Only chown on atomic move if invoked as root
Linux and BSD derivatives do not allow unprivileged users to "give away" files to others for security reasons. (System V derivatives allow that but they're rare nowadays.)
This commit is contained in:
parent
448c0a950e
commit
f4053fcf3a
1 changed files with 1 additions and 1 deletions
|
@ -1146,7 +1146,7 @@ class AnsibleModule(object):
|
||||||
self.set_context_if_different(
|
self.set_context_if_different(
|
||||||
tmp_dest.name, context, False)
|
tmp_dest.name, context, False)
|
||||||
tmp_stat = os.stat(tmp_dest.name)
|
tmp_stat = os.stat(tmp_dest.name)
|
||||||
if dest_stat and (tmp_stat.st_uid != dest_stat.st_uid or tmp_stat.st_gid != dest_stat.st_gid):
|
if dest_stat and (tmp_stat.st_uid != dest_stat.st_uid or tmp_stat.st_gid != dest_stat.st_gid) and os.getuid() == 0:
|
||||||
os.chown(tmp_dest.name, dest_stat.st_uid, dest_stat.st_gid)
|
os.chown(tmp_dest.name, dest_stat.st_uid, dest_stat.st_gid)
|
||||||
os.rename(tmp_dest.name, dest)
|
os.rename(tmp_dest.name, dest)
|
||||||
except (shutil.Error, OSError, IOError), e:
|
except (shutil.Error, OSError, IOError), e:
|
||||||
|
|
Loading…
Reference in a new issue