d(・ω・d) 微分!(∫・ω・)∫ 積分!∂(・ω・∂) 偏微分!(∮・ω・)∮ 沿閉曲線的積分!(∬・ω・)∬ 重積分!∇(・ω・∇)梯度!∇・(・ω・∇・)散度!∇×(・ω・∇×)旋度!Δ(・ω・Δ)拉普拉斯!#゚Å゚)⊂彡☆))゚Д゚)・∵ლ(◉◞౪◟◉ )ლ千言萬語,不如一個「表情符號(emoji)」簡單生動又有趣!ಠ▃ಠ生氣、-`д´-憤怒、(¬_¬)無言、(•͈⌔•͈⑅)傷心、哭、開心、大笑、可愛、困惑、發呆、大眼睛、驚呀、跳舞、興奮、奔跑..≧Д≦ (;≧皿≦) (⁎˃ᆺ˂) ╬ Ò ‸ Ó) <(`^´)> ( >д<) (ꐦ ಠ皿ಠ ) (`Д´) (;`O´)o o(-`д´- 。) ( ˃⌂˂ ) (°ㅂ° ╬) (ʘ言ʘ╬) (Ò 皿 Ó ╬) (-`д´-) 눈_눈 (⋋▂⋌) (¬▂¬) ಠ▃ಠ (>x<) ╰(‵□′)╯
| Current Path : /lib/systemd/system/ |
| Current File : //lib/systemd/system/ssa-agent.socket |
[Unit] Description=PHP Cloudlinux SSA Agent Socket PartOf=ssa-agent.service [Socket] ListenStream=/opt/alt/clos_ssa/run/ssa.sock # SocketMode=0666 is intentional: the socket must be writable by PHP # processes running under any web server (Apache, LiteSpeed, Nginx) # across all supported panels (cPanel, Plesk, DirectAdmin). # Restricting via SocketGroup is not feasible because the group owning # PHP workers differs per panel and web server combination. # Input validation in agent.py _validate_input() limits accepted payloads # to the exact format produced by the C extension (7 fields with strict # types). The world-writable mode does NOT by itself prevent cross-tenant # metric spoofing; that guard lives in the authorization layer, not the # socket ACL. SimpleAgent._authorize_sender() uses the kernel-trusted # SO_PEERCRED UID together with the reported domain's PHP handler to fail # CLOSED when a shared or service peer (nobody/apache, webapps, an unmapped # UID) reports a per-user tenant's domain it does not own. Residual by # design: a victim domain served under a shared handler (DSO/mod_php/Plesk # module), or a panel whose handler API is unavailable (get_domains_php_info # raises, e.g. InterWorx/ispmanager), cannot be told apart from legitimate # shared-UID self-telemetry and is accepted. See # docs/design/ssa-agent-socket.md. SocketMode=0666 Backlog=2048 [Install] WantedBy=sockets.target