)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"0b357f6bc9041a8eb2231f84b3520ac2254d3c5a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"9ef093ac_cb038886","updated":"2023-05-03 08:40:26.000000000","message":"I added a comment to the bug report: https://bugs.launchpad.net/kolla-ansible/+bug/2018338","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4552756e2cd831553475c78a91acefbabca7979d","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"63deeba7_3342408b","updated":"2023-05-03 09:35:40.000000000","message":"the linked bugreport should be opened up - I can\u0027t access it - most likely because it is flagged as a security bug.\n\nplease always open up security bugs to the public when proposing fixes for them, because the information is now public anyway.","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"8dbd77512a827a4fcd0b5d36b4235e7eb3a0e2e8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"647c60f4_4972a121","in_reply_to":"63deeba7_3342408b","updated":"2023-05-03 10:21:24.000000000","message":"in short, bugreport describes an issue with passwords.yml world readable.","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"7b5ddadaa1fd857c62fc51fc246414b0d2ba3b69","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"ed651ee9_4409f940","updated":"2023-05-04 09:39:13.000000000","message":"general comment from my ISO27k1 standpoint:\n\nI don\u0027t know the threat model used here, but it seems to imply there might be malicious users on the same system, where ansible passwords are generated and used.\n\nthus imho all the added checks here are susceptible to TOCTOU Attacks, see:\nhttps://en.wikipedia.org/wiki/Time-of-check_to_time-of-use\n\nBut I have no real solution to that. Maybe the threat model for an attacker could be more specific/written down and we could then design better solutions to avoid future attacks?\n\nIt would be really good to draw a line somewhere against which attacks we try to protect and against which attacks we really can\u0027t do anything and users must secure against the latter themselves.","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"2280b8e67a91dccaeac8048e283f9dcfca64c9f0","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":9,"id":"d8d6d77e_19817d5a","updated":"2023-05-17 13:14:50.000000000","message":"if this fixes a security issue, please add relnotes","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"cad1356f8a8684526074fb2ffa1966f091c61037","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"99948efa_50493943","in_reply_to":"d8d6d77e_19817d5a","updated":"2023-05-18 11:39:13.000000000","message":"Done","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"de7676016e0d23159962bc681c95e9584d02c414","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"12558115_d8d7baa0","in_reply_to":"ed651ee9_4409f940","updated":"2023-05-04 10:04:31.000000000","message":"TOCTOU is not the really problem here. but anyway, You can create another one bugreport and try to fix it.","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"852c74905d970b61bfc16ecfc6facbd32a6bd75d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"89ec5f7d_4b5eed0e","updated":"2023-05-25 19:00:03.000000000","message":"recheck\n\nubuntu upgrade failed","commit_id":"4fe8738e9cce7a5926c2efa22ce1028884853e42"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"2d866050c27cb832e7b3d7e828ea733fb321fa04","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"e431ed3b_ce8fb148","updated":"2023-06-01 07:23:23.000000000","message":"recheck new images built","commit_id":"5fd8117098d3fec6d96f6a918cc2d2bfa2f14c86"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"6436da63ac6703b700a53bba76aed95aca2ad48a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"eedb6ff2_5a6e3dd7","updated":"2023-05-31 13:36:11.000000000","message":"recheck rabbitmq in maintenance mode","commit_id":"5fd8117098d3fec6d96f6a918cc2d2bfa2f14c86"}],"kolla_ansible/cmd/genpwd.py":[{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4552756e2cd831553475c78a91acefbabca7979d","unresolved":true,"context_lines":[{"line_number":101,"context_line":"    except OSError:"},{"line_number":102,"context_line":"        pass"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"}],"source_content_type":"text/x-python","patch_set":7,"id":"6043e394_40d63cf2","line":104,"range":{"start_line":104,"start_character":4,"end_line":104,"end_character":19},"updated":"2023-05-03 09:35:40.000000000","message":"what is the purpose of setting the umask in this line?\nyou set the umask to a different value in line 107 where you write the first time?