/usr/lib/systemd/system
NameSizeModeActions
basic.target.wants/-0755rm
dbus.target.wants/-0755rm
default.target.wants/-0755rm
graphical.target.wants/-0755rm
halt.target.wants/-0755rm
initrd-switch-root.target.wants/-0755rm
initrd.target.wants/-0755rm
kexec.target.wants/-0755rm
local-fs.target.wants/-0755rm
mariadb@bootstrap.service.d/-0755rm
multi-user.target.wants/-0755rm
poweroff.target.wants/-0755rm
reboot.target.wants/-0755rm
remote-fs.target.wants/-0755rm
rescue.target.wants/-0755rm
runlevel1.target.wants/-0755rm
runlevel2.target.wants/-0755rm
runlevel3.target.wants/-0755rm
runlevel4.target.wants/-0755rm
runlevel5.target.wants/-0755rm
sockets.target.wants/-0755rm
sysinit.target.wants/-0755rm
syslog.target.wants/-0755rm
system-update.target.wants/-0755rm
systemd-logind.service.d/-0755rm
systemd-udev-trigger.service.d/-0755rm
timers.target.wants/-0755rm
user-.slice.d/-0755rm
80-nydus-svcs-enable.preset520644editdlrm
acpid.service2490644editdlrm
acpid.socket1460644editdlrm
aibolit-resident.service9470644editdlrm
aibolit-resident.socket2830644editdlrm
alloy.service5560644editdlrm
alt-php54-fpm.service2940644editdlrm
alt-php56-fpm.service2910644editdlrm
alt-php70-fpm.service2910644editdlrm
alt-php70-newrelic-daemon.service3620644editdlrm
alt-php71-fpm.service2930644editdlrm
alt-php71-newrelic-daemon.service3620644editdlrm
alt-php72-fpm.service2930644editdlrm
alt-php72-newrelic-daemon.service3620644editdlrm
alt-php73-fpm.service2930644editdlrm
alt-php73-newrelic-daemon.service3620644editdlrm
alt-php74-fpm.service2930644editdlrm
alt-php74-newrelic-daemon.service3620644editdlrm
alt-php80-fpm.service2930644editdlrm
alt-php80-newrelic-daemon.service3620644editdlrm
alt-php81-fpm.service2930644editdlrm
alt-php81-newrelic-daemon.service3620644editdlrm
alt-php82-fpm.service2930644editdlrm
alt-php82-newrelic-daemon.service3620644editdlrm
alt-php83-fpm.service2930644editdlrm
alt-php83-newrelic-daemon.service3620644editdlrm
alt-php84-fpm.service2930644editdlrm
alt-php84-newrelic-daemon.service3620644editdlrm
alt-php85-fpm.service2930644editdlrm
arp-ethers.service2750644editdlrm
atd.service2220644editdlrm
auditd.service18520644editdlrm
auth-rpcgss-module.service6280644editdlrm
autovt@.service19750644editdlrm
bagent.service4790644editdlrm
basic.target9560644editdlrm
bluetooth.target4190644editdlrm
boot-complete.target4550644editdlrm
cagefs.service7050644editdlrm
chrony-dnssrv@.service2090644editdlrm
chrony-dnssrv@.timer1380644editdlrm
chrony-wait.service5000644editdlrm
chronyd.service5510644editdlrm
cloud-config.service5550644editdlrm
cloud-config.target8830644editdlrm
cloud-final.service7650644editdlrm
cloud-init-hotplugd.service9930644editdlrm
cloud-init-hotplugd.socket4020644editdlrm
cloud-init-local.service8550644editdlrm
cloud-init.service7020644editdlrm
cloud-init.target5170644editdlrm
conntrackd.service3800644editdlrm
console-getty.service10820644editdlrm
container-getty@.service12630644editdlrm
cpupower.service2940644editdlrm
criu.service3160644editdlrm
criu.socket1600644editdlrm
crond.service3560644editdlrm
cryptsetup-pre.target4650644editdlrm
cryptsetup.target4120644editdlrm
ctrl-alt-del.target5830644editdlrm
cyberark-epm.service6060644editdlrm
dbus-org.freedesktop.hostname1.service11020644editdlrm
dbus-org.freedesktop.locale1.service10710644editdlrm
dbus-org.freedesktop.login1.service13830644editdlrm
dbus-org.freedesktop.portable1.service9870644editdlrm
dbus-org.freedesktop.timedate1.service10420644editdlrm
dbus.service3800644editdlrm
dbus.socket1020644editdlrm
db_governor.service5360644editdlrm
