
11368960
0755
edit
dl
rm
restartsrv_syslogd
2458
0755
edit
dl
rm
restartsrv_tailwatchd
11368960
0755
edit
dl
rm
restartsrv_unknown
11368960
0755
edit
dl
rm
restartsrv_xinetd
422
0755
edit
dl
rm
restorecpuserfromcache
2008
0755
edit
dl
rm
restorepkg
51194360
0700
edit
dl
rm
rfc1912_zones.tar
10240
0644
edit
dl
rm
rpmup
5191
0755
edit
dl
rm
rsync-user-homedir.pl
5903
0755
edit
dl
rm
runstatsonce
440
0755
edit
dl
rm
runweblogs
1045
0755
edit
dl
rm
run_if_exists
512
0755
edit
dl
rm
run_plugin_lifecycle
4060
0700
edit
dl
rm
sa-update_wrapper
3418
0755
edit
dl
rm
safetybits.pl
844
0755
edit
dl
rm
secureit
4834
0755
edit
dl
rm
securemysql
4501
0755
edit
dl
rm
securerailsapps
3661
0755
edit
dl
rm
securetmp
17162
0755
edit
dl
rm
sendicq
474
0755
edit
dl
rm
servicedomains
9822
0755
edit
dl
rm
setpostgresconfig
6181
0755
edit
dl
rm
setupftpserver
10726
0755
edit
dl
rm
setupmailserver
9618
0755
edit
dl
rm
setupnameserver
12898
0755
edit
dl
rm
setup_greylist_db
16719
0755
edit
dl
rm
setup_modsec_db
1335
0755
edit
dl
rm
setup_systemd_timer_for_plugins
4015
0700
edit
dl
rm
set_mailman_archive_perms
1796
0755
edit
dl
rm
show_php_settings
3762
0755
edit
dl
rm
shrink_modsec_ip_database
13285
0755
edit
dl
rm
simpleps
3124
0755
edit
dl
rm
slurp_exim_mainlog
5914
0755
edit
dl
rm
smartcheck
15491
0755
edit
dl
rm
smtpmailgidonly
8343
0755
edit
dl
rm
snapshot_prep
6017
0755
edit
dl
rm
spamassassindisable
3830
0755
edit
dl
rm
spamassassin_dbm_cleaner
5993
0755
edit
dl
rm
spamboxdisable
2324
0755
edit
dl
rm
sshcontrol
14722
0755
edit
dl
rm
ssl_crt_status
3928
0755
edit
dl
rm
suspendacct
18516
0755
edit
dl
rm
suspendmysqlusers
4890
0755
edit
dl
rm
swapip
3914
0755
edit
dl
rm
sync-mysql-users-from-grants
1225
0755
edit
dl
rm
synctransfers
1971
0755
edit
dl
rm
sync_child_accounts
1813
0755
edit
dl
rm
sync_contact_emails_to_cpanel_users_files
1163
0755
edit
dl
rm
syslog_check
1391
0755
edit
dl
rm
sysup
645
0755
edit
dl
rm
test_sa_compiled
1093
0755
edit
dl
rm
transfermysqlusers
10627296
0700
edit
dl
rm
transfer_accounts_as_root
4870
0755
edit
dl
rm
transfer_account_as_user
2398
0755
edit
dl
rm
transfer_in_progress
3156
0755
edit
dl
rm
transfer_in_progress.pod
312
0644
edit
dl
rm
try-later
8140
0755
edit
dl
rm
unblockip
667
0755
edit
dl
rm
uninstall_cpanel_analytics
1230
0755
edit
dl
rm
uninstall_dovecot_fts
562
0755
edit
dl
rm
uninstall_plugin
2907
0755
edit
dl
rm
unlink_service_account
2682
0755
edit
dl
rm
unpkgacct
4713
0755
edit
dl
rm
unslavenamedconf
863
0755
edit
dl
rm
unsuspendacct
18387
0755
edit
dl
rm
unsuspendmysqlusers
7266
0755
edit
dl
rm
upcp
44038
0755
edit
dl
rm
upcp-running
2768
0755
edit
dl
rm
upcp.static
977251
0755
edit
dl
rm
update-packages
5191
0755
edit
dl
rm
updatedomainips
605
0755
edit
dl
rm
updatenameserverips
1696
0755
edit
dl
rm
updatenow
5302
0755
edit
dl
rm
updatenow.static
2116708
0755
edit
dl
rm
updatesigningkey
1996
0755
edit
dl
rm
updatessldomains
1856
0755
edit
dl
rm
updatesupportauthorizations
2552
0755
edit
dl
rm
updateuserdatacache
2529
0755
edit
dl
rm
updateuserdomains
774
0755
edit
dl
rm
update_apachectl
480
0755
edit
dl
rm
update_db_cache
430
0755
edit
dl
rm
update_dkim_keys
1485
0755
edit
dl
rm
update_exim_rejects
1242
0755
edit
dl
rm
update_existing_mail_quotas_for_account
4891
0755
edit
dl
rm
update_feature_flags
957
0755
edit
dl
rm
update_freebusy_data
5376
0755
edit
dl
rm
update_known_proxy_ips
1002
0755
edit
dl
rm
update_local_rpm_versions
4669
0755
edit
dl
rm
update_mailman_cache
8545
0755
edit
dl
rm
update_mysql_systemd_config
1094
0755
edit
dl
rm
update_neighbor_netblocks
487
0755
edit
dl
rm
update_sa_config
2196
0755
edit
dl
rm
