mirror of
https://github.com/ansible-collections/ansible.posix.git
synced 2026-07-31 03:44:45 +00:00
Compare commits
56 Commits
2022c1bd86
...
2.2.1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4ac4603af5 | ||
|
|
a4805b92b7 | ||
|
|
ee1461f46c | ||
|
|
78fb77c8d5 | ||
|
|
d4ac6f63f4 | ||
|
|
b42cbb2a97 | ||
|
|
aaacdb9d13 | ||
|
|
955acdca44 | ||
|
|
d9af430396 | ||
|
|
9cf6a06ca7 | ||
|
|
1009d5cb28 | ||
|
|
42feec22c7 | ||
|
|
ec51a15f69 | ||
|
|
0b197ad440 | ||
|
|
165babdd69 | ||
|
|
8b5bba6fa1 | ||
|
|
714c50bdb7 | ||
|
|
c163fb089e | ||
|
|
e29860f4d2 | ||
|
|
668015a48c | ||
|
|
947dacff6a | ||
|
|
76af9b713e | ||
|
|
8f9c844b3d | ||
|
|
d901769726 | ||
|
|
cdce0f5218 | ||
|
|
8feac41f50 | ||
|
|
04274f4ce7 | ||
|
|
1bcf7f3ee4 | ||
|
|
30db9884ce | ||
|
|
d16e94f541 | ||
|
|
535167e254 | ||
|
|
6336671eba | ||
|
|
f7ed590388 | ||
|
|
07c6e38679 | ||
|
|
f6663b7511 | ||
|
|
8831aa205c | ||
|
|
e54b8bf68f | ||
|
|
d792d39716 | ||
|
|
9d3cb96f23 | ||
|
|
a27063e1dc | ||
|
|
2351c27339 | ||
|
|
5902dcab58 | ||
|
|
953577cdb7 | ||
|
|
59493f92aa | ||
|
|
20ea2f068e | ||
|
|
1f1d637b7f | ||
|
|
7128f64169 | ||
|
|
3149f38296 | ||
|
|
8cc459f381 | ||
|
|
82e4990f72 | ||
|
|
98f3e1255e | ||
|
|
a004bd9494 | ||
|
|
a357ceeb49 | ||
|
|
e8fc89fe5a | ||
|
|
ce72b7b1f4 | ||
|
|
f61bb76a86 |
@@ -37,8 +37,9 @@ variables:
|
|||||||
resources:
|
resources:
|
||||||
containers:
|
containers:
|
||||||
- container: default
|
- container: default
|
||||||
|
image: quay.io/ansible/azure-pipelines-test-container:8.0.0
|
||||||
|
- container: legacy
|
||||||
image: quay.io/ansible/azure-pipelines-test-container:7.0.0
|
image: quay.io/ansible/azure-pipelines-test-container:7.0.0
|
||||||
|
|
||||||
pool: Standard
|
pool: Standard
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
@@ -128,6 +129,7 @@ stages:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: templates/matrix.yml
|
- template: templates/matrix.yml
|
||||||
parameters:
|
parameters:
|
||||||
|
container: legacy
|
||||||
nameFormat: "{0}"
|
nameFormat: "{0}"
|
||||||
testFormat: 2.17/{0}
|
testFormat: 2.17/{0}
|
||||||
targets:
|
targets:
|
||||||
@@ -138,6 +140,24 @@ stages:
|
|||||||
- name: Lint
|
- name: Lint
|
||||||
test: lint
|
test: lint
|
||||||
|
|
||||||
|
# 2.16 is LTS
|
||||||
|
- stage: Sanity_2_16
|
||||||
|
displayName: Ansible 2.16 Sanity & Units & Lint
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/matrix.yml
|
||||||
|
parameters:
|
||||||
|
container: legacy
|
||||||
|
nameFormat: "{0}"
|
||||||
|
testFormat: 2.16/{0}
|
||||||
|
targets:
|
||||||
|
- name: Sanity
|
||||||
|
test: sanity
|
||||||
|
- name: Units
|
||||||
|
test: units
|
||||||
|
- name: Lint
|
||||||
|
test: lint
|
||||||
|
|
||||||
## Docker
|
## Docker
|
||||||
- stage: Docker_devel
|
- stage: Docker_devel
|
||||||
displayName: Docker devel
|
displayName: Docker devel
|
||||||
@@ -149,10 +169,10 @@ stages:
|
|||||||
targets:
|
targets:
|
||||||
- name: Fedora 44
|
- name: Fedora 44
|
||||||
test: fedora44
|
test: fedora44
|
||||||
- name: Ubuntu 22.04
|
|
||||||
test: ubuntu2204
|
|
||||||
- name: Ubuntu 24.04
|
- name: Ubuntu 24.04
|
||||||
test: ubuntu2404
|
test: ubuntu2404
|
||||||
|
- name: Ubuntu 26.04
|
||||||
|
test: ubuntu2604
|
||||||
|
|
||||||
- stage: Docker_2_21
|
- stage: Docker_2_21
|
||||||
displayName: Docker 2.21
|
displayName: Docker 2.21
|
||||||
@@ -160,10 +180,10 @@ stages:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: templates/matrix.yml
|
- template: templates/matrix.yml
|
||||||
parameters:
|
parameters:
|
||||||
testFormat: devel/linux/{0}/1
|
testFormat: 2.21/linux/{0}/1
|
||||||
targets:
|
targets:
|
||||||
- name: Fedora 44
|
- name: Fedora 43
|
||||||
test: fedora44
|
test: fedora43
|
||||||
- name: Ubuntu 22.04
|
- name: Ubuntu 22.04
|
||||||
test: ubuntu2204
|
test: ubuntu2204
|
||||||
- name: Ubuntu 24.04
|
- name: Ubuntu 24.04
|
||||||
@@ -220,6 +240,7 @@ stages:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: templates/matrix.yml
|
- template: templates/matrix.yml
|
||||||
parameters:
|
parameters:
|
||||||
|
container: legacy
|
||||||
testFormat: 2.17/linux/{0}/1
|
testFormat: 2.17/linux/{0}/1
|
||||||
targets:
|
targets:
|
||||||
- name: Fedora 39
|
- name: Fedora 39
|
||||||
@@ -227,6 +248,20 @@ stages:
|
|||||||
- name: Ubuntu 22.04
|
- name: Ubuntu 22.04
|
||||||
test: ubuntu2204
|
test: ubuntu2204
|
||||||
|
|
||||||
|
- stage: Docker_2_16
|
||||||
|
displayName: Docker 2.16
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/matrix.yml
|
||||||
|
parameters:
|
||||||
|
container: legacy
|
||||||
|
testFormat: 2.16/linux/{0}/1
|
||||||
|
targets:
|
||||||
|
- name: Fedora 38
|
||||||
|
test: fedora38
|
||||||
|
- name: Ubuntu 22.04
|
||||||
|
test: ubuntu2204
|
||||||
|
|
||||||
## Remote
|
## Remote
|
||||||
- stage: Remote_devel
|
- stage: Remote_devel
|
||||||
displayName: Remote devel
|
displayName: Remote devel
|
||||||
@@ -236,10 +271,10 @@ stages:
|
|||||||
parameters:
|
parameters:
|
||||||
testFormat: devel/{0}/1
|
testFormat: devel/{0}/1
|
||||||
targets:
|
targets:
|
||||||
- name: RHEL 10.1