debug-shell.service10550644editdlrm
default.target5980644editdlrm
dev-hugepages.mount7500644editdlrm
dev-mqueue.mount6650644editdlrm
dnf-makecache.service4570644editdlrm
dnf-makecache.timer3200644editdlrm
dnf-system-upgrade-cleanup.service3220644editdlrm
dnf-system-upgrade.service6010644editdlrm
dracut-cmdline.service9040644editdlrm
dracut-initqueue.service8210644editdlrm
dracut-mount.service7930644editdlrm
dracut-pre-mount.service8220644editdlrm
dracut-pre-pivot.service11250644editdlrm
dracut-pre-trigger.service9140644editdlrm
dracut-pre-udev.service9930644editdlrm
dracut-shutdown-onfailure.service3090644editdlrm
dracut-shutdown.service4400644editdlrm
emergency.service8010644editdlrm
emergency.target4710644editdlrm
exim_queue_prom.service1660644editdlrm
exim_queue_prom.timer2320644editdlrm
exit.target5410644editdlrm
final.target4800644editdlrm
firebird.service2660644editdlrm
fstrim.service960644editdlrm
fstrim.timer2290644editdlrm
gd-fluent-bit.service4060644editdlrm
getty-pre.target5060644editdlrm
getty.target5000644editdlrm
getty@.service19750644editdlrm
governor_sentry_daemon.service3190644editdlrm
graphical.target5980644editdlrm
grub-boot-indeterminate.service2630644editdlrm
gssproxy.service4660644editdlrm
halt-local.service6050644editdlrm
halt.target5270644editdlrm
haproxy.service13430644editdlrm
haveged-switch-root.service3700644editdlrm
haveged.service9720644editdlrm
hibernate.target5090644editdlrm
htcacheclean.service3870644editdlrm
httpd.service6080644editdlrm
hybrid-sleep.target5300644editdlrm
icinga2.service11090644editdlrm
illumio-ven.service4910644editdlrm
import-state.service4410644editdlrm
imunify-agent-proxy.service8160644editdlrm
imunify-agent-proxy.socket2180644editdlrm
imunify-antivirus-sensor.socket6330644editdlrm
imunify-antivirus-user.socket6260644editdlrm
imunify-antivirus.service38430644editdlrm
imunify-antivirus.socket3120644editdlrm
imunify-auditd-log-reader.service4430644editdlrm
imunify-notifier.service3880644editdlrm
imunify-notifier.socket1890644editdlrm
imunify-realtime-av.service4260644editdlrm
imunify360-agent-user.socket6310644editdlrm
imunify360-agent.service46790644editdlrm
imunify360-agent.socket3180644editdlrm
imunify360-dos-protection.service14930644editdlrm
imunify360-pam.service4940644editdlrm
imunify360-pam.socket2330644editdlrm
imunify360-php-daemon.service3900644editdlrm
imunify360-php-daemon.socket2850644editdlrm
imunify360-pure.service2660644editdlrm
imunify360-resource-unlock@.service2760644editdlrm
imunify360-resource-unlock@.timer1750644editdlrm
imunify360-scanlogd.service3420644editdlrm
imunify360-unified-access-logger.service4020644editdlrm
imunify360-wafd.service4750644editdlrm
imunify360-webshield-ssl-cache.service9590644editdlrm
imunify360-webshield.service12780644editdlrm
imunify360.service94990644editdlrm
initrd-cleanup.service6740644editdlrm
initrd-fs.target5930644editdlrm
initrd-parse-etc.service8420644editdlrm
initrd-root-device.target5610644editdlrm
initrd-root-fs.target5660644editdlrm
initrd-switch-root.service5930644editdlrm
initrd-switch-root.target7770644editdlrm
initrd-udevadm-cleanup-db.service7080644editdlrm
initrd.target7630644editdlrm
iprdump.service1840644editdlrm
iprinit.service1430644editdlrm
iprupdate.service1470644editdlrm
iprutils.target1730644editdlrm
irqbalance.service4750644editdlrm
kcare.service8370644editdlrm
kdump.service3880644editdlrm
kexec.target5410644editdlrm
kmod-static-nodes.service7210644editdlrm
kvm_stat.service3680644editdlrm
ldconfig.service6870644editdlrm
libcare-autostart.service2570644editdlrm
libcare.service8720644editdlrm