update_spamassassin_config
10988
0755
edit
dl
rm
update_users_jail
691
0755
edit
dl
rm
update_users_vhosts
801
0755
edit
dl
rm
upgrade_bandwidth_dbs
2272
0755
edit
dl
rm
upgrade_subaccount_databases
2797
0755
edit
dl
rm
userdata_wildcard_cleanup
5877
0755
edit
dl
rm
userdirctl
5134
0755
edit
dl
rm
validate_sshkey_passphrase
1244
0755
edit
dl
rm
verify_api_spec_files
757
0755
edit
dl
rm
verify_pidfile
2008
0755
edit
dl
rm
verify_vhost_includes
7517
0755
edit
dl
rm
vps_optimizer
8007
0755
edit
dl
rm
vzzo-fixer
725
0755
edit
dl
rm
whmlogin
2390
0755
edit
dl
rm
whoowns
1155
0755
edit
dl
rm
wwwacct
31904760
0700
edit
dl
rm
wwwacct2
88
0755
edit
dl
rm
xferpoint
3201
0755
edit
dl
rm
xfertool
16624
0755
edit
dl
rm
xfer_rcube_schema_migrate.pl
2460
0755
edit
dl
rm
xfer_rcube_uid_resolver.pl
1846
0755
edit
dl
rm
zoneexists
800
0755
edit
dl
rm
Edit:
/usr/local/cpanel/scripts/fix-cpanel-perl
(29112B)
#!/usr/bin/perl # Copyright 2026 WebPros International, LLC # All rights reserved. # copyright@cpanel.net http://cpanel.net # This code is subject to the cPanel license. Unauthorized copying is prohibited. package scripts::fixcpanelperl; use strict; use warnings; ### Do not add any extra use/require statements here without talking to BC. ### ### This code is used by the installer for fresh install ### its main goal is to bootstrap & repair cPanel Perl ### ### Thus no dependencies should be added to this special script. ### Because this script uses only system perl code, ### the rest of the cPanel code base gets to have nice things! ### and rely on cPanel Perl stack. use IPC::Open3 (); use POSIX (); use constant COLOR_RED => 31; use constant COLOR_GREEN => 32; use constant COLOR_YELLOW => 33; use constant COLOR_GRAY => 37; use constant UPDATE_SOURCE_DEFAULT => 'httpupdate.cpanel.net'; use constant PKG_VERSION_SOURCE => '11.130'; use constant PKG_DOWNLOADS_DIR => '/usr/local/cpanel/tmp/rpm_downloads'; =pod =head1 NAME scripts::fixcpanelperl =head1 SYNOPSIS # restore cpanel-perl package when missing /scripts/fix-cpanel-perl =head1 DESCRIPTION This script is used during fresh installation to bootstrap cPanel Perl and install a few core dependencies packages to run the installation process using cPanel Perl version as early as possible. The script can also be used to recover from a catastrophic loss or coruption of the cpanel-perl packages blocking check_cpanel_pkgs or upcp to recover the system. This script is automatically invoked if needed when check_cpanel_pkgs cannot run. =head1 NOTE The list of Perl packages install by this script should be short. This script should only use default perl packages install with the system, no Cpanel packages can be use as part of this script. =cut my %shared_install_env = ( LANG => 'C', LANGUAGE => 'C', LC_ALL => 'C', LC_MESSAGES => 'C', LC_CTYPE => 'C', ); our %DISTRO_SETUP = ( 'centos' => { name => 'centos', install_env => { %shared_install_env, }, install_cmd => [ '/bin/rpm', '-Uvh', '--force', '--nodeps' ], template => { base_url => 'http://%httpupdate%/RPM/%cpanel_major%/%distro_name%/%distro_major%/x86_64', file_name => '%package%-%version%~el%distro_major%.%arch%.rpm' }, package_sha512 => 'rpm.sha512', # could use later once pushed to prod sha512 }, 'ubuntu' => { name => 'ubuntu', install_env => { %shared_install_env, DEBIAN_FRONTEND => q[noninteractive], DEBIAN_PRIORITY => q[critical], }, install_cmd => [ '/bin/dpkg', '-i', '--force-confnew' ], template => { base_url => 'http://%httpupdate%/ubuntu/pool', base_file_uri => '%package%', file_name => '%package%_%version%~u%distro_major%_%arch%.deb', }, package_sha512 => 'sha512', }, ); our $CPANEL_CONFIG_FILE = '/var/cpanel/cpanel.config'; our $SIG_VALIDATION_CPCONF_KEY = 'signature_validation'; sub colorize_bold { my ( $color, $msg ) = @_; return $msg if !defined $color || -e '/var/cpanel/disable_cpanel_terminal_colors'; $msg ||= ''; return chr(27) . '[1;' . $color . 