diff --git a/docs/cloudlinuxos/cloudlinux_os_components/README.md b/docs/cloudlinuxos/cloudlinux_os_components/README.md index b461fd831..c49060fcb 100644 --- a/docs/cloudlinuxos/cloudlinux_os_components/README.md +++ b/docs/cloudlinuxos/cloudlinux_os_components/README.md @@ -4351,10 +4351,10 @@ The main requirements: * CageFS is installed * Alt-PHP packages are installed -* Mod_suexec is installed. You can find installation instruction [here](./#apache-suexec-module) +* Use a compatible PHP handler. On cPanel, CGI/FCGI requires suEXEC; suPHP and LiteSpeed do not require `mod_suexec` just to use PHP Selector. For suEXEC installation instructions, see [here](./#apache-suexec-module). * CageFS is initialized without errors * CageFS is enabled for a domain user-owner -* An appropriate PHP handler is selected for PHP version which is system version. PHP Selector is **compatible** with the following technologies: _suPHP, mod_fcgid, CGI (suexec), LiteSpeed_. See also [Compatibility Matrix](/cloudlinuxos/limits/#compatibility-matrix). +* An appropriate PHP handler is selected for PHP version which is system version. PHP Selector is **compatible** with the following technologies: _suPHP, mod_fcgid (with suEXEC on cPanel), CGI (suexec on cPanel), mod_lsapi (cPanel with suEXEC or suPHP), LiteSpeed_. See also [Compatibility Matrix](/cloudlinuxos/limits/#compatibility-matrix). * PHP version in the CloudLinux OS PHP selector does not equal to the Native PHP version ::: tip Note @@ -4403,6 +4403,10 @@ The mark `x` stands for a supported version. The installation of PHP Selector presumes that you already have [CageFS](./#cagefs) & [LVE Manager](/lve_manager/) installed. +:::tip Note +The `yum` commands in this installation and update guide are for RPM-based CloudLinux OS, not Ubuntu 22.04 extension. On Ubuntu 22.04 extension, the PHP installation wizard requests version-specific `alt-phpXX-meta` packages through APT (`XX` is the selected version without its dot). +::: + Use [compatibility matrix](/cloudlinuxos/limits/#compatibility-matrix) to check if your Web Server/PHP mode is supporting PHP Selector. If not, you need a change to one of the supported models. Installation of different versions of PHP & modules: @@ -4491,7 +4495,7 @@ yum groupinstall alt-php ``` -3. Install `mod_suexec` package as root. See installation instructions [here](./#installation-5). +3. For CGI/FCGI handlers, install `mod_suexec` as root. See installation instructions [here](./#installation-5). For other handlers, check the [compatibility matrix](/cloudlinuxos/limits/#compatibility-matrix). 4. Verify that CageFS is initialized successfully. * via SSH by running the following command: @@ -4805,7 +4809,7 @@ cagefsctl --list-enabled | grep -v enabled | grep -v '^$' | while read -r line; done ``` -This command will reset the extensions for all users on PHP version 8.4 to the default list. You can specify a different PHP version by modifying the `--version` argument in the command above. +This command resets the PHP 8.4 extensions to the default list for every CageFS-enabled user, even if they currently use a different PHP version. You can specify a different PHP version by modifying the `--version` argument in the command above. To reset the extensions for a specific user, you can use the following command: ``` @@ -5099,7 +5103,7 @@ Enable PHP-FFmpeg extension via ``` -selectorctl --enable-extensions=ffmpeg --user USERNAME --version X.Y +selectorctl --enable-user-extensions=ffmpeg --user USERNAME --version X.Y ``` @@ -5863,7 +5867,7 @@ Here is an example of how you can generate _OPTIONS_
``` -OPTIONS=`echo disable_functions:exec,syslog|base64 -w 0`,`echo display_errors:off|base64 -w 0`,`echo post_max_size:128M|base64 -w 0` +OPTIONS=`printf %s 'include_path:.:/dir/with,comma'|base64 -w 0`,`printf %s 'display_errors:off'|base64 -w 0`,`printf %s 'post_max_size:128M'|base64 -w 0` echo $OPTIONS ```
diff --git a/docs/cloudlinuxos/command-line_tools/README.md b/docs/cloudlinuxos/command-line_tools/README.md index 5750117fa..84c62a122 100644 --- a/docs/cloudlinuxos/command-line_tools/README.md +++ b/docs/cloudlinuxos/command-line_tools/README.md @@ -1409,7 +1409,7 @@ The global options modify settings in the /etc/cl.sel | --summary (-S) : | prints alternatives state summary. Output format: alternative version, state ('e' for 'enabled', '-' otherwise), chosen as default one or not ('d' for 'default', '-' otherwise). For example:
`$ selectorctl --summary`
`5.2 e -`
`5.3 e -`
`5.4 e -`
`5.5 e -`
`native e d`

if used with `--show-native-version` displays version for native interpreter:
`$ selectorctl --summary --show-native-version`
`5.2 e -`
`5.3 e -`
`5.4 e -`
`5.5 e -`
`native(5.3) e d`
| | --current (-C) : | prints currently globally selected default version (it is stored in the _/etc/cl.selector/defaults.cfg_ file):
`$ selectorctl --current`
`native native /usr/bin/php`

If used with `--show-native-version` , native interpreter version is displayed as well:
