Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
StackCap43382
Advisor
Advisor
Jump to solution

Re-Enable CPLP?

Disabled CPLP in my lab as a test of the non-documented commands.

The below command appears to trigger CPLP to unload the protections:

# cplp disable 

The issue is "# cplp enable" does not work.

Anyone know how to turn it back on?

No need to panic this is a LAB device with no inbound connectivity. 

EDIT: Files are stored here:

[Expert@FWA-01:0]# ls -l /opt/cplp/patches
total 6708
drwxr-x--- 2 admin root 236 Sep 16 21:08 cpcert_2
drwxr-x--- 2 admin root 266 Sep 16 21:08 cpcert_cprid_2
drwxr-x--- 2 admin root 293 Sep 15 09:22 cpikev2_1
-rw-r----- 1 admin root 451744 Jun 16 10:37 libvpn1_R81_20_jumbo_hf_main_997000007.so
-rw-r----- 1 admin root 459968 Jun 16 10:37 libvpn1_R81_20_jumbo_hf_main_997000011.so
-rw-r----- 1 admin root 460000 Jun 16 10:37 libvpn1_R81_20_jumbo_hf_main_997000020.so
-rw-r----- 1 admin root 460000 Jun 16 10:37 libvpn1_R81_20_jumbo_hf_main_997000031.so
-rw-r----- 1 admin root 460000 Jun 16 10:37 libvpn1_R81_20_jumbo_hf_main_997000034.so
-rw-r----- 1 admin root 712276 Jun 16 10:37 libvpn1_R82_10_jumbo_hf_main_999000006.so
-rw-r----- 1 admin root 631232 Jun 16 10:37 libvpn1_R82_10_jumbo_hf_main_999000006_arm.so
-rw-r----- 1 admin root 468184 Jun 16 10:37 libvpn1_R82_jumbo_hf_main_998000004.so
-rw-r----- 1 admin root 468184 Jun 16 10:37 libvpn1_R82_jumbo_hf_main_998000019.so
-rw-r----- 1 admin root 447616 Jun 16 10:37 libvpn1_ivory_main.so
-rw-r----- 1 admin root 468184 Jun 16 10:37 libvpn1_jaguar_main.so
-rw-r----- 1 admin root 712276 Jun 16 10:37 libvpn1_jess_main.so
-rw-r----- 1 admin root 631228 Jun 16 10:37 libvpn1_jess_main_arm.so
-rw-r----- 1 admin root 949 Jun 16 10:37 vpn1_patch.json

You might be able to reapply the fixes using the JSON files contained in the above directory:

cplp apply --file /opt/cplp/patches/cpcert_2/cpcert_patch.json

cplp apply --file /opt/cplp/patches/cpikev2_1/cpikev2_patch.json

 

 

 

CCSME, CCTE, CCME, CCVS
0 Kudos
1 Solution

Accepted Solutions
Bob_Zimmerman
MVP Gold
MVP Gold
[Expert@DallasSC]# ls -R /opt/cplp/
...
/opt/cplp/cplp/cli:
__init__.py    clean.py     gc.py           migrate_state.py  seal.py
__pycache__    comment.py   globals_cmd.py  patches.py        status.py
apply.py       coverage.py  inspect.py      rearm.py          unload.py
boot.py        disable.py   jumbo.py        residue.py        watch.py
checkpatch.py  event.py     list_cmd.py     revert.py
...

[Expert@DallasSC]# cat /opt/cplp/cplp/cli/disable.py 
"""disable -- turn cplp off on this host.

The big red "off" switch: revert every still-applied patch (restoring
original bytes in live processes) AND remove the cpd scheduler task that
`cplp boot` registered, so nothing re-applies afterward.

    cplp disable                       # revert all + remove the CPLP_WATCH cpd task
    cplp disable --task-name MYTASK    # ...removing a custom-named task
    cplp disable --keep-task           # revert all but leave the cpd task

After this, `cplp list` shows every entry reverted + inactive, and the
scheduler no longer runs `cplp watch`. Re-arm with a fresh `cplp apply`
(+ `cplp boot`) when needed. Guards (`cplp jumbo`) are left untouched.
"""
...

