# www.archline.hu — clean baseline (constituents + generator) This repo produces the **clean code baseline** of the www.archline.hu docroot (Cadline, Joomla 3.8.11, host `tanis.cadline.hu`) — the post-compromise, malware-free, faithful reproduction of the live server's source files. The baseline is the **input** to the operator's HIDS baseline-diff verifier (per-vhost known-good reference); the verification itself runs there, not here. ## Model: constituents + a generator script (not a checked-out tree) A deployed Joomla docroot differs from any repo/source layout: extensions install their files across many docroot paths (`administrator/…`, `components/…`, `media/…`, `plugins/…`) via their manifest. So this repo stores the baseline **constituents** and a script **assembles** the deployed baseline: ``` ./build-baseline.sh # → out/ = the deployed CODE docroot (the baseline) ``` - `core/` — Joomla 3.8.11 official package (deployed form). - `packages//` — upstream-obtainable extensions; the pristine package is manifest-mapped to deployed paths by `lib/jmap.py`, then our legit delta (`cadline.patch`) is applied — so git history shows exactly how we differ from upstream. - `deployed//` — no-source extensions: vetted live files, placed directly. - `cadline//` — Cadline own-code (+ submodules for the deployed-layout Cadline repos). - `overrides/` — Cadline core modifications as patches on vanilla. - Malware (`malware-iocs.md`) and runtime data are excluded; the result is code only. See [`RUNBOOK.md`](RUNBOOK.md) for the build recipe and module inventory, [`PROVENANCE.md`](PROVENANCE.md) for per-extension origins, and [`malware-iocs.md`](malware-iocs.md) for the excluded IOC set. ## Authority The live docroot (RO mirror) is the source of truth — the goal is its faithful, malware-free reproduction. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk); it is not a target. ## References - The archline.hu 2026 security audit and incident analysis (operator-held). - The baseline is consumed by the operator's per-vhost HIDS baseline-diff verifier.