|
- name: RHEL 10.2
|
||||||
test: rhel/10.1
|
test: rhel/10.2
|
||||||
- name: RHEL 9.7
|
- name: RHEL 9.8
|
||||||
test: rhel/9.7
|
test: rhel/9.8
|
||||||
- name: FreeBSD 14.4
|
- name: FreeBSD 14.4
|
||||||
test: freebsd/14.4
|
test: freebsd/14.4
|
||||||
- name: FreeBSD 15.0
|
- name: FreeBSD 15.0
|
||||||
@@ -251,7 +286,7 @@ stages:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: templates/matrix.yml
|
- template: templates/matrix.yml
|
||||||
parameters:
|
parameters:
|
||||||
testFormat: devel/{0}/1
|
testFormat: 2.21/{0}/1
|
||||||
targets:
|
targets:
|
||||||
- name: RHEL 10.1
|
- name: RHEL 10.1
|
||||||
test: rhel/10.1
|
test: rhel/10.1
|
||||||
@@ -291,8 +326,8 @@ stages:
|
|||||||
test: rhel/10.1
|
test: rhel/10.1
|
||||||
- name: RHEL 9.7
|
- name: RHEL 9.7
|
||||||
test: rhel/9.7
|
test: rhel/9.7
|
||||||
- name: FreeBSD 14.2
|
- name: FreeBSD 14.3
|
||||||
test: freebsd/14.2
|
test: freebsd/14.3
|
||||||
- name: FreeBSD 13.5
|
- name: FreeBSD 13.5
|
||||||
test: freebsd/13.5
|
test: freebsd/13.5
|
||||||
|
|
||||||
@@ -317,19 +352,34 @@ stages:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: templates/matrix.yml
|
- template: templates/matrix.yml
|
||||||
parameters:
|
parameters:
|
||||||
|
container: legacy
|
||||||
testFormat: 2.17/{0}/1
|
testFormat: 2.17/{0}/1
|
||||||
targets:
|
targets:
|
||||||
# 2.17 remote target doesn't have RHEL 9 image
|
|
||||||
- name: RHEL 10.0
|
- name: RHEL 10.0
|
||||||
test: rhel/10.0
|
test: rhel/10.0
|
||||||
- name: FreeBSD 13.5
|
- name: FreeBSD 13.5
|
||||||
test: freebsd/13.5
|
test: freebsd/13.5
|
||||||
|
|
||||||
|
- stage: Remote_2_16
|
||||||
|
displayName: Remote 2.16
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/matrix.yml
|
||||||
|
parameters:
|
||||||
|
container: legacy
|
||||||
|
testFormat: 2.16/{0}/1
|
||||||
|
targets:
|
||||||
|
- name: RHEL 10.1
|
||||||
|
test: rhel/10.1
|
||||||
|
|
||||||
## Finally
|
## Finally
|
||||||
|
|
||||||
- stage: Summary
|
- stage: Summary
|
||||||
condition: succeededOrFailed()
|
condition: succeededOrFailed()
|
||||||
dependsOn:
|
dependsOn:
|
||||||
|
- Sanity_2_16
|
||||||
|
- Remote_2_16
|
||||||
|
- Docker_2_16
|
||||||
- Sanity_2_17
|
- Sanity_2_17
|
||||||
- Remote_2_17
|
- Remote_2_17
|
||||||
- Docker_2_17
|
- Docker_2_17
|
||||||
|
|||||||
@@ -14,6 +14,12 @@ parameters:
|
|||||||
type: object
|
type: object
|
||||||
default: []
|
default: []
|
||||||
|
|
||||||
|
# An optional container resource name to use for the test jobs.
|
||||||
|
# Defaults to "default" if not specified.
|
||||||
|
- name: container
|
||||||
|
type: string
|
||||||
|
default: default
|
||||||
|
|
||||||
# An optional format string used to generate the job name.
|
# An optional format string used to generate the job name.
|
||||||
# - {0} is the name of an item in the targets list.
|
# - {0} is the name of an item in the targets list.
|
||||||
- name: nameFormat
|
- name: nameFormat
|
||||||
@@ -43,6 +49,7 @@ parameters:
|
|||||||
jobs:
|
jobs:
|
||||||
- template: test.yml
|
- template: test.yml
|
||||||
parameters:
|
parameters:
|
||||||
|
container: ${{ parameters.container }}
|
||||||
jobs:
|
jobs:
|
||||||
- ${{ if eq(length(parameters.groups), 0) }}:
|
- ${{ if eq(length(parameters.groups), 0) }}:
|
||||||
- ${{ each target in parameters.targets }}:
|
- ${{ each target in parameters.targets }}:
|
||||||
|
|||||||
@@ -7,11 +7,17 @@ parameters:
|
|||||||
- name: jobs
|
- name: jobs
|
||||||
type: object
|
type: object
|
||||||
|
|
||||||
|
# An optional container resource name to use for the test jobs.
|
||||||
|
# Defaults to "default" if not specified.
|
||||||
|
- name: container
|
||||||
|
type: string
|
||||||
|
default: default
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
- ${{ each job in parameters.jobs }}:
|
- ${{ each job in parameters.jobs }}:
|
||||||
- job: test_${{ replace(replace(replace(job.test, '/', '_'), '.', '_'), '-', '_') }}
|
- job: test_${{ replace(replace(replace(job.test, '/', '_'), '.', '_'), '-', '_') }}
|
||||||
displayName: ${{ job.name }}
|
displayName: ${{ job.name }}
|
||||||
container: default
|
container: ${{ parameters.container }}
|
||||||
workspace:
|
workspace:
|
||||||
clean: all
|
clean: all
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -4,6 +4,92 @@ ansible.posix Release Notes
|
|||||||
|
|
||||||
.. contents:: Topics
|
.. contents:: Topics
|
||||||
|
|
||||||
|
v2.2.1
|
||||||
|
======
|
||||||
|
|
||||||
|
Release Summary
|
||||||
|
---------------
|
||||||
|
|
||||||
|
This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
``ansible.posix`` 2.2.0
|
||||||
|
|
||||||
|
Security Fixes
|
||||||
|
--------------
|
||||||
|
|
||||||
|
- authorized_key - fix local privilege escalation via symlink-following when running as root (https://github.com/ansible-collections/ansible.posix/issues/759).
|
||||||
|
|
||||||
|
Bugfixes
|
||||||
|
--------
|
||||||
|
|
||||||
|
- sysctl - reload sysctl only if the sysctl file is ``/etc/sysctl.conf`` or ``/etc/sysctl.conf.local`` (https://github.com/ansible-collections/ansible.posix/issues/663).
