New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Less permissive bwrap options #999
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Shrews
force-pushed
the
bwrap-fix
branch
3 times, most recently
from
February 16, 2022 16:51
090ee31
to
9b8ad01
Compare
Shrews
changed the title
[DNM] Less permissive bwrap options
Less permissive bwrap options
Feb 16, 2022
shanemcd
approved these changes
Feb 16, 2022
Shrews
added a commit
to Shrews/ansible-runner
that referenced
this pull request
Feb 17, 2022
Less permissive bwrap options Reviewed-by: Shane McDonald <me@shanemcd.com> (cherry picked from commit 3ab4473)
Shrews
added a commit
to Shrews/ansible-runner
that referenced
this pull request
Feb 17, 2022
Less permissive bwrap options Reviewed-by: Shane McDonald <me@shanemcd.com> (cherry picked from commit 3ab4473)
This was referenced Feb 17, 2022
Shrews
added a commit
to Shrews/ansible-runner
that referenced
this pull request
Feb 17, 2022
shanemcd
added a commit
that referenced
this pull request
Feb 17, 2022
[backport][stable/1.4.x] Less permissive bwrap options (#999)
ansible-zuul bot
pushed a commit
that referenced
this pull request
Mar 8, 2022
Fix broken password-based SSH Fallout from the recent changes in #999. I came up with the solution here after piecing together info in comments from @sivel and @jborean93. (thanks!) Users who tried to use SSH w/ a login password were seeing: <ec2-44-203-148-21.compute-1.amazonaws.com> SSH: EXEC sshpass -d8 ssh -C -o ControlMaster=auto -o ControlPersist=60s -o 'User="testuser"' -o ConnectTimeout=10 -o ControlPath=/var/lib/awx/.ansible/cp/6abb5dc2c2 ec2-44-203-148-21.compute-1.amazonaws.com '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo ~/.ansible/tmp `"&& mkdir "` echo ~/.ansible/tmp/ansible-tmp-1646413970.94-16-215594703579950 `" && echo ansible-tmp-1646413970.94-16-215594703579950="` echo ~/.ansible/tmp/ansible-tmp-1646413970.94-16-215594703579950 `" ) && sleep 0'"'"'' <ec2-44-203-148-21.compute-1.amazonaws.com> (3, '', "Failed to change pseudo terminal's permission: Operation not permitted\n") <ec2-44-203-148-21.compute-1.amazonaws.com> Failed to connect to the host via ssh: Failed to change pseudo terminal's permission: Operation not permitted ec2-44-203-148-21.compute-1.amazonaws.com | UNREACHABLE! => { "changed": false, "msg": "Failed to create temporary directory.In some cases, you may have been able to authenticate and did not have permissions on the target directory. Consider changing the remote tmp path in ansible.cfg to a path rooted in \"/tmp\", for more error information use -vvv. Failed command was: ( umask 77 && mkdir -p \"` echo ~/.ansible/tmp `\"&& mkdir \"` echo ~/.ansible/tmp/ansible-tmp-1646413970.94-16-215594703579950 `\" && echo ansible-tmp-1646413970.94-16-215594703579950=\"` echo ~/.ansible/tmp/ansible-tmp-1646413970.94-16-215594703579950 `\" ), exited with result 3", "unreachable": true } Critical part being Failed to change pseudo terminal's permission: Operation not permitted. Reviewed-by: David Shrewsbury <None>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
No description provided.