libcare.socket2050644editdlrm
loadmodules.service3550644editdlrm
local-fs-pre.target4350644editdlrm
local-fs.target5470644editdlrm
lsapi-cache.service3010644editdlrm
lve.service4650644editdlrm
lvectl.service4970644editdlrm
lvemanager.service3110644editdlrm
lvestats-burstwatcher-config.service5010444editdlrm
lvestats-burstwatcher.service4000444editdlrm
lvestats.service3980444editdlrm
lve_namespaces.service4160644editdlrm
man-db-cache-update.service3580644editdlrm
man-db-restart-cache-update.service3010644editdlrm
mariadb-extra.socket5270644editdlrm
mariadb-extra@.socket5540644editdlrm
mariadb.service58120644editdlrm
mariadb.socket6090644editdlrm
mariadb@.service99400644editdlrm
mariadb@.socket6160644editdlrm
messagebus.service3800644editdlrm
microcode.service2840644editdlrm
mlocate-updatedb.service2310644editdlrm
mlocate-updatedb.timer1460644editdlrm
multi-user.target5320644editdlrm
mysql.service58120644editdlrm
mysqld.service58120644editdlrm
named-setup-rndc.service1210644editdlrm
named.service8590644editdlrm
netconsole.service3360644editdlrm
netstatinput_prom.service1700644editdlrm
netstatinput_prom.timer2360644editdlrm
network-online.target5050644editdlrm
network-pre.target5020644editdlrm
network.target5210644editdlrm
NetworkManager-dispatcher.service6410644editdlrm
NetworkManager-wait-online.service11480644editdlrm
NetworkManager.service13510644editdlrm
nfs-blkmap.service2950644editdlrm
nfs-client.target4130644editdlrm
nfs-convert.service6080644editdlrm
nfs-idmapd.service2220644editdlrm
nfs-mountd.service2870644editdlrm
nfs-server.service9780644editdlrm
nfs-utils.service5670644editdlrm
nfsdcld.service2360644editdlrm
nftables.service3930644editdlrm
nis-domainname.service3780644editdlrm
nscd.service5120644editdlrm
nscd.socket1330644editdlrm
nss-lookup.target5540644editdlrm
nss-user-lookup.target5130644editdlrm
nydus-ex-api.service2590644editdlrm
nydus-ex.service2490644editdlrm
ossec-hids-authd.service2210644editdlrm
ossec-hids-hybrid.service3530644editdlrm
ossec-hids.service3410644editdlrm
paths.target3940644editdlrm
plymouth-halt.service4180644editdlrm
plymouth-kexec.service4180644editdlrm
plymouth-poweroff.service4270644editdlrm
plymouth-quit-wait.service2240644editdlrm
plymouth-quit.service2180644editdlrm
plymouth-read-write.service2680644editdlrm
plymouth-reboot.service4200644editdlrm
plymouth-start.service5630644editdlrm
plymouth-switch-root-initramfs.service3720644editdlrm
plymouth-switch-root.service3150644editdlrm
polkit.service1720644editdlrm
poweroff.target5920644editdlrm
printer.target4170644editdlrm
proc-fs-nfsd.mount980644editdlrm
proc-sys-fs-binfmt_misc.automount7450644editdlrm
proc-sys-fs-binfmt_misc.mount6550644editdlrm
proxyexecd.service3530644editdlrm
puppet.service9240644editdlrm
qemu-guest-agent.service5220644editdlrm
qualys-cloud-agent.service3660644editdlrm
quotaon.service6170644editdlrm
rc-local.service7710644editdlrm
rdisc.service2080644editdlrm
reboot.target5830644editdlrm
remote-cryptsetup.target5490644editdlrm
remote-fs-pre.target4360644editdlrm
remote-fs.target5220644editdlrm
rescue.service7920644editdlrm
rescue.target4920644editdlrm
rhnsd.service1780644editdlrm
rhnsd.timer1310644editdlrm
rpc-gssd.service2810644editdlrm
rpc-statd-notify.service3870644editdlrm
rpc-statd.service4140644editdlrm
rpcbind.service5440644editdlrm
rpcbind.socket3680644editdlrm
rpcbind.target5400644editdlrm
rpc_pipefs.target800644editdlrm
rrdcached.service3760644editdlrm
rrdcached.socket3120644editdlrm
rsyslog.service9600644editdlrm
runlevel0.target5920644editdlrm
runlevel1.target4920644editdlrm
