| Current Path : /proc/3/root/proc/self/root/scripts/ |
| Current File : //proc/3/root/proc/self/root/scripts/getremotecpmove |
#!/usr/local/cpanel/3rdparty/bin/perl
# Copyright 2026 WebPros International, LLC
# All rights reserved.
# copyright@cpanel.net http://cpanel.net
# This code is subject to the cPanel license. Unauthorized copying is prohibited.
package scripts::getremotecpmove;
use cPstrict;
no warnings; ## no critic qw(ProhibitNoWarnings)
use Socket ();
use Cpanel::Carp ();
use Cpanel::Encoder::Tiny ();
use Cpanel::Encoder::URI ();
use Cpanel::MD5 ();
use Cpanel::FileUtils::Open ();
use Cpanel::Filesys::Home ();
use Cpanel::Locale ();
use Cpanel::Rand::Get ();
use Cpanel::RemoteAPI::cPanel ();
use Cpanel::Version::Compare ();
local $| = 1;
my $locale = Cpanel::Locale->get_handle();
__PACKAGE__->script(@ARGV) unless caller;
sub script {
my ( $self, @args ) = @_;
chdir("/usr/local/cpanel/scripts");
my $host = $args[0];
my $user = $args[1];
$host =~ s/\///g;
$user =~ s/\///g;
$host =~ s/\.\.//g;
$user =~ s/\.\.//g;
my $pass = <STDIN>;
$pass =~ s/\n//g;
$host = "[$host]" if $host =~ tr{:}{};
if ( !length $pass ) {
print $locale->maketext( "This utility requires that the account password be sent over “[_1]”.", 'STDIN' );
exit(1);
}
my $part = Cpanel::Filesys::Home::get_homematch_with_most_free_space() || '/home';
my @PKGDEBUG;
my ( $fetch_ok, $archive_file, $extractdir, $md5sum, $pkgdebug ) = fetch_acct_by_cpanel( 'user' => $user, 'host' => $host, 'pass' => $pass, 'part' => $part );
push @PKGDEBUG, $pkgdebug;
if ( !$fetch_ok ) {
print "Failed to fetch cpmove file via cPanel API.\n";
exit(1);
}
if ($fetch_ok) {
if ($md5sum) {
my $newmd5 = Cpanel::MD5::getmd5sum($archive_file);
if ( $newmd5 eq $md5sum ) {
print "Checksum Matches!\n";
}
else {
print "Checksum Failure [[$newmd5]] [[$md5sum]]…trace information follows…<table width=\"100%\" style=\"border: 1px #000 solid;\"><tr><td><pre>" . join( "\n\n\n", @PKGDEBUG ) . "</pre></td></tr></table>\n\n";
exit(1);
}
}
elsif ( -z $archive_file ) {
print "Checksum Failure: Failed to download account file.\n";
exit(1);
}
print "extract dir name is: $extractdir\n";
print "pkgacctfile is: $archive_file\n";
print "MOVE IS GOOD!\n";
exit(0);
}
else {
print "Failed to fetch account via cpanel and ftp/web\n";
exit(1);
}
}
my $api;
sub _api ( $host, $user, $pass ) {
return $api ||= Cpanel::RemoteAPI::cPanel->new_from_password(
$host,
$user => $pass,
)->disable_tls_verify();
}
sub _can_fullbackup_to_homedir ($api) {
my $MIN_VERSION = '77';
my $version = eval { $api->get_cpanel_version_or_die };
return 0 unless defined $version;
return Cpanel::Version::Compare::compare( $version, '>=', $MIN_VERSION );
}
# Runs before the (potentially hours-long) remote backup so that we don’t
# burn the source’s disk and CPU on a download that’s going to be refused.
# A nonexistent file under “./download/” gets a 404 if we’re authorized to
# be there at all, and a 401/403 if not.
#
# This only ever short-circuits on an explicit refusal. Anything else — a
# transport failure, a proxy or [asis,WAF] rewriting the 404, or a source
# old enough to answer a missing file differently — is not evidence that
# the download would fail, so we fall through and let the download itself
# report. That keeps an unrecognized answer no worse than the behavior
# before this probe existed.
sub _download_is_authorized ($api) {
my $probe_name = 'cpanel-transfer-authz-probe-' . Cpanel::Rand::Get::getranddata(16);
# Cpanel::HTTP::Client throws on a 599/transport failure rather than
# returning it, and _establish_session() dies too. Never let that
# escape, and never print it: the exception phrase embeds the request
# URL, which carries the source’s live “cpsess” token.
my $resp = eval { $api->request_session_document( 'GET', "/download/$probe_name" ) };
return 1 if !$resp;
return 0 if $resp->{'status'} == 401 || $resp->{'status'} == 403;
return 1;