'm' . $msg . chr(27) . '[0;m'; } sub DEBUG($) { return _MSG( 'DEBUG', " " . shift ) } sub ERROR($) { return _MSG( colorize_bold( COLOR_RED, 'ERROR' ), colorize_bold( COLOR_GRAY, shift ) ); } sub WARN($) { return _MSG( colorize_bold( COLOR_YELLOW, 'WARN' ), colorize_bold( COLOR_YELLOW, shift ) ); } sub OK($) { return _MSG( colorize_bold( COLOR_GREEN, 'OK' ), colorize_bold( COLOR_GRAY, shift ) ); } sub INFO($) { return _MSG( 'INFO', shift ) } sub FATAL($) { _MSG( colorize_bold( COLOR_RED, 'FATAL' ), colorize_bold( COLOR_RED, shift ) ); die "\n"; } # Cached and used all over the place. our ( $wget_bin, $wget_args, $GPG_BIN ); our ( $DISTRO_TYPE, $DISTRO_MAJOR ); our $_distro_instance; my %sha; exit script(@ARGV) unless caller(); # return the instance of the current distro sub current_distro { return $_distro_instance if $_distro_instance; $DISTRO_TYPE or FATAL("DISTRO_TYPE is not set"); $_distro_instance = $DISTRO_SETUP{$DISTRO_TYPE} or FATAL("Unknown distro type $DISTRO_TYPE. Cannot bootstrap cpanel-perl"); return $_distro_instance; } # init all our global for the scripts sub _init { ( $wget_bin, $wget_args ) = get_download_tool_binary(); $GPG_BIN = gpg_bin(); ( $DISTRO_TYPE, $DISTRO_MAJOR ) = os_info(); # order matters current_distro() or FATAL("Cannot guess current distro"); return; } sub script { my (@args) = @_; return 0 if cpanel_perl_is_stable(); loop_protection(); ERROR("Core cpanel-perl modules have been found to be corrupt. Attempting to correct this.") unless $ENV{CPANEL_BASE_INSTALL}; # init globals first, or things will break in a hard to debug way since output is stifled on install _init(); fetch_and_install_gpg_keys() unless $ENV{CPANEL_BASE_INSTALL_GPG_KEYS_IMPORTED}; download_pkg_sha512(); chdir(PKG_DOWNLOADS_DIR) or FATAL( "Fail to chdir to " . PKG_DOWNLOADS_DIR ); my $core_perl_pid; if ( $core_perl_pid = fork() ) { # handle just after... } elsif ( defined $core_perl_pid ) { wget_and_validate_file( core_perl_pkg() ); install_packages( core_perl_pkg() ) and exit 1; exit(0); } else { die "The system failed to fork because of an error: $!"; } # download package while doing the first transaction my $pkgs = pkgs_to_download(); foreach my $package_name ( sort keys %$pkgs ) { wget_and_validate_file( $package_name, $pkgs->{$package_name} ); } { waitpid( $core_perl_pid, 0 ); FATAL "Core perl package transaction failed" unless $? == 0; } install_packages(%$pkgs); FATAL "package transaction failed" unless $? == 0; OK("cpanel-perl is now restored, checking all cpanel packages."); my @to_cleanup = ( current_distro()->{package_sha512}, current_distro()->{package_sha512} . '.asc', @{ get_packages_filename( core_perl_pkg() ) }, @{ get_packages_filename(%$pkgs) }, ); cleanup_files(@to_cleanup); # updatenow.static will do the needful during an install. return 0 if $ENV{CPANEL_BASE_INSTALL}; # This should be changed to check_cpanel_pkgs at some point if ( !-x '/usr/local/cpanel/3rdparty/bin/perl' ) { FATAL "/usr/local/cpanel/3rdparty/bin/perl is missing"; } if ( !