`$ selectorctl --current --show-native-version`
`native(5.3) native(5.3.19) /usr/bin/php`| | --set-current (-B): | sets specified version as globally default one (in _/etc/cl.selector/defaults.cfg_ file). For example, to set current default version of PHP to 5.4, use:
`$ selectorctl --set-current=5.4` | -| --disable-alternative (-N): | adds state=disabled option to alternative section. With it a corresponding alternative gets removed from user alternatives selection list. For instance to disable PHP 5.2, run: `$ selectorctl --disable-alternative=5.2` | +| --disable-alternative (-N): | adds state=disabled option to alternative section. With it a corresponding alternative gets removed from user alternatives selection list. The current global default cannot be disabled; set another default first. For instance to disable PHP 5.2, run: `$ selectorctl --disable-alternative=5.2` | | --enable-alternative (-Y): | Enables alternative version, removes state=disabled option, if present, from alternative section. For example to enable PHP 5.2: `$ selectorctl --enable-alternative=5.2` | | --enable-extensions (-E): | enables extensions for particular PHP version by adding comma-separated list of extensions of modules for alternative in _/etc/cl.selector/defaults.cfg_ . Requires --version option. For example:
`$ selectorctl --enable-extensions=pdo,phar --version=5.2`| | --disable-extensions (-D): | removes extensions for a particular PHP version. Comma-separated list of extensions will be removed from /etc/cl.selector/defaults.cfg . Requires --version . Example:
`$ selectorctl --disable-extensions=pdo,phar --version=5.2` | @@ -1421,21 +1421,21 @@ The global options modify settings in the /etc/cl.sel All end user settings are contained in individual user's alt_php.ini files and controlled using the `selectorctl` command. ::: tip Note -Starting from cagefs-7.6.17, users inside CageFS can manipulate PHP Selector using the end-user options. If a command is run by a user, the `--user` option is not required. +Starting from cagefs-7.6.17, users inside CageFS can manipulate PHP Selector using the end-user options. The `--user` requirements below apply when an administrator runs a command outside CageFS; users inside CageFS can omit `--user`, and if supplied, it must match their own username. ::: | | | |-|-| | --user-summary (-s): | Prints user alternatives state summary. Example:
`$ selectorctl --user-summary --user=user1`
`5.2 e - -`
`5.3 e - -`
`5.4 e - -`
`5.5 e - -`
`native e d s`

Columns are: alternative version, state ('e' for 'enabled', '-' otherwise), chosen as default one or not('d' for 'default', '-' otherwise), selected as user default one or not ('s' for 'selected', '-' otherwise).
If used with `--show-native-version` , version for native interpreter is shown in parenthesis:
`$ selectorctl --user-summary --user=user1 --show-native-version`
`5.2 e - -`
`5.3 e - -`
`5.4 e - -`
`5.5 e - -`
`native(5.3) e d s`

`--user` option is required. | -| --current (-c): | prints currently globally selected default version (in _/etc/cl.selector/defaults.cfg_ file):
`$ selectorctl --current`
`5.3 5.3.28 /opt/alt/php53/usr/bin/php-cgi`

If used with `--show-native-version` to display native version:
`$ selectorctl --user-current --user=user1`
`5.3 5.3.28 /opt/alt/php53/usr/bin/php-cgi`

`--user` option is required.| +| --user-current (-c): | prints the PHP version currently selected for an end user:
`$ selectorctl --user-current --user=user1`
`5.3 5.3.28 /opt/alt/php53/usr/bin/php-cgi`

`--show-native-version` displays the native PHP version when native is selected. Administrators must specify `--user` ; a user inside CageFS can omit it.| | --set-user-current (-b): | sets specified version as the one to use for this end user:
`$ selectorctl --set-user-current=5.4 --user=user1`
changes user symlinks for the PHP interpreter to point to alternative 5.4.
--user option is required.| | --enable-user-extensions (-e): | Enables comma-separated list of extensions for the user user. Information is saved to _alt_php.ini_ file. Requires `--version` and `--user` options.
`$ selectorctl --enable-user-extensions=pdo,phar --version=5.2 --user=user1` | | --disable-user-extensions (-d): | Disables extensions provided as comma-separated list. Requires `--version` and `--user` options.
`$ selectorctl --disable-user-extensions=pdo,phar --version=5.2 --user=user1` | -|--for-all-users: | Allows to enable/disable extensions for all users with the required PHP version. Works only with `--enable-user-extensions` or `--disable-user-extensions` option.
`$ selectorctl --enable-user-extensions=gd --version=5.3 --for-all-users`
`$ selectorctl --disable-user-extensions=gd --version=5.3 --for-all-users`| +|--for-all-users: | Applies extension changes to all CageFS-enabled users for the specified PHP version, even if another version is currently selected. Cannot be combined with `--user`. Works only with `--enable-user-extensions` or `--disable-user-extensions` option.
