troubleshoot: document NFS permission fix for new-document creation (2026-08-11)

Files under /srv/nc-files (NFS export on desslok) created at initial AIO
setup were written by uid 0 with mode 0755 root:www-data. PHP-FPM workers
run as www-data (uid 33), which can't create new files in those dirs.

Symptom: any of "Permission denied" on new document, file upload, or
Collabora discovery. Same class of bug as the Collabora
remoteData/discovery warning.

Fix: chmod g+w on the affected parents. Snapshots saved to /var/tmp
for rollback.

Add Option A (narrow target list) and Option B (sweep all
group=www-data dirs without g+w) procedures to troubleshooting.html.
This commit is contained in:
2026-08-11 12:51:40 -05:00
parent b4777a5e4d
commit 58b4793ebe
+41
View File
@@ -41,6 +41,7 @@
<li><a href="#backup-script-ownership">Backup script won't run as tigo — root-owned 755 instead</a></li> <li><a href="#backup-script-ownership">Backup script won't run as tigo — root-owned 755 instead</a></li>
<li><a href="#appdata-missing">"Appdata directory is not present" — wrong datadir (rewire 2026-08-11)</a></li> <li><a href="#appdata-missing">"Appdata directory is not present" — wrong datadir (rewire 2026-08-11)</a></li>
<li><a href="#nextcloud-not-spawning">nextcloud container not appearing after config change</a></li> <li><a href="#nextcloud-not-spawning">nextcloud container not appearing after config change</a></li>
<li><a href="#new-document-permission-denied">New document / upload / Collabora "Permission denied" (NFS perms)</a></li>
<li><a href="#collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</a></li> <li><a href="#collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</a></li>
</ul> </ul>
</div> </div>
@@ -476,6 +477,46 @@ curl -skb $JAR -c $JAR \
# 4. Restart Apache # 4. Restart Apache
curl -skb $JAR -X POST "$BASE/api/docker/start"</code></pre> curl -skb $JAR -X POST "$BASE/api/docker/start"</code></pre>
<h2 id="new-document-permission-denied">"Can't create file: Permission denied" (Collabora, file upload, new document)</h2>
<p class="meta">Filed 2026-08-11. Root cause: NFS-mounted user files written by uid 0 during initial AIO setup, creating <code>0755 root:www-data</code> dirs everywhere. PHP-FPM workers run as <code>www-data</code> (uid 33) — they traverse via the group bit but can't create new files because <code>g+w</code> is unset.</p>
<p><strong>Symptom (any of these share the same root cause):</strong></p>
<ul>
<li>Click "New document" in Nextcloud → fails to save.</li>
<li>File upload fails with "Permission denied".</li>
<li>Collabora logs <code>Could not create path "/appdata_*/richdocuments/remoteData/discovery"</code>.</li>
</ul>
<p><strong>Diagnose:</strong></p>
<pre><code># Confirm a specific dir is unwritable for www-data
ssh homework03 \
'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
bash -c "mkdir -p /mnt/ncdata/race/files/_probe &amp;&amp; echo OK > /mnt/ncdata/race/files/_probe/foo || echo DENIED; rm -rf /mnt/ncfiles/race/files/_probe"'
# If DENIED, list the perms:
ssh homework03 'sudo -n ls -la /srv/nc-files/race/files/ /srv/nc-files/admin/files/ /srv/nc-files/appdata_*/richdocuments/remoteData/'</code></pre>
<p><strong>Fix (narrow — Option A):</strong></p>
<pre><code>ssh homework03 'sudo -n bash -s' &lt;&lt;'EOF'
# Snapshot for rollback
SNAP=/var/tmp/office-perm-snapshot-$(date -u +%Y%m%d-%H%M%S)
find /srv/ncfiles -type d \( -path '/srv/ncfiles/*/files' -o -path '/srv/ncfiles/appdata_*/richdocuments/remoteData' \) -printf '%m %u:%g %p\n' | sort &gt; "$SNAP"
echo "snapshot: $SNAP"
# Add group-write to every parent www-data needs to create under
for d in $(find /srv/nc-files -type d \( -path '/srv/nc-files/*/files' -o -path '/srv/nc-files/appdata_*/richdocuments/remoteData' \) -printf '%p\n'); do
chmod g+w "$d"
done
EOF</code></pre>
<p><strong>Fix (sweep — Option B, for repeat occurrences):</strong></p>
<pre><code>ssh homework03 'sudo -n find /srv/nc-files -group www-data -type d \
! -perm -g+w -exec chmod g+w {} +'</code></pre>
<p><strong>Why this happens:</strong> Nextcloud AIO spawns the nextcloud container running as uid 0 during initial setup. It creates the entire data tree, dir modes included, before the runtime drops to www-data. NFS preserves those modes forever; the export never re-runs the owning UID through a daemon-side map. Result: <code>root:www-data 0755</code> everywhere from the factory, no group-write.</p>
<p><strong>Verify:</strong></p>
<pre><code>ssh homework03 'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
bash -c "mkdir -p /mnt/ncdata/race/files/_vfile &amp;&amp; echo OK > /mnt/ncdata/race/files/_vfile/x &amp;&amp; cat /mnt/ncdata/race/files/_vfile/x &amp;&amp; rm -rf /mnt/ncdata/race/files/_vfile"'
# Expect: OK / OK / OK</code></pre>
<p><strong>Rollback:</strong> the snapshot file lists every dir's pre-fix mode. To restore:</p>
<pre><code>SNAP=/var/tmp/office-perm-snapshot-20260811-175027 # (example)
ssh homework03 "sudo -n awk 'NR&gt;2 {print \$3}' $SNAP | while read d; do chmod 755 \"\$d\"; done"</code></pre>
<p class="meta">Note: this also resolves the Collabora discovery warning — same class of bug.</p>
<h2 id="collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</h2> <h2 id="collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</h2>
<div class="callout info"> <div class="callout info">