Go to file
LÁZÁR Imre AI Agent 22d0a1a00f chore(build): drop unused JMAP variable
jmap.py is an authoring-only tool and is not invoked at build time; remove the
dead variable so the script matches the README.

Signed-off-by: LÁZÁR Imre <imre@illusion.hu>
Assisted-by: claude-code@claude-opus-4-8
2026-07-16 13:58:28 +02:00
cadline feat(cadline): convert common_cadline_libraries + maintenance to submodules 2026-07-16 13:47:32 +02:00
core core: add Joomla 3.8.11 official package (deployed-form source) 2026-07-16 09:40:46 +02:00
deployed feat(baseline): add remaining legit files (postupdate, isis js, windwalker cli, sbtrack) 2026-07-16 11:40:36 +02:00
lib build(baseline): add lib/jmap.py Joomla manifest-mapper + tests 2026-07-16 11:27:45 +02:00
overrides feat(cadline): convert common_cadline_libraries + maintenance to submodules 2026-07-16 13:47:32 +02:00
packages feat(pkg): add Phoca Commander 3.0.2 (vetted live, stock) 2026-07-16 11:30:03 +02:00
tests build(baseline): add lib/jmap.py Joomla manifest-mapper + tests 2026-07-16 11:27:45 +02:00
.gitignore build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00
.gitmodules feat(cadline): convert common_cadline_libraries + maintenance to submodules 2026-07-16 13:47:32 +02:00
build-baseline.sh chore(build): drop unused JMAP variable 2026-07-16 13:58:28 +02:00
malware-iocs.md docs: remove operator-internal (git.illusion.hu) references 2026-07-16 12:14:05 +02:00
malware-iocs.paths build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00
PROVENANCE.md build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00
README.md docs(readme): clear build guide for the HIDS/verifier side 2026-07-16 13:57:47 +02:00
RUNBOOK.md docs: remove operator-internal (git.illusion.hu) references 2026-07-16 12:14:05 +02:00

www.archline.hu — clean baseline (constituents + generator)

This repo produces the clean code baseline of the www.archline.hu docroot (Cadline, Joomla 3.8.11, host tanis.cadline.hu) — the post-compromise, malware-free, faithful reproduction of the live server's source files.

The baseline is the input to the HIDS baseline-diff verifier: a per-vhost, known-good reference tree the verifier compares the live docroot against (baseline-match / data / malware / residual). This repo only produces that tree; the verification runs on the HIDS side.


Building the baseline (read this first)

The repo does not contain the deployed docroot — it contains the baseline constituents plus a generator script. Run the script to produce the deployed tree:

# 1. Clone WITH submodules (common_cadline_libraries + maintenance are submodules):
git clone --recurse-submodules ssh://git@git.cadline.hu:22222/cadline_web/www_archline_hu.git
cd www_archline_hu
#    (if you already cloned without --recurse-submodules:)
git submodule update --init

# 2. Generate the baseline:
./build-baseline.sh            # → ./out/

# 3. Use ./out/ as the per-vhost vanilla_ref (the known-good reference tree).

out/ is the deployed code docroot (~23.5k files). It is git-ignored and fully regenerated on every run (the script is idempotent — it rm -rf out/ first). Point the verifier's baseline-diff at out/, or copy it to wherever the verifier expects the ref.

Prerequisites: bash, rsync, git (for submodules), find, sed. No PHP, no build toolchain, no network at build time (submodules are already cloned). lib/jmap.py (python3) is a maintenance tool used only when authoring a package's pristine commit — it is not invoked by build-baseline.sh.

What out/ contains / excludes:

  • Contains: Joomla 3.8.11 core + every installed extension (110 components, ~98 modules, 164 plugins, 8 templates) + the Cadline-own code — all as deployed files.
  • Excludes: malware/IOCs (see malware-iocs.md) and runtime data (cache/, tmp/, logs/, images/, public/, media data). The result is code only.
  • Byte-matches the live docroot for all legit code; it is intentionally clean on the 4 files the attacker infected (3 trojanized core files + shaper_helix3/index.php), so the verifier flags those on the live server. Verified: non-malware code residual = 0.

Repo layout (the constituents)

Path What How build-baseline.sh uses it
core/ Joomla 3.8.11 official package (deployed form) rsync → out/, minus demo assets + data dirs
packages/<slug>/ 5 upstream-obtainable extensions, deployed-layout, reconciled to live bytes. Modified ones are two commits (pristine upstream → live delta) so git log/git diff shows exactly how we differ from upstream. rsync → out/
deployed/<slug>/ ~55 no-source extensions: vetted live files (deployed layout). _shared/ holds cross-extension language/vendor/manifests. rsync → out/
cadline/<slug>/ Cadline own-code. cadline/backend/common_cadline_libraries and …/maintenance are git submodules of the developer repos (cadcommonlib / maintenance). rsync → out/ (.git excluded)
overrides/ Cadline core modifications (live versions overlaid on the package core) + a few package-missing core files. rsync → out/ (last, so it wins)
lib/jmap.py Generic Joomla manifest→deployed-path mapper (authoring aid only). not used at build time

Details: RUNBOOK.md (recipe + module inventory), PROVENANCE.md (per-extension origins), malware-iocs.md (excluded IOC set).


Updating the baseline

  • Developer-controlled code (common_cadline_libraries, maintenance): the developer pushes to the cadcommonlib / maintenance repos, then:
    git submodule update --remote     # pull the developer's latest
    ./build-baseline.sh               # regenerate out/
    git add -A && git commit          # record the new submodule pointers
    
  • Everything else (Joomla core EOL, 3rd-party extensions): effectively frozen; if a legit change ever lands, re-sync the affected deployed/<slug>/ or overrides/ from the live docroot and commit.

Known divergence (heads-up for the verifier): common_cadline_libraries and maintenance currently take the authoritative submodule HEAD content, which differs from the current live docroot (mixed CRLF/LF + a content drift on crm_hardlock.class.php / POfile.php) because live was not last deployed from those HEADs. The verifier will flag this until live is re-deployed from the submodules or the drift is reconciled. Line-ending normalization, if wanted, is a verifier-side choice.


Authority

The live docroot (RO mirror) is the source of truth for reproduction; the developer git repos are authoritative for the code they own. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk) — it is not a target.

References

  • The archline.hu 2026 security audit and incident analysis (operator-held).
  • The excluded malware set is documented in malware-iocs.md.