Skip to content

fix: make xqueue app dir traversable so automated jobs can source xqu… - #394

Merged
naincy128 merged 1 commit into
masterfrom
naincy/xqueue-app-dir-traversable
Oct 8, 2026
Merged

naincy128 merged 1 commit into
masterfrom
naincy/xqueue-app-dir-traversable

Conversation

@naincy128

Copy link
Copy Markdown
Contributor

Problem

The xqueue/prod-edx-queued_submissions_to_cloudwatch Jenkins job started failing on the current prod xqueue instance:

/bin/sh: 1: .: cannot open /edx/app/xqueue/xqueue_env: Permission denied

The job SSHes in as xqueue_mgmt_commands and runs . /edx/app/xqueue/xqueue_env as that user. Only the following manage.py call goes through sudo -u www-data.

xqueue_env is already 0644 (see "setup the app env file"), so the file mode is not the problem. The parent directory is:

  • /edx/app/xqueue is the xqueue user's home directory. The add_user role creates it with useradd, and no playbook sets a mode on it.
  • On focal, useradd creates home directories as 0755. On jammy, HOME_MODE defaults to 0750, which gives drwxr-x--- xqueue:www-data.
  • xqueue_mgmt_commands is not in www-data, so it cannot enter the directory to read the file.

This lines up with xqueue moving to jammy in #386.

Change

Add a task to the xqueue role that sets {{ xqueue_app_dir }} to 0755, so the directory is set up the same way on focal and jammy.

@naincy128
naincy128 merged commit 3c2e79e into master Oct 8, 2026
3 checks passed
@naincy128
naincy128 deleted the naincy/xqueue-app-dir-traversable branch October 8, 2026 07:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants