You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux下创建目录触发java.nio.file.AccessDeniedException问题求助

Troubleshooting java.nio.file.AccessDeniedException When Creating Directory on Linux

Hey Bruno, sorry to hear you're hitting this access denied snag on Linux while your folder creation job runs smoothly on Windows. Let's break down the most likely culprits and fixes based on your code and stack trace.

Possible Causes & Fixes

1. Don't Just Check the Target Directory—Verify Parent Folder Permissions

Even if /path/to/dir/ has full rwxrwxrwx permissions, the parent directories above it (like /path/to/ or /path/) need to let your JAR process traverse and write into them. On Linux:

  • A directory's execute (x) permission is required to navigate into it.
  • The write (w) permission is required to create subdirectories or files inside it.

To audit the full directory chain:

# List permissions for every parent directory in the path
namei -l /path/to/dir/

Look for any folder in the chain where the user running your JAR doesn't have both x (traverse) and w (write) access.

2. Confirm Which User Is Running the JAR

Your hunch about the process lacking permissions is probably right. First, find out which user is executing your JAR:

# Locate your JAR process and its owner
ps aux | grep your-jar-filename.jar

Once you have the user (e.g., tomcat, nobody, or a custom service account), test if they can actually write to /path/to/dir/:

# Switch to the process user and try creating a test file
sudo -u <process-user> touch /path/to/dir/test-permission-check.txt

If this fails with Permission denied, you'll need to adjust permissions or ownership:

# Option 1: Give the process user ownership of the target directory
sudo chown <process-user>:<process-group> /path/to/dir/

# Option 2: Add write access for the process user's group (less secure: use o+w for all users)
sudo chmod g+w /path/to/dir/

3. Watch for Umask Interference

Your code sets the new directory to rwxrwxrwx, but Linux's umask will automatically strip certain permissions by default. For example, a default umask of 0022 will reduce 777 to 755. While this isn't the direct cause of your access denied error, it's worth noting if you need strict control over permissions. You can override the umask for the process before running the JAR, or adjust it via a system command in your code (Java doesn't have a native API for this).

4. Check SELinux/AppArmor Restrictions

Many Linux distros use security modules like SELinux (RHEL/CentOS) or AppArmor (Ubuntu) that enforce access rules beyond file permissions. These can block directory creation even if your file permissions look perfect.

  • For SELinux:

    # Temporarily disable SELinux to test (reboot will re-enable it)
    sudo setenforce 0
    

    If the job works after this, you'll need to update SELinux policies to allow your JAR to write to the directory. Check audit logs for details:

    sudo ausearch -m avc -ts recent
    
  • For AppArmor:

    # Check if AppArmor is enforcing policies for your process
    sudo aa-status
    

    If your JAR is restricted, update the AppArmor profile to grant write access to /path/to/dir/.

5. Double-Check Your Directory Creation Logic

Looking at your stack trace, I see it references Files.createDirectories()—but your code uses Files.createDirectory(). Quick reminder: createDirectory() throws an error if any parent directory in the path doesn't exist, while createDirectories() creates all missing parents. If your actual code is calling createDirectories(), make sure every parent folder in /path/to/dir/<year> has the necessary permissions for the process user.

Also, be aware of race conditions: another process could create the directory between your Files.exists() check and Files.createDirectory() call. Wrap the creation in a try-catch that ignores FileAlreadyExistsException to avoid unnecessary errors.

Final Tips

Start with the simplest checks first: verifying the process user's access to the parent directory and auditing the full directory permission chain. These are the most common fixes for this issue on Linux.

内容的提问来源于stack exchange,提问作者Bruno Miguel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 06:22:40