-e '/usr/local/cpanel/scripts/check_cpanel_pkgs' ) { FATAL "Unable to run scripts/check_cpanel_pkgs. You will need to run updatenow.static and then re-run /usr/local/cpanel/scripts/check_cpanel_pkgs --fix"; } setup_env_for_distro(); exec(qw{/usr/local/cpanel/3rdparty/bin/perl /usr/local/cpanel/scripts/check_cpanel_pkgs --fix --long-list --no-digest}) or FATAL "Failed to exec /usr/local/cpanel/scripts/check_cpanel_pkgs --fix"; return 255; } sub loop_protection { $ENV{CPANEL_FIX_PERL} = 0 unless defined $ENV{CPANEL_FIX_PERL}; ++$ENV{CPANEL_FIX_PERL}; if ( $ENV{CPANEL_FIX_PERL} > 3 ) { cpanel_perl_is_stable(1); FATAL "$0 was run mulitple times without fixing your system. Aborting. (loop detection)"; return 1; } elsif ( $ENV{CPANEL_FIX_PERL} > 1 ) { WARN( "Running $0 an extra time " . $ENV{CPANEL_FIX_PERL} ); } return; } sub render_filename { my ( $package, $version_arch ) = @_; my $filename = current_distro()->{template}->{file_name} or FATAL("Undefined file_name"); # 3.75-1.cp108.noarch my ( $v, $arch ) = ( $version_arch =~ m{^(.+)\.([^\.]+)$} ); FATAL("Cannot parse version / arch from $package $version_arch") unless defined $v && defined $arch; if ( current_distro()->{name} eq 'ubuntu' ) { $arch = ( $arch =~ m/86/ ) ? 'amd64' : 'all'; } return tt( $filename, { package => $package, version => $v, arch => $arch } ); } sub render_fileuri { my ( $package, $version_arch ) = @_; my $filename = render_filename( $package, $version_arch ); my $uri = ''; # not for all distro if ( my $base_file_uri = current_distro()->{template}->{base_file_uri} ) { $uri = tt( $base_file_uri, { package => $package, version_arch => $version_arch } ); } $uri .= '/' if defined $uri && length $uri; $uri .= $filename; return $uri; } sub get_packages_filename { my @files; while ( scalar @_ ) { my $package = shift @_; my $version_arch = shift @_; push @files, render_filename( $package, $version_arch ); } return \@files; } sub install_packages { my (@packages) = @_; return unless scalar @packages; my $files = get_packages_filename(@packages); my @cmd = ( @{ current_distro()->{install_cmd} }, @$files ); DEBUG( "Installing packages: " . join( ' ', @cmd ) ); local %ENV = %ENV; setup_env_for_distro(); return system(@cmd); } sub setup_env_for_distro { # setup some special environment variables for running the install command my $env = current_distro()->{install_env}; return unless defined $env && ref $env; foreach my $k ( keys %$env ) { $ENV{$k} = $env->{$k}; } return; } sub cleanup_files { my (@files) = @_; foreach my $f (@files) { unlink( PKG_DOWNLOADS_DIR . '/' . $f ); } return; } sub os_info { my ( $distro_type, $distro_major ); # DO NOT use Cpanel-OS symlink here. It can be inaccurate if the server has been elevated. if ( open( my $fh, "<", "/etc/os-release" ) ) { # All distros we support have this file. my $line; # buffer while ( $line = <$fh> ) { if ( index( $line, "ID=" ) == 0 ) { $distro_type = _clean_value( $line => length("ID=") ); } elsif ( index( $line, "VERSION_ID=" ) == 0 ) { $distro_major = _clean_value( $line => length("VERSION_ID=") ); $distro_major =~ s/\..+//; # Strip off .04 from 20.04 } last if $distro_type && $distro_major; } } else { die("Unable to find /etc/os-release for system info"); } $distro_type = 'centos' if $distro_type =~ m/cloud|red|alma|rhel/i; ($distro_major) = $distro_major =~ m/^\s*0*\s*(\d+)/ if $distro_type eq 'centos'; # Strip off the minor version for centos RPMs. Alma linux is a special snowflake! return ( $distro_type, $distro_major ); } sub _clean_value { my ( $str, $strip ) = @_; die "Internal _clean_value() called without a value (did you make changes to this code recently?)\n" if !defined $str; chomp $str; $str = substr( $str, $strip ); if ( substr( $str, 0, 1 ) eq '"' ) { $str = substr( $str, 1, length($str) ); $str = substr( $str, 0, length($str) - 1 ); } return $str; } sub cpanel_perl_is_stable { my ($debug) = @_; my $perl_bin = '/usr/local/cpanel/3rdparty/bin/perl'; my $command = $perl_bin; $command .