fix(tasks): match @includedir directive in /etc/sudoers

The regular expression required a leading hash, but sudo 1.9.1 introduced @includedir and distributions such as
Debian 12, Ubuntu 22.04, RHEL 9 and Arch Linux ship /etc/sudoers with that syntax. Since the existing line was never
matched, lineinfile appended a second directive and /etc/sudoers.d was included twice.

The dot in sudoers.d is escaped as well, so the expression no longer matches unrelated paths.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent c3f714a7c6
commit d2e4036430
+2 -1
View File
@@ -34,7 +34,8 @@
ansible.builtin.lineinfile:
dest: /etc/sudoers
state: present
regexp: "^(#)+(\\s)*includedir(\\s)*/etc/sudoers.d"
# sudo >= 1.9.1 ships the directive as @includedir, older releases as #includedir
regexp: "^[#@]+(\\s)*includedir(\\s)*/etc/sudoers\\.d"
line: "#includedir /etc/sudoers.d"
validate: 'visudo --check --file %s'
mode: "0440"