Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Make native filesystem directory permissions configurable to support shared POSIX ACL access

Open Beginner friendly
#15,566 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
74/100
Issue type
Feature
Clarity
Clearly specified
Activity status
Active
Tech stack
laravel, php
Domain
backend

Research direction

Start by reading AbstractAdapter::makeDirectory() and the relevant configuration in config/statamic/system.php. Then find the tests covering the native filesystem adapter and directory creation. Done means newly created directories use the configured mode, the default remains 0755, and existing directories are not changed.

Written by the indexing model from the issue text.

Description

Bug description

Statamic’s native filesystem adapter creates directories with a hardcoded 0755 mode. On Linux deployments where CLI and web processes use different Unix accounts and share write access through POSIX ACLs, this restricts the inherited access ACL mask to r-x.

The named user entries are inherited, but their effective write permission is removed. This can prevent Blade nocache fragments from being written:

file_put_contents(.../storage/statamic/tmp/nocache/_nocache….blade.php):
Failed to open stream: Permission denied

The permission mechanism was reproduced locally using Statamic’s native filesystem adapter.

Relevant code

This path uses the native filesystem adapter, so Laravel disk permissions configured in config/filesystems.php do not affect it. The static page writer’s configurable permissions also do not cover these temporary Blade views.

Reproduction
Proposed change

Expose the native filesystem directory creation mode through configuration, preserving 0755 as the default for backwards compatibility.

For example, introduce a setting in config/statamic/system.php:

'directory_permissions' => 0755,

The native adapter would use that configured mode instead of the hardcoded value. Deployments using shared group or ACL access could choose 0775 or 0770.

This should affect newly created directories only, without recursively changing existing permissions or altering the separate static page writer configuration.

Expected behavior

With a configured mode of 0775 or 0770, inherited ACL write permissions remain effective for the other account, allowing CLI and web processes to share Statamic’s temporary directories.

Changing the process umask alone cannot solve this: it cannot add the group-class write bit missing from the explicitly requested 0755 mode.

How to reproduce

In a disposable application checkout:

  1. Use different Unix accounts for CLI commands and web requests.
  2. Grant both accounts write access to storage/statamic through access and default ACLs, with a default mask of rwx.
  3. Start with storage/statamic/tmp/nocache absent.
  4. Boot the application through a CLI command.
  5. Render a Blade template containing a nocache region through the web account.

Directories created by the CLI account inherit ACLs like:

user::rwx
user:web_account:rwx       #effective:r-x
group::rwx                #effective:r-x
mask::r-x
default:user:web_account:rwx
default:mask::rwx

The web account cannot create the fragment. The directory owner retains write access; the failure affects the other account accessing it through the masked ACL entries.

Restoring the access mask allows writing again:

setfacl -R -m m::rwX storage/statamic/tmp
Logs

Environment
- Statamic: 6.34.1
- Laravel: 12.69.3
Installation

Fresh statamic/statamic site via CLI

Additional details

No response

Dominant language
PHP
Stars
4.9k
Forks
647
Avg merge
1d 9h
Merged PRs (30d)
102

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from statamic/cms

All issues in statamic/cms

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.