/
usr
/
lib
/
.build-id
/
e0
/
/usr/lib/.build-id/e0
mkdir
upload
Name
Size
Mode
Actions
17d440cc7c2b169a1ff2827edf42defb6774f7
354504
0755
edit
dl
rm
34ae5bdb5f6ab8bc0e0e3faa56ce7b04ab79ec
115608
0755
edit
dl
rm
054b89b09aa650420dde06c962938211a05ab7
-
0
edit
dl
rm
72d49b7892eb848bc6f6d2b95fe901be72c7a3
-
0
edit
dl
rm
73e9e74d7f252f5bf513a3a4ad629e03c7fc6c
-
0
edit
dl
rm
80f7755ffd34cf52a89d8c8cd33dd572e77592
31728
0755
edit
dl
rm
302fa38857ee79a0e3d6997f8628e82c1f019d
-
0
edit
dl
rm
938ba31c7dbf4762df4c9d5e81e7b1da0c9f3e
19416
0755
edit
dl
rm
945b3cd060006c48df958f13340d3c206a1bf3
-
0
edit
dl
rm
7457e679c3022b8d8c3057aaa14176a84ab1fe
4758816
0755
edit
dl
rm
923095d772bc3a1bba7ca4bc7ae1be8398ab1c
222112
0755
edit
dl
rm
aaa55d8837fbc0bb31aec5110f6cade78ac894
6009
0755
edit
dl
rm
b56126188fad7378d03ae692f1037950db616d
15264
0755
edit
dl
rm
cea4402dbb7d7e89fa3e000dca947c11162cca
24056
0755
edit
dl
rm
d22c9b5a9ffcfe4ef74756883073ad3b9c0859
9846016
0755
edit
dl
rm
d70f0608433fb36c094086f5ff78ab4499fd50
189808
0755
edit
dl
rm
d193d89dcf0ee36f158080db73a50c98e16e3f
20168
0755
edit
dl
rm
Edit:
/usr/bin/at
(6009B)
#!/usr/bin/bash ##CageFS proxyexec wrapper - ver 18 if [[ $EUID -eq 0 ]]; then echo 'Cannot be run as root' exit 1 fi # POSIX single-quote escaping for values embedded in the ssh remote # command. Unlike `printf %q`, single-quoted output re-parses correctly # under any POSIX shell (the origin login shell need not be bash) and is # lossless for arbitrary bytes. Each embedded ' becomes the '\'' sequence. sq() { local s=${1//\'/\'\\\'\'} printf "'%s'" "$s" } USR=`/usr/bin/whoami` USER_TOKEN_PATH="/var/.cagefs/.cagefs.token" WEBSITE_ISOLATION_FLAG="/opt/cloudlinux/flags/enabled-flags.d/website-isolation.flag" # Trust boundary for the website-isolation token path: it must point # directly at the regular file that create_website_token_directory() # creates inside its root-owned per-user storage area. That area is # /var/cagefs/<prefix>/<user>/.cagefs/website/... on the host and is # bind-mounted into the cage at /var/.cagefs/website/... — both views # are accepted because libenter.enter_site() picks one or the other # depending on whether it runs inside or outside the cage. The file # itself is never a symlink, so we reject symlinks outright rather # than canonicalizing with realpath. Without this gate the attacker # controls both the env var WEBSITE_TOKEN_PATH and the file contents # at that path; the file contents land in $TOKEN, which is embedded # into the ssh remote command argv below and re-parsed by the remote # shell — so shell metacharacters in the file would execute on the # origin host. (Slite #7 / CLOS-4490) if [[ -f "$WEBSITE_ISOLATION_FLAG" && -n "$WEBSITE_TOKEN_PATH" ]]; then if [[ -L "$WEBSITE_TOKEN_PATH" ]]; then echo "cagefs.proxy: WEBSITE_TOKEN_PATH '$WEBSITE_TOKEN_PATH' must not be a symlink" >&2 exit 1 fi if [[ ! -f "$WEBSITE_TOKEN_PATH" ]]; then echo "cagefs.proxy: WEBSITE_TOKEN_PATH '$WEBSITE_TOKEN_PATH' is not an existing regular file" >&2 exit 1 fi # Reject `..