`$ selectorctl --enable-user-extensions=gd --version=5.3 --for-all-users`
`$ selectorctl --disable-user-extensions=gd --version=5.3 --for-all-users`| | --replace-user-extensions (-r): | Replaces extensions with a provided comma-separated list of extensions Requires `--version` and `--user` options:
`$ selectorctl --replace-user-extensions=pdo,phar --version=5.2 --user=user1` | -| --reset-user-extensions (-t): | Resets extensions for end user to default list of extensions as defined in default.cfg . Requires `--version` and `--user` options.
`$ selectorctl --reset-user-extensions --version=5.2 --user=user1` | +| --reset-user-extensions (-t): | Resets extensions for end user to default list of extensions as defined in defaults.cfg . Requires `--version` and `--user` options.
`$ selectorctl --reset-user-extensions --version=5.2 --user=user1` | | --list-user-extensions (-g): | lists enabled user extensions for an alternative. Requires `--version` and `--user` options.
`$ selectorctl --list-user-extensions --version=5.3 --user=user1`
`xml`
`xmlreader`
`xmlrpc`

if `--all` option present, command will list all alternatives extensions marked enabled or disabled for given user. For example:
`$ selectorctl --list-user-extensions --version=5.3 --user=user1 --all`
`- xmlreader`
`- xmlrpc`
`- xmlwriter`
`- xrange`
`+ xsl`

Plus sign (+) stands for 'enabled', minus (–) stands for 'disabled'. Enabled and disabled state relates to presence or absence of corresponding extensions in user _alt_php.ini_ file.| -| --add-options (-k): | adds options (as in _php.ini_ ) to user _alt_php.ini_ file. For example:
`$ selectorctl --add-options=log_errors:on,display_errors:on --version=5.2 --user=user1`
adds `log_error` and `display_errors` options with values 'on' to user _alt_php.ini_ file overwriting default values for a user. Requires `--version` and `--user` options.| +| --add-options (-k): | adds options (as in _php.ini_ ) to user _alt_php.ini_ file. For example:
`$ selectorctl --add-options=log_errors:on,display_errors:on --version=5.2 --user=user1`
adds `log_errors` and `display_errors` options with values 'on' to user _alt_php.ini_ file overwriting default values for a user. Requires `--version` and `--user` options.| | --replace-options (-m): | replaces all options in user _alt_php.ini_ file with specified ones. Requires `--version` and `--user` options.
`$ selectorctl --replace-options=log_errors:on,display_errors:on --version=5.2 --user=user1` | | --delete-options (-x): | removes custom options from user _alt_php.ini_ file. Requires `--version` and `--user` options.
`$ selectorctl --delete-options=log_errors,display_errors --version=5.2 --user=user1` | | --print-options (-P): | print options from _/etc/cl.selector/php.conf_ file with default values or ones overwritten in user's _alt_php.ini_ file.
`$ selectorctl --print-options --version=5.2 --user=user1`
`TITLE:allow_url_fopen`
`DEFAULT:On`
`COMMENT:Allows PHP file functions to retrieve data from remote
locations over FTP or HTTP. This option is a great security risk, thus do not turn it on without necessity.`
`TYPE:bool`
`...`

Requires `--user` option. `--version` option is optional. When `--version` is omitted, options for current selected version will be printed. By default outputs as plain test. If `--json` , `--csv` , `--perl` is specified, outputs data in corresponding format. For example, with `--perl` option, the output is perl hash structure that can be evaluated. | @@ -1447,7 +1447,7 @@ Starting from cagefs-7.6.17, users inside CageFS can manipulate PHP Selector usi | | | |-|-| -| --base64 (-Q) | Sometimes PHP options values can contain commas and other symbols that break command line formatting. In such a case convert a key:value pair into base64 and pass it as value for option-related arguments. For example, to add disable_functions=exec,popen,system and display_errors=on to user options, do the following:
`$ selectorctl --add-options=$(echo disable_functions:exec,popen,system \| base64 -w 0),$(echo display_errors:on \| base64 -w 0) --version=5.2 --user=user1 --base64`
Option '-w 0' of base64 executable stands for 'disable wrapping of lines' . Without it base64 output will break the command. | +| --base64 (-Q) | Sometimes PHP options values can contain commas and other symbols that break command line formatting. In such a case convert a key:value pair into base64 and pass it as value for option-related arguments. For example, to set include_path to a path containing a comma and display_errors=on (when both directives are allowed in /etc/cl.selector/php.conf ), do the following:
`$ selectorctl --add-options=$(printf %s 'include_path:.:/dir/with,comma' \| base64 -w 0),$(printf %s 'display_errors:on' \| base64 -w 0) --version=5.2 --user=user1 --base64`
Option '-w 0' of base64 executable stands for 'disable wrapping of lines' . Without it base64 output will break the command. Use printf instead of echo so decoded option values have no trailing newline. | | --quiet | makes selectorctl continue when it encounter option not found in _php.conf_ . Without it selectorctl exits with error.|