{"record":{"id":"a3c2a416de6d61dc","repo":"gofiber/fiber","slug":"cannot-chmod-o-for-q-w","errorCode":null,"errorMessage":"cannot chmod %#o for %q: %w","messagePattern":"cannot chmod %#o for %q: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"listen.go","lineNumber":487,"sourceCode":"\t\t}\n\t}\n\n\tif tlsConfig != nil {\n\t\tlistener, err = tls.Listen(cfg.ListenerNetwork, addr, tlsConfig)\n\t} else {\n\t\tlistener, err = net.Listen(cfg.ListenerNetwork, addr)\n\t}\n\n\t// Check for error before using the listener\n\tif err != nil {\n\t\t// Wrap the error from tls.Listen/net.Listen\n\t\treturn nil, fmt.Errorf(\"failed to listen: %w\", err)\n\t}\n\n\tif cfg.ListenerNetwork == NetworkUnix {\n\t\tif err = os.Chmod(addr, cfg.UnixSocketFileMode); err != nil {\n\t\t\t_ = listener.Close() //nolint:errcheck // best-effort cleanup on the error path\n\t\t\treturn nil, fmt.Errorf(\"cannot chmod %#o for %q: %w\", cfg.UnixSocketFileMode, addr, err)\n\t\t}\n\t}\n\n\tif cfg.ListenerAddrFunc != nil {\n\t\tcfg.ListenerAddrFunc(listener.Addr())\n\t}\n\n\treturn listener, nil\n}\n\nfunc (app *App) printMessages(cfg *ListenConfig, listenData *ListenData) {\n\tapp.startupMessage(listenData, cfg)\n\n\tif cfg.EnablePrintRoutes {\n\t\tapp.printRoutesMessage()\n\t}\n}\n","sourceCodeStart":469,"sourceCodeEnd":505,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/listen.go#L469-L505","documentation":"Returned by createListener after a Unix socket listener is successfully created but os.Chmod on the socket path fails. Fiber sets UnixSocketFileMode so cooperating processes can connect; a chmod failure means the socket exists but with default permissions, likely blocking clients. The listener is closed before returning so callers do not get a half-configured socket.","triggerScenarios":"UnixSocketFileMode is invalid (note: zero FileMode is a no-op elsewhere but here os.Chmod is invoked unconditionally for unix networks); the socket path was deleted by another process between Listen and Chmod; the filesystem does not support chmod (some FUSE mounts, /proc); EPERM running under a seccomp/AppArmor profile that blocks chmod.","commonSituations":"Default UnixSocketFileMode of 0o660 is fine on ext4 but a restrictive container runtime blocks chmod; another supervisor (systemd socket activation) raced Fiber to the path; the socket lives on a tmpfs with noexec/nodev that also rejects mode changes; misconfigured seccomp in Docker blocking the fchmod syscall.","solutions":["Check the runtime allows chmod on the socket directory: strace -e fchmod ./myapp.","Move the socket to a standard runtime directory that supports chmod (e.g. /run/<service>/).","Loosen or fix the seccomp/AppArmor profile to permit fchmod/fchmodat.","Ensure no other process (systemd socket activation, prior instance) is racing the path.","Verify UnixSocketFileMode is a sane permission (typically 0o660 or 0o660)."],"exampleFix":"// before: socket on a mount that rejects chmod\napp.Listen(\"/mnt/ro/fiber.sock\", fiber.ListenConfig{ListenerNetwork: fiber.NetworkUnix})\n\n// after: socket on a runtime dir that supports chmod\napp.Listen(\"/run/fiber/fiber.sock\", fiber.ListenConfig{ListenerNetwork: fiber.NetworkUnix, UnixSocketFileMode: 0o660})","handlingStrategy":"validation","validationCode":"func checkUnixSocketChmod(path string, mode os.FileMode) error {\n    parent := filepath.Dir(path)\n    // verify the parent supports chmod by probing a temp file\n    probe := filepath.Join(parent, \".chmod-probe\")\n    f, err := os.Create(probe)\n    if err != nil { return fmt.Errorf(\"cannot create probe in socket dir: %w\", err) }\n    _ = f.Close()\n    if err := os.Chmod(probe, mode); err != nil {\n        _ = os.Remove(probe)\n        return fmt.Errorf(\"chmod not supported in socket dir: %w\", err)\n    }\n    _ = os.Remove(probe)\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Place the socket on a filesystem that supports chmod (tmpfs, ext4).","If running under Docker, allow fchmod in the seccomp profile.","Avoid read-only mounts for the socket directory.","Set UnixSocketFileMode explicitly to a sane value (0o660)."],"tags":["unix-socket","filesystem","permissions","startup","listen"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}