\n\nas far as I can see, this umask is never used?","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7dd45dd951162c308f4bbe440d3ac2a40e8c8641","unresolved":false,"context_lines":[{"line_number":101,"context_line":"    except OSError:"},{"line_number":102,"context_line":"        pass"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"}],"source_content_type":"text/x-python","patch_set":7,"id":"f50b8da6_841c2a2d","line":104,"range":{"start_line":104,"start_character":4,"end_line":104,"end_character":19},"in_reply_to":"6043e394_40d63cf2","updated":"2023-05-03 09:50:29.000000000","message":"umask() sets the calling process\u0027s file mode creation mask (umask) to mask \u0026 0777 (i.e., only the file permission bits of mask are used), the umask  is  used  by  open(2), mkdir(2), and other system calls that create files to modify the permissions placed on newly created files or directories.\n\nman 2 umask","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"309712b7d9a09f74637a39eb86b84ff94c43bd20","unresolved":false,"context_lines":[{"line_number":101,"context_line":"    except OSError:"},{"line_number":102,"context_line":"        pass"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"}],"source_content_type":"text/x-python","patch_set":7,"id":"05f5cb84_702b10f0","line":104,"range":{"start_line":104,"start_character":4,"end_line":104,"end_character":19},"in_reply_to":"ba17a8ba_2f1c9cba","updated":"2023-05-03 12:36:43.000000000","message":"your test is invalid because umask() don\u0027t work with files already exist.\nadd the os.remove() and test again. also changed workflow is described in bugreport comment.","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"ff7de38591df359ee3ecfe0188a8fb4e64131654","unresolved":true,"context_lines":[{"line_number":101,"context_line":"    except OSError:"},{"line_number":102,"context_line":"        pass"},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"}],"source_content_type":"text/x-python","patch_set":7,"id":"ba17a8ba_2f1c9cba","line":104,"range":{"start_line":104,"start_character":4,"end_line":104,"end_character":19},"in_reply_to":"f50b8da6_841c2a2d","updated":"2023-05-03 12:27:55.000000000","message":"I know what umask in general does, but you do not explain why you set it specifically here. you already set mode for os.open on line 107, which, according to my understanding and testing should be sufficient? I have build a little script which shows that the resulting file mode is the same, regardless of setting the umask, see here:\n\nhttps://paste.opendev.org/show/bf3vIG6yCaCXqnwn83aK/\n\nOutput:\nold umask:  0\nfile mode before write:  w\nfile mode after write:  w\nfile perms:  0o100644\nnew umask:  79\nfile perms before write:  0o100644\nfile mode before write:  w\nfile mode after write:  w\nfile perms:  0o100644\n\nI fail to understand what your usage of umask is trying to achieve, or is this a WIP - then please specify that - and there is code still missing? or is this a defense in depth approach if other file writes are introduced in later patches? then please also specify that in a comment in the code.\n\nit is not clear what the purpose of the code is, that is, _why_ is the code here, not _what_ does the code do.\n\nI already said as much in my first comment:\n\n\u003e what is the purpose of setting the umask[..]?\n\nI did not ask \"what does umask do\"? because I know that.\n\nThank you!","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"4552756e2cd831553475c78a91acefbabca7979d","unresolved":true,"context_lines":[{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"},{"line_number":108,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":109,"context_line":""},{"line_number":110,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"dca10dce_39604c9f","line":107,"range":{"start_line":107,"start_character":4,"end_line":107,"end_character":68},"updated":"2023-05-03 09:35:40.000000000","message":"what is the purpose with using both fdopen and open here?\n\nos.open should suffice?\n\nalso I believe you want at least give write access to the current user?\n\na umask of 777 results in a file with no one having permissions on it - write protected - however it can still be deleted/changed by the file owner.","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"8dbd77512a827a4fcd0b5d36b4235e7eb3a0e2e8","unresolved":false,"context_lines":[{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"},{"line_number":108,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":109,"context_line":""},{"line_number":110,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"74445176_86083414","line":107,"range":{"start_line":107,"start_character":4,"end_line":107,"end_character":68},"in_reply_to":"b0f06499_ec17ca70","updated":"2023-05-03 10:21:24.000000000","message":"Also, by the way, builtin open() is not the same as os.open().\n\nBuilt-in open() takes a file name and returns a new Python file object. This is what you need in the majority of cases.