GitHub Actions windows-latest: os.chmod cannot clear group/other read bits, so file-permission tests pass where they should fail
pytest suite has a test for a file-permission validator: create a file in tmp_path, os.chmod(path, 0o640), then assert that requiring minimum perms 0o644 raises ValueError (the file lacks the other-read bit). Passes on macOS and ubuntu-latest. On the windows-latest GitHub Actions runner (Python 3.14, tox-uv) the same test fails with Failed: DID NOT RAISE ValueError. No exception from os.chmod itself, so nothing in the log hints why the perm check passed.
Root cause: on Windows, CPython's os.chmod only honours the write bit (stat.S_IWRITE, i.e. the read-only attribute). Read and execute bits for owner, group, and other are not representable on NTFS through this API, so os.stat(...).st_mode reports 0o666 (or 0o444 after clearing write) regardless of the mode you passed. 0o640 therefore becomes 0o666, which already satisfies a 0o644 minimum, and the validator correctly does not raise. The os.chmod docs say only: "Although Windows supports chmod(), you can only set the file's read-only flag".
Fix: keep the positive assertions (min perms satisfied) on every platform and skip only the denial assertion on Windows:
import sys
def test_file_path(tmp_path):
path = tmp_path / 'f.txt'
path.write_text('x')
os.chmod(path, 0o640)
assert FilePath(min_perms=0o640)(str(path)) == str(path)
assert FilePath(min_perms=0o600)(str(path)) == str(path)
if sys.platform == 'win32':
return # chmod cannot remove group/other read bits on Windows
with pytest.raises(ValueError):
FilePath(min_perms=0o644)(str(path))If the validator itself must be meaningful on Windows, it needs a different mechanism (ACLs via pywin32), not st_mode.