|
||||||
|
|
||||||
|
v2.2.0
|
||||||
|
======
|
||||||
|
|
||||||
|
Release Summary
|
||||||
|
---------------
|
||||||
|
|
||||||
|
This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
``ansible.posix`` 2.1.0
|
||||||
|
|
||||||
|
Minor Changes
|
||||||
|
-------------
|
||||||
|
|
||||||
|
- acl - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- authorized_key - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- cgroup_perf_recap callback - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- csh shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- firewalld_info - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- firewalld_info - use module.warn instead of passing ``warnings`` to ``exit_json`` (https://github.com/ansible-collections/ansible.posix/issues/710).
|
||||||
|
- fish shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- json callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- jsonl callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- mount - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- patch - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- profile_roles callback - fix deprecated ``ansible.module_utils.six`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- profile_tasks - Add option to provide a different date/time format (https://github.com/ansible-collections/ansible.posix/issues/279).
|
||||||
|
- profile_tasks callback - fix deprecated ``ansible.module_utils.six`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- removed ANSIBLE_METADATA from remaining plugins.
|
||||||
|
- rhel_rpm_ostree - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- rpm_ostree_upgrade - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- seboolean - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- synchronize - fix deprecated ``ansible.module_utils._text``, ``ansible.module_utils.common._collections_compat``, and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- sysctl - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
|
||||||
|
Bugfixes
|
||||||
|
--------
|
||||||
|
|
||||||
|
- acl - correctly assert needed changes when pointing to a directory and recursive is set to true.
|
||||||
|
- ansible.posix.authorized_key - fixes error on permission denied in authorized_key module (https://github.com/ansible-collections/ansible.posix/issues/462).
|
||||||
|
- firewalld_info - stop returning warnings as return values; this has been deprecated by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670).
|
||||||
|
- mount - stop returning warnings as return values; this has been deprecated by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670).
|
||||||
|
- patch - removed use of deprecated ``_AnsibleActionDone`` API (https://github.com/ansible-collections/ansible.posix/pull/687).
|
||||||
|
|
||||||
|
v2.1.0
|
||||||
|
======
|
||||||
|
|
||||||
|
Release Summary
|
||||||
|
---------------
|
||||||
|
|
||||||
|
This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
``ansible.posix`` 2.0.0
|
||||||
|
|
||||||
|
Minor Changes
|
||||||
|
-------------
|
||||||
|
|
||||||
|
- profile_tasks and profile_roles callback plugins - avoid deleted/deprecated callback functions, instead use modern interface that was introduced a longer time ago (https://github.com/ansible-collections/ansible.posix/issues/650).
|
||||||
|
|
||||||
|
Bugfixes
|
||||||
|
--------
|
||||||
|
|
||||||
|
- ansible.posix.cgroup_perf_recap - fixes json module load path (https://github.com/ansible-collections/ansible.posix/issues/630).
|
||||||
|
|
||||||
v2.0.0
|
v2.0.0
|
||||||
======
|
======
|
||||||
|
|
||||||
|
|||||||
13
README.md
13
README.md
@@ -78,10 +78,15 @@ ansible-doc -t callback ansible.posix.profile_tasks
|
|||||||
|
|
||||||
The following ansible-core versions have been tested with this collection:
|
The following ansible-core versions have been tested with this collection:
|
||||||
|
|
||||||
- ansible-core 2.20 (devel)
|
- ansible-core 2.22 (devel)
|
||||||
- ansible-core 2.19 (stable) *
|
- ansible-core 2.21 (stable)
|
||||||
- ansible-core 2.18 (stable)
|
- ansible-core 2.20 (stable)
|
||||||
- ansible-core 2.17 (stable)
|
- ansible-core 2.19 (stable)
|
||||||
|
- ansible-core 2.18 (LTS)
|
||||||
|
- ansible-core 2.17 (EoL)
|
||||||
|
- ansible-core 2.16 (EoL)
|
||||||
|
|
||||||
|
For most up to date support info, see the [ansible-core support matrix](https://docs.ansible.com/projects/ansible/latest/reference_appendices/release_and_maintenance.html#ansible-core-support-matrix)
|
||||||
|
|
||||||
## Contributing
|
## Contributing
|
||||||
|
|
||||||
|
|||||||
@@ -490,3 +490,115 @@ releases:
|
|||||||
- 597_remove_fstab_comment_on_updating.yml
|
- 597_remove_fstab_comment_on_updating.yml
|
||||||
- 598_icmp_block_inversion.yml
|
- 598_icmp_block_inversion.yml
|
||||||
release_date: '2024-12-04'
|
release_date: '2024-12-04'
|
||||||
|
2.1.0:
|
||||||
|
changes:
|
||||||
|
bugfixes:
|
||||||
|
- ansible.posix.cgroup_perf_recap - fixes json module load path (https://github.com/ansible-collections/ansible.posix/issues/630).
|
||||||
|
minor_changes:
|
||||||
|
- profile_tasks and profile_roles callback plugins - avoid deleted/deprecated
|
||||||
|
callback functions, instead use modern interface that was introduced a longer
|
||||||
|
time ago (https://github.com/ansible-collections/ansible.posix/issues/650).
|
||||||
|
release_summary: 'This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
|
||||||
|
``ansible.posix`` 2.0.0'
|
||||||
|
fragments:
|
||||||
|
- 2.1.0.yml
|
||||||
|
- 631_fixes_module_path.yml
|
||||||
|
- 642_ci_add_rhel10.yml
|
||||||
|
- 650-profile_tasks_roles.yml
|
||||||
|
- 654_ci_bump_core_version.yml
|
||||||
|
release_date: '2025-07-16'
|
||||||
|
2.2.0:
|
||||||
|
changes:
|
||||||
|
bugfixes:
|
||||||
|
- acl - correctly assert needed changes when pointing to a directory and recursive
|
||||||
|
is set to true.
|
||||||
|
- ansible.posix.authorized_key - fixes error on permission denied in authorized_key
|
||||||
|
module (https://github.com/ansible-collections/ansible.posix/issues/462).
|
||||||
|
- firewalld_info - stop returning warnings as return values; this has been deprecated
|
||||||
|
by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670).
|
||||||
|
- mount - stop returning warnings as return values; this has been deprecated
|
||||||
|
by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670).
|
||||||
|
- patch - removed use of deprecated ``_AnsibleActionDone`` API (https://github.com/ansible-collections/ansible.posix/pull/687).
|
||||||
|
minor_changes:
|
||||||
|
- acl - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- authorized_key - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six``
|
||||||
|
imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- cgroup_perf_recap callback - fix deprecated ``ansible.module_utils._text``
|
||||||
|
and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- csh shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- firewalld_info - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- firewalld_info - use module.warn instead of passing ``warnings`` to ``exit_json``
|
||||||
|
(https://github.com/ansible-collections/ansible.posix/issues/710).
|
||||||
|
- fish shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- json callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- jsonl callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- mount - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six``
|
||||||
|
imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- patch - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- profile_roles callback - fix deprecated ``ansible.module_utils.six`` import
|
||||||
|
(https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- profile_tasks - Add option to provide a different date/time format (https://github.com/ansible-collections/ansible.posix/issues/279).
