Ubuntu Apache2服务器无法上传文件,持sudo权限请求排查方案
Alright, let's walk through systematic steps to diagnose and resolve this 550 Permission Denied error when uploading to /var/www via Filezilla—especially since you have sudo access and the server was set up quickly. We'll start with basic checks before moving to more advanced scenarios.
Basic Troubleshooting Steps
1. Verify /var/www Directory Permissions & Ownership
First, check who owns the directory and what permissions are set. Run this via SSH:
ls -ld /var/www
You should see output like:
drwxr-xr-x 2 www-data www-data 4096 Aug 10 12:00 /var/www
- The owner and group should typically be
www-data(Apache's default user/group). - If your SSH/Filezilla user isn't part of the
www-datagroup, you won't have write access by default.
2. Confirm Your Filezilla User Matches Your SSH User
Make sure you're using the same username for both SSH and Filezilla. If you're logging into Filezilla with a different user, that account might not have the necessary permissions to write to /var/www.
Basic Fixes
1. Add Your User to the www-data Group
Grant your user group-level write access by adding them to Apache's group:
sudo usermod -aG www-data your_username
Note: You'll need to log out of SSH/Filezilla and log back in for this change to take effect.
2. Adjust Directory Group Write Permissions
If the /var/www directory doesn't allow group write access, fix it with:
sudo chmod g+w /var/www
For subdirectories and files (if you need recursive access):
sudo chmod -R g+w /var/www
Avoid using
chmod 777—it's a major security risk. Group-based permissions are far safer.
Advanced Troubleshooting Steps
1. Check AppArmor Restrictions
Ubuntu uses AppArmor by default, which can block FTP access to certain directories. Check if AppArmor is enforcing rules for your FTP server:
sudo aa-status
Look for entries related to your FTP daemon (e.g., vsftpd). If it's listed as "enforcing", check its profile:
cat /etc/apparmor.d/usr.sbin.vsftpd
Ensure there's a line like:
/var/www/** rw,
2. Inspect FTP Server Configuration
If you're using vsftpd (common on Ubuntu), verify write access is enabled in its config:
sudo nano /etc/vsftpd.conf
Look for these settings:
write_enable=YES local_umask=002 # This ensures new files have group write permissions (775 instead of 755)
Save the file and restart the FTP service:
sudo systemctl restart vsftpd
3. Check File System Mount Options
Occasionally, a read-only mount can trigger permission errors. Verify /var (or the partition hosting /var/www) is mounted as read-write:
mount | grep /var
If you see ro in the options, remount it as read-write:
sudo mount -o remount,rw /var
To make this permanent, edit /etc/fstab and remove any ro flags for the partition.
4. Verify Disk Space
Believe it or not, a full disk can sometimes throw permission errors. Check available space:
df -h
If any partition is at 100% usage, free up space before trying to upload again.
Advanced Fixes
1. Update AppArmor Profile
If AppArmor is blocking access, edit the FTP profile:
sudo nano /etc/apparmor.d/usr.sbin.vsftpd
Add this line inside the { } block:
/var/www/** rw,
Then reload AppArmor:
sudo systemctl reload apparmor
2. Adjust FTP Umask for Better Permissions
If you want uploaded files to inherit group write permissions by default, set local_umask=002 in /etc/vsftpd.conf (as mentioned earlier) and restart the service. This ensures new files have permissions 775 instead of 755, so the www-data group can modify them too.
内容的提问来源于stack exchange,提问作者brothman01

