docs: add clean-baseline README on main
Establish the www.archline.hu clean-baseline repo. This root commit on main documents the baseline definition (only our code, deployable) and the reproducible per-commit reconstruction method used on the build branch. Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8
This commit is contained in:
commit
42033421e6
43
README.md
Normal file
43
README.md
Normal file
@ -0,0 +1,43 @@
|
|||||||
|
# www.archline.hu — clean baseline (constituents + generator)
|
||||||
|
|
||||||
|
This repo produces the **clean code baseline** of the www.archline.hu docroot
|
||||||
|
(Cadline, Joomla 3.8.11, host `tanis.cadline.hu`) — the post-compromise, malware-free,
|
||||||
|
faithful reproduction of the live server's source files. The baseline is the **input**
|
||||||
|
to the operator's HIDS baseline-diff verifier (per-vhost known-good reference); the
|
||||||
|
verification itself runs there, not here.
|
||||||
|
|
||||||
|
## Model: constituents + a generator script (not a checked-out tree)
|
||||||
|
|
||||||
|
A deployed Joomla docroot differs from any repo/source layout: extensions install their
|
||||||
|
files across many docroot paths (`administrator/…`, `components/…`, `media/…`,
|
||||||
|
`plugins/…`) via their manifest. So this repo stores the baseline **constituents** and a
|
||||||
|
script **assembles** the deployed baseline:
|
||||||
|
|
||||||
|
```
|
||||||
|
./build-baseline.sh # → out/ = the deployed CODE docroot (the baseline)
|
||||||
|
```
|
||||||
|
|
||||||
|
- `core/` — Joomla 3.8.11 official package (deployed form).
|
||||||
|
- `packages/<slug>/` — upstream-obtainable extensions; the pristine package is
|
||||||
|
manifest-mapped to deployed paths by `lib/jmap.py`, then our legit delta
|
||||||
|
(`cadline.patch`) is applied — so git history shows exactly how we differ from upstream.
|
||||||
|
- `deployed/<slug>/` — no-source extensions: vetted live files, placed directly.
|
||||||
|
- `cadline/<slug>/` — Cadline own-code (+ submodules for the deployed-layout Cadline repos).
|
||||||
|
- `overrides/` — Cadline core modifications as patches on vanilla.
|
||||||
|
- Malware (`malware-iocs.md`) and runtime data are excluded; the result is code only.
|
||||||
|
|
||||||
|
See [`RUNBOOK.md`](RUNBOOK.md) for the build recipe and module inventory,
|
||||||
|
[`PROVENANCE.md`](PROVENANCE.md) for per-extension origins, and
|
||||||
|
[`malware-iocs.md`](malware-iocs.md) for the excluded IOC set.
|
||||||
|
|
||||||
|
## Authority
|
||||||
|
|
||||||
|
The live docroot (RO mirror) is the source of truth — the goal is its faithful,
|
||||||
|
malware-free reproduction. The earlier single-commit "monolith" baseline is an
|
||||||
|
unvalidated helper only (it dropped extension manifests and clean core files and kept
|
||||||
|
installer junk); it is not a target.
|
||||||
|
|
||||||
|
## References
|
||||||
|
|
||||||
|
- The archline.hu 2026 security audit and incident analysis (operator-held).
|
||||||
|
- The baseline is consumed by the operator's per-vhost HIDS baseline-diff verifier.
|
||||||
Loading…
Reference in New Issue
Block a user