= " -M$_" foreach minimum_cpanel_perl_modules(); my $got = `$command -E'sub foo (\$bar) { ... }; print q{ok}' 2>&1`; ## no critic qw(Cpanel::ProhibitQxAndBackticks) print "command failed:\n\n$command -E'sub foo (\$bar) { ... }; print q{ok}' 2>&1\n\nerror message: $got\n" if $debug; return 0 unless !$? && $got && $got eq 'ok'; if ( my $v = _perl_version() ) { my $out = `$perl_bin -E 'say \$]'`; return unless $out =~ m{^\Q$v\E}; } return 1; } sub _perl_major { my ($perl_pkg) = core_perl_pkg(); return $1 if $perl_pkg =~ m{-(\d+)$}; return; } sub _perl_version { my $major = _perl_major() or return; if ( $major =~ m{^(\d)(\d+)$} ) { my ( $rev, $version ) = ( $1, $2 ); return sprintf( '%d.%03d', $rev, $version ); } return; } sub download_pkg_sha512 { # Setup the directory as best we can. unlink PKG_DOWNLOADS_DIR; # Just in case it's a file (that'd be weird) system( '/bin/mkdir', '-p', PKG_DOWNLOADS_DIR ) unless -d PKG_DOWNLOADS_DIR; -d PKG_DOWNLOADS_DIR or FATAL( "Can't make directory " . PKG_DOWNLOADS_DIR ); my $package_sha512 = current_distro()->{package_sha512} or FATAL("no package_sha512 filename set"); my $sha_file = sprintf( "%s/%s", PKG_DOWNLOADS_DIR, $package_sha512 ); my $sig_file = sprintf( "%s/%s.asc", PKG_DOWNLOADS_DIR, $package_sha512 ); # my $sha_url = sprintf( "%s/%s", url_base(), $package_sha512 ); my $sig_url = sprintf( "%s/%s.asc", url_base(), $package_sha512 ); download_file( $sig_url, $sig_file ); download_file( $sha_url, $sha_file ); verify_file_signature( $sha_file, $sig_file, $sha_url ); open( my $fh, '<', $sha_file ) or FATAL("Can't read $sha_file"); while ( my $line = <$fh> ) { chomp $line; my ( $sha, $file ) = split( qr{\s+}, $line ); $sha{$file} = $sha; } close $fh; return; } my $url_base; #cached; sub url_base { return $url_base if defined $url_base; return $url_base = tt( current_distro()->{template}->{base_url} ); } sub tt { my ( $str, $extra ) = @_; return unless defined $str; my $httpupdate = get_update_source(); my $cpanel_major = PKG_VERSION_SOURCE; $extra = {} unless defined $extra; my $tt = { httpupdate => $httpupdate, cpanel_major => $cpanel_major, distro_name => $DISTRO_TYPE, distro_major => $DISTRO_MAJOR, ref $extra ? %$extra : (), }; my $s = sub { my $k = shift or FATAL("Undefined key"); my $v = $tt->{$k}; FATAL("Unexpected template variables '$k' in base URL ") unless defined $v; return $v; }; $str =~ s{\%([a-z_]+)\%}{$s->($1)}eg; return $str; } sub get_download_tool_binary { for my $bin (qw(/bin/wget /usr/bin/wget /usr/local/bin/wget)) { # check if the binary exists next unless -e $bin && -x _ && -s _; # use it if ( `$bin --version 2>/dev/null` =~ m/GNU\s+Wget\s+[0-9]+\.[0-9]+/ims ) { ## no critic qw(ProhibitQxAndBackticks) return ( $bin, ' -nv --no-dns-cache --tries=20 --timeout=60 --dns-timeout=60 --read-timeout=30 --waitretry=1 --retry-connrefused -O' ); } } # If $wget_bin is not set, then wget is not installed and # We do not have a fallback for Cpanel::SecureDownload::fetch_url() FATAL("Can't bootstrap cpanel-perl without a working file download method. Try installing the wget package manually."); return; } sub gpg_bin { for my $bin (qw(/bin/gpg /usr/bin/gpg /usr/local/bin/gpg)) { next unless -e $bin && -x _ && -s _; return $bin; } FATAL "Can't bootstrap cpanel-perl without gpg. Try installing the gnupg2 package manually."; return; } sub _MSG { my $level = shift; my $msg = shift || ''; chomp $msg; my $message_caller_depth = 1; my ( $sec, $min, $hour, $mday, $mon, $year, $wday, $yday, $isdst ) = localtime; my ( $package, $filename, $line ) = caller($message_caller_depth); my $stamp_msg = sprintf( "%04d-%02d-%02d %02d:%02d:%02d %4s (%5s): %s\n", $year + 1900, $mon + 1, $mday, $hour, $min, $sec, $line, $level, $msg ); print $stamp_msg; return; } { my $update_source; sub get_update_source { return $update_source if defined $update_source; my $source_file = '/etc/cpsources.conf'; # pull in from cpsources.conf if it's set. if ( open( my $fh, "<", $source_file ) ) { while (<$fh>) { next if $_ !