Three non-blocking findings from the re-review of this branch. No design change:
the extension's fail-open-absolute invariant is untouched (still zero error
emitters, every RINIT return is SUCCESS) and both RINIT guards stay pure
narrowing.
1. entrypoint-lsphp.sh: 99-user-opcache.ini was still emitted unquoted
-------------------------------------------------------------------
Twenty-five lines below the mapping fix, the opcache override block
interpolated the raw env into an unquoted `echo` — the same injection class
the mapping fix closed. Measured on this branch's image, before this commit:
OPCACHE_MEMORY_MB=$'128\nprecision = 7\n; '
-> 99-user-opcache.ini gained a `precision = 7` line
-> lsphp -i reported precision => 7 => 7
WHP casts (int) and clamps 32-512 / 2000-32000 (site-pool-env.php), so this
is not exploitable today — but "the panel validates it" is precisely the
argument this branch already rejected for `domain`, and the panel is a
different repo on a different release cadence. Both siblings in the block are
now validated at the point of use (digits only, length-capped, range-checked)
and emitted double-quoted. A rejected value is dropped with a WARNING and the
image default applies; nothing here is ever fatal.
The accepted ranges are PHP's own limits for these directives (>= 8 MB;
[200, 1000000] files), deliberately a strict SUPERSET of the panel's clamps,
so widening a panel clamp later cannot start silently rejecting real sites.
The block now also removes a stale fragment when it has nothing valid to
write: the container filesystem outlives `docker restart`, so without that an
override that is later cleared — or rejected — would keep applying from the
previous boot's file.
2. 99-user-error-log.ini was written from an unvetted $user
--------------------------------------------------------
It was emitted before the INI_TOKENS_OK branch. Contained in practice (a
newline is inert inside the quotes, and a `${`-bearing user cannot exist
because useradd would have failed under `set -euo pipefail`), but "this
particular unvetted value happens to be contained" is the reasoning this
branch rejected one screenful up. Now gated identically.
Costs a rejected user nothing it needs: `log_errors = On` is already baked in
by 99-prod-overrides.ini, so PHP still logs — to stderr, i.e. `docker logs`,
which is more visible than a per-site file, not less. Verified fleet-wide
that no legitimate user reaches the branch (30 shared_ols sites, 4 hosts).
3. MINFO reported "active" for mappings RINIT ignores
---------------------------------------------------
The absolute-path guard was added to RINIT and MINFO kept testing only "both
values non-empty", so:
from=mnt/users/bob/site.com (relative -> INERT since the guard landed)
lsphp -i -> Rewriting => active
That row is what the post-deploy fleet canary greps to confirm parity is live,
so the diagnostic would have masked exactly the failure the canary exists to
find — and the C comment added by this branch documents it as the only runtime
signal. RINIT and MINFO now share one predicate pair
(cacpp_mapping_configured / cacpp_mapping_active) rather than two longhand
copies, which is what drifted. MINFO now distinguishes "inactive (mapping not
absolute)" from "inactive (unconfigured)" — different operational problems.
Pure reporting change: the predicates are side-effect-free and cannot fail, so
MINFO gains no error path.
Tests: two new .phpt cover both directions of the MINFO fix (009 relative
mapping must report inactive, 010 well-formed mapping must still report active),
so tightening it cannot overshoot into the opposite lie. The build gate's
EXPECTED count is derived from `ls tests/*.phpt`, so it picked them up: 10/10.
Non-vacuity, all five demonstrated by mutation:
- opcache quoting reverted -> injection lands, `precision => 7` observed
- error-log gate removed -> fragment written from the unvetted user
- MINFO reverted to non-empty -> 009 FAILS, build gate exits 1
- MINFO forced always-inactive -> 010 FAILS, build gate exits 1
- all restored -> 10/10, build exit 0
Cloud Apache Container
This is a base container for running PHP-based applications, supporting multiple PHP versions (7.4, 8.0, 8.1, 8.2, 8.3, 8.4). The default is PHP 8.3. The container is based on AlmaLinux 9 and uses Apache with mod_ssl. It is designed for both development and production use.
You must have Docker or compatible containerization software running.
What's New?