\n\nBuilt-in open() is an equivalent of combining os.open() (to create a file descriptor) and os.fdopen() (to wrap it in a file object):\n\nfunctionally equivalent to open(filename, \"r\") is: f \u003d os.fdopen(os.open(filename, os.O_RDONLY))","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"7dd45dd951162c308f4bbe440d3ac2a40e8c8641","unresolved":false,"context_lines":[{"line_number":104,"context_line":"    os.umask(0o117)"},{"line_number":105,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"    with os.fdopen(os.open(passwords_file, flags, 0o777), \u0027w\u0027) as f:"},{"line_number":108,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":109,"context_line":""},{"line_number":110,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"b0f06499_ec17ca70","line":107,"range":{"start_line":107,"start_character":4,"end_line":107,"end_character":68},"in_reply_to":"dca10dce_39604c9f","updated":"2023-05-03 09:50:29.000000000","message":"777 is not umask, but the mode (optional and the default value 0o777 which I provided).\n\nPython method open() opens the file file and set various flags according to flags and possibly its mode according to mode.The default mode is 0777 (octal), and the current umask value is first masked out.\n\nFollowing is the syntax for open() method − os.open(file, flags[, mode]);\n\nos.open() takes a file name and returns a new file descriptor. This file descriptor can be passed to other low-level functions, such as os.read() and os.write(), or to os.fdopen(), as described below. You only need this when writing code that depends on operating-system-dependent APIs, such as using the O_EXCL flag to open(2).\n\nos.fdopen() takes an existing file descriptor — typically produced by Unix system calls such as pipe() or dup(), and builds a Python file object around it. Effectively it converts a file descriptor to a full file object, which is useful when interfacing with C code or with APIs that only create low-level file descriptors.","commit_id":"0dad6735ac407211ecd9e208e51597fd7a2f3a71"},{"author":{"_account_id":32553,"name":"Sven Kieske","email":"sven_oss@posteo.de","username":"skieske"},"change_message_id":"7b5ddadaa1fd857c62fc51fc246414b0d2ba3b69","unresolved":true,"context_lines":[{"line_number":106,"context_line":"                ])"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"    try:"},{"line_number":109,"context_line":"        os.remove(passwords_file)"},{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""}],"source_content_type":"text/x-python","patch_set":9,"id":"0bed20a2_c3a8e7b1","line":109,"updated":"2023-05-04 09:39:13.000000000","message":"should we print/document somewhere a warning that we delete previous password files?","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"1c1ecd3b8d39a02bf8a5027e89846f0da162c8e6","unresolved":false,"context_lines":[{"line_number":106,"context_line":"                ])"},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"    try:"},{"line_number":109,"context_line":"        os.remove(passwords_file)"},{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""}],"source_content_type":"text/x-python","patch_set":9,"id":"5ae55118_83acd9c4","line":109,"in_reply_to":"0bed20a2_c3a8e7b1","updated":"2023-05-04 10:02:27.000000000","message":"no, because it removed only for recreating with correct permissions. also it not always removed, for this we have try/except/pass block.","commit_id":"416cc7c81ffe7336f6c182c6d2da2163d9a55a7e"},{"author":{"_account_id":35263,"name":"Matt Crees","email":"mattc@stackhpc.com","username":"mattcrees"},"change_message_id":"8e803db67e1380e3e6041aec79ded37a5732640c","unresolved":true,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IROTH:"},{"line_number":68,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""},{"line_number":69,"context_line":"              \" world-readable. The permissions would be changed.\")"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IWOTH:"},{"line_number":72,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""}],"source_content_type":"text/x-python","patch_set":10,"id":"c33fb469_2bcaf2d4","line":69,"range":{"start_line":69,"start_character":48,"end_line":69,"end_character":53},"updated":"2023-05-24 14:22:29.000000000","message":"nit: ``would`` -\u003e ``will``","commit_id":"9b8f36b855e9813186c3e721a4965ad27c349104"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"ca3f55546cc000e6da9d53e6f1fe67a2c3e6e4ad","unresolved":false,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IROTH:"},{"line_number":68,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""},{"line_number":69,"context_line":"              \" world-readable. The permissions would be changed.\")"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IWOTH:"},{"line_number":72,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""}],"source_content_type":"text/x-python","patch_set":10,"id":"14e3e4f1_07f2b2ae","line":69,"range":{"start_line":69,"start_character":48,"end_line":69,"end_character":53},"in_reply_to":"c33fb469_2bcaf2d4","updated":"2023-05-24 14:24:38.000000000","message":"Done","commit_id":"9b8f36b855e9813186c3e721a4965ad27c349104"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"2d004bd438af016c81534b6b89499a3f789b1f31","unresolved":true,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"300bfedd_ea6476a5","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"updated":"2023-05-25 15:27:57.000000000","message":"Alternative approach avoiding umask:\n\nflags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC\nmode \u003d 