~ m/^\s*HTTPUPDATE\s*=\s*(\S+)/; $update_source = "$1"; last; } } $update_source = UPDATE_SOURCE_DEFAULT unless $update_source; INFO("Downloading bootstrap packages from $update_source"); return $update_source; } } sub wget_and_validate_file { my ( $package_name, $version_arch ) = @_; my $uri = render_fileuri( $package_name, $version_arch ); my $filename; if ( index( $uri, '/' ) == -1 ) { $filename = $uri; } else { ($filename) = ( $uri =~ m{/([^/]+)$} ); } FATAL("Cannot guess filename for path $uri") unless length $filename; my $url = url_base() . '/' . $uri; my $expected_sha = $sha{$uri}; FATAL("No sha defined for file $uri") unless defined $expected_sha; my $pkg_file_path = download_file( $url, PKG_DOWNLOADS_DIR . '/' . $filename ); my $result = `/usr/bin/sha512sum $pkg_file_path 2>&1`; ## no critic qw(Cpanel::ProhibitQxAndBackticks) my ($sha) = $result =~ m/^([a-fA-F0-9]+)/; if ( $expected_sha ne $sha ) { FATAL("Couldn't verify the expected sha ($sha{$filename}) for $filename. Got $sha"); } return; } ## used by unit tests - this should be the only 'require' statement ## sub _require_securedownload { require Cpanel::SecureDownload; return; } # # Cpanel::SecureDownload is the preferred method as it will # attempt Cpanel::HTTP::Client, curl, then wget. And it will # attempt to use Mozilla::CA if available. # However, depending on the broken state if perl, it might # not work. In that case we can go back to directly invoking # wget via backticks as before. # sub attempt_secure_download_file { my ( $url, $dest_file ) = @_; # Add this so that Cpanel::SecureDownload will pick up the # latest version of Mozilla::CA if we have it installed local @INC = ( '/usr/local/cpanel', '/usr/local/cpanel/3rdparty/perl/542/cpanel-lib', @INC ); my ( $success, $msg ); eval { _require_securedownload(); my %options = ( 'output-file' => $dest_file, 'not-verbose' => 1, 'tries' => 20, 'retry-delay' => 1, 'timeout' => 60, 'dns-timeout' => 60, 'read-timeout' => 30, 'no-dns-cache' => 1, 'retry-connrefused' => 1, ); ( $success, $msg ) = Cpanel::SecureDownload::fetch_url( $url, %options ); }; if ( !$@ && $success && -e $dest_file && !-z $dest_file ) { return 1; } # Warn if an exception had been thrown, that means there was trouble loading # Cpanel::SecureDownload. However, we do not need to warn on errors returned # from fetch_url as it already warns when each method fails if ($@) { WARN "Could not invoke Cpanel::SecureDownload::fetch_url: $@"; } return; } sub minimum_cpanel_perl_modules { return qw{ AnyEvent B::COW CDB_File Call::Context Class::XSAccessor Compress::Raw::Lzma File::Path::Tiny File::Slurper Guard IO::Pty IO::SigGuard IO::Socket::SSL JSON JSON::XS Module::Runtime Net::Curl Net::Curl::Promiser Net::SSLeay PerlIO::utf8_strict Proc::FastSpawn Promise::ES6 Promise::XS Sereal::Decoder Sereal::Encoder Simple::Accessor Sub::Uplevel Test::Exception Try::Tiny Types::Serialiser URI X::Tiny YAML::Syck cPanel::APIClient common::sense }; } sub core_perl_pkg { return ( 'cpanel-perl-542' => '5.42.0-6.cp130.x86_64' ); } sub pkgs_to_download { my %packages = qw{ cpanel-3rdparty-bin 130.1-2.cp130.noarch cpanel-perl-542-anyevent 7.17-1.cp130.noarch