runlevel2.target5320644editdlrm
runlevel3.target5320644editdlrm
runlevel4.target5320644editdlrm
runlevel5.target5980644editdlrm
runlevel6.target5830644editdlrm
saslauthd.service2740644editdlrm
selinux-autorelabel-mark.service4060644editdlrm
selinux-autorelabel.service3010644editdlrm
selinux-autorelabel.target2300644editdlrm
sentinelone.service8630644editdlrm
serial-getty@.service14860644editdlrm
shutdown.target4420644editdlrm
sigpwr.target4020644editdlrm
sleep.target4600644editdlrm
slices.target4490644editdlrm
smartcard.target4200644editdlrm
smartd.service3290644editdlrm
sockets.target3960644editdlrm
sound.target4200644editdlrm
ssa-agent.service18740644editdlrm
ssa-agent.socket14160644editdlrm
sshd-keygen.target1230644editdlrm
sshd-keygen@.service2470644editdlrm
sshd.service4560644editdlrm
sshd.socket1810644editdlrm
sshd@.service3420644editdlrm
suspend-then-hibernate.target5770644editdlrm
suspend.target5030644editdlrm
swap.target3930644editdlrm
sys-fs-fuse-connections.mount7950644editdlrm
sys-kernel-config.mount7670644editdlrm
sys-kernel-debug.mount7100644editdlrm
sysinit.target5580644editdlrm
syslog.socket14070644editdlrm
sysstat-collect.service3890644editdlrm
sysstat-collect.timer3250644editdlrm
sysstat-summary.service3690644editdlrm
sysstat-summary.timer3560644editdlrm
sysstat.service4750644editdlrm
system-update-cleanup.service14150644editdlrm
system-update-pre.target5430644editdlrm
system-update.target6170644editdlrm
systemd-ask-password-console.path7040644editdlrm
systemd-ask-password-console.service7280644editdlrm
systemd-ask-password-plymouth.path4540644editdlrm
systemd-ask-password-plymouth.service4350644editdlrm
systemd-ask-password-wall.path6320644editdlrm
systemd-ask-password-wall.service7600644editdlrm
systemd-backlight@.service7600644editdlrm
systemd-binfmt.service10930644editdlrm
systemd-coredump.socket5370644editdlrm
systemd-coredump@.service11040644editdlrm
systemd-exit.service4940644editdlrm
systemd-firstboot.service7990644editdlrm
systemd-fsck-root.service6180644editdlrm
systemd-fsck@.service6710644editdlrm
systemd-halt.service5880644editdlrm
systemd-hibernate-resume@.service6750644editdlrm
systemd-hibernate.service5450644editdlrm
systemd-hostnamed.service11020644editdlrm
systemd-hwdb-update.service8260644editdlrm
systemd-hybrid-sleep.service5630644editdlrm
systemd-initctl.service5500644editdlrm
systemd-initctl.socket5460644editdlrm
systemd-journal-catalog-update.service7110644editdlrm
systemd-journal-flush.service8270644editdlrm
systemd-journald-audit.socket6470644editdlrm
systemd-journald-dev-log.socket11300644editdlrm
systemd-journald.service15370644editdlrm
systemd-journald.socket8820644editdlrm
systemd-kexec.service6010644editdlrm
systemd-localed.service10710644editdlrm
systemd-logind.service13830644editdlrm
systemd-machine-id-commit.service7370644editdlrm
systemd-modules-load.service10110644editdlrm
systemd-portabled.service9870644editdlrm
systemd-poweroff.service5560644editdlrm
systemd-pstore.service8400644editdlrm
systemd-quotacheck.service6630644editdlrm
systemd-random-seed.service8000644editdlrm
systemd-reboot.service5510644editdlrm
systemd-remount-fs.service8020644editdlrm
systemd-resolved.service16680644editdlrm
systemd-rfkill.service7280644editdlrm
systemd-rfkill.socket6570644editdlrm
systemd-suspend-then-hibernate.service6000644editdlrm
systemd-suspend.service5410644editdlrm
systemd-sysctl.service6970644editdlrm
systemd-sysusers.service7040644editdlrm
systemd-timedated.service10420644editdlrm
systemd-tmpfiles-clean.service6630644editdlrm
systemd-tmpfiles-clean.timer4900644editdlrm
