晋太元中,武陵人捕鱼为业。缘溪行,忘路之远近。忽逢桃花林,夹岸数百步,中无杂树,芳草鲜美,落英缤纷。渔人甚异之,复前行,欲穷其林。 林尽水源,便得一山,山有小口,仿佛若有光。便舍船,从口入。初极狭,才通人。复行数十步,豁然开朗。土地平旷,屋舍俨然,有良田、美池、桑竹之属。阡陌交通,鸡犬相闻。其中往来种作,男女衣着,悉如外人。黄发垂髫,并怡然自乐。 见渔人,乃大惊,问所从来。具答之。便要还家,设酒杀鸡作食。村中闻有此人,咸来问讯。自云先世避秦时乱,率妻子邑人来此绝境,不复出焉,遂与外人间隔。问今是何世,乃不知有汉,无论魏晋。此人一一为具言所闻,皆叹惋。余人各复延至其家,皆出酒食。停数日,辞去。此中人语云:“不足为外人道也。”(间隔 一作:隔绝) 既出,得其船,便扶向路,处处志之。及郡下,诣太守,说如此。太守即遣人随其往,寻向所志,遂迷,不复得路。 南阳刘子骥,高尚士也,闻之,欣然规往。未果,寻病终。后遂无问津者。
| DIR:/opt/cloudlinux/venv/lib64/python3.11/site-packages/clcagefslib/webisolation/crontab/ |
| Current File : //opt/cloudlinux/venv/lib64/python3.11/site-packages/clcagefslib/webisolation/crontab/constants.py |
# -*- coding: utf-8 -*-
#
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2025 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENCE.TXT
#
"""Constants and regex patterns for crontab parsing."""
import re
# Path to the isolation wrapper script
ISOLATION_WRAPPER = "/usr/sbin/cagefs_enter_site"
# Environment variable that indicates website isolation is active
DOCUMENT_ROOT_ENV = "PROXYEXEC_DOCUMENT_ROOT"
# Pattern to match crontab schedule fields (5 fields for standard cron)
# Matches: minute hour day month weekday
CRON_SCHEDULE_PATTERN = re.compile(rb"^(\S+\s+\S+\s+\S+\s+\S+\s+\S+)\s+(.*)$")
# Pattern to match crontab(5) nickname schedules (`@hourly`, `@daily`,
# `@midnight`, `@reboot`, `@weekly`, `@monthly`, `@yearly`, `@annually`).
# crond recognises these as single-token schedules followed by a command;
# the standard 5-field pattern above never matches them, so they must be
# classified explicitly here to reach the wrap loop that prepends the
# cagefs_enter_site isolation prefix in per-docroot sections.
CRON_NICKNAME_PATTERN = re.compile(
rb"^(@(?:reboot|yearly|annually|monthly|weekly|daily|midnight|hourly))\s+(.+)$"
)
# Pattern to match a crontab(5) environment-assignment line: `name = value`
# with optional whitespace around `=`. `name` is a POSIX-style identifier
# (matching cronie's env_get(): [A-Za-z_][A-Za-z0-9_]*). Anchored at start of
# the (stripped) line so leading whitespace is ignored at the call site.
#
# F-09 (CLOS-5947) DiD: vixie-cron's `load_env` (suexec_src/vixie-cron/env.c
# NAMEI state) also accepts `"NAME"=value` and `'NAME'=value` — the name may
# be single- or double-quoted. Without matching those, a docroot-scoped
# `"SHELL"=/path/attacker` would be parsed as a CommentLine, preserved by the
# processor's env-drop, and honoured by crond at run time — the wrapped jobs
# below it would spawn through the attacker's SHELL before the cagefs_enter
# isolation wrapper. Recognise all three forms here so the classifier drops
# them uniformly.
CRON_ENV_ASSIGNMENT_PATTERN = re.compile(
rb"^(?:[A-Za-z_][A-Za-z0-9_]*|\"[A-Za-z_][A-Za-z0-9_]*\"|'[A-Za-z_][A-Za-z0-9_]*')\s*="
)
# Markers for website cron sections
WEBSITE_CRON_BEGIN_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+BEGIN\s+(.+)$")
WEBSITE_CRON_END_PATTERN = re.compile(rb"^##\s+WEBSITE\s+CRON\s+END\s*$")
|