# www.archline.hu — clean baseline (constituents + generator) This repo produces the **clean code baseline** of the www.archline.hu docroot (Cadline, Joomla 3.8.11, host `tanis.cadline.hu`) — the post-compromise, malware-free, faithful reproduction of the live server's source files. The baseline is the **input** to the HIDS baseline-diff verifier: a per-vhost, known-good reference tree the verifier compares the live docroot against (`baseline-match / data / malware / residual`). This repo only *produces* that tree; the verification runs on the HIDS side. --- ## Building the baseline (read this first) The repo does **not** contain the deployed docroot — it contains the baseline *constituents* plus a generator script. Run the script to produce the deployed tree: ```sh # 1. Clone WITH submodules (common_cadline_libraries + maintenance are submodules): git clone --recurse-submodules ssh://git@git.cadline.hu:22222/cadline_web/www_archline_hu.git cd www_archline_hu # (if you already cloned without --recurse-submodules:) git submodule update --init # 2. Generate the baseline: ./build-baseline.sh # → ./out/ # 3. Use ./out/ as the per-vhost vanilla_ref (the known-good reference tree). ``` `out/` is the deployed **code** docroot (~23.5k files). It is git-ignored and fully regenerated on every run (the script is idempotent — it `rm -rf out/` first). Point the verifier's baseline-diff at `out/`, or copy it to wherever the verifier expects the ref. **Prerequisites:** `bash`, `rsync`, `git` (for submodules), `find`, `sed`. No PHP, no build toolchain, no network at build time (submodules are already cloned). `lib/jmap.py` (python3) is a *maintenance* tool used only when authoring a package's pristine commit — **it is not invoked by `build-baseline.sh`**. **What `out/` contains / excludes:** - **Contains:** Joomla 3.8.11 core + every installed extension (110 components, ~98 modules, 164 plugins, 8 templates) + the Cadline-own code — all as deployed files. - **Excludes:** malware/IOCs (see [`malware-iocs.md`](malware-iocs.md)) and runtime **data** (`cache/`, `tmp/`, `logs/`, `images/`, `public/`, media data). The result is code only. - Byte-matches the live docroot for all legit code; it is intentionally **clean** on the 4 files the attacker infected (3 trojanized core files + `shaper_helix3/index.php`), so the verifier flags those on the live server. Verified: non-malware code residual = 0. --- ## Repo layout (the constituents) | Path | What | How `build-baseline.sh` uses it | |---|---|---| | `core/` | Joomla 3.8.11 official package (deployed form) | rsync → `out/`, minus demo assets + data dirs | | `packages//` | 5 upstream-obtainable extensions, deployed-layout, reconciled to live bytes. Modified ones are two commits (pristine upstream → live delta) so `git log`/`git diff` shows exactly how we differ from upstream. | rsync → `out/` | | `deployed//` | ~55 no-source extensions: vetted live files (deployed layout). `_shared/` holds cross-extension language/vendor/manifests. | rsync → `out/` | | `cadline//` | Cadline own-code. `cadline/backend/common_cadline_libraries` and `…/maintenance` are **git submodules** of the developer repos (cadcommonlib / maintenance). | rsync → `out/` (`.git` excluded) | | `overrides/` | Cadline core modifications (live versions overlaid on the package core) + a few package-missing core files. | rsync → `out/` (last, so it wins) | | `lib/jmap.py` | Generic Joomla manifest→deployed-path mapper (authoring aid only). | not used at build time | Details: [`RUNBOOK.md`](RUNBOOK.md) (recipe + module inventory), [`PROVENANCE.md`](PROVENANCE.md) (per-extension origins), [`malware-iocs.md`](malware-iocs.md) (excluded IOC set). --- ## Updating the baseline - **Developer-controlled code** (`common_cadline_libraries`, `maintenance`): the developer pushes to the cadcommonlib / maintenance repos, then: ```sh git submodule update --remote # pull the developer's latest ./build-baseline.sh # regenerate out/ git add -A && git commit # record the new submodule pointers ``` - **Everything else** (Joomla core EOL, 3rd-party extensions): effectively frozen; if a legit change ever lands, re-sync the affected `deployed//` or `overrides/` from the live docroot and commit. **Known divergence (heads-up for the verifier):** `common_cadline_libraries` and `maintenance` currently take the *authoritative* submodule HEAD content, which differs from the current live docroot (mixed CRLF/LF + a content drift on `crm_hardlock.class.php` / `POfile.php`) because live was not last deployed from those HEADs. The verifier will flag this until live is re-deployed from the submodules or the drift is reconciled. Line-ending normalization, if wanted, is a verifier-side choice. --- ## Authority The live docroot (RO mirror) is the source of truth for reproduction; the developer git repos are authoritative for the code they own. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk) — it is not a target. ## References - The archline.hu 2026 security audit and incident analysis (operator-held). - The excluded malware set is documented in [`malware-iocs.md`](malware-iocs.md).