}
# Called only on a failed download, to name the real cause instead of the
# generic HTTP failure. Never mention HTTP Basic: after this change we
# never send it, so it can’t be why the download failed.
#
# Requires an explicitly false “data”, not merely a falsy one. UAPI reports
# a disabled feature as a defined 0, but it also returns success with
# “data” never set in two cases that are not a disabled feature: an
# always-on feature, where Cpanel::API::Features::has_feature() early
# returns before touching “data”, and a feature name it does not recognize,
# which sets it to undef. Reading undef as “disabled” sends the operator to
# change a setting on a server they do not administer, for a download that
# failed for some other reason — a 403 from demo mode, a non-admin team
# user, or a transport error.
sub _explain_download_failure ( $api, $host ) {
my $result = eval { $api->request_uapi( 'Features', 'has_feature', { name => 'filemanager' } ) };
return 0 if !$result || !$result->status();
my $has_feature = $result->data();
if ( defined($has_feature) && !$has_feature ) {
print $locale->maketext( "The account “[_1]” on “[_2]” does not have the “[_3]” feature enabled, which the file download requires.", $api->get_username(), $host, 'filemanager' ) . "\n";
return 1;
}
return 0;
}
# The reason a document fetch failed at the transport layer, or undef if the
# exception does not name one.
#
# Cpanel::HTTP::Client turns HTTP::Tiny's 599 into a
# Cpanel::Exception::HTTP::Network, whose “error” field is HTTP::Tiny's own
# message: “SSL connection failed for <host>: …”, “Could not connect to
# '<host>:<port>': …”, “Timed out while waiting for socket to become ready
# for reading”, “Unexpected end of stream”. Each of those names only the
# host and the port.
#
# The exception itself must never be printed: _default_phrase() interpolates
# get_url_without_password(), which is the entire session URL and so carries
# the source's live “cpsess” token. Report the field instead of the
# exception, and strip a token out of the field anyway, in case a future
# HTTP::Tiny starts naming the URL in its own message.
sub _transport_failure_reason ($err) {
return undef if !ref($err) || !eval { $err->isa('Cpanel::Exception::HTTP::Network') };
my $reason = $err->get('error');
return undef if !defined($reason) || !length($reason);
$reason =~ s{cpsess[0-9]+}{cpsess…}g;
return $reason;
}
# Says why the archive download failed, as precisely as the evidence allows.
#
# The status is the single most useful thing when the request came back, and
# the pre-session implementation reported it. $resp is undef when the
# request threw instead, which is every transport-level failure — an expired
# or mismatched certificate, a stalled link, a source that closed the
# connection mid-archive. Those are the failures that most need a cause, and
# before this script stopped letting the exception propagate to STDERR they
# were the only ones that had one, so redact the token out of the reason
# rather than discarding the reason along with it.
sub _report_download_failure ( $api, $host, $resp, $exception ) {
if ($resp) {
print $locale->maketext( "Cannot download the account archive from “[_1]”: [_2] [_3]", $host, $resp->{'status'}, $resp->{'reason'} ) . "\n";
}
elsif ( my $why = _transport_failure_reason($exception) ) {
print $locale->maketext( "Cannot download the account archive from “[_1]” because the connection failed: [_2]", $host, $why ) . "\n";
}
else {
print $locale->maketext( "Cannot download the account archive from “[_1]” because the connection failed.", $host ) . "\n";
}
return _explain_download_failure( $api, $host );
}
# Flushes and closes the downloaded archive, discarding it on failure.
# Returns the error, or undef if it was written intact.
#
# close() is where the buffered tail is flushed, so a deferred write error
# -- ENOSPC on the last block, most likely, since the destination was chosen
# for having the most free space and has just had a whole archive written to
# it -- surfaces here or not at all. Nothing downstream would catch it:
# _archive_rejection_reason() reads two bytes for the gzip magic, and
# script()'s “-z” test only asks whether the file is non-empty, so a
# truncated archive passes both and is handed to restore as though it were
# complete.
sub _archive_write_failure_reason ( $out_fh, $dest ) {
return undef if close($out_fh);
my $err = $!;
unlink($dest);
return $err;
}
# Returns a reason the response headers describe markup rather than an
# archive, or undef. Shared by the in-stream check, which has only the
# headers, and the post-download check, which also inspects the file, so the
# two cannot drift apart.
sub _markup_content_type_reason ($headers) {
my $type = $headers->{'content-type'};
