ⓘ Require a live Usermin miniserv PID before allowing one-time login URL creation, so the feature is only offered when the session backend can actually be used.
ⓘ Centralize global file ACL checks for server-local reads and applies them to batch, LDAP batch, MySQL, and PostgreSQL local import and restore flows. Files are read under the configured `fileunix` identity and staged with the correct command-user ownership, preventing constrained Webmin users from bypassing `root`, `otherdirs`, or `fileunix`.
9ceffce70f (r191495975)
ⓘ Fail closed when checking local batch file imports for Webmin-only users that do not have a Unix home directory.
This prevents an unset global file root ACL, or a home-relative root such as `~/path`, from being treated as filesystem-root access. Explicitly configured allowed directories still work as before.
ⓘ This tightens local server-side batch file execution in the Users and Groups module.
Both user and group batch endpoints now read local batch files through a shared helper that enforces the module `batchdir` ACL, the user’s global file chooser ACL (`root` / `otherdirs`), and the configured `fileunix` read identity. Existing ACLs remain compatible by treating a missing `batchdir` as `/`, while an explicitly blank value denies local server batch files.
Regression coverage was added for allowed paths, denied paths, `otherdirs`, missing/blank `batchdir`, symlink escape rejection, and successful local batch reads.
----
Reproduction / verification steps:
1. Create a constrained Webmin user with access to the `Users and Groups` module.
2. Set the user's Global ACL:
- Root directory for file browser: `/home/user1`
- Other directories to allow: empty
- Browse as Unix user: `nobody`
3. Set the user's `Users and Groups` module ACL:
- Can view batch file form?: `Yes`
- Batch files must be under directory: `/`
4. Create test files on the Webmin host:
```sh
sudo mkdir -p /home/user1
echo ROOT_SECRET_MARKER | sudo tee /root/batch-secret.txt >/dev/null
sudo chown root:root /root/batch-secret.txt
sudo chmod 600 /root/batch-secret.txt
echo ALLOWED_BATCH_MARKER | sudo tee /home/user1/allowed.batch >/dev/null
sudo chmod 644 /home/user1/allowed.batch
sudo ln -sf /root/batch-secret.txt /home/user1/link-secret.batch
echo ROOT_ONLY_ALLOWED_MARKER | sudo tee /home/user1/root-only.batch >/dev/null
sudo chown root:root /home/user1/root-only.batch
sudo chmod 600 /home/user1/root-only.batch
```
5. Log in to Webmin as the constrained user and request:
```text
/useradmin/batch_exec.cgi?source=1&local=/root/batch-secret.txt
/useradmin/gbatch_exec.cgi?source=1&local=/root/batch-secret.txt
```
Expected fixed result:
```text
Local file location is not allowed
```
6. Request an allowed readable file:
```text
/useradmin/batch_exec.cgi?source=1&local=/home/user1/allowed.batch
/useradmin/gbatch_exec.cgi?source=1&local=/home/user1/allowed.batch
```
Expected fixed result:
```text
Invalid action at line 1 : ALLOWED_BATCH_MARKER
```
7. Request a symlink inside the allowed directory that points outside it:
```text
/useradmin/batch_exec.cgi?source=1&local=/home/user1/link-secret.batch
/useradmin/gbatch_exec.cgi?source=1&local=/home/user1/link-secret.batch
```
Expected fixed result:
```text
Local file location is not allowed
```
8. Request a root-only file inside the allowed directory:
```text
/useradmin/batch_exec.cgi?source=1&local=/home/user1/root-only.batch
/useradmin/gbatch_exec.cgi?source=1&local=/home/user1/root-only.batch
```
Expected fixed result:
```text
Local file not found
```
The fixed behavior confirms that local batch file imports now enforce the configured global file ACL, reject symlink escapes, and read files using the configured Unix identity instead of the privileged Webmin process.
ⓘ Normalize APT install-result names like `libtinfo6:amd64` to `libtinfo6` so scheduled updates can correctly detect dependency-updated packages and avoid false failure reports.
https://github.com/virtualmin/virtualmin-gpl/issues/1247
ⓘ Move miniserv helper functions into `miniserv-lib.pl`, remove the caller guard from `miniserv.pl`, and keep tests loading the helper library directly while preserving daemon startup behavior.
https://github.com/webmin/webmin/pull/2695
ⓘ Move XML-RPC marshalling helpers into `xmlrpc-lib.pl`, remove the caller guard from `xmlrpc.cgi`, and preserve coverage through direct library tests plus the CGI invocation regression.
https://github.com/webmin/webmin/pull/2763
ⓘ Report SSL certificate and TCP connection, timeout, and DNS failures as down or timed out instead of not installed, and tighten built-in status
monitor loading.
The SSL certificate and TCP monitors returned -1 (not installed) for
connection failures, timeouts, and DNS errors, causing false "service
uninstalled" then "back up" notifications. Report these as down (0) or timed out (-3) instead, reserving -1 for genuinely missing.
Also survive a broken monitor library without aborting the whole scheduled check run, and fix the remote alive-monitor Webmin-down fallback typo.
https://forum.virtualmin.com/t/service-monitor-uninstalled-then-back-up/137514?u=ilia
ⓘ Prevent Webmin from swallowing Certbot's key-path output when extracting PEM paths, while preserving IPv6 cert-name support and adding regression coverage.
ⓘ Create and configure missing bond devices with ip link, attach partner interfaces before assigning addresses, avoid legacy module auto-creation when ip is available, and add regression coverage.
Ref.: https://github.com/webmin/webmin/pull/2777
This PR adds SELinux context handling for Webmin’s default runtime directory on EL systems.
Setup now persists and applies a `var_run_t` fcontext rule when SELinux is enabled, falls back safely when SELinux tooling is unavailable, and removes the local fcontext rule when `/var/webmin` is deleted during uninstall.