Skip to content

[bug] TestInboundFileSandboxPerms: 4 tests fail on Windows (exact POSIX mode assertions, chmod is a no-op approximation) #5932

Description

@uhhgxg

Problem summary

Four tests in backend/tests/test_channel_file_attachments.py::TestInboundFileSandboxPerms fail deterministically on Windows hosts because they assert exact POSIX permission modes, which os.chmod cannot produce on Windows.

Affected area(s)

  • Backend API (gateway / endpoints / SSE)
  • CI infra

What happened?

Running the backend test suite on Windows (Python 3.12, pytest), these 4 tests fail:

  • test_make_inbound_file_sandbox_readable_sets_group_other_read
  • test_make_inbound_file_sandbox_readable_preserves_owner_bits
  • test_make_inbound_file_sandbox_readable_skips_symlink
  • test_make_inbound_file_sandbox_readable_swap_after_lstat_does_not_follow_symlink

Root cause: on Windows, os.chmod(path, 0o600) only toggles the read-only attribute; stat.S_IMODE(os.stat(f).st_mode) therefore always reports 0o666 for a writable file, so assertions like assert mode == 0o644 or assert mode == 0o600 can never hold. The function under test (_make_inbound_file_sandbox_readable in app/channels/manager.py) is inherently POSIX-oriented — its docstring describes the AIO/Docker sandbox scenario where "the gateway writes inbound files as root with 0o600" — so these exact-mode assertions are POSIX-only by design.

Note the same test file already uses this pattern for a genuinely POSIX-only case:

@pytest.mark.skipif(not (hasattr(os, "mkfifo") and hasattr(os, "O_NOFOLLOW")), reason="POSIX-only: mkfifo + O_NOFOLLOW")

Expected behavior

The suite should pass (or cleanly skip) on Windows hosts. Since the asserted Unix permission-bit semantics do not exist on Windows, the affected tests should be skipped there (same approach as #5922/#5924 and the in-file POSIX-only skipif precedent), without changing behavior on Linux/macOS.

Steps to reproduce

  1. On a Windows host, from backend/:
  2. python -m pytest tests/test_channel_file_attachments.py::TestInboundFileSandboxPerms -q
  3. Observe 4 failures, e.g. assert 438 == 420 (0o666 == 0o644).

Relevant logs

tests/test_channel_file_attachments.py::TestInboundFileSandboxPerms::test_make_inbound_file_sandbox_readable_sets_group_other_read
    mode = stat.S_IMODE(os.stat(f).st_mode)
>   assert mode == 0o644
E   assert 438 == 420

4 failed, 1 passed, 1 skipped in ...

How are you running DeerFlow?

Local (make dev)

Operating system

Windows

Platform details

Windows 11 x64, Git Bash, Python 3.12 venv (backend/.venv), pytest. Reproduced on latest main (bf9a019).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageAwaiting maintainer triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions