File: //proc/self/root/opt/alt/python37/lib/python3.7/site-packages/cl_proc_hidepid.py
# -*- coding: utf-8 -*-
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2019 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENSE.TXT
# Module contains functions for remounting /proc with hidepid=2 option
# see CAG-796 for details
from __future__ import print_function
from __future__ import absolute_import
import subprocess
from clcommon.sysctl import SysCtlConf, SYSCTL_CL_CONF_FILE
def hidepid_found():
"""
Search for line like "proc /proc proc defaults,hidepid=2,gid=clsupergid 0 0" in /etc/fstab
Return True if /proc is mounted with hidepid option in /etc/fstab
"""
fstab = '/etc/fstab'
try:
with open(fstab, 'r') as f:
for line in f:
line = line.strip()
if line and not line.startswith('#'):
splitted_line = line.split()
if splitted_line and splitted_line[0] == 'proc' and 'hidepid=' in splitted_line[3]:
return True
except (IOError, IndexError) as e:
print('Error: failed to parse', fstab, ':', str(e))
return False
def execute(cmd, verbose):
if verbose:
print('executing', ' '.join(cmd))
return subprocess.call(cmd)
def remount_proc(verbose=False):
"""
Remount /proc with hidepid=2 option when needed
"""
sysctl = SysCtlConf(config_file=SYSCTL_CL_CONF_FILE)
if verbose:
print('apply sysctl settings')
if hidepid_found():
# admin can override hidepid option via /etc/fstab
if verbose:
print('hidepid option is found in /etc/fstab - remounting /proc with options from /etc/fstab')
return execute(['/bin/mount', '-o', 'remount', '/proc'], verbose)
proc_can_see_other_uid = sysctl.get('fs.proc_can_see_other_uid')
super_gid = sysctl.get('fs.proc_super_gid')
if proc_can_see_other_uid != '0':
if verbose:
print('virtualized procfs feature is not enabled in sysctl conf - disable hidepid')
return execute(['/bin/mount', '-o', 'remount,hidepid=0,gid=0', '/proc'], verbose)
if verbose:
print('enable hidepid for /proc')
return execute(['/bin/mount', '-o', 'remount,hidepid=2,gid='+super_gid, '/proc'], verbose)