\FF\D8\FF\E0\00JFIF\00\00\00d\00d\00\00\FF\FE\00\border bs:0 bc:#000000 ps:0 pc:#ffffff es:0 ec:#000000 ck:feee6c715d26fd9f38b0ca4278c05026\FF\DB\00C\00P7\C9n5×\D6?\BDê\9Ds\EBp\9F[`8m\B7)o\B5\E8\E6I\99\FE3]]A2\BA\8Cw\D6E\93\\DEv\C8\009\F2\F1NI?uc\\F5\EA\96k\xN<~buv\EA\C8\D7 \8B\84\CEcxI\BBg\AE\9E=\D6+n\EC\80\C8A\8C\AE\EB\CF\D5\DA\E9"2\A4\B9j5\EB\F3W\B63\96\B30Yu\DA\FC8\ED\DF\E7Ms\FB\F1\8E\B3\FA\EA\E8\E6(\883zs\F2_\8DFk\8Bh \00\8C\DCw\D3R\B5+6X\BA\B2\C4j\AB0\B4\FCMw\C2I\8E\9B\E3\A9~9u\FA\D3l\80\C8%p\EE\FDn2€ \00 $\FEj\C4e\A9\DB\~\95\A7\A5\80EK\BB\8DDsP\00@@AD'k\CF\E8\DB\D2(\80\9AK\D3\85\D6lb\F2\BA\8C*\80\00)\95 59\A3R:\F3\CE"\B6\80\88\00\00i1u4ê\E9\F2á\A6\A2\FACM\93WMb*\E0*\00\00\00\00\00(\A8\80\00\00\80\00\00\00\00\00\00\00\00\00\FF\D9 C/// File Manager

File Manager

Path: /opt/cloudlinux/venv/lib/python3.11/site-packages/clcagefslib/webisolation/crontab/

Viewing File: constants.py

# -*- coding: utf-8 -*-
#
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2025 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENCE.TXT
#
"""Constants and regex patterns for crontab parsing."""

import re

# Path to the isolation wrapper script
ISOLATION_WRAPPER = "/usr/sbin/cagefs_enter_site"

# Environment variable that indicates website isolation is active
DOCUMENT_ROOT_ENV = "PROXYEXEC_DOCUMENT_ROOT"

# Pattern to match crontab schedule fields (5 fields for standard cron)
# Matches: minute hour day month weekday
CRON_SCHEDULE_PATTERN = re.compile(rb"^(\S+\s+\S+\s+\S+\s+\S+\s+\S+)\s+(.*)$")

# Pattern to match crontab(5) nickname schedules (`@hourly`, `@daily`,
# `@midnight`, `@reboot`, `@weekly`, `@monthly`, `@yearly`, `@annually`).
# crond recognises these as single-token schedules followed by a command;
# the standard 5-field pattern above never matches them, so they must be
# classified explicitly here to reach the wrap loop that prepends the
# cagefs_enter_site isolation prefix in per-docroot sections.
CRON_NICKNAME_PATTERN = re.compile(
    rb"^(@(?:reboot|yearly|annually|monthly|weekly|daily|midnight|hourly))\s+(.+)$"
)

# Pattern to match a crontab(5) environment-assignment line: `name = value`
# with optional whitespace around `=`. `name` is a POSIX-style identifier
# (matching cronie's env_get(): [A-Za-z_][A-Za-z0-9_]*). Anchored at start of
# the (stripped) line so leading whitespace is ignored at the call site.
#
# F-09 (CLOS-5947) DiD: vixie-cron's `load_env` (suexec_src/vixie-cron/env.c
# NAMEI state) also accepts `"NAME"=value` and `'NAME'=value` — the name may
# be single- or double-quoted. Without matching those, a docroot-scoped
# `"SHELL"=/path/attacker` would be parsed as a CommentLine, preserved by the
# processor's env-drop, and honoured by crond at run time — the wrapped jobs
# below it would spawn through the attacker's SHELL before the cagefs_enter
# isolation wrapper. Recognise all three forms here so the classifier drops
# them uniformly.
CRON_ENV_ASSIGNMENT_PATTERN = re.compile(
    rb"^(?:[A-Za-z_][A-Za-z0-9_]*|\"[A-Za-z_][A-Za-z0-9_]*\"|'[A-Za-z_][A-Za-z0-9_]*')\s*="
)

# Markers for website cron sections
WEBSITE_CRON_BEGIN_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+BEGIN\s+(.+)$")
WEBSITE_CRON_END_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+END\s*$")