# RUNBOOK — building the www.archline.hu baseline This repo stores the **constituents** of the clean code baseline, not the deployed tree. [`build-baseline.sh`](build-baseline.sh) deterministically "deploys" them into `out/` — the code docroot that `illusion/hids` (imrcli `vanilla_ref`) diffs the live server against. The deployed layout differs from the repo layout, so the build maps each constituent to its Joomla-installed location. ## Goal Reproduce the live www.archline.hu **source files as faithfully as possible, minus malware**. Authority = the live docroot (RO mirror); the previous single-commit "monolith" baseline is an unvalidated helper only (it dropped manifests and clean core files, kept junk — not a target). ## Directory contract | Dir | Holds | build-baseline.sh step | |---|---|---| | `core/` | Joomla 3.8.11 official full package (deployed form, installer removed) | 1 — rsync minus demo/data | | `packages//pristine/` | extracted upstream package (with manifest) | 2 — `lib/jmap.py` manifest-map | | `packages//cadline.patch` | our legit delta on that module (optional) | 2 — `patch -p1` after map | | `deployed//` | no-source extension, vetted deployed files (deployed layout) | 3 — direct rsync | | `cadline//` | Cadline own-code (deployed layout) | 4 — direct rsync | | `overrides/*.patch` | Cadline core modifications (vs vanilla) | 5 — `patch -p1` | | `malware-iocs.paths` | IOC exclusion safety net | 6 | Modified module → **two git commits**: pristine (`packages//pristine/`) then the delta (`cadline.patch`), so `git diff` documents exactly our change vs upstream. ## Build & verify ``` ./build-baseline.sh # → out/ (the deployed code baseline) ``` Verification (residual→0, malware/data buckets) lives in **`illusion/hids`** (imrcli), which consumes `out/` as the per-vhost `vanilla_ref`. This repo only produces the input. **Current build result (verified against the live RO mirror):** `out/` = 23,578 clean code files. Byte-matches live for all legit code; differs only on the 4 known-infected files where the baseline is intentionally clean (3 trojanized core files + the `shaper_helix3/index.php` cloaking). **Non-malware code residual = 0** — every live code file is either in the baseline or is excluded malware / scan artifact. 5 benign extra files (clean core the package carries but live dropped). `public/` (~219k files) and other runtime data are excluded as data, not code. ## Module inventory (categorization) ### core - Joomla 3.8.11 — official full package. Clean; live's 3 injected core files (see `malware-iocs.md`) are restored by using the package version. ### packages/ — upstream package obtainable (manifest-mapped; provenance + delta) - `oneallsociallogin` — OneAll 5.5.0, github.com/oneall/social-login-joomla @5.5.0; **modified** (CRM) → cadline.patch - `remoteimage` — asikart/remoteimage @2.0.10 (stock) - `phocacommander` — PhocaCz/PhocaCommander @3.0.2 (stock) - `phocadownload` — PhocaCz/PhocaDownload @3.1.2; **modified** (10 files) → cadline.patch - `easyfileuploader` — ollily/easyfileuploader; **modified** (3 files) → cadline.patch - *(K2, JoomGallery, Windwalker: git repos exist but no version-matching package → currently `deployed/`; promote to `packages/` if a 2.8.0/3.3.4 package is obtained.)* ### deployed/ — no obtainable package (vetted live files) K2, JoomGallery, Windwalker; sh404SEF, JCK Editor, SP Page Builder, iCagenda, Akeeba Backup, Convert Forms (+NR Framework), Regular Labs (Sourcerer/AMM/Modals/lib), AcyMailing, MightySites, JSN/JoomlaShine, Jumi, TF Learn, Smart Countdown, Smart Shoutbox, Slideshow CK, Social Login&Share, SP Easy Image Gallery, IceMegaMenu, Image Swoop, Helix3 (clean index.php), and the repo-less modules/plugins/libs/templates (bt_googlemaps, os_touchslider, jflickr, *_timeline, ut_joomstagram, xpertscroller, anycode, flippingbook, joombig, youtuber, jw_allvideos/sig, socialnetworks, fancybox, mootable, EUCookie, extblank, tmlazyload, p3p, xef, _theme3037, trada, …). JCK: **modified** (menunodes.php CVE-2018-17254 mitigation) — no upstream, documented in PROVENANCE.md. ### cadline/ — Cadline own-code com_showroom, com_albanner, com_alworkshops, com_followedlinks, com_nonprofit, com_presentation, com_project, com_tcexam, com_versions; mod_al_*, mod_alusers, mod_alworkshops, mod_course_list, mod_webinar*, mod_wsregister; plg content/workshopdates; templates blankframe, category; docroot apps (beiratkozas, iskolak, phpext) + root PHPs (crashadmin.php, crm_hardlock.class.php, login-external.php, tips.php, sbtrack.php, recaptchalib.php, configuration.php). `common_cadline_libraries` and `maintenance/` come from the Cadline-internal repos cadcommonlib / maintenance (see PROVENANCE.md) but are kept as **vetted live files for byte-fidelity** (could be converted to git submodules later — that would not change the byte-baseline). `public/` is **excluded — user data** (~219k images/project files), not code. ### overrides/ — Cadline core modifications (23 files) com_content / com_users (registration/login/reset/remind), mod_login, captcha/recaptcha, language ini, phpversioncheck — the ~26 legit customizations (§16.1), as patches on vanilla.