Skip to content

getDiagnosticsData fails: www-data cannot mkdir /var/www/html/userdata on SSVM (Permission denied) #13959

Description

@kristofer-atlas

problem

Retrieving diagnostics from a system VM fails. The archive is collected on the target VM, but the async job then errors and no download URL is produced:

Unable to create a link for entity at diagnostics//diagnostics_files_<timestamp>.zip on ssvm, Error in creating directory =mkdir: cannot create directory '/var/www/html/userdata/<uuid>/': Permission denied

Expected: the job succeeds and returns a usable download URL.

versions

  • CloudStack 4.22.1.0 (management and agents)
  • System VMs from the stock systemvm-kvm-4.22.0 template, not customized
  • KVM hypervisors, NFS secondary storage

The steps to reproduce the bug

  1. Run getDiagnosticsData against a running system VM, e.g. cmk get diagnosticsdata targetid=<CPVM uuid> files=/var/log/cloud.log.
  2. Wait for the async job to complete.
  3. The job fails with errorcode 530 and the error above.

What to do about it?

The download directory is created as the www-data user (UploadManagerImpl.java#L277-L291), but the docroot on the SSVM is not writable by www-data. Shipping /var/www/html/userdata owned by www-data in the system VM template, or creating it as root and chowning, would fix it. extractVolume/extractTemplate downloads use the same directory and may be affected as well; only the diagnostics case is verified.

Workaround on a running SSVM: mkdir -p /var/www/html/userdata && chown www-data:www-data /var/www/html/userdata (lost on SSVM recreation).

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Status
    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions