Heray-Was-Here
Server : Apache
System : Linux dal-shared-66.hostwindsdns.com 4.18.0-513.24.1.lve.1.el8.x86_64 #1 SMP Thu May 9 15:10:09 UTC 2024 x86_64
User : krnuyqrm ( 1183)
PHP Version : 7.4.33
Disable Function : NONE
Directory :  /proc/self/root/proc/thread-self/root/proc/self/root/usr/lib/systemd/system/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : //proc/self/root/proc/thread-self/root/proc/self/root/usr/lib/systemd/system/ssa-agent.socket
[Unit]
Description=PHP Cloudlinux SSA Agent Socket
PartOf=ssa-agent.service

[Socket]
ListenStream=/opt/alt/clos_ssa/run/ssa.sock
# SocketMode=0666 is intentional: the socket must be writable by PHP
# processes running under any web server (Apache, LiteSpeed, Nginx)
# across all supported panels (cPanel, Plesk, DirectAdmin).
# Restricting via SocketGroup is not feasible because the group owning
# PHP workers differs per panel and web server combination.
# Input validation in agent.py _validate_input() limits accepted payloads
# to the exact format produced by the C extension (7 fields with strict
# types). The world-writable mode does NOT by itself prevent cross-tenant
# metric spoofing; that guard lives in the authorization layer, not the
# socket ACL. SimpleAgent._authorize_sender() uses the kernel-trusted
# SO_PEERCRED UID together with the reported domain's PHP handler to fail
# CLOSED when a shared or service peer (nobody/apache, webapps, an unmapped
# UID) reports a per-user tenant's domain it does not own. Residual by
# design: a victim domain served under a shared handler (DSO/mod_php/Plesk
# module), or a panel whose handler API is unavailable (get_domains_php_info
# raises, e.g. InterWorx/ispmanager), cannot be told apart from legitimate
# shared-UID self-telemetry and is accepted. See
# docs/design/ssa-agent-socket.md.
SocketMode=0666
Backlog=2048

[Install]
WantedBy=sockets.target

Hry