1
0
Fork 0
mirror of https://github.com/ansible-collections/community.general.git synced 2024-09-14 20:13:21 +02:00

Fix secure temp file creation (#19096)

* For realz this time

* Fix tempfile.mkstemp (#2)

* back to square one, removing temp file from the mix

* Adding temp back

* Adding tuple  back

* Adding another tuple back

* Trying to get around weird Jenkins behavior of blowing up when both .hpi and jpi file found

* Incorporating PR feedback

* Delete .hpi file instead of backing it up, some basic clean up

* Moving file deletion to the right location

* Blank lines. They always get me.
This commit is contained in:
Irina Muchnik 2016-12-10 06:33:34 -08:00 committed by John R Barker
parent 2adde7a6d1
commit 9f58e69d63

View file

@ -442,6 +442,13 @@ class JenkinsPlugin(object):
msg_exception="Plugin installation has failed.",
data=data)
hpi_file = '%s/plugins/%s.hpi' % (
self.params['jenkins_home'],
self.params['name'])
if os.path.isfile(hpi_file):
os.remove(hpi_file)
changed = True
else:
# Check if the plugin directory exists
@ -567,7 +574,7 @@ class JenkinsPlugin(object):
msg_exception="Updates download failed.")
# Write the updates file
updates_file = tempfile.mkstemp()
update_fd, updates_file = tempfile.mkstemp()
try:
fd = open(updates_file, 'wb')
@ -644,7 +651,7 @@ class JenkinsPlugin(object):
def _write_file(self, f, data):
# Store the plugin into a temp file and then move it
tmp_f = tempfile.mkstemp()
tmp_f_tuple, tmp_f = tempfile.mkstemp()
try:
fd = open(tmp_f, 'wb')