You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7+PHP 7.2.5下仅/tmp可操作文件,其他目录权限报错求助

Troubleshooting File Permissions on CentOS 7 with PHP 7.2.5

Hey there, let's break down why you're only able to perform file operations in /tmp even after disabling PrivateTmp and adjusting directory permissions. This is a common headache on CentOS, so let's go through the most likely fixes step by step.

1. SELinux Context Mismatch (The #1 Culprit)

CentOS ships with SELinux enabled by default, and it often overrides standard Unix permissions—even 777 won't help if the security context is wrong. Here's how to check and fix it:

  • First, verify the current context of /var/www/html with:
    ls -Z /var/www/html
    
    You should see something like system_u:object_r:httpd_sys_content_t:s0 for read-only access. For write permissions, we need httpd_sys_rw_content_t.
  • To temporarily set the correct context (resets on reboot):
    chcon -Rv --type=httpd_sys_rw_content_t /var/www/html
    
  • To make the change permanent (survives reboots):
    semanage fcontext -a -t httpd_sys_rw_content_t "/var/www/html(/.*)?"
    restorecon -Rv /var/www/html
    
  • Also, ensure the SELinux boolean for httpd write access is enabled:
    setsebool -P httpd_unified on
    
    The -P flag makes this persistent across reboots.

2. PHP open_basedir Restriction

PHP might be configured to limit file operations to specific directories. Let's check:

  • Run this command to see your current open_basedir setting:
    php -i | grep open_basedir
    
  • If the output only includes /tmp, edit your php.ini file (usually at /etc/php.ini) and update the line to include /var/www/html:
    open_basedir = /tmp:/var/www/html
    
  • Restart httpd to apply the change:
    systemctl restart httpd
    

3. Systemd Service Hardening Limits

Even with PrivateTmp disabled, systemd might have other protections blocking writes to /var/www/html. Let's check the httpd service configuration:

  • First, look for any override files or the main service file:
    cat /usr/lib/systemd/system/httpd.service
    # Or check for overrides:
    ls /etc/systemd/system/httpd.service.d/
    
  • Look for lines like ProtectSystem=strict or ProtectHome=true—these restrict where the httpd process can write.
  • To modify these settings, create an override file:
    systemctl edit httpd
    
    Add these lines to the editor:
    [Service]
    ProtectSystem=false
    ProtectHome=false
    
  • Save and exit, then reload systemd and restart httpd:
    systemctl daemon-reload
    systemctl restart httpd
    

4. Verify PHP Process User

If you're using PHP-FPM (common with newer setups), make sure the PHP-FPM process runs as the same user that owns /var/www/html (apache:apache):

  • Check the PHP-FPM pool configuration (usually at /etc/php-fpm.d/www.conf):
    user = apache
    group = apache
    
  • If it's set to a different user (like www-data), either change it to apache or adjust the ownership of /var/www/html to match the PHP-FPM user.
  • Restart PHP-FPM after making changes:
    systemctl restart php-fpm
    

Start with the SELinux check first—it's almost always the issue on CentOS. If that doesn't fix it, move through the other steps one by one.

内容的提问来源于stack exchange,提问作者ABraut

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:11:33