Nginx Unit配置PHP/Laravel应用遇权限拒绝(已设777权限)
Nginx Unit 部署 Laravel 权限拒绝问题排查与解决
问题描述
按照Nginx Unit官方Laravel配置指南操作(仅修改文件夹名称),提交配置JSON时出现权限拒绝错误,错误日志如下:
2023/06/15 20:01:27 [info] 5192#5192 "laravel" prototype started 2023/06/15 20:01:27 [info] 5193#5193 "laravel" application started 2023/06/15 20:01:27 [alert] 5193#5193 root realpath(/home/victor/workspace/estatutario/public/) failed (13: Permission denied) 2023/06/15 20:01:27 [notice] 5192#5192 app process 5193 exited with code 1 2023/06/15 20:01:27 [warn] 913#913 failed to start application "laravel" 2023/06/15 20:01:27 [alert] 913#913 failed to apply new conf 2023/06/15 20:01:27 [notice] 897#897 process 5192 exited with code 0
使用的config.json配置:
{ "listeners": { "*:8003": { "pass": "routes" } }, "routes": [ { "match": { "uri": "!/index.php" }, "action": { "share": "/home/victor/workspace/estatutario/public$uri", "fallback": { "pass": "applications/laravel" } } } ], "applications": { "laravel": { "type": "php", "root": "/home/victor/workspace/estatutario/public/", "script": "index.php" } } }
已做的排查操作:
- 将项目目录权限设为777,且所有者为
unit用户:
victor@webapps-dev:~/workspace/estatutario$ ls -la total 384 drwxrwxrwx 13 unit unit 4096 Jun 15 01:04 . drwxrwxr-x 16 victor victor 4096 Jun 15 19:53 .. drwxrwxrwx 7 unit unit 4096 Jun 15 01:00 app -rwxrwxrwx 1 unit unit 1686 Jun 15 01:00 artisan drwxrwxrwx 3 unit unit 4096 Jun 15 01:00 bootstrap (...)
- 确认项目路径为
/home/victor/workspace/estatutario - 确认Nginx Unit运行用户为
unit:
victor@webapps-dev:~$ ps -ef | grep unit root 897 1 0 19:15 ? 00:00:00 unit: main v1.30.0 [/usr/sbin/unitd] unit 912 897 0 19:15 ? 00:00:00 unit: controller unit 913 897 0 19:15 ? 00:00:00 unit: router victor 5559 1507 0 20:10 pts/0 00:00:00 grep --color=auto unit
解决方案
问题出在父目录的权限上,你只设置了项目目录estatutario的权限,但Nginx Unit的unit用户需要遍历从根目录到public文件夹的所有父目录,包括/home/victor和/home/victor/workspace。
具体操作步骤:
- 给
/home/victor目录添加执行权限(执行权限允许用户进入目录):
chmod o+x /home/victor
如果unit用户属于victor组,可使用更精准的权限设置:
chmod g+x /home/victor
- 同样给
workspace目录添加执行权限:
chmod o+x /home/victor/workspace
或对应组权限设置:
chmod g+x /home/victor/workspace
- 重新提交配置JSON:
curl -X PUT -d @config.json --unix-socket /run/control.unit.sock http://localhost/config
原理说明
在Linux系统中,要访问某个目录下的文件,用户需要拥有该目录及其所有父目录的执行权限(x权限)。即使项目目录设置了777权限,如果父目录未给unit用户执行权限,unit用户无法进入父目录,也就无法访问到项目的public文件夹,从而触发Permission denied错误。
内容的提问来源于stack exchange,提问作者Victor Ribeiro
相关产品推荐
相关产品推荐

