From 58b4793ebe96412596ab2a5b1eb99cb3528c45ec Mon Sep 17 00:00:00 2001 From: Lord Race Date: Tue, 11 Aug 2026 12:51:40 -0500 Subject: [PATCH] troubleshoot: document NFS permission fix for new-document creation (2026-08-11) Files under /srv/nc-files (NFS export on desslok) created at initial AIO setup were written by uid 0 with mode 0755 root:www-data. PHP-FPM workers run as www-data (uid 33), which can't create new files in those dirs. Symptom: any of "Permission denied" on new document, file upload, or Collabora discovery. Same class of bug as the Collabora remoteData/discovery warning. Fix: chmod g+w on the affected parents. Snapshots saved to /var/tmp for rollback. Add Option A (narrow target list) and Option B (sweep all group=www-data dirs without g+w) procedures to troubleshooting.html. --- troubleshooting.html | 43 ++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 42 insertions(+), 1 deletion(-) diff --git a/troubleshooting.html b/troubleshooting.html index 550f93c..d66c0b0 100644 --- a/troubleshooting.html +++ b/troubleshooting.html @@ -41,7 +41,8 @@
  • Backup script won't run as tigo — root-owned 755 instead
  • "Appdata directory is not present" — wrong datadir (rewire 2026-08-11)
  • nextcloud container not appearing after config change
  • -
  • Collabora logs "Could not create path .../richdocuments/remoteData/discovery"
  • +
  • New document / upload / Collabora "Permission denied" (NFS perms)
  • +
  • Collabora logs "Could not create path .../richdocuments/remoteData/discovery"
  • @@ -476,6 +477,46 @@ curl -skb $JAR -c $JAR \ # 4. Restart Apache curl -skb $JAR -X POST "$BASE/api/docker/start" +

    "Can't create file: Permission denied" (Collabora, file upload, new document)

    +

    Filed 2026-08-11. Root cause: NFS-mounted user files written by uid 0 during initial AIO setup, creating 0755 root:www-data dirs everywhere. PHP-FPM workers run as www-data (uid 33) — they traverse via the group bit but can't create new files because g+w is unset.

    +

    Symptom (any of these share the same root cause):

    + +

    Diagnose:

    +
    # Confirm a specific dir is unwritable for www-data
    +ssh homework03 \
    +  'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
    +     bash -c "mkdir -p /mnt/ncdata/race/files/_probe && echo OK > /mnt/ncdata/race/files/_probe/foo || echo DENIED; rm -rf /mnt/ncfiles/race/files/_probe"'
    +# If DENIED, list the perms:
    +ssh homework03 'sudo -n ls -la /srv/nc-files/race/files/ /srv/nc-files/admin/files/ /srv/nc-files/appdata_*/richdocuments/remoteData/'
    +

    Fix (narrow — Option A):

    +
    ssh homework03 'sudo -n bash -s' <<'EOF'
    +# Snapshot for rollback
    +SNAP=/var/tmp/office-perm-snapshot-$(date -u +%Y%m%d-%H%M%S)
    +find /srv/ncfiles -type d \( -path '/srv/ncfiles/*/files' -o -path '/srv/ncfiles/appdata_*/richdocuments/remoteData' \) -printf '%m %u:%g %p\n' | sort > "$SNAP"
    +echo "snapshot: $SNAP"
    +
    +# Add group-write to every parent www-data needs to create under
    +for d in $(find /srv/nc-files -type d \( -path '/srv/nc-files/*/files' -o -path '/srv/nc-files/appdata_*/richdocuments/remoteData' \) -printf '%p\n'); do
    +  chmod g+w "$d"
    +done
    +EOF
    +

    Fix (sweep — Option B, for repeat occurrences):

    +
    ssh homework03 'sudo -n find /srv/nc-files -group www-data -type d \
    +  ! -perm -g+w -exec chmod g+w {} +'
    +

    Why this happens: Nextcloud AIO spawns the nextcloud container running as uid 0 during initial setup. It creates the entire data tree, dir modes included, before the runtime drops to www-data. NFS preserves those modes forever; the export never re-runs the owning UID through a daemon-side map. Result: root:www-data 0755 everywhere from the factory, no group-write.

    +

    Verify:

    +
    ssh homework03 'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
    +  bash -c "mkdir -p /mnt/ncdata/race/files/_vfile && echo OK > /mnt/ncdata/race/files/_vfile/x && cat /mnt/ncdata/race/files/_vfile/x && rm -rf /mnt/ncdata/race/files/_vfile"'
    +# Expect: OK / OK / OK
    +

    Rollback: the snapshot file lists every dir's pre-fix mode. To restore:

    +
    SNAP=/var/tmp/office-perm-snapshot-20260811-175027   # (example)
    +ssh homework03 "sudo -n awk 'NR>2 {print \$3}' $SNAP | while read d; do chmod 755 \"\$d\"; done"
    +

    Note: this also resolves the Collabora discovery warning — same class of bug.

    +

    Collabora logs "Could not create path .../richdocuments/remoteData/discovery"