The developer-controlled Cadline repos (cadcommonlib, maintenance) become git submodules so updates flow through: git submodule update --remote -> build -> commit new pointers. Pinned to their authoritative HEADs. build-baseline.sh inits the submodules and normalizes their CRLF to LF (the deploy transform) so the assembled baseline byte-matches the deployed form. constants.php (live-only config, not in the repo; carries a DB credential tracked in the credential inventory) is kept as an overlay (overrides/) per instruction — removal happens at source later. Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8 |
||
|---|---|---|
| cadline | ||
| core | ||
| deployed | ||
| lib | ||
| overrides | ||
| packages | ||
| tests | ||
| .gitignore | ||
| .gitmodules | ||
| build-baseline.sh | ||
| malware-iocs.md | ||
| malware-iocs.paths | ||
| PROVENANCE.md | ||
| README.md | ||
| RUNBOOK.md | ||
www.archline.hu — clean baseline (constituents + generator)
This repo produces the clean code baseline of the www.archline.hu docroot
(Cadline, Joomla 3.8.11, host tanis.cadline.hu) — the post-compromise, malware-free,
faithful reproduction of the live server's source files. The baseline is the input
to the operator's HIDS baseline-diff verifier (per-vhost known-good reference); the
verification itself runs there, not here.
Model: constituents + a generator script (not a checked-out tree)
A deployed Joomla docroot differs from any repo/source layout: extensions install their
files across many docroot paths (administrator/…, components/…, media/…,
plugins/…) via their manifest. So this repo stores the baseline constituents and a
script assembles the deployed baseline:
./build-baseline.sh # → out/ = the deployed CODE docroot (the baseline)
core/— Joomla 3.8.11 official package (deployed form).packages/<slug>/— upstream-obtainable extensions; the pristine package is manifest-mapped to deployed paths bylib/jmap.py, then our legit delta (cadline.patch) is applied — so git history shows exactly how we differ from upstream.deployed/<slug>/— no-source extensions: vetted live files, placed directly.cadline/<slug>/— Cadline own-code (+ submodules for the deployed-layout Cadline repos).overrides/— Cadline core modifications as patches on vanilla.- Malware (
malware-iocs.md) and runtime data are excluded; the result is code only.
See RUNBOOK.md for the build recipe and module inventory,
PROVENANCE.md for per-extension origins, and
malware-iocs.md for the excluded IOC set.
Authority
The live docroot (RO mirror) is the source of truth — the goal is its faithful, malware-free reproduction. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk); it is not a target.
References
- The archline.hu 2026 security audit and incident analysis (operator-held).
- The baseline is consumed by the operator's per-vhost HIDS baseline-diff verifier.