# HTTP::Tiny collapses a repeated header into an arrayref.
$type = $type->[0] if ref $type eq 'ARRAY';
$type = '' if !defined $type;
return undef if $type !~ m{text/|/html\b|/xhtml|/xml\b}i;
return $locale->maketext( "the remote server sent “[_1]” content", $type );
}
# The archive download's data_callback. Named rather than inline so it can
# be exercised without a live transfer; progress state lives in $state so
# the caller can see, once the request has returned, why the stream was
# rejected.
sub _make_download_callback ( $out_fh, $state ) {
return sub {
my ( $data, $resp ) = @_;
my $headers = $resp->{'headers'} // {};
# Reject markup on the very first chunk rather than after the whole
# body is on disk. A WAF block page or a captive portal can answer
# 200 with an unbounded body, and it is being written to whichever
# home partition had the most free space, so waiting for the
# response to finish means filling that partition first.
if ( !$state->{'checked_type'}++ ) {
if ( my $reason = _markup_content_type_reason($headers) ) {
$state->{'rejection'} = $reason;
# Unwinds through request(); the caller reads “rejection”.
die "the download is not an account archive\n";
}
}
if ( !defined $state->{'cl'} ) {
if ( ( $headers->{'content-length'} // '' ) =~ /^\d+$/ ) {
$state->{'cl'} = $headers->{'content-length'};
}
}
$state->{'bytesread'} += length $data;
$state->{'cc'}++;
if ( $state->{'cc'} == 170 && $state->{'cl'} ) {
my $cl = $state->{'cl'};
my $new_percent = int( ( $state->{'bytesread'} / $cl ) * ( $cl == 1 ? 1 : 100 ) );
if ( $new_percent != ( $state->{'percent'} // 0 ) ) {
$state->{'percent'} = $new_percent;
print "..${new_percent}" . ( $cl == 1 ? '' : '%' ) . "..\n";
}
$state->{'cc'} = 0;
}
print {$out_fh} $data;
return 1;
};
}
# Returns a human-readable reason the downloaded file is not the account
# archive we asked for, or undef if it looks like one. Deliberately
# conservative: it only rejects on positive evidence of the wrong thing, so
# an unfamiliar-but-valid content type never blocks a good transfer.
sub _archive_rejection_reason ( $resp, $path, $backup_file ) {
if ( my $reason = _markup_content_type_reason( $resp->{'headers'} // {} ) ) {
return $reason;
}
# Only .gz archives have a magic number we can rely on here.
return undef if $backup_file !~ m/\.gz\z/;
open my $fh, '<', $path or return undef;
binmode $fh;
my $magic = '';
read( $fh, $magic, 2 );
close $fh;
return undef if $magic eq "\x1f\x8b";
return $locale->maketext("the file is not [asis,gzip]-compressed data");
}
sub fetch_acct_by_cpanel {
my %OPTS = @_;
my $host = $OPTS{'host'};
my $user = $OPTS{'user'};
my $pass = $OPTS{'pass'};
my $filesystem_target_dir = $OPTS{'part'};
print "Trying to fetch cpmove file via cPanel API!\n";
my $api = _api( $host, $user, $pass );
print $locale->maketext("Fetching current backups from remote server …");
my ( $login_ok, $current_resp_data, $current_bck_ref ) = get_current_backups($api);
return 0 if !$login_ok;
print " " . $locale->maketext( "[quant,_1,backup,backups] found.", ( scalar keys %$current_bck_ref ) );
print "\n";
print $locale->maketext(" … done.") . "\n";
foreach my $bck ( keys %$current_bck_ref ) {
if ( $current_bck_ref->{$bck} ) {
print $locale->maketext( "A backup to the file “[_1]” is currently in progress on the remote server.", $bck ) . "\n";
print $locale->maketext("Please wait until it is complete and try again.") . "\n";
exit(1);
