troubleshoot: document NFS permission fix for new-document creation (2026-08-11)
Files under /srv/nc-files (NFS export on desslok) created at initial AIO setup were written by uid 0 with mode 0755 root:www-data. PHP-FPM workers run as www-data (uid 33), which can't create new files in those dirs. Symptom: any of "Permission denied" on new document, file upload, or Collabora discovery. Same class of bug as the Collabora remoteData/discovery warning. Fix: chmod g+w on the affected parents. Snapshots saved to /var/tmp for rollback. Add Option A (narrow target list) and Option B (sweep all group=www-data dirs without g+w) procedures to troubleshooting.html.
This commit is contained in:
+42
-1
@@ -41,7 +41,8 @@
|
|||||||
<li><a href="#backup-script-ownership">Backup script won't run as tigo — root-owned 755 instead</a></li>
|
<li><a href="#backup-script-ownership">Backup script won't run as tigo — root-owned 755 instead</a></li>
|
||||||
<li><a href="#appdata-missing">"Appdata directory is not present" — wrong datadir (rewire 2026-08-11)</a></li>
|
<li><a href="#appdata-missing">"Appdata directory is not present" — wrong datadir (rewire 2026-08-11)</a></li>
|
||||||
<li><a href="#nextcloud-not-spawning">nextcloud container not appearing after config change</a></li>
|
<li><a href="#nextcloud-not-spawning">nextcloud container not appearing after config change</a></li>
|
||||||
<li><a href="#collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</a></li>
|
<li><a href="#new-document-permission-denied">New document / upload / Collabora "Permission denied" (NFS perms)</a></li>
|
||||||
|
<li><a href="#collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</a></li>
|
||||||
</ul>
|
</ul>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -476,6 +477,46 @@ curl -skb $JAR -c $JAR \
|
|||||||
# 4. Restart Apache
|
# 4. Restart Apache
|
||||||
curl -skb $JAR -X POST "$BASE/api/docker/start"</code></pre>
|
curl -skb $JAR -X POST "$BASE/api/docker/start"</code></pre>
|
||||||
|
|
||||||
|
<h2 id="new-document-permission-denied">"Can't create file: Permission denied" (Collabora, file upload, new document)</h2>
|
||||||
|
<p class="meta">Filed 2026-08-11. Root cause: NFS-mounted user files written by uid 0 during initial AIO setup, creating <code>0755 root:www-data</code> dirs everywhere. PHP-FPM workers run as <code>www-data</code> (uid 33) — they traverse via the group bit but can't create new files because <code>g+w</code> is unset.</p>
|
||||||
|
<p><strong>Symptom (any of these share the same root cause):</strong></p>
|
||||||
|
<ul>
|
||||||
|
<li>Click "New document" in Nextcloud → fails to save.</li>
|
||||||
|
<li>File upload fails with "Permission denied".</li>
|
||||||
|
<li>Collabora logs <code>Could not create path "/appdata_*/richdocuments/remoteData/discovery"</code>.</li>
|
||||||
|
</ul>
|
||||||
|
<p><strong>Diagnose:</strong></p>
|
||||||
|
<pre><code># Confirm a specific dir is unwritable for www-data
|
||||||
|
ssh homework03 \
|
||||||
|
'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
|
||||||
|
bash -c "mkdir -p /mnt/ncdata/race/files/_probe && echo OK > /mnt/ncdata/race/files/_probe/foo || echo DENIED; rm -rf /mnt/ncfiles/race/files/_probe"'
|
||||||
|
# If DENIED, list the perms:
|
||||||
|
ssh homework03 'sudo -n ls -la /srv/nc-files/race/files/ /srv/nc-files/admin/files/ /srv/nc-files/appdata_*/richdocuments/remoteData/'</code></pre>
|
||||||
|
<p><strong>Fix (narrow — Option A):</strong></p>
|
||||||
|
<pre><code>ssh homework03 'sudo -n bash -s' <<'EOF'
|
||||||
|
# Snapshot for rollback
|
||||||
|
SNAP=/var/tmp/office-perm-snapshot-$(date -u +%Y%m%d-%H%M%S)
|
||||||
|
find /srv/ncfiles -type d \( -path '/srv/ncfiles/*/files' -o -path '/srv/ncfiles/appdata_*/richdocuments/remoteData' \) -printf '%m %u:%g %p\n' | sort > "$SNAP"
|
||||||
|
echo "snapshot: $SNAP"
|
||||||
|
|
||||||
|
# Add group-write to every parent www-data needs to create under
|
||||||
|
for d in $(find /srv/nc-files -type d \( -path '/srv/nc-files/*/files' -o -path '/srv/nc-files/appdata_*/richdocuments/remoteData' \) -printf '%p\n'); do
|
||||||
|
chmod g+w "$d"
|
||||||
|
done
|
||||||
|
EOF</code></pre>
|
||||||
|
<p><strong>Fix (sweep — Option B, for repeat occurrences):</strong></p>
|
||||||
|
<pre><code>ssh homework03 'sudo -n find /srv/nc-files -group www-data -type d \
|
||||||
|
! -perm -g+w -exec chmod g+w {} +'</code></pre>
|
||||||
|
<p><strong>Why this happens:</strong> Nextcloud AIO spawns the nextcloud container running as uid 0 during initial setup. It creates the entire data tree, dir modes included, before the runtime drops to www-data. NFS preserves those modes forever; the export never re-runs the owning UID through a daemon-side map. Result: <code>root:www-data 0755</code> everywhere from the factory, no group-write.</p>
|
||||||
|
<p><strong>Verify:</strong></p>
|
||||||
|
<pre><code>ssh homework03 'sudo -n docker exec -u www-data nextcloud-aio-nextcloud \
|
||||||
|
bash -c "mkdir -p /mnt/ncdata/race/files/_vfile && echo OK > /mnt/ncdata/race/files/_vfile/x && cat /mnt/ncdata/race/files/_vfile/x && rm -rf /mnt/ncdata/race/files/_vfile"'
|
||||||
|
# Expect: OK / OK / OK</code></pre>
|
||||||
|
<p><strong>Rollback:</strong> the snapshot file lists every dir's pre-fix mode. To restore:</p>
|
||||||
|
<pre><code>SNAP=/var/tmp/office-perm-snapshot-20260811-175027 # (example)
|
||||||
|
ssh homework03 "sudo -n awk 'NR>2 {print \$3}' $SNAP | while read d; do chmod 755 \"\$d\"; done"</code></pre>
|
||||||
|
<p class="meta">Note: this also resolves the Collabora discovery warning — same class of bug.</p>
|
||||||
|
|
||||||
<h2 id="collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</h2>
|
<h2 id="collabora-discovery-warning">Collabora logs "Could not create path .../richdocuments/remoteData/discovery"</h2>
|
||||||
|
|
||||||
<div class="callout info">
|
<div class="callout info">
|
||||||
|
|||||||
Reference in New Issue
Block a user