|
||||||
|
- profile_tasks callback - fix deprecated ``ansible.module_utils.six`` import
|
||||||
|
(https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- removed ANSIBLE_METADATA from remaining plugins.
|
||||||
|
- rhel_rpm_ostree - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- rpm_ostree_upgrade - fix deprecated ``ansible.module_utils._text`` import
|
||||||
|
(https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- seboolean - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- synchronize - fix deprecated ``ansible.module_utils._text``, ``ansible.module_utils.common._collections_compat``,
|
||||||
|
and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
- sysctl - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six``
|
||||||
|
imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
||||||
|
release_summary: 'This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
|
||||||
|
``ansible.posix`` 2.1.0'
|
||||||
|
fragments:
|
||||||
|
- 2.2.0.yml
|
||||||
|
- 626_profile_tasks_datetime_format.yml
|
||||||
|
- 638_fix_recursive_acl.yml
|
||||||
|
- 639_fix_authorized_key.yml
|
||||||
|
- 660_ci_azp_syntax.yml
|
||||||
|
- 665_update_readme_20250728.yml
|
||||||
|
- 666_azp_update_20250728.yml
|
||||||
|
- 670-deprecations.yml
|
||||||
|
- 673_update_ci_20250805.yml
|
||||||
|
- 682_update_ci_20250929.yml
|
||||||
|
- 686_fix_deprecated_imports.yml
|
||||||
|
- 693_azp_update_20251205.yml
|
||||||
|
- ansible_metadata_removed.yml
|
||||||
|
- firewalld_info_warnings.yml
|
||||||
|
- patch_removed.yml
|
||||||
|
release_date: '2026-05-18'
|
||||||
|
2.2.1:
|
||||||
|
changes:
|
||||||
|
bugfixes:
|
||||||
|
- sysctl - reload sysctl only if the sysctl file is ``/etc/sysctl.conf`` or
|
||||||
|
``/etc/sysctl.conf.local`` (https://github.com/ansible-collections/ansible.posix/issues/663).
|
||||||
|
release_summary: 'This is the minor release of the ``ansible.posix`` collection.
|
||||||
|
|
||||||
|
This changelog contains all changes to the modules and plugins
|
||||||
|
|
||||||
|
in the stable-2 branch that have been added after the release of
|
||||||
|
|
||||||
|
``ansible.posix`` 2.2.0'
|
||||||
|
security_fixes:
|
||||||
|
- authorized_key - fix local privilege escalation via symlink-following when
|
||||||
|
running as root (https://github.com/ansible-collections/ansible.posix/issues/759).
|
||||||
|
fragments:
|
||||||
|
- 2.2.1.yml
|
||||||
|
- 643-sysctl-docs.yml
|
||||||
|
- 751_ci_test_container_update.yml
|
||||||
|
- 755_ci_test_container_update.yml
|
||||||
|
- 759_cve_2026_11837.yml
|
||||||
|
- 763_ci_azp_update_devel.yml
|
||||||
|
- freebsd_sysctl.yml
|
||||||
|
release_date: '2026-07-01'
|
||||||
|
|||||||
@@ -1,2 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- Bump version to 3.0.0 for the next release (https://github.com/ansible-collections/ansible.posix/issues/603).
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- Remove ubuntu20.04 from CI tests (https://github.com/ansible-collections/ansible.posix/issues/612).
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
minor_changes:
|
|
||||||
- profile_tasks - Add option to provide a different date/time format (https://github.com/ansible-collections/ansible.posix/issues/279).
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
bugfixes:
|
|
||||||
- ansible.posix.cgroup_perf_recap - fixes json module load path (https://github.com/ansible-collections/ansible.posix/issues/630).
|
|
||||||
trivial:
|
|
||||||
- ansible.posix.seboolean - remove unnecessary condition from seboolean integration tests (https://github.com/ansible-collections/ansible.posix/issues/630).
|
|
||||||
- ansible.posix.selinux - optimize conditions for selinux integration tests (https://github.com/ansible-collections/ansible.posix/issues/630).
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
bugfixes:
|
|
||||||
- ansible.posix.authorized_key - fixes error on permission denied in authorized_key module (https://github.com/ansible-collections/ansible.posix/issues/462).
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- Add Red Hat Enterprise Linux 10.0 to the CI matrix (https://github.com/ansible-collections/ansible.posix/issues/642).
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
minor_changes:
|
|
||||||
- "profile_tasks and profile_roles callback plugins - avoid deleted/deprecated callback functions, instead use modern interface that was introduced a longer time ago (https://github.com/ansible-collections/ansible.posix/issues/650)."
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
trivial:
|
|
||||||
- Bump ansible-core version to 2.20 of devel branch and add 2.19 to CI
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- AZP - fixed syntax error in CI test.
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
trivial:
|
|
||||||
- README - Update README to reflect Ansible Core 2.19 release.
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
trivial:
|
|
||||||
- AZP - Update AZP matrix to follow ansible-test changes.
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
bugfixes:
|
|
||||||
- "firewalld_info - stop returning warnings as return values; this has been deprecated by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670)."
|
|
||||||
- "mount - stop returning warnings as return values; this has been deprecated by ansible-core (https://github.com/ansible-collections/ansible.posix/pull/670)."
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- Update AZP CI matrix (https://github.com/ansible-collections/ansible.posix/issues/673).
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
trivial:
|
|
||||||
- Updatng AZP CI matrix to ignore ansible-bad-import-from on six(https://github.com/ansible-collections/ansible.posix/pull/682).
|
|
||||||
- Skipped sanity[cannot-ignore] to keep backward compatibility with Python2.
|
|
||||||
- Consolidate all ansible-lint option locations into .ansible-lint file.
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
minor_changes:
|
|
||||||
- acl - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- authorized_key - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- cgroup_perf_recap callback - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- csh shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- firewalld_info - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- fish shell plugin - fix deprecated ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- json callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- jsonl callback - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- mount - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- patch - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- profile_roles callback - fix deprecated ``ansible.module_utils.six`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- profile_tasks callback - fix deprecated ``ansible.module_utils.six`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- rhel_rpm_ostree - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- rpm_ostree_upgrade - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- seboolean - fix deprecated ``ansible.module_utils._text`` import (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- synchronize - fix deprecated ``ansible.module_utils._text``, ``ansible.module_utils.common._collections_compat``, and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
- sysctl - fix deprecated ``ansible.module_utils._text`` and ``ansible.module_utils.six`` imports (https://github.com/ansible-collections/ansible.posix/issues/686).
