Make native filesystem directory permissions configurable to support shared POSIX ACL access
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 74/100
Research direction
Start by reading AbstractAdapter::makeDirectory() and the relevant configuration in config/statamic/system.php. Then find the tests covering the native filesystem adapter and directory creation. Done means newly created directories use the configured mode, the default remains 0755, and existing directories are not changed.
Written by the indexing model from the issue text.
Description
Bug description
Statamic’s native filesystem adapter creates directories with a hardcoded 0755 mode. On Linux deployments where CLI and web processes use different Unix accounts and share write access through POSIX ACLs, this restricts the inherited access ACL mask to r-x.
The named user entries are inherited, but their effective write permission is removed. This can prevent Blade nocache fragments from being written:
file_put_contents(.../storage/statamic/tmp/nocache/_nocache….blade.php):
Failed to open stream: Permission denied
The permission mechanism was reproduced locally using Statamic’s native filesystem adapter.
Relevant code
ViewServiceProvider::boot()(https://github.com/statamic/cms/blob/v6.34.1/src/Providers/ViewServiceProvider.php) createsstorage/statamic/tmp/nocacheduring application boot, including CLI boot.AbstractAdapter::makeDirectory()(https://github.com/statamic/cms/blob/v6.34.1/src/Filesystem/AbstractAdapter.php) delegates to Laravel’s filesystem with mode0755, recursive creation enabled.CompilesNocache::compileNocache()(https://github.com/statamic/cms/blob/v6.34.1/src/View/Blade/Concerns/CompilesNocache.php) writes fragments throughStatamic\Facades\File.
This path uses the native filesystem adapter, so Laravel disk permissions configured in config/filesystems.php do not affect it. The static page writer’s configurable permissions also do not cover these temporary Blade views.
Reproduction
Proposed change
Expose the native filesystem directory creation mode through configuration, preserving 0755 as the default for backwards compatibility.
For example, introduce a setting in config/statamic/system.php:
'directory_permissions' => 0755,
The native adapter would use that configured mode instead of the hardcoded value. Deployments using shared group or ACL access could choose 0775 or 0770.
This should affect newly created directories only, without recursively changing existing permissions or altering the separate static page writer configuration.
Expected behavior
With a configured mode of 0775 or 0770, inherited ACL write permissions remain effective for the other account, allowing CLI and web processes to share Statamic’s temporary directories.
Changing the process umask alone cannot solve this: it cannot add the group-class write bit missing from the explicitly requested 0755 mode.
How to reproduce
In a disposable application checkout:
- Use different Unix accounts for CLI commands and web requests.
- Grant both accounts write access to
storage/statamicthrough access and default ACLs, with a default mask ofrwx. - Start with
storage/statamic/tmp/nocacheabsent. - Boot the application through a CLI command.
- Render a Blade template containing a nocache region through the web account.
Directories created by the CLI account inherit ACLs like:
user::rwx
user:web_account:rwx #effective:r-x
group::rwx #effective:r-x
mask::r-x
default:user:web_account:rwx
default:mask::rwx
The web account cannot create the fragment. The directory owner retains write access; the failure affects the other account accessing it through the masked ACL entries.
Restoring the access mask allows writing again:
setfacl -R -m m::rwX storage/statamic/tmp
Logs
Environment
- Statamic: 6.34.1
- Laravel: 12.69.3
Installation
Fresh statamic/statamic site via CLI
Additional details
No response
- Dominant language
- PHP
- Stars
- 4.9k
- Forks
- 647
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 102
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from statamic/cms
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
assets
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
accessibility
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
antlers
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day
-
CP Cache Utility: Opening the cache manager times out when the Glide Cached Presets are too bigOpenutilities
Difficulty 4/5 3-5 days Newbie friendliness 35/100
statamic/cms#15623 · 2 reactions ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 2 days
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
smarty-php/smarty#1215 ·
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 4 days