` as a path component so the prefix check below cannot # be bypassed via traversal (e.g. /var/cagefs/../etc/passwd matches # the /var/cagefs/* glob but resolves outside the trusted area). case "$WEBSITE_TOKEN_PATH" in */../*|*/..) echo "cagefs.proxy: WEBSITE_TOKEN_PATH '$WEBSITE_TOKEN_PATH' must not contain '..' path components" >&2 exit 1 ;; esac case "$WEBSITE_TOKEN_PATH" in /var/cagefs/*|/var/.cagefs/*) ;; *) echo "cagefs.proxy: WEBSITE_TOKEN_PATH must be under /var/cagefs/ or /var/.cagefs/ (got '$WEBSITE_TOKEN_PATH')" >&2 exit 1 ;; esac USER_TOKEN_PATH="$WEBSITE_TOKEN_PATH" fi # The -L/-f/prefix gate above is defense-in-depth, TOCTOU is not exploitable because the # forwarded $TOKEN must still equal the legit on-disk bytes that the # origin's cagefs.server reads with open(..., O_NOFOLLOW) from a # uid-derived path (see find_website_by_token() in # proxyexec/cagefs.server.c) — a swapped symlink redirects what we # cat, never what the server reads, so a TOCTOU substitution can only # replace the forwarded bytes with something that fails the server's # constant-time comparison. TOKEN=`/bin/cat ${USER_TOKEN_PATH}` # Tokens are generated as fixed-length alphanumerics by # _generate_password() in py/clcagefslib/webisolation/jail_utils.py and # by the corresponding C helper. Any non-alphanumeric byte means the # token file was tampered with — refuse to forward it into the ssh # remote command, where the remote shell would re-parse metacharacters. # Use POSIX `case` rather than `[[ =~ ]]` because the wrapper is also # invoked through `sh` (e.g. jenkins_tests/rpm_tests/p_cagefs/ # 939-environment_var-check.sh), and dash treats `[[` as a missing # command — the regex form would falsely trip and exit the script. case "$TOKEN" in "" | *[!A-Za-z0-9]*) echo "cagefs.proxy: refusing to forward malformed token from $USER_TOKEN_PATH" >&2 exit 1 ;; esac # It's user's tmp directory and write to it is secure procedure # because this script is running only under usual user PIDFILE="/tmp/.cagefs.proxy.$$" USER_INTERRUPT=13 CWD=`pwd` ctrl_c_handler() { if [[ -f "$PIDFILE" ]]; then pid=`/bin/cat $PIDFILE` /bin/rm -f $PIDFILE > /dev/null 2>&1 /bin/kill -s SIGINT "$pid" > /dev/null 2>&1 fi exit $USER_INTERRUPT } if [[ -e /var/.cagefs/origin ]]; then ORIGIN=`/bin/cat /var/.cagefs/origin` # ssh(1) joins the remote-command argv with single spaces and ships # the result for the origin user's login shell to re-parse. The local # bash double-quotes around "$CWD" and "$@" only protect parsing on # THIS host — once ssh has taken the argv, the quoting is gone and # any shell metacharacter embedded in $CWD (`pwd`, attacker controls # via mkdir+cd inside the cage) or in any "$@" element (caller argv # for sendmail/crontab/etc.) is interpreted by the remote shell. # CLOS-4490 hardened $TOKEN by content validation; that approach # does not work for $CWD or $@ (legitimate paths/args may contain # spaces, parens, ampersands), so we single-quote each caller- # controlled element with sq() before composing the remote command. # ssh re-parses the command only once (the origin login shell), so a # single quoting pass per value is enough here. $USR is `whoami` so # it cannot contain metacharacters in any sane account database, but # we quote it too for defense in depth. (CLOS-4596) Q_ARGS= for _arg in "$@"; do Q_ARGS="$Q_ARGS $(sq "$_arg")" done /usr/bin/ssh -F /etc/ssh/cagefs-rexec_config "$USR@$ORIGIN" \ "CAGEFS_TOKEN=$TOKEN /usr/sbin/proxyexec -c cagefs.sock $(sq "$USR") $(sq "$CWD") AT $$$Q_ARGS" RETVAL=$? else trap 'ctrl_c_handler' 2 CAGEFS_TOKEN="$TOKEN" /usr/sbin/proxyexec -c cagefs.sock "$USR" "$CWD" AT $$ "$@" RETVAL=$? /bin/rm -f $PIDFILE > /dev/null 2>&1 fi exit $RETVAL
Save
cmd:
run