- Optimized Image: The Dockerfile has been refactored for smaller size, faster builds, and improved security. Unnecessary files and caches are removed during build.
- Pre-built Images for Each PHP Version: On every push, images for all supported PHP versions are built and pushed to the registry. You can pull the exact version you need (e.g.,
cac:php74,cac:php84, orcac:latest). - .dockerignore Added: The build context is now minimized, making builds faster and more secure.
Quick Start: Local Development with local-dev.sh
The easiest way to start a local development environment is with the provided local-dev.sh script. This script automates container setup, volume creation, log directories, and WordPress installation.
Usage Example
./local-dev.sh -n local-dev
Flags:
-nName of the container (required)-pHTTP port (default: 80)-sHTTPS port (default: 443)-rRoot path for files and database (default: current directory)-aPHP version (default: 8.3; options: 74, 80, 81, 82, 83, 84)-vEnable verbose mode-hShow help
The script will:
- Create a user directory and log folders
- Create a Docker volume for MySQL
- Start the container with the correct environment variables
- Generate helper scripts in your root path:
instance_start– Start the containerinstance_stop– Stop the containerinstance_logs– Tail Apache logsinstance_db_info– Show MySQL credentials
- Install WordPress in your web root
- Print MySQL credentials
Manual Docker Usage
You can also run the container manually:
mkdir -p local-development/domain.tld
cd local-development/domain.tld
mkdir user
mkdir -p user/logs/{apache,system}
docker run -d -it -p 80:80 -p 443:443 -e PHPVER=84 -e environment=DEV --mount type=bind,source="$(pwd)"/user,target=/home/myuser -v"$name-mysql":/var/lib/mysql -e uid=30001 -e user=myuser -e domain=localhost --name local-dev repo.anhonesthost.net/cloud-hosting-platform/cac:latest
Accessing the Container
docker exec -it local-dev /bin/bash
WordPress Installation
If using local-dev.sh, WordPress is installed automatically. For manual setup:
cat /home/myuser/mysql_creds
su - myuser
cd ~/public_html
wp core download
Then visit https://localhost (accept the SSL warning) to complete setup.
Features
- Multiple PHP Versions: 7.4, 8.0, 8.1, 8.2, 8.3, 8.4 (set with
PHPVERor-aflag) - Pre-built Images: Pull the image for your desired PHP version directly from the registry. No need to build locally unless customizing.
- Optimized Build: Smaller, faster, and more secure images thanks to the improved Dockerfile and
.dockerignore. - Automatic Database Setup: MariaDB is started in DEV mode, credentials are auto-generated and stored in
/home/$user/mysql_creds. - Database Backups: Cron job backs up the database every 15 minutes to
/home/$user/_db_backups. - Log Management: Log rotation compresses logs older than 3 days and deletes those older than 7 days.
- Memcached: Started automatically in DEV mode.
- SSL: Self-signed certificate enabled by default.
- Default Web Content:
/home/$user/public_htmlis the web root./pingendpoint andphpinfo.phpare available for diagnostics. - Helper Scripts:
instance_start,instance_stop,instance_logs,instance_db_info(created bylocal-dev.sh).
Environment Variables
Required:
uid– User ID for file permissionsuser– Username for file permissionsdomain– Primary domain for configuration
Optional:
environment– Set toDEVto start memcached and MySQL locally for developmentserveralias– Comma-separated list of alternative hostnamesPHPVER– PHP version (see above)
Helpful Notes
- To restart the instance:
./instance_startordocker start {container-name} - To stop:
./instance_stopordocker stop {container-name} - To view logs:
./instance_logsordocker logs -f {container-name} - To get DB credentials:
./instance_db_infoorcat /home/$user/mysql_creds - To delete a container:
docker rm {container-name}(does not delete user files or DB volume) - To view running containers:
docker ps - To view all containers:
docker ps --all - To view images:
docker images
Troubleshooting
- The first run may take several minutes as dependencies are installed.
- If you need to change PHP version, stop and remove the container, then recreate with the desired version.
- For advanced configuration, see the scripts in the
scripts/directory. - The image is optimized for size and speed, but local development in DEV mode may install additional packages (MariaDB, memcached) at runtime using microdnf.
- The build context is minimized by the included
.dockerignorefile.