Linux下创建目录触发java.nio.file.AccessDeniedException问题求助
java.nio.file.AccessDeniedException When Creating Directory on Linux Hey Bruno, sorry to hear you're hitting this access denied snag on Linux while your folder creation job runs smoothly on Windows. Let's break down the most likely culprits and fixes based on your code and stack trace.
Possible Causes & Fixes
1. Don't Just Check the Target Directory—Verify Parent Folder Permissions
Even if /path/to/dir/ has full rwxrwxrwx permissions, the parent directories above it (like /path/to/ or /path/) need to let your JAR process traverse and write into them. On Linux:
- A directory's
execute(x) permission is required to navigate into it. - The
write(w) permission is required to create subdirectories or files inside it.
To audit the full directory chain:
# List permissions for every parent directory in the path namei -l /path/to/dir/
Look for any folder in the chain where the user running your JAR doesn't have both x (traverse) and w (write) access.
2. Confirm Which User Is Running the JAR
Your hunch about the process lacking permissions is probably right. First, find out which user is executing your JAR:
# Locate your JAR process and its owner ps aux | grep your-jar-filename.jar
Once you have the user (e.g., tomcat, nobody, or a custom service account), test if they can actually write to /path/to/dir/:
# Switch to the process user and try creating a test file sudo -u <process-user> touch /path/to/dir/test-permission-check.txt
If this fails with Permission denied, you'll need to adjust permissions or ownership:
# Option 1: Give the process user ownership of the target directory sudo chown <process-user>:<process-group> /path/to/dir/ # Option 2: Add write access for the process user's group (less secure: use o+w for all users) sudo chmod g+w /path/to/dir/
3. Watch for Umask Interference
Your code sets the new directory to rwxrwxrwx, but Linux's umask will automatically strip certain permissions by default. For example, a default umask of 0022 will reduce 777 to 755. While this isn't the direct cause of your access denied error, it's worth noting if you need strict control over permissions. You can override the umask for the process before running the JAR, or adjust it via a system command in your code (Java doesn't have a native API for this).
4. Check SELinux/AppArmor Restrictions
Many Linux distros use security modules like SELinux (RHEL/CentOS) or AppArmor (Ubuntu) that enforce access rules beyond file permissions. These can block directory creation even if your file permissions look perfect.
For SELinux:
# Temporarily disable SELinux to test (reboot will re-enable it) sudo setenforce 0If the job works after this, you'll need to update SELinux policies to allow your JAR to write to the directory. Check audit logs for details:
sudo ausearch -m avc -ts recentFor AppArmor:
# Check if AppArmor is enforcing policies for your process sudo aa-statusIf your JAR is restricted, update the AppArmor profile to grant write access to
/path/to/dir/.
5. Double-Check Your Directory Creation Logic
Looking at your stack trace, I see it references Files.createDirectories()—but your code uses Files.createDirectory(). Quick reminder: createDirectory() throws an error if any parent directory in the path doesn't exist, while createDirectories() creates all missing parents. If your actual code is calling createDirectories(), make sure every parent folder in /path/to/dir/<year> has the necessary permissions for the process user.
Also, be aware of race conditions: another process could create the directory between your Files.exists() check and Files.createDirectory() call. Wrap the creation in a try-catch that ignores FileAlreadyExistsException to avoid unnecessary errors.
Final Tips
Start with the simplest checks first: verifying the process user's access to the parent directory and auditing the full directory permission chain. These are the most common fixes for this issue on Linux.
内容的提问来源于stack exchange,提问作者Bruno Miguel