systemd-tmpfiles-setup-dev.service7710644editdlrm
systemd-tmpfiles-setup.service7510644editdlrm
systemd-udev-settle.service8670644editdlrm
systemd-udev-trigger.service7710644editdlrm
systemd-udevd-control.socket6350644editdlrm
systemd-udevd-kernel.socket6100644editdlrm
systemd-udevd.service10700644editdlrm
systemd-update-done.service6740644editdlrm
systemd-update-utmp-runlevel.service8010644editdlrm
systemd-update-utmp.service8020644editdlrm
systemd-user-sessions.service6360644editdlrm
systemd-vconsole-setup.service6220644editdlrm
systemd-volatile-root.service6940644editdlrm
tcsd.service1280644editdlrm
time-sync.target4350644editdlrm
timedatex.service2380644editdlrm
timers.target4450644editdlrm
tmp.mount7820644editdlrm
tuned.service4390644editdlrm
umount.target4570644editdlrm
unbound-anchor.service2960644editdlrm
unbound-anchor.timer3460644editdlrm
user-runtime-dir@.service6290644editdlrm
user.slice4320644editdlrm
user@.service6710644editdlrm
var-lib-nfs-rpc_pipefs.mount1910644editdlrm
var-lve-dbgovernor\x2dshm.mount2780644editdlrm
venAgentMgr.service2510644editdlrm
venAgentMonitor.service2720644editdlrm
venIPsec.service6910644editdlrm
venPlatformHandler.service4800644editdlrm
venVtapServer.service2510644editdlrm
Edit: /usr/lib/systemd/system/imunify360.service (9499B)
[Unit] Description=Imunify360 resident Before=cagefs.service After=network.target iptables.service firewalld.service systemd-modules-load.service Wants=ossec-hids.service imunify360-php-daemon.service imunify-realtime-av.service imunify-notifier.socket # Service will NOT start if this file exists ConditionPathExists=!/var/lib/rpm-state/imunify360-transaction-in-progress [Service] CPUAccounting=true MemoryAccounting=true BlockIOAccounting=true Slice=Imunify-agent.slice Environment=PROTOCOL_BUFFERS_PYTHON_IMPLEMENTATION=upb Environment=LANG=en_US.UTF-8 Environment=LC_ALL=en_US.UTF-8 Environment=PYTHONNOUSERSITE=1 Environment=IMUNIFY360_LOGGING_PREFIX=r. Environment=SQLITE_TMPDIR=/var/imunify360/tmp Environment=FGW_FS_BASE_DIR=/var/imunify360/gw.dir Environment=FGW_FS_MAX_CONCURRENT_QUEUES=100 # NATS embedded server for cross-component messaging (DEF-39879) Environment=I360_NATS_ENABLED=true Environment=I360_NATS_STORE_DIR=/var/imunify360/nats Environment=I360_NATS_PORT=44222 Environment=I360_NATS_TOKEN_PATH=/var/run/imunify360/nats.token # Manage /var/run/imunify360/ manually instead of using systemd's RuntimeDirectory=. # RuntimeDirectoryPreserve=yes was added in systemd v235 and is silently ignored on # systemd v219 (CloudLinux 7); without preserve, RuntimeDirectory= would delete the # directory on service stop, wiping wafd_imunify_daemon's libiplists-daemon.sock and # breaking webshield until wafd is manually restarted (DEF-41462). Type=notify ExecStartPre=/bin/mkdir -p /var/run/imunify360 ExecStartPre=/bin/chmod 0755 /var/run/imunify360 ExecStartPre=/usr/share/imunify360/scripts/set-service-resources.sh imunify360.service 50 50 ExecStart=/usr/bin/imunify-service ExecStartPost=/bin/bash -c "echo $MAINPID > /var/run/imunify360.pid" ExecStartPost=/bin/systemctl restart imunify360-resource-unlock@imunify360.timer PIDFile=/var/run/imunify360.pid #TODO: must be not less than defence360agent/cli/server.py:stop(seconds=8) TimeoutStartSec=900 TimeoutStopSec=60 Restart=on-failure RestartSec=5 StartLimitInterval=600s StartLimitBurst=5 # Don't send SIGTERM on service stop to remaining processes in cgroup # (SIGKILL on timeout is still sent) KillMode=mixed # NoNewPrivileges=true # CapabilityBoundingSet=CAP_BPF CAP_CHOWN CAP_DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_FOWNER