}
}
if ( !_download_is_authorized($api) ) {
# Nothing has been downloaded at this point, and no backup has been
# built: say what actually happened rather than reusing the
# download-failure wording.
print $locale->maketext( "The account “[_1]” on “[_2]” is not permitted to download files, which this transfer requires.", $user, $host ) . "\n";
_explain_download_failure( $api, $host );
return 0;
}
print $locale->maketext("Starting the backup …") . "\n";
if ( _can_fullbackup_to_homedir($api) ) {
# start the backup
my $result = $api->request_uapi(
'Backup', 'fullbackup_to_homedir',
{
# If the remote is pre-v88 it’ll just ignore this parameter,
# so we don’t need a version check here.
dbbackup_mysql => 'schema',
# Same situation as “dbbackup_mysql”, but for v94.
homedir => 'skip',
},
);
if ( $result->status() ) {
my $pid = $result->data()->{'pid'};
print "Remote backup started (PID $pid)\n";
}
else {
die "Failed to start backup on $host as $user: " . $result->errors_as_string();
}
}
else {
# “Fileman” is an API1 module: it has no API2 counterpart, so this
# must not go through request_api2().
my $resp = $api->request_api1( 'Fileman', 'fullbackup' );
if ( !$resp->{'event'}{'result'} ) {
my $err = $resp->{'event'}{'reason'} // 'unknown error';
die "Failed to start backup on $host as $user: $err";
}
}
# Having started the backup, we now look for a new cpmove file. The file
# is built in-place. This file will, when it’s finished, be the new
# account archive that we’ll download.
my ( $backup_file, $new_resp_data, $new_bck_ref );
FIND:
for ( 1 .. 10 ) {
print $locale->maketext("Waiting for backup to start …") . "\n";
sleep(5);
print $locale->maketext(" … done.") . "\n";
print $locale->maketext("Checking remote server for backups …");
( $login_ok, $new_resp_data, $new_bck_ref ) = get_current_backups($api);
return 0 if !$login_ok;
print " " . $locale->maketext( "[quant,_1,backup,backups] found.", ( scalar keys %$new_bck_ref ) );
print "\n";
foreach my $back ( keys %{$new_bck_ref} ) {
if ( !exists $current_bck_ref->{$back} ) {
$backup_file = $back;
last FIND;
}
}
}
if ( !$backup_file ) {
print "Failed to retrieve the backup from the remote machine (if a previous backup is in progress you will need to wait until it is complete)!\n";
print "(Trace information follows for initial backups)…<table width=\"100%\" style=\"border: 1px #000 solid;\"><tr><td><pre>" . _convert_response_data_to_trace_html($current_resp_data) . "</pre></td></tr></table>\n";
print "(Trace information follows for backups after request started)…<table width=\"100%\" style=\"border: 1px #000 solid;\"><tr><td><pre>" . _convert_response_data_to_trace_html($new_resp_data) . "</pre></td></tr></table>\n";
return 0;
}
print $locale->maketext( "The remote server is creating the backup file “[_1]”.", $backup_file ) . "\n";
print $locale->maketext("Starting wait cycle for remote backup.") . "\n";
my $bck_ref;
my $MAX_POLL = 1440; # AKA about 24 hours
for my $attempt ( 1 .. $MAX_POLL ) {
print $locale->maketext( "Polling remote server (Attempt [numf,_1]/[numf,_2]) …", $attempt, $MAX_POLL ) . "\n";
( $login_ok, undef, $bck_ref ) = get_current_backups($api);
return 0 if !$login_ok;
if ( exists $bck_ref->{$backup_file} ) {
if ( !$bck_ref->{$backup_file} ) {
last;
}
else {
print $locale->maketext( "The backup file, [_1], is still being generated on the remote server “[_2]”.", $backup_file, $host ) . "\n";
print "…60…\n";
sleep(15);
print "…45…\n";
sleep(15);
}
}
else {
print $locale->maketext( "The backup file “[_1]” unexpectedly disappeared from the remote server “[_2]”.", $backup_file, $host ) . "\n";
return 0;
}
print "…30…\n";
sleep(15);
print "…15…\n";
sleep(15);
}
print $locale->maketext( "Downloading “[_1]” …", $backup_file ) . "\n";
chdir($filesystem_target_dir) || return 0;
my $now = time();
my $out_fh;
my $dest = "cpmove-$user-$now.tmp";
if ( !Cpanel::FileUtils::Open::sysopen_with_real_perms( $out_fh, $dest, 'O_WRONLY|O_TRUNC|O_CREAT', 0600 ) ) {
print "Could not open output file, “$dest” for download.\n";
return 0;
}
my %state;
my $resp = eval {
$api->request_session_document(
'GET',
"/download/$backup_file",
{ data_callback => _make_download_callback( $out_fh, \%state ) },
);
};
my $exception = $@;
