don't create world-readable archives of LXC containers

with the default umask tar will create a world-readable archive of the

container, which may contain sensitive data



Signed-off-by: Evgeni Golov <evgeni@golov.de>
reviewable/pr18780/r1
Evgeni Golov 10 years ago committed by Brian Coca
parent 719b9b229b
commit 6bfd2846f8

@ -1366,6 +1366,8 @@ class LxcContainerManagement(object):
:type source_dir: ``str``
"""
old_umask = os.umask(0077)
archive_path = self.module.params.get('archive_path')
if not os.path.isdir(archive_path):
os.makedirs(archive_path)
@ -1396,6 +1398,9 @@ class LxcContainerManagement(object):
build_command=build_command,
unsafe_shell=True
)
os.umask(old_umask)
if rc != 0:
self.failure(
err=err,

Loading…
Cancel
Save