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
---
|
|
||||||
trivial:
|
|
||||||
- AZP - Update AZP matrix to follow ansible-test changes.
|
|
||||||
- Add ignore file for Ansible Core 2.21.
|
|
||||||
- Remove ignore lines for ansible-bad-import-from in 2.20 sanity tests.
|
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
namespace: ansible
|
namespace: ansible
|
||||||
name: posix
|
name: posix
|
||||||
version: 3.0.0
|
version: 2.2.1
|
||||||
readme: README.md
|
readme: README.md
|
||||||
authors:
|
authors:
|
||||||
- Ansible (github.com/ansible)
|
- Ansible (github.com/ansible)
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ __metaclass__ = type
|
|||||||
|
|
||||||
import os
|
import os
|
||||||
|
|
||||||
from ansible.errors import AnsibleError, AnsibleAction, _AnsibleActionDone, AnsibleActionFail
|
from ansible.errors import AnsibleError, AnsibleAction, AnsibleActionFail
|
||||||
from ansible.module_utils.common.text.converters import to_native
|
from ansible.module_utils.common.text.converters import to_native
|
||||||
from ansible.module_utils.parsing.convert_bool import boolean
|
from ansible.module_utils.parsing.convert_bool import boolean
|
||||||
from ansible.plugins.action import ActionBase
|
from ansible.plugins.action import ActionBase
|
||||||
@@ -46,7 +46,8 @@ class ActionModule(ActionBase):
|
|||||||
elif remote_src:
|
elif remote_src:
|
||||||
# everything is remote, so we just execute the module
|
# everything is remote, so we just execute the module
|
||||||
# without changing any of the module arguments
|
# without changing any of the module arguments
|
||||||
raise _AnsibleActionDone(result=self._execute_module(task_vars=task_vars))
|
result.update(self._execute_module(task_vars=task_vars))
|
||||||
|
return result
|
||||||
|
|
||||||
try:
|
try:
|
||||||
src = self._find_needle('files', src)
|
src = self._find_needle('files', src)
|
||||||
|
|||||||
@@ -6,9 +6,6 @@
|
|||||||
from __future__ import (absolute_import, division, print_function)
|
from __future__ import (absolute_import, division, print_function)
|
||||||
__metaclass__ = type
|
__metaclass__ = type
|
||||||
|
|
||||||
ANSIBLE_METADATA = {'metadata_version': '1.1',
|
|
||||||
'status': ['preview'],
|
|
||||||
'supported_by': 'community'}
|
|
||||||
|
|
||||||
DOCUMENTATION = '''
|
DOCUMENTATION = '''
|
||||||
name: cgroup_perf_recap
|
name: cgroup_perf_recap
|
||||||
|
|||||||
@@ -244,16 +244,16 @@ def acl_changed(module, cmd, entry, use_nfsv4_acls=False):
|
|||||||
lines = run_acl(module, cmd)
|
lines = run_acl(module, cmd)
|
||||||
counter = 0
|
counter = 0
|
||||||
for line in lines:
|
for line in lines:
|
||||||
if line.endswith('*,*') and not use_nfsv4_acls:
|
if not use_nfsv4_acls and not line.endswith('*,*'):
|
||||||
return False
|
return True
|
||||||
# if use_nfsv4_acls and entry is listed
|
# if use_nfsv4_acls and entry is listed
|
||||||
if use_nfsv4_acls and entry == line:
|
if use_nfsv4_acls and entry == line:
|
||||||
counter += 1
|
counter += 1
|
||||||
|
|
||||||
# The current 'nfs4_setfacl --test' lists a new entry,
|
# The current 'nfs4_setfacl --test' lists a new entry,
|
||||||
# which will be added at the top of list, followed by the existing entries.
|
# which will be added at the top of the list, followed by the existing entries.
|
||||||
# So if the entry has already been registered, the entry should be find twice.
|
# So if the entry has already been registered, the entry should be found twice.
|
||||||
if counter == 2:
|
if not use_nfsv4_acls or counter == 2:
|
||||||
return False
|
return False
|
||||||
return True
|
return True
|
||||||
|
|
||||||
|
|||||||
@@ -121,10 +121,10 @@ EXAMPLES = r'''
|
|||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
user: deploy
|
user: deploy
|
||||||
state: present
|
state: present
|
||||||
key: '{{ item }}'
|
key: "{{ lookup('file', item) }}"
|
||||||
with_file:
|
loop:
|
||||||
- public_keys/doe-jane
|
- public_keys/doe-jane
|
||||||
- public_keys/doe-john
|
- public_keys/doe-john
|
||||||
|
|
||||||
- name: Set authorized key defining key options
|
- name: Set authorized key defining key options
|
||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
@@ -307,6 +307,17 @@ class keydict(dict):
|
|||||||
return [item[1] for item in self.items()]
|
return [item[1] for item in self.items()]
|
||||||
|
|
||||||
|
|
||||||
|
def _safe_open_write(module, path, follow):
|
||||||
|
flags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC
|
||||||
|
if not follow and hasattr(os, 'O_NOFOLLOW'):
|
||||||
|
flags |= os.O_NOFOLLOW
|
||||||
|
try:
|
||||||
|
fd = os.open(path, flags, int('0600', 8))
|
||||||
|
except OSError as e:
|
||||||
|
module.fail_json(msg="File open failed %s : %s" % (path, to_native(e)))
|
||||||
|
return fd
|
||||||
|
|
||||||
|
|
||||||
def keyfile(module, user, write=False, path=None, manage_dir=True, follow=False):
|
def keyfile(module, user, write=False, path=None, manage_dir=True, follow=False):
|
||||||
"""
|
"""
|
||||||
Calculate name of authorized keys file, optionally creating the
|
Calculate name of authorized keys file, optionally creating the
|
||||||
@@ -359,7 +370,7 @@ def keyfile(module, user, write=False, path=None, manage_dir=True, follow=False)
|
|||||||
module.fail_json(msg="Failed to create directory %s : %s" % (sshdir, to_native(e)))
|
module.fail_json(msg="Failed to create directory %s : %s" % (sshdir, to_native(e)))
|
||||||
if module.selinux_enabled():
|
if module.selinux_enabled():
|
||||||
module.set_default_selinux_context(sshdir, False)
|
module.set_default_selinux_context(sshdir, False)
|
||||||
os.chown(sshdir, uid, gid)
|
os.chown(sshdir, uid, gid, follow_symlinks=follow)
|
||||||
os.chmod(sshdir, int('0700', 8))
|
os.chmod(sshdir, int('0700', 8))
|
||||||
|
|
||||||
if not os.path.exists(keysfile):
|
if not os.path.exists(keysfile):
|
||||||
@@ -367,16 +378,13 @@ def keyfile(module, user, write=False, path=None, manage_dir=True, follow=False)
|
|||||||
