functional backport of 74448 (#74567)

Co-authored-by: Alicia Cozine <acozine@users.noreply.github.com>
pull/74590/head
Alicia Cozine 4 years ago committed by GitHub
parent 167726e291
commit 4da2e2db79
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -278,7 +278,7 @@
# choice but to create world readable temporary files to execute a module on # choice but to create world readable temporary files to execute a module on
# the remote machine. This option is False by default for security. Users may # the remote machine. This option is False by default for security. Users may
# turn this on to have behaviour more like Ansible prior to 2.1.x. See # turn this on to have behaviour more like Ansible prior to 2.1.x. See
# https://docs.ansible.com/ansible/latest/user_guide/become.html#becoming-an-unprivileged-user # https://docs.ansible.com/ansible/latest/user_guide/become.html#risks-of-becoming-an-unprivileged-user
# for more secure ways to fix this than enabling this option. # for more secure ways to fix this than enabling this option.
# #
#allow_world_readable_tmpfiles = False #allow_world_readable_tmpfiles = False

@ -660,7 +660,7 @@ class ActionBase(with_metaclass(ABCMeta, object)):
'allow_world_readable_tmpfiles is a no-op. See this ' 'allow_world_readable_tmpfiles is a no-op. See this '
'URL for more details: ' 'URL for more details: '
'https://docs.ansible.com/ansible/become.html' 'https://docs.ansible.com/ansible/become.html'
'#becoming-an-unprivileged-user') '#risks-of-becoming-an-unprivileged-user')
if execute: if execute:
group_mode = 'g+rwx' group_mode = 'g+rwx'
else: else:
@ -695,7 +695,7 @@ class ActionBase(with_metaclass(ABCMeta, object)):
'to create when becoming an unprivileged user ' 'to create when becoming an unprivileged user '
'(rc: %s, err: %s}). For information on working around this, see ' '(rc: %s, err: %s}). For information on working around this, see '
'https://docs.ansible.com/ansible/become.html' 'https://docs.ansible.com/ansible/become.html'
'#becoming-an-unprivileged-user' % ( '#risks-of-becoming-an-unprivileged-user' % (
res['rc'], res['rc'],
to_native(res['stderr']))) to_native(res['stderr'])))

Loading…
Cancel
Save