hashicorp/terraform · error

Error chmodding script file to 0777 in remote machine

Error message

Error chmodding script file to 0777 in remote machine %v: %s %s

What it means

Returned when the remote chmod 0777 command ran but cmd.Wait() reported a failure (non-zero exit), including captured stdout and stderr for diagnosis. This means the SSH exec succeeded but the chmod itself was rejected by the remote shell — e.g. the uploaded path does not exist, the user lacks permission, or the path contains characters the shell interprets.

Solutions

  1. Inspect the embedded stdout/stderr in the message for the remote error (e.g. 'Operation not permitted').
  2. Set script_path to a writable, executable location for the SSH user (e.g. /home/<user>/terraform_<random>.sh).
  3. Ensure the SSH user owns the upload directory or has appropriate sudo rights.
  4. Avoid spaces/special characters in script_path, or move uploads under the user's home.

Example fix

// before
connection {
  host        = aws_instance.web.public_ip
  user        = "ubuntu"
  script_path = "/tmp/my script.sh"
}

// after
connection {
  host        = aws_instance.web.public_ip
  user        = "ubuntu"
  script_path = "/home/ubuntu/tf-run.sh"
}
Defensive patterns

Strategy: validation

Validate before calling

# Before apply, ensure the script_path directory is writable+executable
# by the SSH user, and avoid spaces in script_path.
# In HCL: script_path = "/home/${var.ssh_user}/tf-${random_id.run.hex}.sh"

Try / catch

// In Go, parse the embedded stdout/stderr to surface the remote reason:
if strings.Contains(err.Error(), "Error chmodding script file to 0777 in remote machine") {
    return fmt.Errorf("remote chmod failed (check perms/path): %w", err)
}

Prevention

When it happens

Trigger: script_path resolves to a directory the SSH user cannot chmod (owned by root, read-only filesystem, noexec mount); the script path contains spaces/shell metacharacters not quoted; SELinux/AppArmor denying mode change; the file was uploaded to a path that differs from the chmod path.

Common situations: Default ScriptPath under /tmp on a hardened host that mounts /tmp noexec or with restrictive owner; a custom script_path with spaces; running as a non-root user against a root-owned path.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/4bfd84c9380f9027. Report an issue: GitHub.

Appendix: source

Thrown at internal/communicator/ssh/communicator.go:477

	if err := c.Upload(path, &script); err != nil {
		return err
	}
	if c.connInfo.TargetPlatform != TargetPlatformWindows {
		var stdout, stderr bytes.Buffer
		cmd := &remote.Cmd{
			Command: fmt.Sprintf("chmod 0777 %s", path),
			Stdout:  &stdout,
			Stderr:  &stderr,
		}
		if err := c.Start(cmd); err != nil {
			return fmt.Errorf(
				"Error chmodding script file to 0777 in remote "+
					"machine: %s", err)
		}

		if err := cmd.Wait(); err != nil {
			return fmt.Errorf(
				"Error chmodding script file to 0777 in remote "+
					"machine %v: %s %s", err, stdout.String(), stderr.String())
		}
	}
	return nil
}

// UploadDir implementation of communicator.Communicator interface
func (c *Communicator) UploadDir(dst string, src string) error {
	log.Printf("[DEBUG] Uploading dir '%s' to '%s'", src, dst)
	scpFunc := func(w io.Writer, r *bufio.Reader) error {
		uploadEntries := func() error {
			f, err := os.Open(src)
			if err != nil {
				return err
			}
			defer f.Close()

View on GitHub (pinned to d32a084675)