So it looks like to fully rearm it, you need to run two things:

[Expert@DallasSC]# cplp list
No recorded patches

[Expert@DallasSC]# cplp boot
cplp boot: install (task=CPLP_WATCH, interval=60s, cplp=/usr/local/bin/cplp, vs0-only via /opt/cplp/bin/cplp_vs0)
cplp boot: scheduled 'CPLP_WATCH' -> '/opt/cplp/bin/cplp_vs0 /usr/local/bin/cplp watch --once --boot-task CPLP_WATCH --vs0-only' every 60s
cplp boot: scheduled 'CPLP_REPORT' -> '/opt/cplp/bin/cplp_vs0 /usr/local/bin/cplp coverage --scheduled --vs0-only' every 86400s

[Expert@DallasSC]# find /opt/cplp/patches/ -name '*.json' -exec cplp apply --file {} \;
apply --file /opt/cplp/patches/cpm_patch.json: 10 target(s) (one-shot per pid)
Patch not applied to fwm: running build 999000018 (branch R82_10_jumbo_hf_main) is not in the supported range (999000003..999000003); 10 function(s) queued and will apply automatically once the build is supported.
apply --file: 10 patch(es) armed-pending (10 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpca_patch.json: 1 target(s) (one-shot per pid)
Patch not applied to libcpca.so: running build 999000015 (branch R82_10_jumbo_hf_main) is not in the supported range (999000011..999000011); 1 function(s) queued and will apply automatically once the build is supported.
apply --file: 1 patch(es) armed-pending (1 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpcert_cprid_2/cpcert_cprid_patch.json: 5 target(s) (one-shot per pid)
Patch not applied to cprid: running build 999000008 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 5 function(s) queued and will apply automatically once the build is supported.
apply --file: 5 patch(es) armed-pending (5 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpcert_2/cpcert_patch.json: 5 target(s) (one-shot per pid)
Patch not applied to libcpcert.so: running build 999000015 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 5 function(s) queued and will apply automatically once the build is supported.
apply --file: 25 patch(es) armed-pending (25 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/fwm_1/fwm_patch.json: 1 target(s) (one-shot per pid)
Patch not applied to fwm: running build 999000018 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 1 function(s) queued and will apply automatically once the build is supported.
apply --file: 1 patch(es) armed-pending (1 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.

[Expert@DallasSC]# cplp list
ID(PATCH:PROC)        STATUS     MODE        PIDS    INSTALLED            COMMENT
--------------------------------------------------------------------------
cpca:cpca             jumbofix   livepatch   0/0     2026-09-30 18:29:31  sk185152
cpcert:cpca           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:iked           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:vpnd           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad         nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd         nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid    nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpm:fwm               jumbofix   livepatch   0/0     2026-09-30 18:29:31  sk185152 sk185169
fwm:fwm               nopatch    livepatch   0/0     2026-09-30 18:29:33  CVE-2026-91843

View solution in original post

0 Kudos
2 Replies
Bob_Zimmerman
MVP Gold
MVP Gold
[Expert@DallasSC]# ls -R /opt/cplp/
...
/opt/cplp/cplp/cli:
__init__.py    clean.py     gc.py           migrate_state.py  seal.py
__pycache__    comment.py   globals_cmd.py  patches.py        status.py
apply.py       coverage.py  inspect.py      rearm.py          unload.py
boot.py        disable.py   jumbo.py        residue.py        watch.py
checkpatch.py  event.py     list_cmd.py     revert.py
...

[Expert@DallasSC]# cat /opt/cplp/cplp/cli/disable.py 
"""disable -- turn cplp off on this host.