if not os.path.exists(basedir):
|
if not os.path.exists(basedir):
|
||||||
os.makedirs(basedir)
|
os.makedirs(basedir)
|
||||||
|
|
||||||
f = None
|
fd = _safe_open_write(module, keysfile, follow)
|
||||||
try:
|
os.close(fd)
|
||||||
f = open(keysfile, "w") # touches file so we can set ownership and perms
|
|
||||||
finally:
|
|
||||||
f.close()
|
|
||||||
if module.selinux_enabled():
|
if module.selinux_enabled():
|
||||||
module.set_default_selinux_context(keysfile, False)
|
module.set_default_selinux_context(keysfile, False)
|
||||||
|
|
||||||
try:
|
try:
|
||||||
os.chown(keysfile, uid, gid)
|
os.chown(keysfile, uid, gid, follow_symlinks=follow)
|
||||||
os.chmod(keysfile, int('0600', 8))
|
os.chmod(keysfile, int('0600', 8))
|
||||||
except OSError:
|
except OSError:
|
||||||
pass
|
pass
|
||||||
@@ -607,7 +615,7 @@ def enforce_state(module, params):
|
|||||||
|
|
||||||
# check current state -- just get the filename, don't create file
|
# check current state -- just get the filename, don't create file
|
||||||
do_write = False
|
do_write = False
|
||||||
params["keyfile"] = keyfile(module, user, do_write, path, manage_dir)
|
params["keyfile"] = keyfile(module, user, do_write, path, manage_dir, follow)
|
||||||
existing_content = readfile(module, params["keyfile"])
|
existing_content = readfile(module, params["keyfile"])
|
||||||
existing_keys = parsekeys(module, existing_content)
|
existing_keys = parsekeys(module, existing_content)
|
||||||
|
|
||||||
@@ -696,6 +704,11 @@ def enforce_state(module, params):
|
|||||||
|
|
||||||
if not module.check_mode:
|
if not module.check_mode:
|
||||||
writefile(module, filename, new_content)
|
writefile(module, filename, new_content)
|
||||||
|
user_entry = pwd.getpwnam(user)
|
||||||
|
uid = user_entry.pw_uid
|
||||||
|
gid = user_entry.pw_gid
|
||||||
|
os.chown(filename, uid, gid, follow_symlinks=follow)
|
||||||
|
os.chmod(filename, int('0600', 8))
|
||||||
params['changed'] = True
|
params['changed'] = True
|
||||||
|
|
||||||
return params
|
return params
|
||||||
|
|||||||
@@ -333,10 +333,6 @@ def main():
|
|||||||
if not HAS_FIREWALLD:
|
if not HAS_FIREWALLD:
|
||||||
module.fail_json(msg=missing_required_lib('python-firewall'))
|
module.fail_json(msg=missing_required_lib('python-firewall'))
|
||||||
|
|
||||||
# If you want to show warning messages in the task running process,
|
|
||||||
# you can append the message to the 'warn' list.
|
|
||||||
warn = list()
|
|
||||||
|
|
||||||
try:
|
try:
|
||||||
client = fw_client.FirewallClient()
|
client = fw_client.FirewallClient()
|
||||||
|
|
||||||
@@ -356,8 +352,7 @@ def main():
|
|||||||
collect_zones = list(set(specified_zones) & set(all_zones))
|
collect_zones = list(set(specified_zones) & set(all_zones))
|
||||||
ignore_zones = list(set(specified_zones) - set(collect_zones))
|
ignore_zones = list(set(specified_zones) - set(collect_zones))
|
||||||
if ignore_zones:
|
if ignore_zones:
|
||||||
warn.append(
|
module.warn('Please note: zone:(%s) have been ignored in the gathering process.' % ", ".join(ignore_zones))
|
||||||
'Please note: zone:(%s) have been ignored in the gathering process.' % ','.join(ignore_zones))
|
|
||||||
else:
|
else:
|
||||||
collect_zones = get_all_zones(client)
|
collect_zones = get_all_zones(client)
|
||||||
|
|
||||||
@@ -396,7 +391,6 @@ def main():
|
|||||||
result['collected_zones'] = collect_zones
|
result['collected_zones'] = collect_zones
|
||||||
result['undefined_zones'] = ignore_zones
|
result['undefined_zones'] = ignore_zones
|
||||||
result['firewalld_info'] = firewalld_info
|
result['firewalld_info'] = firewalld_info
|
||||||
result['warnings'] = warn
|
|
||||||
module.exit_json(**result)
|
module.exit_json(**result)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -7,9 +7,6 @@
|
|||||||
from __future__ import absolute_import, division, print_function
|
from __future__ import absolute_import, division, print_function
|
||||||
__metaclass__ = type
|
__metaclass__ = type
|
||||||
|
|
||||||
ANSIBLE_METADATA = {'metadata_version': '1.1',
|
|
||||||
'status': ['preview'],
|
|
||||||
'supported_by': 'community'}
|
|
||||||
|
|
||||||
DOCUMENTATION = '''
|
DOCUMENTATION = '''
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -7,9 +7,6 @@
|
|||||||
from __future__ import absolute_import, division, print_function
|
from __future__ import absolute_import, division, print_function
|
||||||
__metaclass__ = type
|
__metaclass__ = type
|
||||||
|
|
||||||
ANSIBLE_METADATA = {'metadata_version': '1.1',
|
|
||||||
'status': ['preview'],
|
|
||||||
'supported_by': 'community'}
|
|
||||||
|
|
||||||
DOCUMENTATION = '''
|
DOCUMENTATION = '''
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -44,6 +44,7 @@ options:
|
|||||||
- If V(true), performs a C(/sbin/sysctl -p) if the O(sysctl_file) is
|
- If V(true), performs a C(/sbin/sysctl -p) if the O(sysctl_file) is
|
||||||
updated. If V(false), does not reload C(sysctl) even if the
|
updated. If V(false), does not reload C(sysctl) even if the
|
||||||
O(sysctl_file) is updated.
|
O(sysctl_file) is updated.
|
||||||
|
- For FreeBSD, can not be used with O(sysctl_file) other than C(/etc/sysctl.conf) or C(/etc/sysctl.conf.local).
|
||||||
type: bool
|
type: bool
|
||||||
default: true
|
default: true
|
||||||
sysctl_file:
|
sysctl_file:
|
||||||
@@ -56,6 +57,17 @@ options:
|
|||||||
- Verify token value with the sysctl command and set with C(-w) if necessary.
|
- Verify token value with the sysctl command and set with C(-w) if necessary.
|
||||||
type: bool
|
type: bool
|
||||||
default: false
|
default: false
|
||||||
|
attributes:
|
||||||
|
check_mode:
|
||||||
|
support: full
|
||||||
|
description: Can run in check_mode and return changed status prediction without modifying target.
|
||||||
|
diff_mode:
|
||||||
|
support: none
|
||||||
|
description: Does not support differences output.
|
||||||
|
platform:
|
||||||
|
platforms: posix
|
||||||
|
support: full
|
||||||
|
description: Supported on POSIX-compliant systems.
