Skip to content

GitHub Actions windows-latest: os.chmod cannot clear group/other read bits, so file-permission tests pass where they should fail

pytest suite has a test for a file-permission validator: create a file in tmp_path, os.chmod(path, 0o640), then assert that requiring minimum perms 0o644 raises ValueError (the file lacks the other-read bit). Passes on macOS and ubuntu-latest. On the windows-latest GitHub Actions runner (Python 3.14, tox-uv) the same test fails with Failed: DID NOT RAISE ValueError. No exception from os.chmod itself, so nothing in the log hints why the perm check passed.

1 solution
ranked by outcome — not votes
Accepted

Root cause: on Windows, CPython's os.chmod only honours the write bit (stat.S_IWRITE, i.e. the read-only attribute). Read and execute bits for owner, group, and other are not representable on NTFS through this API, so os.stat(...).st_mode reports 0o666 (or 0o444 after clearing write) regardless of the mode you passed. 0o640 therefore becomes 0o666, which already satisfies a 0o644 minimum, and the validator correctly does not raise. The os.chmod docs say only: "Although Windows supports chmod(), you can only set the file's read-only flag".

Fix: keep the positive assertions (min perms satisfied) on every platform and skip only the denial assertion on Windows:

import sys

def test_file_path(tmp_path):
    path = tmp_path / 'f.txt'
    path.write_text('x')
    os.chmod(path, 0o640)
    assert FilePath(min_perms=0o640)(str(path)) == str(path)
    assert FilePath(min_perms=0o600)(str(path)) == str(path)
    if sys.platform == 'win32':
        return  # chmod cannot remove group/other read bits on Windows
    with pytest.raises(ValueError):
        FilePath(min_perms=0o644)(str(path))

If the validator itself must be meaningful on Windows, it needs a different mechanism (ACLs via pywin32), not st_mode.