|
|
@ -5,10 +5,12 @@
|
|
|
|
tasks:
|
|
|
|
tasks:
|
|
|
|
|
|
|
|
|
|
|
|
- name: Ensure sudo password absent but required.
|
|
|
|
- name: Ensure sudo password absent but required.
|
|
|
|
shell: whoami
|
|
|
|
|
|
|
|
become: true
|
|
|
|
become: true
|
|
|
|
become_user: mitogen__pw_required
|
|
|
|
become_user: mitogen__pw_required
|
|
|
|
|
|
|
|
command:
|
|
|
|
|
|
|
|
cmd: whoami
|
|
|
|
register: out
|
|
|
|
register: out
|
|
|
|
|
|
|
|
changed_when: false
|
|
|
|
ignore_errors: true
|
|
|
|
ignore_errors: true
|
|
|
|
when:
|
|
|
|
when:
|
|
|
|
# https://github.com/ansible/ansible/pull/70785
|
|
|
|
# https://github.com/ansible/ansible/pull/70785
|
|
|
@ -32,10 +34,12 @@
|
|
|
|
or is_mitogen
|
|
|
|
or is_mitogen
|
|
|
|
|
|
|
|
|
|
|
|
- name: Ensure password sudo incorrect.
|
|
|
|
- name: Ensure password sudo incorrect.
|
|
|
|
shell: whoami
|
|
|
|
|
|
|
|
become: true
|
|
|
|
become: true
|
|
|
|
become_user: mitogen__pw_required
|
|
|
|
become_user: mitogen__pw_required
|
|
|
|
|
|
|
|
command:
|
|
|
|
|
|
|
|
cmd: whoami
|
|
|
|
register: out
|
|
|
|
register: out
|
|
|
|
|
|
|
|
changed_when: false
|
|
|
|
vars:
|
|
|
|
vars:
|
|
|
|
ansible_become_pass: nopes
|
|
|
|
ansible_become_pass: nopes
|
|
|
|
ignore_errors: true
|
|
|
|
ignore_errors: true
|
|
|
@ -59,18 +63,27 @@
|
|
|
|
or ansible_version.full is version("2.11", ">=", strict=True)
|
|
|
|
or ansible_version.full is version("2.11", ">=", strict=True)
|
|
|
|
or is_mitogen
|
|
|
|
or is_mitogen
|
|
|
|
|
|
|
|
|
|
|
|
# TODO: https://github.com/dw/mitogen/issues/692
|
|
|
|
- block:
|
|
|
|
# - name: Ensure password sudo succeeds.
|
|
|
|
- name: Ensure password sudo succeeds
|
|
|
|
# shell: whoami
|
|
|
|
become: true
|
|
|
|
# become: true
|
|
|
|
become_user: mitogen__pw_required
|
|
|
|
# become_user: mitogen__pw_required
|
|
|
|
vars:
|
|
|
|
# register: out
|
|
|
|
ansible_become_pass: pw_required_password
|
|
|
|
# vars:
|
|
|
|
command:
|
|
|
|
# ansible_become_pass: pw_required_password
|
|
|
|
cmd: whoami
|
|
|
|
|
|
|
|
register: sudo_password_success_whoami
|
|
|
|
|
|
|
|
changed_when: false
|
|
|
|
|
|
|
|
|
|
|
|
# - assert:
|
|
|
|
- assert:
|
|
|
|
# that:
|
|
|
|
that:
|
|
|
|
# - out.stdout == 'mitogen__pw_required'
|
|
|
|
- sudo_password_success_whoami.stdout == 'mitogen__pw_required'
|
|
|
|
|
|
|
|
fail_msg: |
|
|
|
|
|
|
|
|
sudo_password_success_whoami={{ sudo_password_success_whoami }}
|
|
|
|
|
|
|
|
when:
|
|
|
|
|
|
|
|
# https://github.com/ansible/ansible/pull/70785
|
|
|
|
|
|
|
|
- ansible_facts.distribution not in ["MacOSX"]
|
|
|
|
|
|
|
|
or ansible_version.full is version("2.11", ">=", strict=True)
|
|
|
|
|
|
|
|
or is_mitogen
|
|
|
|
tags:
|
|
|
|
tags:
|
|
|
|
- sudo
|
|
|
|
- sudo
|
|
|
|
- sudo_password
|
|
|
|
- sudo_password
|
|
|
|