You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ansible/test/units/module_utils/basic
Sam Doran 7e4cffc5d2
[stable-2.10] Change default file permissions so they are not world readable (#70221) (#70824)
* Change default file permissions so they are not world readable

CVE-2020-1736

Set the default permissions for files we create with atomic_move() to 0o0660. Track
which files we create that did not exist and warn if the module supports 'mode'
and it was not specified and the module did not call set_mode_if_different(). This allows the user to take action and specify a mode rather than using the defaults.

A code audit is needed to find all instances of modules that call atomic_move()
but do not call set_mode_if_different(). The findings need to be documented in
a changelog since we are not warning. Warning in those instances would be frustrating
to the user since they have no way to change the module code.

- use a set for storing list of created files
- just check the argument spac and params rather than using another property
- improve the warning message to include the default permissions.
(cherry picked from commit 5260527c4a)

Co-authored-by: Sam Doran <sdoran@redhat.com>
4 years ago
..
__init__.py AnsibleModules.log() fix for python3 9 years ago
test__log_invocation.py Porting tests to pytest (#33387) 7 years ago
test__symbolic_mode_to_octal.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_argument_spec.py [2.10] api: time.clock compatible code (#70677) 4 years ago
test_atomic_move.py [stable-2.10] Change default file permissions so they are not world readable (#70221) (#70824) 4 years ago
test_deprecate_warn.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_dict_converters.py Split basic units (#33510) 7 years ago
test_exit_json.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_filesystem.py Move unit test compat code out of `lib/ansible/`. (#46996) 6 years ago
test_get_file_attributes.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_get_module_path.py Move unit test compat code out of `lib/ansible/`. (#46996) 6 years ago
test_heuristic_log_sanitize.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_imports.py unit tests: remove unused imports (#59636) 5 years ago
test_log.py Fix unit test parametrize order on Python 3.5. 6 years ago
test_no_log.py Sanitize URI module keys with no_log values (#70762) (#70820) 4 years ago
test_platform_distribution.py Discover Flatcar Linux properly for hostname (#69627) 5 years ago
test_run_command.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_safe_eval.py [stable-2.10] Clean up unit test boilerplate. 4 years ago
test_sanitize_keys.py Sanitize URI module keys with no_log values (#70762) (#70820) 4 years ago
test_selinux.py Move unit test compat code out of `lib/ansible/`. (#46996) 6 years ago
test_set_mode_if_different.py unit tests: remove unused imports (#60462) 5 years ago
test_tmpdir.py [stable-2.10] Clean up unit test boilerplate. 4 years ago