Hubzilla won't start: /store/[data]/smarty3 must be writable by webserver

140 Views Asked by At

I followed the manual instructions to set up Hubzilla here.

https://project.hubzilla.org/help/en/admin/administrator_guide#Manual_Installation

I ran the command

chmod -R 777 store

But it still gives me this error when I view the page in the browser.

ERROR: folder /var/www/html//store/[data]/smarty3 must be writable by webserver.

I tried chown -R apache:apache store and chmod o-w -R store to tighten it up, but that didn't work so I just ran chmod -R 777 store again. Here are the permissions.

[root@fsphub html]# ls -ld store
drwxrwxrwx. 3 apache apache 20 Dec  1 22:08 store

[root@fsphub html]# ls -lR store
store:
total 0
drwxrwxrwx. 3 apache apache 21 Dec  1 22:08 [data]

store/[data]:
total 0
drwxrwxrwx. 2 apache apache 6 Dec  1 22:08 smarty3

store/[data]/smarty3:
total 0

Apache is running as apache.

[root@fsphub html]# ps -ef | grep http
root     16997     1  0 21:47 ?        00:00:00 /usr/sbin/httpd -DFOREGROUND
apache   16998 16997  0 21:47 ?        00:00:00 /usr/sbin/httpd -DFOREGROUND

What could be wrong?

PHP 7.2.12

1

There are 1 best solutions below

0
Chloe On BEST ANSWER

It was due to SELinux being on. https://wiki.centos.org/HowTos/SELinux

# sestatus
SELinux status:                 enabled
Current mode:                   enforcing

# sealert -a /var/log/audit/audit.log

SELinux is preventing /usr/sbin/httpd from write access on the directory smarty3.

***** Plugin httpd_write_content (92.2 confidence) suggests ***************

If you want to allow httpd to have write access on the smarty3 directory Then you need to change the label on 'smarty3' Do
# semanage fcontext -a -t httpd_sys_rw_content_t 'smarty3'
# restorecon -v 'smarty3'

Raw Audit Messages
type=AVC msg=audit(1543792561.65:60034): avc: denied { write } for pid=21907 comm="httpd" name="smarty3" dev="vda1" ino=621797 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:httpd_sys_content_t:s0 tclass=dir

# ls -lZd store/\[data\]/smarty3/
drwxrwxrwx. apache apache unconfined_u:object_r:httpd_sys_content_t:s0 store/[data]/smarty3/

So I ran

# semanage fcontext -a -t httpd_sys_rw_content_t store/\[data\]/smarty3/
# restorecon -v store/\[data\]/smarty3/

But that just didn't work so I used

setenforce 0

To change the mode to permissive.