The big red "off" switch: revert every still-applied patch (restoring
original bytes in live processes) AND remove the cpd scheduler task that
`cplp boot` registered, so nothing re-applies afterward.

    cplp disable                       # revert all + remove the CPLP_WATCH cpd task
    cplp disable --task-name MYTASK    # ...removing a custom-named task
    cplp disable --keep-task           # revert all but leave the cpd task

After this, `cplp list` shows every entry reverted + inactive, and the
scheduler no longer runs `cplp watch`. Re-arm with a fresh `cplp apply`
(+ `cplp boot`) when needed. Guards (`cplp jumbo`) are left untouched.
"""
...

So it looks like to fully rearm it, you need to run two things:

[Expert@DallasSC]# cplp list
No recorded patches

[Expert@DallasSC]# cplp boot
cplp boot: install (task=CPLP_WATCH, interval=60s, cplp=/usr/local/bin/cplp, vs0-only via /opt/cplp/bin/cplp_vs0)
cplp boot: scheduled 'CPLP_WATCH' -> '/opt/cplp/bin/cplp_vs0 /usr/local/bin/cplp watch --once --boot-task CPLP_WATCH --vs0-only' every 60s
cplp boot: scheduled 'CPLP_REPORT' -> '/opt/cplp/bin/cplp_vs0 /usr/local/bin/cplp coverage --scheduled --vs0-only' every 86400s

[Expert@DallasSC]# find /opt/cplp/patches/ -name '*.json' -exec cplp apply --file {} \;
apply --file /opt/cplp/patches/cpm_patch.json: 10 target(s) (one-shot per pid)
Patch not applied to fwm: running build 999000018 (branch R82_10_jumbo_hf_main) is not in the supported range (999000003..999000003); 10 function(s) queued and will apply automatically once the build is supported.
apply --file: 10 patch(es) armed-pending (10 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpca_patch.json: 1 target(s) (one-shot per pid)
Patch not applied to libcpca.so: running build 999000015 (branch R82_10_jumbo_hf_main) is not in the supported range (999000011..999000011); 1 function(s) queued and will apply automatically once the build is supported.
apply --file: 1 patch(es) armed-pending (1 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpcert_cprid_2/cpcert_cprid_patch.json: 5 target(s) (one-shot per pid)
Patch not applied to cprid: running build 999000008 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 5 function(s) queued and will apply automatically once the build is supported.
apply --file: 5 patch(es) armed-pending (5 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/cpcert_2/cpcert_patch.json: 5 target(s) (one-shot per pid)
Patch not applied to libcpcert.so: running build 999000015 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 5 function(s) queued and will apply automatically once the build is supported.
apply --file: 25 patch(es) armed-pending (25 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.
apply --file /opt/cplp/patches/fwm_1/fwm_patch.json: 1 target(s) (one-shot per pid)
Patch not applied to fwm: running build 999000018 (branch R82_10_jumbo_hf_main) is not in the supported range (no matching patch installed); 1 function(s) queued and will apply automatically once the build is supported.
apply --file: 1 patch(es) armed-pending (1 unsupported build, 0 no live process of their own); `cplp watch` resolves each once it can.

[Expert@DallasSC]# cplp list
ID(PATCH:PROC)        STATUS     MODE        PIDS    INSTALLED            COMMENT
--------------------------------------------------------------------------
cpca:cpca             jumbofix   livepatch   0/0     2026-09-30 18:29:31  sk185152
cpcert:cpca           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:iked           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:vpnd           nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad         nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd         nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid    nopatch    livepatch   0/0     2026-09-30 18:29:32  CVE-2026-85102 CVE-2026-85103
cpm:fwm               jumbofix   livepatch   0/0     2026-09-30 18:29:31  sk185152 sk185169
fwm:fwm               nopatch    livepatch   0/0     2026-09-30 18:29:33  CVE-2026-91843
0 Kudos
StackCap43382
Advisor
Advisor

Perfect Thanks!

CCSME, CCTE, CCME, CCVS
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events