cpanel-perl-542-b-cow 0.007-1.cp130.x86_64 cpanel-perl-542-call-context 0.05-1.cp130.noarch cpanel-perl-542-cdb.file 0.99-1.cp130.x86_64 cpanel-perl-542-class-xsaccessor 1.19-1.cp130.x86_64 cpanel-perl-542-common-sense 3.75-1.cp130.noarch cpanel-perl-542-compress-raw-lzma 2.213-1.cp130.x86_64 cpanel-perl-542-cpanel-apiclient 0.10-1.cp130.noarch cpanel-perl-542-file-path-tiny 1.0-1.cp130.noarch cpanel-perl-542-file-slurper 0.014-1.cp130.noarch cpanel-perl-542-guard 1.023-1.cp130.x86_64 cpanel-perl-542-io-sigguard 0.15-1.cp130.noarch cpanel-perl-542-io-socket-ssl 2.089-1.cp130.noarch cpanel-perl-542-io-tty 1.23-1.cp130.x86_64 cpanel-perl-542-json 4.10-1.cp130.noarch cpanel-perl-542-json-xs 4.04-1.cp130.x86_64 cpanel-perl-542-mime-base32 1.303-1.cp130.noarch cpanel-perl-542-module-runtime 0.018-1.cp130.noarch cpanel-perl-542-net-curl 0.57-1.cp130.x86_64 cpanel-perl-542-net-curl-promiser 0.20-1.cp130.noarch cpanel-perl-542-net-ssleay 1.94-1.cp130.x86_64 cpanel-perl-542-perlio-utf8.strict 0.010-1.cp130.x86_64 cpanel-perl-542-proc-fastspawn 1.2-1.cp130.x86_64 cpanel-perl-542-promise-es6 0.28-1.cp130.noarch cpanel-perl-542-promise-xs 0.20-1.cp130.x86_64 cpanel-perl-542-sereal-decoder 5.004-1.cp130.x86_64 cpanel-perl-542-sereal-encoder 5.004-1.cp130.x86_64 cpanel-perl-542-simple-accessor 1.13-1.cp130.noarch cpanel-perl-542-sub-uplevel 0.2800-1.cp130.noarch cpanel-perl-542-test-exception 0.43-1.cp130.noarch cpanel-perl-542-try-tiny 0.32-1.cp130.noarch cpanel-perl-542-types-serialiser 1.01-1.cp130.noarch cpanel-perl-542-uri 5.32-1.cp130.noarch cpanel-perl-542-x-tiny 0.22-1.cp130.noarch cpanel-perl-542-yaml-syck 1.47-1.cp130.x86_64 }; return \%packages; } sub download_file { my ( $url, $dest_file ) = @_; DEBUG "Retrieving $url"; # Don't call attempt_secure_download_file on new installs, as Cpanel::SecureDownload will # not be present on the system at the point where fix-cpanel-perl is called. if ( !$ENV{'CPANEL_BASE_INSTALL'} && attempt_secure_download_file( $url, $dest_file ) ) { return $dest_file; } my $output = `$wget_bin $wget_args '$dest_file' $url 2>&1`; ## no critic qw(Cpanel::ProhibitQxAndBackticks) if ( !-e $dest_file || -z $dest_file ) { unlink $dest_file; FATAL "The system could not fetch $url to file $dest_file: $output"; } return $dest_file; } sub signature_validation_enabled { my $config = read_config(); return 1 unless defined $config->{$SIG_VALIDATION_CPCONF_KEY}; return 0 if $config->{$SIG_VALIDATION_CPCONF_KEY} eq '0' || lc( $config->{$SIG_VALIDATION_CPCONF_KEY} ) eq 'off'; return 1; } sub verify_file_signature { my ( $file, $sig, $url ) = @_; if ( !signature_validation_enabled() ) { INFO "Skipping signature validation [currently disabled in cpanel.config]"; return; } INFO "FILE - $file"; INFO "SIG - $sig"; INFO "URL - $url"; my @gpg_args = ( '--logger-fd', '1', '--status-fd', '1', '--homedir', gpg_homedir(), '--verify', $sig, $file, ); # Verify the validity of the GPG signature. # Information on these return values can be found in 'doc/DETAILS' in the GnuPG source. my ( %notes, $curnote ); my ( $gpg_out, $success, $status ); my $gpg_pid = IPC::Open3::open3( undef, $gpg_out, undef, $GPG_BIN, @gpg_args ); while ( my $line = readline($gpg_out) ) { if ( $line =~ /^\[GNUPG:\] VALIDSIG ([A-F0-9]+) (\d+-\d+-\d+) (\d+) ([A-F0-9]+) ([A-F0-9]+) ([A-F0-9]+) ([A-F0-9]+) ([A-F0-9]+) ([A-F0-9]+) ([A-F0-9]+)$/ ) { $status = "Valid signature for $file"; $success = 1; } elsif ( $line =~ /^\[GNUPG:\] NOTATION_NAME (.+)$/ ) { $curnote = $1; $notes{$curnote} = ''; } elsif ( $line =~ /^\[GNUPG:\] NOTATION_DATA (.+)$/ ) { $notes{$curnote} .