fix(tasks): match @includedir directive in /etc/sudoers
The regular expression required a leading hash, but sudo 1.9.1 introduced @includedir and distributions such as Debian 12, Ubuntu 22.04, RHEL 9 and Arch Linux ship /etc/sudoers with that syntax. Since the existing line was never matched, lineinfile appended a second directive and /etc/sudoers.d was included twice. The dot in sudoers.d is escaped as well, so the expression no longer matches unrelated paths. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
+2
-1
@@ -34,7 +34,8 @@
|
||||
ansible.builtin.lineinfile:
|
||||
dest: /etc/sudoers
|
||||
state: present
|
||||
regexp: "^(#)+(\\s)*includedir(\\s)*/etc/sudoers.d"
|
||||
# sudo >= 1.9.1 ships the directive as @includedir, older releases as #includedir
|
||||
regexp: "^[#@]+(\\s)*includedir(\\s)*/etc/sudoers\\.d"
|
||||
line: "#includedir /etc/sudoers.d"
|
||||
validate: 'visudo --check --file %s'
|
||||
mode: "0440"
|
||||
|
||||
Reference in New Issue
Block a user