You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7下Apache可写目录Folder-2执行PHP copy时权限拒绝求助

Troubleshooting "Permission Denied" with PHP copy() to Folder-2 on CentOS 7

Let's break down the most likely causes for this issue, especially since Folder-1 works fine and the third-party server has no problems—this points to environment-specific restrictions on your CentOS 7 system.

1. SELinux Contexts (The #1 Suspect)

That + at the end of your Folder-2 permissions (drwxrwxr-x+) is a big clue: it means SELinux security contexts are applied to the directory. CentOS 7 enables SELinux by default in enforcing mode, which blocks Apache/PHP from writing to directories that don't have the correct context—even if file system permissions look okay.

Folder-1 (your uploads directory) probably has an SELinux context like httpd_sys_rw_content_t or httpd_upload_dir_t that allows Apache to write to it. Folder-2 likely doesn't have this context.

  • First, check the SELinux contexts for both folders:
    ls -Z /path/to/Folder-1 /path/to/Folder-2
    
  • If Folder-2's context doesn't match Folder-1's (e.g., it shows default_t instead of httpd_sys_rw_content_t), fix it with these commands (they'll permanently set the context, even after reboots):
    semanage fcontext -a -t httpd_sys_rw_content_t "/path/to/Folder-2(/.*)?"
    restorecon -Rv /path/to/Folder-2
    

2. PHP open_basedir Restriction

PHP's open_basedir setting limits which directories scripts can access. Even if file system permissions are correct, open_basedir will block writes to directories not in its allowed list.

  • Check your current open_basedir configuration:
    php -i | grep open_basedir
    
  • If Folder-2 isn't listed, edit your php.ini (or your virtual host's PHP configuration) to add it:
    open_basedir = /path/to/Folder-1:/path/to/Folder-2:/other/allowed/paths
    
  • Restart Apache to apply the change:
    systemctl restart httpd
    

3. Parent Directory Permissions

Don't overlook the parent directory of Folder-2! If the parent folder doesn't grant Apache (or the myuser group) at least read and execute (rx) permissions, Apache can't even access Folder-2, let alone write to it.

  • Check the parent directory's permissions:
    ls -ld /path/to/parent-of-Folder-2
    
  • If the parent directory doesn't have rx for the myuser group (since Folder-2 is owned by apache:myuser), fix it with:
    chmod g+rx /path/to/parent-of-Folder-2
    

Since you're using copy() with a GitHub repository URL, make sure PHP's allow_url_fopen is enabled—without it, PHP can't read remote files, and the error might misleadingly show as "Permission denied".

  • Verify the setting:
    php -i | grep allow_url_fopen
    
  • If it's set to Off, update your php.ini:
    allow_url_fopen = On
    
  • Restart Apache to activate the change.

5. Access Control Lists (ACLs)

The + in permissions can also indicate extra ACL rules beyond standard Unix permissions. Let's check if Apache has explicit write access via ACLs:

  • View Folder-2's ACLs:
    getfacl /path/to/Folder-2
    
  • If Apache isn't listed with rwx permissions, add them:
    setfacl -m u:apache:rwx /path/to/Folder-2
    

Final Note

Given that the third-party server works, SELinux is the most probable fix here—many managed servers set SELinux to permissive mode or pre-configure correct contexts for web directories. Start with checking SELinux contexts first, as that's the most common gotcha on CentOS 7.

内容的提问来源于stack exchange,提问作者Johan Martin Aarstein

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 21:27:45