CentOS 7下Apache可写目录Folder-2执行PHP copy时权限拒绝求助
copy() to Folder-2 on CentOS 7 Let's break down the most likely causes for this issue, especially since Folder-1 works fine and the third-party server has no problems—this points to environment-specific restrictions on your CentOS 7 system.
1. SELinux Contexts (The #1 Suspect)
That + at the end of your Folder-2 permissions (drwxrwxr-x+) is a big clue: it means SELinux security contexts are applied to the directory. CentOS 7 enables SELinux by default in enforcing mode, which blocks Apache/PHP from writing to directories that don't have the correct context—even if file system permissions look okay.
Folder-1 (your uploads directory) probably has an SELinux context like httpd_sys_rw_content_t or httpd_upload_dir_t that allows Apache to write to it. Folder-2 likely doesn't have this context.
- First, check the SELinux contexts for both folders:
ls -Z /path/to/Folder-1 /path/to/Folder-2 - If Folder-2's context doesn't match Folder-1's (e.g., it shows
default_tinstead ofhttpd_sys_rw_content_t), fix it with these commands (they'll permanently set the context, even after reboots):semanage fcontext -a -t httpd_sys_rw_content_t "/path/to/Folder-2(/.*)?" restorecon -Rv /path/to/Folder-2
2. PHP open_basedir Restriction
PHP's open_basedir setting limits which directories scripts can access. Even if file system permissions are correct, open_basedir will block writes to directories not in its allowed list.
- Check your current
open_basedirconfiguration:php -i | grep open_basedir - If Folder-2 isn't listed, edit your
php.ini(or your virtual host's PHP configuration) to add it:open_basedir = /path/to/Folder-1:/path/to/Folder-2:/other/allowed/paths - Restart Apache to apply the change:
systemctl restart httpd
3. Parent Directory Permissions
Don't overlook the parent directory of Folder-2! If the parent folder doesn't grant Apache (or the myuser group) at least read and execute (rx) permissions, Apache can't even access Folder-2, let alone write to it.
- Check the parent directory's permissions:
ls -ld /path/to/parent-of-Folder-2 - If the parent directory doesn't have
rxfor themyusergroup (since Folder-2 is owned byapache:myuser), fix it with:chmod g+rx /path/to/parent-of-Folder-2
4. Remote URL Access (If $githubRepository is a Remote Link)
Since you're using copy() with a GitHub repository URL, make sure PHP's allow_url_fopen is enabled—without it, PHP can't read remote files, and the error might misleadingly show as "Permission denied".
- Verify the setting:
php -i | grep allow_url_fopen - If it's set to
Off, update yourphp.ini:allow_url_fopen = On - Restart Apache to activate the change.
5. Access Control Lists (ACLs)
The + in permissions can also indicate extra ACL rules beyond standard Unix permissions. Let's check if Apache has explicit write access via ACLs:
- View Folder-2's ACLs:
getfacl /path/to/Folder-2 - If Apache isn't listed with rwx permissions, add them:
setfacl -m u:apache:rwx /path/to/Folder-2
Final Note
Given that the third-party server works, SELinux is the most probable fix here—many managed servers set SELinux to permissive mode or pre-configure correct contexts for web directories. Start with checking SELinux contexts first, as that's the most common gotcha on CentOS 7.
内容的提问来源于stack exchange,提问作者Johan Martin Aarstein

