Establish the www.archline.hu clean-baseline repo. This root commit on main documents the baseline definition (only our code, deployable) and the reproducible per-commit reconstruction method used on the build branch. Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8 |
||
|---|---|---|
| README.md | ||
www.archline.hu — clean baseline (constituents + generator)
This repo produces the clean code baseline of the www.archline.hu docroot
(Cadline, Joomla 3.8.11, host tanis.cadline.hu) — the post-compromise, malware-free,
faithful reproduction of the live server's source files. The baseline is the input
to the operator's HIDS baseline-diff verifier (per-vhost known-good reference); the
verification itself runs there, not here.
Model: constituents + a generator script (not a checked-out tree)
A deployed Joomla docroot differs from any repo/source layout: extensions install their
files across many docroot paths (administrator/…, components/…, media/…,
plugins/…) via their manifest. So this repo stores the baseline constituents and a
script assembles the deployed baseline:
./build-baseline.sh # → out/ = the deployed CODE docroot (the baseline)
core/— Joomla 3.8.11 official package (deployed form).packages/<slug>/— upstream-obtainable extensions; the pristine package is manifest-mapped to deployed paths bylib/jmap.py, then our legit delta (cadline.patch) is applied — so git history shows exactly how we differ from upstream.deployed/<slug>/— no-source extensions: vetted live files, placed directly.cadline/<slug>/— Cadline own-code (+ submodules for the deployed-layout Cadline repos).overrides/— Cadline core modifications as patches on vanilla.- Malware (
malware-iocs.md) and runtime data are excluded; the result is code only.
See RUNBOOK.md for the build recipe and module inventory,
PROVENANCE.md for per-extension origins, and
malware-iocs.md for the excluded IOC set.
Authority
The live docroot (RO mirror) is the source of truth — the goal is its faithful, malware-free reproduction. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk); it is not a target.
References
- The archline.hu 2026 security audit and incident analysis (operator-held).
- The baseline is consumed by the operator's per-vhost HIDS baseline-diff verifier.