|
||||||
author:
|
author:
|
||||||
- David CHANIAL (@davixx)
|
- David CHANIAL (@davixx)
|
||||||
'''
|
'''
|
||||||
@@ -155,6 +167,11 @@ class SysctlModule(object):
|
|||||||
|
|
||||||
self.platform = platform.system().lower()
|
self.platform = platform.system().lower()
|
||||||
|
|
||||||
|
# system specific tests
|
||||||
|
freebsd_sysctl_files = ['/etc/sysctl.conf', '/etc/sysctl.conf.local']
|
||||||
|
if self.platform == 'freebsd' and self.sysctl_file not in freebsd_sysctl_files and self.args['reload']:
|
||||||
|
self.module.fail_json(msg="%s can not be reloaded. Set reload=False." % self.sysctl_file)
|
||||||
|
|
||||||
# Whitespace is bad
|
# Whitespace is bad
|
||||||
self.args['name'] = self.args['name'].strip()
|
self.args['name'] = self.args['name'].strip()
|
||||||
self.args['value'] = self._parse_value(self.args['value'])
|
self.args['value'] = self._parse_value(self.args['value'])
|
||||||
|
|||||||
@@ -1,20 +1,6 @@
|
|||||||
---
|
---
|
||||||
# (c) 2017, Martin Krizek <mkrizek@redhat.com>
|
# (c) 2017, Martin Krizek <mkrizek@redhat.com>
|
||||||
|
# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
|
||||||
# This file is part of Ansible
|
|
||||||
#
|
|
||||||
# Ansible is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# Ansible is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
- name: Create ansible user
|
- name: Create ansible user
|
||||||
ansible.builtin.user:
|
ansible.builtin.user:
|
||||||
@@ -43,15 +29,17 @@
|
|||||||
|
|
||||||
- name: Create ansible dir
|
- name: Create ansible dir
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "{{ test_dir }}"
|
path: "{{ item.path }}"
|
||||||
state: directory
|
state: directory
|
||||||
mode: "0755"
|
mode: "{{ item.mode }}"
|
||||||
|
loop:
|
||||||
|
- { path: "{{ test_dir }}", mode: "0755" }
|
||||||
|
- { path: "{{ test_recursive_dir }}", mode: "0755" }
|
||||||
|
|
||||||
- name: Install acl package
|
- name: Install acl package
|
||||||
ansible.builtin.package:
|
ansible.builtin.package:
|
||||||
name: acl
|
name: acl
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
- name: Grant ansible user read access to a file
|
- name: Grant ansible user read access to a file
|
||||||
ansible.posix.acl:
|
ansible.posix.acl:
|
||||||
@@ -249,3 +237,38 @@
|
|||||||
- "'default:mask::rwx' in getfacl_output.stdout_lines"
|
- "'default:mask::rwx' in getfacl_output.stdout_lines"
|
||||||
- "'default:other::r-x' in getfacl_output.stdout_lines"
|
- "'default:other::r-x' in getfacl_output.stdout_lines"
|
||||||
- "'default:group:{{ test_group }}:rw-' not in getfacl_output.stdout_lines"
|
- "'default:group:{{ test_group }}:rw-' not in getfacl_output.stdout_lines"
|
||||||
|
|
||||||
|
##############################################################################
|
||||||
|
|
||||||
|
- name: create file
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: "{{ test_recursive_dir }}/txt.txt"
|
||||||
|
mode: '0440'
|
||||||
|
content: "hw"
|
||||||
|
|
||||||
|
- name: Change ACLs recursively
|
||||||
|
ansible.posix.acl:
|
||||||
|
path: "{{ test_recursive_dir }}"
|
||||||
|
entity: "{{ test_user }}"
|
||||||
|
etype: user
|
||||||
|
permissions: rX
|
||||||
|
state: present
|
||||||
|
recursive: true
|
||||||
|
register: output_acl_change
|
||||||
|
|
||||||
|
- name: Remove ACLs recursively again
|
||||||
|
ansible.posix.acl:
|
||||||
|
path: "{{ test_recursive_dir }}"
|
||||||
|
entity: "{{ test_user }}"
|
||||||
|
etype: user
|
||||||
|
permissions: r
|
||||||
|
state: present
|
||||||
|
recursive: true
|
||||||
|
register: output_acl_remove
|
||||||
|
|
||||||
|
- assert:
|
||||||
|
that:
|
||||||
|
- output_acl_change is changed
|
||||||
|
- output_acl_change is not failed
|
||||||
|
- output_acl_remove is changed
|
||||||
|
- output_acl_remove is not failed
|
||||||
|
|||||||
@@ -1,20 +1,6 @@
|
|||||||
---
|
---
|
||||||
# (c) 2017, Martin Krizek <mkrizek@redhat.com>
|
# (c) 2017, Martin Krizek <mkrizek@redhat.com>
|
||||||
|
# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
|
||||||
# This file is part of Ansible
|
|
||||||
#
|
|
||||||
# Ansible is free software: you can redistribute it and/or modify
|
|
||||||
# it under the terms of the GNU General Public License as published by
|
|
||||||
# the Free Software Foundation, either version 3 of the License, or
|
|
||||||
# (at your option) any later version.
|
|
||||||
#
|
|
||||||
# Ansible is distributed in the hope that it will be useful,
|
|
||||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
||||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
||||||
# GNU General Public License for more details.
|
|
||||||
#
|
|
||||||
# You should have received a copy of the GNU General Public License
|
|
||||||
# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
|
|
||||||
|
|
||||||
- name: Test ACL
|
- name: Test ACL
|
||||||
vars:
|
vars:
|
||||||
@@ -22,6 +8,7 @@
|
|||||||
test_group: ansible_group
|
test_group: ansible_group
|
||||||
test_file: "{{ output_dir }}/ansible file"
|
test_file: "{{ output_dir }}/ansible file"
|
||||||
test_dir: "{{ output_dir }}/ansible_dir/with some space"
|
test_dir: "{{ output_dir }}/ansible_dir/with some space"
|
||||||
|
test_recursive_dir: "{{ output_dir }}/recursive_dir"
|
||||||
block:
|
block:
|
||||||
- name: Include tests task file
|
- name: Include tests task file
|
||||||
ansible.builtin.include_tasks: acl.yml
|
ansible.builtin.include_tasks: acl.yml
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
---
|
||||||
|
#
|
||||||
|
# Check: keysfile is symlink and follow=false
|
||||||
|
#
|
||||||
|
- name: Try to add key with keysfile as symlink
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: testuser
|
||||||
|
key: "{{ rsa_key_basic }}"
|
||||||
|
state: present
|
||||||
|
manage_dir: false
|
||||||
|
follow: false
|
||||||
|
|
||||||
|
- name: Assert target file ownership unchanged
|
||||||
|
ansible.builtin.stat:
|
||||||
|
path: /tmp/symlink_test_target/target_file
|
||||||
|
register: target_file_stat
|
||||||
|
|
||||||
|
- name: Verify target file is still owned by root
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- target_file_stat.stat.uid == 0
|
||||||
|
...
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
- name: Remove testuser
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: testuser
|
||||||
|
state: absent
|
||||||
|
remove: true
|
||||||
|
|
||||||
|
- name: Remove symlink target directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /tmp/symlink_test_target
|
||||||
|
state: absent
|
||||||
|
...
