You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Symfony4部署Fedora服务器时缓存目录权限异常求助

Fixing Symfony 4 Permission Issues on Fedora 28 (Apache + PHP 7.2)

Hey there, let’s work through this permission headache you’re hitting with your first Symfony 4 deployment on Fedora 28. Moving from the built-in PHP server to Apache often trips people up because of stricter filesystem and security policies—especially SELinux, which is enabled by default on Fedora. Here’s a step-by-step breakdown to get your cache and translations directories working properly:

1. Ditch the 777 Permissions (They’re Unsafe & Often Ineffective)

First off, setting 777 on directories is a bad security practice, and SELinux will often block Apache from writing to them anyway. Let’s reset to more secure, functional permissions:

  • Set the correct owner for your project (replace your_username with your actual SSH user):
    chown -R apache:your_username /var/www/html/HAY
    
  • Set default directory and file permissions:
    find /var/www/html/HAY -type d -exec chmod 755 {} \;
    find /var/www/html/HAY -type f -exec chmod 644 {} \;
    

Symfony relies heavily on the var directory for cache, logs, and translations. Use setfacl to grant persistent write access to both Apache and your user:

  • First, make sure the ACL package is installed:
    dnf install acl
    
  • Apply recursive ACL permissions to var:
    setfacl -R -m u:apache:rwX -m u:$(whoami):rwX /var/www/html/HAY/var
    setfacl -dR -m u:apache:rwX -m u:$(whoami):rwX /var/www/html/HAY/var
    
    The -d flag ensures any new files/directories created in var inherit these permissions automatically.

3. Fix SELinux Contexts (The Most Common Fedora Culprit)

Fedora’s SELinux blocks Apache from writing to directories unless they have the correct security context. Let’s update the var directory:

  • Apply the temporary context (will reset on reboot):
    chcon -R -t httpd_sys_rw_content_t /var/www/html/HAY/var
    
  • Make the context permanent so it survives reboots:
    semanage fcontext -a -t httpd_sys_rw_content_t "/var/www/html/HAY/var(/.*)?"
    restorecon -R /var/www/html/HAY/var
    
    The httpd_sys_rw_content_t label tells SELinux that Apache is allowed to read and write to this directory.

4. Clear Cache the Right Way

Always clear the cache using the Apache user to avoid permission mismatches:

sudo -u apache php /var/www/html/HAY/bin/console cache:clear --env=dev

If you accidentally run cache:clear as root, fix the permissions afterward:

chown -R apache:apache /var/www/html/HAY/var/cache /var/www/html/HAY/var/log

Why This Works

Your original issue happened because even though you set apache:apache ownership, SELinux was still blocking writes, and 777 bypasses standard permissions but doesn’t override SELinux policies. Combining proper ownership, ACLs, and SELinux context adjustments aligns with both Symfony’s requirements and Fedora’s security rules.

内容的提问来源于stack exchange,提问作者Lyes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:11:10