ansible/docs/docsite/rst/porting_guides
Sam Doran 5260527c4a
Change default file permissions so they are not world readable (#70221)
* Change default file permissions so they are not world readable

CVE-2020-1736

Set the default permissions for files we create with atomic_move() to 0o0660. Track
which files we create that did not exist and warn if the module supports 'mode'
and it was not specified and the module did not call set_mode_if_different(). This allows the user to take action and specify a mode rather than using the defaults.

A code audit is needed to find all instances of modules that call atomic_move()
but do not call set_mode_if_different(). The findings need to be documented in
a changelog since we are not warning. Warning in those instances would be frustrating
to the user since they have no way to change the module code.

- use a set for storing list of created files
- just check the argument spac and params rather than using another property
- improve the warning message to include the default permissions
2020-07-22 17:05:38 -04:00
..
porting_guide_2.0.rst
porting_guide_2.3.rst remove build errors including guess (#69711) 2020-05-29 11:56:49 -05:00
porting_guide_2.4.rst
porting_guide_2.5.rst Intersphinx (#68090) 2020-03-06 14:16:35 -08:00
porting_guide_2.6.rst
porting_guide_2.7.rst Intersphinx (#68090) 2020-03-06 14:16:35 -08:00
porting_guide_2.8.rst Intersphinx (#68090) 2020-03-06 14:16:35 -08:00
porting_guide_2.9.rst Intersphinx (#68090) 2020-03-06 14:16:35 -08:00
porting_guide_2.10.rst Porting guide: transfer entries to collection changelogs (#70064) 2020-06-16 10:04:32 -05:00
porting_guide_2.11.rst Change default file permissions so they are not world readable (#70221) 2020-07-22 17:05:38 -04:00
porting_guides.rst Bump devel to 2.11.0 (#70121) 2020-06-17 14:22:38 -05:00