= $1; } elsif ( $line =~ /^\[GNUPG:\] BADSIG ([A-F0-9]+) (.+)$/ ) { $status = "Invalid signature for $file."; } elsif ( $line =~ /^\[GNUPG:\] NO_PUBKEY ([A-F0-9]+)$/ ) { $status = "Could not find public key in keychain."; } elsif ( $line =~ /^\[GNUPG:\] NODATA ([A-F0-9]+)$/ ) { $status = "Could not find a GnuPG signature in the signature file."; } } waitpid( $gpg_pid, 0 ); $status ||= "Unknown error from gpg."; $status .= " ($file)"; if ($success) { INFO $status; } else { FATAL $status; } # At this point, the signature should be valid. # We now need to check to see if the filename signature notation is correct. my ($url_path) = $url =~ m{^https?://[-.a-zA-Z0-9]+(/.+)}; $url_path or FATAL("Can't parse $url"); if ( defined( $notes{'filename@gpg.notations.cpanel.net'} ) ) { my $file_note = $notes{'filename@gpg.notations.cpanel.net'}; if ( $file_note ne $url_path ) { FATAL "Filename notation ($file_note) does not match URL ($url_path)."; } } else { FATAL "Signature does not contain a filename notation."; } return; } sub fetch_and_install_gpg_keys { my $pub_keys = public_keys(); _create_gpg_homedir(); INFO("fetch and install gpg keys"); FATAL("gpg bin unset") unless defined $GPG_BIN; foreach my $key ( @{ keys_to_download() } ) { INFO("Downloading GPG public key, $pub_keys->{$key}"); my $target = secure_downloads() . $pub_keys->{$key}; my $dest = gpg_homedir() . "/" . $pub_keys->{$key}; my $wget_out = download_file( $target, $dest, 1, 1 ); if ( !-e $dest ) { WARN("Could not download GPG public key at $target : $wget_out"); return; } my $gpg_cmd = $GPG_BIN . " -q --homedir " . gpg_homedir() . " --import " . $dest; DEBUG($gpg_cmd); my $out = `$gpg_cmd`; ## no critic qw(ProhibitQxAndBackticks) ERROR($out) if $? && length $out; } return; } sub _create_gpg_homedir { mkdir( gpg_homedir(), 0700 ) if !-e gpg_homedir(); return; } our $CACHE_CONFIG; sub read_config { my $file = $CPANEL_CONFIG_FILE; return $CACHE_CONFIG if $CACHE_CONFIG; my $config = {}; open( my $fh, "<", $file ) or return $config; while ( my $line = readline $fh ) { chomp $line; if ( $line =~ m/^\s*([^=]+?)\s*$/ ) { my $key = $1 or next; # Skip loading the key if it's undef or 0 $config->{$key} = undef; } elsif ( $line =~ m/^\s*([^=]+?)\s*=\s*(.*?)\s*$/ ) { my $key = $1 or next; # Skip loading the key if it's undef or 0 $config->{$key} = $2; } } $CACHE_CONFIG = $config; return $config; } sub keys_to_download { my $config = read_config(); my $keyrings = gpg_keyrings(); my $use_key = 'release'; # default key if ( defined $config->{'signature_validation'} && $config->{'signature_validation'} =~ /^Release and (?:Development|Test) Keyrings$/ ) { $use_key = 'development'; } my $mirror = get_update_source(); if ( $mirror =~ /^(?:.*\.dev|qa-build|next)\.cpanel\.net$/ ) { if ( !defined $config->{'signature_validation'} ) { $use_key = 'development'; } elsif ( $use_key ne 'development' ) { WARN("Using cPanel GPG '$use_key' key for mirror $mirror (consider using 'development')"); } } FATAL("Unknown key for $use_key") unless defined $keyrings->{$use_key}; WARN("Using cPanel GPG key '$use_key'") if $use_key ne 'release'; return $keyrings->{$use_key}; } # The installer may set $ENV{'CPANEL_BASE_INSTALL_GPG_KEYS_IMPORTED'} # to true in which case the keys will be in /var/cpanel/.gpgtmpdir sub gpg_homedir { return '/var/cpanel/.gpgtmpdir'; } sub public_keys { return { 'release' => 'cPanelPublicKey.asc', 'development' => 'cPanelDevelopmentKey.asc', }; } sub secure_downloads { return 'https://securedownloads.cpanel.net/'; } sub gpg_keyrings { return { 'release' => ['release'], 'development' => [ 'release', 'development' ], }; } 1;
Save
cmd:
run