Only chown on atomic move if invoked as root
Linux and BSD derivatives do not allow unprivileged users to "give away" files to others for security reasons. (System V derivatives allow that but they're rare nowadays.)
This commit is contained in:
parent
448c0a950e
commit
f4053fcf3a
1 changed files with 1 additions and 1 deletions
|
@ -1146,7 +1146,7 @@ class AnsibleModule(object):
|
|||
self.set_context_if_different(
|
||||
tmp_dest.name, context, False)
|
||||
tmp_stat = os.stat(tmp_dest.name)
|
||||
if dest_stat and (tmp_stat.st_uid != dest_stat.st_uid or tmp_stat.st_gid != dest_stat.st_gid):
|
||||
if dest_stat and (tmp_stat.st_uid != dest_stat.st_uid or tmp_stat.st_gid != dest_stat.st_gid) and os.getuid() == 0:
|
||||
os.chown(tmp_dest.name, dest_stat.st_uid, dest_stat.st_gid)
|
||||
os.rename(tmp_dest.name, dest)
|
||||
except (shutil.Error, OSError, IOError), e:
|
||||
|
|
Loading…
Reference in a new issue