CentOS 7+PHP 7.2.5下仅/tmp可操作文件,其他目录权限报错求助
Hey there, let's break down why you're only able to perform file operations in /tmp even after disabling PrivateTmp and adjusting directory permissions. This is a common headache on CentOS, so let's go through the most likely fixes step by step.
1. SELinux Context Mismatch (The #1 Culprit)
CentOS ships with SELinux enabled by default, and it often overrides standard Unix permissions—even 777 won't help if the security context is wrong. Here's how to check and fix it:
- First, verify the current context of
/var/www/htmlwith:
You should see something likels -Z /var/www/htmlsystem_u:object_r:httpd_sys_content_t:s0for read-only access. For write permissions, we needhttpd_sys_rw_content_t. - To temporarily set the correct context (resets on reboot):
chcon -Rv --type=httpd_sys_rw_content_t /var/www/html - To make the change permanent (survives reboots):
semanage fcontext -a -t httpd_sys_rw_content_t "/var/www/html(/.*)?" restorecon -Rv /var/www/html - Also, ensure the SELinux boolean for httpd write access is enabled:
Thesetsebool -P httpd_unified on-Pflag makes this persistent across reboots.
2. PHP open_basedir Restriction
PHP might be configured to limit file operations to specific directories. Let's check:
- Run this command to see your current
open_basedirsetting:php -i | grep open_basedir - If the output only includes
/tmp, edit yourphp.inifile (usually at/etc/php.ini) and update the line to include/var/www/html:open_basedir = /tmp:/var/www/html - Restart httpd to apply the change:
systemctl restart httpd
3. Systemd Service Hardening Limits
Even with PrivateTmp disabled, systemd might have other protections blocking writes to /var/www/html. Let's check the httpd service configuration:
- First, look for any override files or the main service file:
cat /usr/lib/systemd/system/httpd.service # Or check for overrides: ls /etc/systemd/system/httpd.service.d/ - Look for lines like
ProtectSystem=strictorProtectHome=true—these restrict where the httpd process can write. - To modify these settings, create an override file:
Add these lines to the editor:systemctl edit httpd[Service] ProtectSystem=false ProtectHome=false - Save and exit, then reload systemd and restart httpd:
systemctl daemon-reload systemctl restart httpd
4. Verify PHP Process User
If you're using PHP-FPM (common with newer setups), make sure the PHP-FPM process runs as the same user that owns /var/www/html (apache:apache):
- Check the PHP-FPM pool configuration (usually at
/etc/php-fpm.d/www.conf):user = apache group = apache - If it's set to a different user (like
www-data), either change it toapacheor adjust the ownership of/var/www/htmlto match the PHP-FPM user. - Restart PHP-FPM after making changes:
systemctl restart php-fpm
Start with the SELinux check first—it's almost always the issue on CentOS. If that doesn't fix it, move through the other steps one by one.
内容的提问来源于stack exchange,提问作者ABraut