CAP_KILL CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_PERFMON CAP_SETGID CAP_SETUID CAP_SYS_ADMIN CAP_SYS_PTRACE CAP_SYS_RESOURCE # AmbientCapabilities= covers caps subprocesses need as effective. # NoNewPrivileges=true disables the kernel's "raise effective from # permitted on UID-0 exec" path, so without Ambient children run with # effective=empty and fail with EPERM. Why each non-obvious cap is here: # - CAP_NET_RAW: iptables-1.8.5's xt_set extension opens # AF_INET SOCK_RAW IPPROTO_RAW (libxt_set.c:get_version) to probe # ipset; EPERM here is reported as "Can't open socket to ipset". # - CAP_BPF / CAP_PERFMON / CAP_SYS_ADMIN: the agent's Go firewall # stack creates a BPF map (nats_port) via bpf(BPF_MAP_CREATE); # fails with "operation not permitted" without these. # - CAP_SYS_RESOURCE: cagefsctl opens /proc/lve/list to probe the # CloudLinux LVE kernel module before any other operation; the # LVE handler gates that open on CAP_SYS_RESOURCE, and EPERM # there is reported as "Error: current running kernel is NOT # supported" (misleading — the kernel IS supported, the caller # just lacks the cap). Verified by strace + bisect on CL9 + CSF. # - The rest are baseline daemon caps: CHOWN/FOWNER/SETUID/SETGID for # managing per-user file ownership during malware fixes; # DAC_OVERRIDE / DAC_READ_SEARCH for traversing system dirs; # SYS_PTRACE for the agent's own diagnostic helpers. # AmbientCapabilities=CAP_BPF CAP_CHOWN CAP_DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_FOWNER CAP_KILL CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_PERFMON CAP_SETGID CAP_SETUID CAP_SYS_ADMIN CAP_SYS_PTRACE CAP_SYS_RESOURCE # ProtectSystem=true keeps /usr, /boot, /efi read-only. We previously # tried =full (which also locks /etc) but every concrete failure in # this MR's review came from panel-provided tools that the agent # invokes as subprocesses (whmapi, custombuild, server_pref, # rebuildhttpdconf, ie_config, cagefsctl, …) needing to write # somewhere under /etc/. The allowlist for those grew to ~20 entries # and was still racy on fresh installs (companion packages create # their /etc/ dirs after the unit starts; `-` prefix entries are # evaluated at start time and silently skipped). =true gets us out # of the wack-a-mole and still delivers the MR's stated security # goal — preventing privilege escalation — via NoNewPrivileges=true # and CapabilityBoundingSet=. The /etc/* ReadWritePaths= entries # below are now redundant under =true; kept for documentation and # resilience if =true is ever reverted to =full. ProtectSystem=false # ReadWritePaths=/etc/sysconfig/imunify360 # ReadWritePaths=/etc/imunify360 # ReadWritePaths=/etc/imunify-agent-proxy # ReadWritePaths=/etc/cron.d # Optional ('-' prefix): wafd/webshield ship in companion packages and # may not be present at service start (e.g. fresh install); panel # integration dirs only exist on specific distros. # ReadWritePaths=-/etc/imunify360-wafd # ReadWritePaths=-/etc/imunify360-webshield # ReadWritePaths=-/etc/csf # ReadWritePaths=-/etc/httpd/conf.d # ReadWritePaths=-/etc/httpd/conf/plesk.conf.d # ReadWritePaths=-/etc/httpd/conf/extra # ReadWritePaths=-/etc/apache2/conf.d # ReadWritePaths=-/etc/apache2/conf-enabled # ReadWritePaths=-/etc/apache2/plesk.conf.d # ReadWritePaths=-/etc/modsecurity.d # ReadWritePaths=-/etc/yum.repos.d # ReadWritePaths=-/etc/apt/sources.list.d # Additional dirs the agent rewrites at runtime, surfaced by build 523: # - /usr/share/i360-php-opts: proactive-defense PHP-immunity DB # (im360/subsys/proactive.py + i360-storage-replacehdb-v2 helper). # - /etc/httpd/conf/modsecurity.d: Plesk modsec rules (RBL whitelist, # malware-list .tmp tempfiles); sibling of plesk.conf.d, not a child. # - /usr/local/directadmin: DA modsec includes and per-user domain # files rewritten on each sync. # ReadWritePaths=-/usr/share/i360-php-opts # ReadWritePaths=-/etc/httpd/conf/modsecurity.d # ReadWritePaths=-/usr/local/directadmin # Additional cPanel + CageFS dirs surfaced by build 535: # - /usr/local/cpanel: where the cPanel hook installer drops # ImunifyHook.pm. # - /etc/cagefs, /var/cagefs, /usr/share/cagefs, /usr/share/cagefs-skeleton: # rewritten by `cagefsctl --force-update-etc` which the agent's cagefs plugin # spawns; without these the subprocess hangs and the agent's # asyncio cancel surfaces as cascading test setup failures. # /usr/share/cagefs-skeleton is a SEPARATE top-level dir (not under # /usr/share/cagefs); cagefsctl's check_skeleton() does os.chmod() on it, # which raises EROFS under ProtectSystem=. On a CageFS host the resulting # cagefsctl failure makes migration 129_fixed_cagefs_unmount fall back to a # synchronous `systemctl restart cagefs`, which deadlocks against # Before=cagefs.service and hangs agent startup (DEF-47738). # ReadWritePaths=-/usr/local/cpanel # ReadWritePaths=-/etc/cagefs # ReadWritePaths=-/var/cagefs # ReadWritePaths=-/usr/share/cagefs # ReadWritePaths=-/usr/share/cagefs-skeleton # Plesk plugin scripts dir (build 550): the agent installs/updates # /usr/local/psa/admin/plib/modules/imunify360/scripts/ on hooks. # ReadWritePaths=-/usr/local/psa/admin/plib/modules/imunify360 # Plesk runtime state — notification log written by send-notifications.php # (/usr/local/psa/var/modules/imunify360/imunify360-local.log) and the # plesk-sendmail spool/tempfile dir. ProtectSystem=true bind-mounts /usr # read-only and CAP_DAC_OVERRIDE cannot bypass a mount-layer RO, so the # Plesk notification hook fails with EACCES without this entry. # ReadWritePaths=-/usr/local/psa/var # Webuzo keeps Apache (and the modsec audit log) under /usr/local/apps; # the resident-agent's modsec sensor tails that log and persists its read # position to a .filetail.state file beside it. ProtectSystem=true # bind-mounts /usr read-only, so without this the state write fails with EROFS. # ReadWritePaths=-/usr/local/apps # LiteSpeed keeps its config tree under /usr/local/lsws, including the # per-domain .d/modsec.conf files rewritten by the agent's # integration.sh rewrite-domain-configs. ProtectSystem=true makes /usr # read-only, so without this carve-out the per-domain modsec rewrite fails # with EROFS. # ReadWritePaths=-/usr/local/lsws # CSF installs its post-hook script as /usr/local/csf/bin/csfpost.sh (preferred # over /etc/csf/csfpost.sh when present); the ExportWBList plugin rewrites it # on activation. ProtectSystem=true makes /usr read-only, so without this # carve-out the rewrite fails with EROFS. # ReadWritePaths=-/usr/local/csf # PrivateTmp= deliberately not set. Tried =yes in v9.x and reverted: # the agent and several subsystems share /tmp with co-resident # processes — pytest fixtures touch /tmp/sample_enabled to enable # the Sample backup backend (rpm-tests/utils/backups.py), and the # realtime inotify malware scanner watches user-controlled paths # including /tmp on production hosts (PHP session/upload files). # A private /tmp namespace silently hides both. The security goal # of preventing /tmp data leaks is mostly carried by ProtectSystem= # and NoNewPrivileges= already. [Install] WantedBy=multi-user.target