ansible-hardening: Filesystem modes with letters are not working
Bug #1731005 reported by
Major Hayden
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack-Ansible |
Fix Released
|
High
|
Major Hayden |
Bug Description
The letter-based modes from the ansible-hardening role are removing certain permissions that they should not remove. Example:
mode: "u-X,g-ws,o-rwxt"
This removes the setuid bit from the directory along with the execute permissions. For the V-72017 requirement, this removes a user's execute bit for their own home directory, which is really awful.
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/518593
Review: https:/