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
---
|
||||||
|
- name: Create testuser for symlink tests
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: testuser
|
||||||
|
create_home: true
|
||||||
|
register: testuser_result
|
||||||
|
|
||||||
|
- name: Create symlink target directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /tmp/symlink_test_target
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
mode: '0700'
|
||||||
|
|
||||||
|
- name: Create a target file owned by root
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /tmp/symlink_test_target/target_file
|
||||||
|
content: "sensitive data"
|
||||||
|
owner: root
|
||||||
|
mode: '0600'
|
||||||
|
|
||||||
|
- name: Remove .ssh directory if exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ testuser_result.home }}/.ssh"
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- name: Create .ssh directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ testuser_result.home }}/.ssh"
|
||||||
|
state: directory
|
||||||
|
mode: '0700'
|
||||||
|
|
||||||
|
- name: Create symlink from authorized_keys to target file
|
||||||
|
ansible.builtin.file:
|
||||||
|
src: /tmp/symlink_test_target/target_file
|
||||||
|
dest: "{{ testuser_result.home }}/.ssh/authorized_keys"
|
||||||
|
state: link
|
||||||
|
...
|
||||||
@@ -17,7 +17,7 @@
|
|||||||
# You should have received a copy of the GNU General Public License
|
# You should have received a copy of the GNU General Public License
|
||||||
# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
|
# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
|
||||||
|
|
||||||
- name: Setup testing environment
|
- name: Setup for testing environment
|
||||||
ansible.builtin.import_tasks: setup_steps.yml
|
ansible.builtin.import_tasks: setup_steps.yml
|
||||||
|
|
||||||
- name: Test for multiple keys handling
|
- name: Test for multiple keys handling
|
||||||
@@ -37,3 +37,12 @@
|
|||||||
|
|
||||||
- name: Test for permission denied files
|
- name: Test for permission denied files
|
||||||
ansible.builtin.import_tasks: check_permissions.yml
|
ansible.builtin.import_tasks: check_permissions.yml
|
||||||
|
|
||||||
|
- name: CVE-2026-11837 Setup for symlink tests
|
||||||
|
ansible.builtin.import_tasks: check_symlink_setup.yml
|
||||||
|
|
||||||
|
- name: CVE-2026-11837 Test for symlink tests
|
||||||
|
ansible.builtin.import_tasks: check_symlink.yml
|
||||||
|
|
||||||
|
- name: CVE-2026-11837 Cleanup symlink test
|
||||||
|
ansible.builtin.import_tasks: check_symlink_cleanup.yml
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
- name: Assert turn active_zones true
|
- name: Assert turn active_zones true
|
||||||
ansible.builtin.assert:
|
ansible.builtin.assert:
|
||||||
that:
|
that:
|
||||||
|
- result.collected_zones == ['public']
|
||||||
|
|
||||||
- name: Ensure firewalld_zones with zone list
|
- name: Ensure firewalld_zones with zone list
|
||||||
ansible.posix.firewalld_info:
|
ansible.posix.firewalld_info:
|
||||||
@@ -31,3 +32,6 @@
|
|||||||
- name: Assert specified zones
|
- name: Assert specified zones
|
||||||
ansible.builtin.assert:
|
ansible.builtin.assert:
|
||||||
that:
|
that:
|
||||||
|
- result.collected_zones == ['public']
|
||||||
|
- result.undefined_zones == ['invalid_zone']
|
||||||
|
- '"invalid_zone" in result.warnings[0]'
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
tests/utils/shippable/check_matrix.py replace-urlopen
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
tests/utils/shippable/check_matrix.py replace-urlopen
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
boto3
|
|
||||||
placebo
|
|
||||||
pycrypto
|
|
||||||
passlib
|
|
||||||
pypsrp
|
|
||||||
python-memcached
|
|
||||||
pytz
|
|
||||||
pyvmomi
|
|
||||||
redis
|
|
||||||
requests
|
|
||||||
setuptools > 0.6 # pytest-xdist installed via requirements does not work with very old setuptools (sanity_ok)
|
|
||||||
unittest2 ; python_version < '2.7'
|
|
||||||
importlib ; python_version < '2.7'
|
|
||||||
netaddr
|
|
||||||
ipaddress
|
|
||||||
netapp-lib
|
|
||||||
solidfire-sdk-python
|
|
||||||
|
|
||||||
# requirements for F5 specific modules
|
|
||||||
f5-sdk ; python_version >= '2.7'
|
|
||||||
f5-icontrol-rest ; python_version >= '2.7'
|
|
||||||
deepdiff
|
|
||||||
|
|
||||||
# requirement for Fortinet specific modules
|
|
||||||
pyFMG
|
|
||||||
|
|
||||||
# requirement for aci_rest module
|
|
||||||
xmljson
|
|
||||||
|
|
||||||
# requirement for winrm connection plugin tests
|
|
||||||
pexpect
|
|
||||||
|
|
||||||
# requirement for the linode module
|
|
||||||
linode-python # APIv3
|
|
||||||
linode_api4 ; python_version > '2.6' # APIv4
|
|
||||||
|
|
||||||
# requirement for the gitlab module
|
|
||||||
python-gitlab
|
|
||||||
httmock
|
|
||||||
|
|
||||||
# requirment for kubevirt modules
|
|
||||||
openshift ; python_version >= '2.7'
|
|
||||||
|
|||||||
@@ -65,13 +65,16 @@ fi
|
|||||||
export ANSIBLE_COLLECTIONS_PATH="${PWD}/../../../"
|
export ANSIBLE_COLLECTIONS_PATH="${PWD}/../../../"
|
||||||
|
|
||||||
# START: HACK install dependencies
|
# START: HACK install dependencies
|
||||||
if [ "${ansible_version}" == "2.9" ] || [ "${ansible_version}" == "2.10" ]; then
|
if [ "${ansible_version}" == "2.16" ]; then
|
||||||
# Note: Since community.general 5.x, Ansible Core versions prior to 2.11 are not supported.
|
# Note: Since community.general 12.x dropped support for ansible-core 2.16,
|
||||||
# So we need to use 4.8.1 for Ansible 2.9 and Ansible Engine 2.10.
|
# we need to use stable-11 for ansible-core 2.16.
|
||||||
retry git clone --depth=1 --single-branch -b 4.8.1 https://github.com/ansible-collections/community.general.git "${ANSIBLE_COLLECTIONS_PATH}/ansible_collections/community/general"
|
target_branch='stable-11'
|
||||||
else
|
else
|
||||||
retry git clone --depth=1 --single-branch https://github.com/ansible-collections/community.general.git "${ANSIBLE_COLLECTIONS_PATH}/ansible_collections/community/general"
|
target_branch='main'
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
retry git clone --depth=1 --single-branch -b "${target_branch}" https://github.com/ansible-collections/community.general.git "${ANSIBLE_COLLECTIONS_PATH}/ansible_collections/community/general"
|
||||||
|
|
||||||
# Note: we're installing with git to work around Galaxy being a huge PITA (https://github.com/ansible/galaxy/issues/2429)
|
# Note: we're installing with git to work around Galaxy being a huge PITA (https://github.com/ansible/galaxy/issues/2429)
|
||||||
# END: HACK
|
# END: HACK
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user