Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.
Layers:
- core/ vanilla Joomla 3.9.2 official package (installer removed)
- cadline/ own-code from the developer source (beiratkozas, maintenance,
mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
the developer source lacks
- deployed/ 95 third-party module slugs taken from live, YARA-vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base
The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently. 289
planted paths are excluded through malware-iocs.paths.
Verification: build-baseline.sh -> out/ = 12286 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; not one IOC path
present; no disguised .json dropper; core verified as 3.9.2.
Assisted-by: claude-code@claude-opus-4-8
80 lines
2.0 KiB
PHP
80 lines
2.0 KiB
PHP
<?php
|
|
/**
|
|
* @package Joomla.Cli
|
|
*
|
|
* @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved.
|
|
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
|
*/
|
|
|
|
/**
|
|
* A command line cron job to attempt to remove files that should have been deleted at update.
|
|
*/
|
|
|
|
// We are a valid entry point.
|
|
const _JEXEC = 1;
|
|
|
|
// Load system defines
|
|
if (file_exists(dirname(__DIR__) . '/defines.php'))
|
|
{
|
|
require_once dirname(__DIR__) . '/defines.php';
|
|
}
|
|
|
|
if (!defined('_JDEFINES'))
|
|
{
|
|
define('JPATH_BASE', dirname(__DIR__));
|
|
require_once JPATH_BASE . '/includes/defines.php';
|
|
}
|
|
|
|
// Get the framework.
|
|
require_once JPATH_LIBRARIES . '/import.legacy.php';
|
|
|
|
// Bootstrap the CMS libraries.
|
|
require_once JPATH_LIBRARIES . '/cms.php';
|
|
|
|
// Configure error reporting to maximum for CLI output.
|
|
error_reporting(E_ALL);
|
|
ini_set('display_errors', 1);
|
|
|
|
// Load Library language
|
|
$lang = JFactory::getLanguage();
|
|
|
|
// Try the files_joomla file in the current language (without allowing the loading of the file in the default language)
|
|
$lang->load('files_joomla.sys', JPATH_SITE, null, false, false)
|
|
// Fallback to the files_joomla file in the default language
|
|
|| $lang->load('files_joomla.sys', JPATH_SITE, null, true);
|
|
|
|
/**
|
|
* A command line cron job to attempt to remove files that should have been deleted at update.
|
|
*
|
|
* @since 3.0
|
|
*/
|
|
class DeletefilesCli extends JApplicationCli
|
|
{
|
|
/**
|
|
* Entry point for CLI script
|
|
*
|
|
* @return void
|
|
*
|
|
* @since 3.0
|
|
*/
|
|
public function doExecute()
|
|
{
|
|
// Import the dependencies
|
|
jimport('joomla.filesystem.file');
|
|
jimport('joomla.filesystem.folder');
|
|
|
|
// We need the update script
|
|
JLoader::register('JoomlaInstallerScript', JPATH_ADMINISTRATOR . '/components/com_admin/script.php');
|
|
|
|
// Instantiate the class
|
|
$class = new JoomlaInstallerScript;
|
|
|
|
// Run the delete method
|
|
$class->deleteUnexistingFiles();
|
|
}
|
|
}
|
|
|
|
// Instantiate the application object, passing the class name to JCli::getInstance
|
|
// and use chaining to execute the application.
|
|
JApplicationCli::getInstance('DeletefilesCli')->execute();
|