# The stream was markup, and the callback stopped it partway through.
if ( my $reason = $state{'rejection'} ) {
close($out_fh);
unlink($dest);
print $locale->maketext( "The download from “[_1]” is not an account archive: [_2]", $host, $reason ) . "\n";
return 0;
}
if ( !$resp || !$resp->{'success'} ) {
# The partial .tmp is worthless once the transfer failed, and the
# caller returns to script() which never learns about it.
close($out_fh);
unlink($dest);
_report_download_failure( $api, $host, $resp, $exception );
return 0;
}
if ( my $err = _archive_write_failure_reason( $out_fh, $dest ) ) {
print $locale->maketext( "Cannot write the account archive from “[_1]” to disk: [_2]", $host, $err ) . "\n";
return 0;
}
# A 2xx carrying markup is not an archive: a proxy interstitial, a WAF
# block page, a captive portal, or a redirect chain that ended at a
# login form. Without this the HTML lands in the .tmp, gets renamed to
# cpmove-$user-$now.tar.gz, passes the “-z” check in script() because it
# is not empty, and is handed to restore as though it were an account.
#
# The callback already rejected an unmistakably textual content type on
# the first chunk, so what is left for this check is the rest: the
# magic-number test, which needs the finished file, and a body whose
# content type only became available at the end. Both checks are
# required, and neither replaces the other —
# HTTP::Tiny::_prepare_data_cb() replaces the caller's callback with its
# own buffering closure whenever the status is not 2xx, and _request()
# suppresses it during redirects, so a callback-only guard would never
# see anything but a final 2xx.
if ( my $reason = _archive_rejection_reason( $resp, $dest, $backup_file ) ) {
print $locale->maketext( "The download from “[_1]” is not an account archive: [_2]", $host, $reason ) . "\n";
unlink($dest);
return 0;
}
print " … done.\n";
my $extractdir = $backup_file;
$extractdir =~ s/(\.tar)?(\.gz)?$//g;
# We are chdired to $filesystem_target_dir at this point
system( '/bin/mv', '-f', '--', $dest, "cpmove-$user-$now.tar.gz" );
return ( 1, "$filesystem_target_dir/cpmove-$user-$now.tar.gz", $extractdir, '', '' );
}
sub get_current_backups ($api) {
#look for backups
my %CURRENT_BACKUPS;
my $resp = $api->request_api2( 'Backups', 'listfullbackups' );
if ( my $err = $resp->{'error'} ) {
my $hostname = $api->get_hostname();
print Cpanel::Encoder::Tiny::safe_html_encode_str("cPanel login on $hostname failed: $err");
return ( 0, [], {} );
}
for my $item_hr ( $resp->{'data'}->@* ) {
my $is_in_progress = $item_hr->{'status'} =~ m<progress>i;
$CURRENT_BACKUPS{ $item_hr->{'file'} } = $is_in_progress ? 1 : 0;
}
return ( 1, $resp->{'data'}, \%CURRENT_BACKUPS );
}
# NOTE: This function is pulled from Cpanel::Backups::listfullbackups and is used to preserve
# pre-existing functionality which would dump the cpapi1 HTML response as part of the
# trace information when the script failed to retrieve a backup file from the remote server
sub _convert_response_data_to_trace_html ($response_data) {
my $html;
foreach my $bck_ref (@$response_data) {
my $html_safe_file = Cpanel::Encoder::Tiny::safe_html_encode_str( $bck_ref->{'file'} );
my $uri_safe_file = Cpanel::Encoder::URI::uri_encode_str( $bck_ref->{'file'} );
if ( $bck_ref->{'status'} eq 'complete' ) {
$html .= qq(<div class="okmsg"><b><a href="$ENV{'cp_security_token'}/download?file=$uri_safe_file">$html_safe_file</a></b> ($bck_ref->{'localtime'})<br /></div>\n);
}
elsif ( $bck_ref->{'status'} eq 'inprogress' ) {
$html .= qq(<div class="warningmsg">$html_safe_file ($bck_ref->{'localtime'}) [in progress]<br /></div>\n);
}
else {
$html .= qq(<div class="errormsg">$html_safe_file ($bck_ref->{'localtime'}) [failed, timeout]<br /></div>\n);
}
}
return $html;
}
1;