0o640\n\nwith os.fdopen(os.open(passwords_file, flags, mode\u003dmode), \u0027w\u0027) as f:\n\n1. It\u0027s easier to understand the mode\n2. User can apply their own umask, e.g. if they don\u0027t trust the group","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"9d99036c35614c99a09b39a1fb0806e17ed485a7","unresolved":false,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"775e2ffc_2fe96581","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"in_reply_to":"300bfedd_ea6476a5","updated":"2023-05-25 15:30:02.000000000","message":"Done","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"8cf3dd0b62c6b3314c29703efaa923662da0a872","unresolved":true,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"f1dacee7_96430586","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"in_reply_to":"31f52efc_5181b2c8","updated":"2023-05-31 08:23:35.000000000","message":"Perhaps we should instead use flags\u003d0600, and the user can chmod afterwards if they wish.","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"d0b87434c9bf3202c7e61266d9e9808a144b9d9a","unresolved":true,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"31f52efc_5181b2c8","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"in_reply_to":"5877b297_268001ce","updated":"2023-05-31 08:22:06.000000000","message":"They can provide a more open umask, but it will be limited to 0640 by our flags.\n\nHowever, with your approach, the user may have set a umask of 0177 (corresponding to 0600), but this code overwrites that umask allowing group read of the file.","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"c29d307ef8baf55f05f8f7aa8d8c2de17c20eb66","unresolved":false,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"5877b297_268001ce","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"in_reply_to":"775e2ffc_2fe96581","updated":"2023-05-25 21:27:14.000000000","message":"easier to understand, but the user really didn\u0027t read the code, and it can provide their own umask and made the file world readable/writable!","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"1d1f80bade715c7e61b13a23e409026662ec15f1","unresolved":false,"context_lines":[{"line_number":110,"context_line":"    except OSError:"},{"line_number":111,"context_line":"        pass"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"    os.umask(0o137)  # 0640 effective access rights"},{"line_number":114,"context_line":"    flags \u003d os.O_WRONLY | os.O_CREAT | os.O_TRUNC"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"    with os.fdopen(os.open(passwords_file, flags), \u0027w\u0027) as f:"},{"line_number":117,"context_line":"        f.write(yaml.safe_dump(passwords, default_flow_style\u003dFalse))"},{"line_number":118,"context_line":""},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"def main():"}],"source_content_type":"text/x-python","patch_set":11,"id":"3f6de67f_90f8e190","line":117,"range":{"start_line":113,"start_character":0,"end_line":117,"end_character":68},"in_reply_to":"f1dacee7_96430586","updated":"2023-05-31 11:24:44.000000000","message":"Done","commit_id":"a7be11ad6c294595457071e11948b5bcd768c710"}],"kolla_ansible/cmd/readpwd.py":[{"author":{"_account_id":35263,"name":"Matt Crees","email":"mattc@stackhpc.com","username":"mattcrees"},"change_message_id":"8e803db67e1380e3e6041aec79ded37a5732640c","unresolved":true,"context_lines":[{"line_number":32,"context_line":""},{"line_number":33,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IROTH:"},{"line_number":34,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""},{"line_number":35,"context_line":"              \" world-readable. The permissions would be changed.\")"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IWOTH:"},{"line_number":38,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""}],"source_content_type":"text/x-python","patch_set":10,"id":"9fecde6c_877ed6d0","line":35,"range":{"start_line":35,"start_character":48,"end_line":35,"end_character":53},"updated":"2023-05-24 14:22:29.000000000","message":"ditto","commit_id":"9b8f36b855e9813186c3e721a4965ad27c349104"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"ca3f55546cc000e6da9d53e6f1fe67a2c3e6e4ad","unresolved":false,"context_lines":[{"line_number":32,"context_line":""},{"line_number":33,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IROTH:"},{"line_number":34,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""},{"line_number":35,"context_line":"              \" world-readable. The permissions would be changed.\")"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"    if os.stat(passwords_file).st_mode \u0026 stat.S_IWOTH:"},{"line_number":38,"context_line":"        print(f\"WARNING: Passwords file \\\"{passwords_file}\\\" is\""}],"source_content_type":"text/x-python","patch_set":10,"id":"ea1feaf6_02007df6","line":35,"range":{"start_line":35,"start_character":48,"end_line":35,"end_character":53},"in_reply_to":"9fecde6c_877ed6d0","updated":"2023-05-24 14:24:38.000000000","message":"Done","commit_id":"9b8f36b855e9813186c3e721a4965ad27c349104"}]}
