# Set file upload to inherit permission of parent directory

**URL:** <https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819>\
**Category:** Get Help\
**Created:** [October 17, 2024, 8:09pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819 "2024-10-17T20:09:23Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![samagids](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/samagids/32/2445_2.png) [@samagids](https://discourse.openondemand.org/u/samagids)\
**Post date:** [October 17, 2024, 8:09pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/1 "2024-10-17T20:09:23Z")

</div>

I currently have OOD 3.1.9  
SELinux enabled  
We are still testing OOD for production use.

When we upload files or directories, they work fine, but for some reason, they do not inherit the group ownership of the parent directory.

How can I fix this?

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 18, 2024, 1:32pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/2 "2024-10-18T13:32:00Z")

</div>

This was actually a bugfix in 3.1.9. The issue I suspect is that you’re not actually able to `chown` that file to that group. You’ll see errors in `/var/log/ondemand-nginx/$USER/error.log` for the same.

On that same file in the same directory - are you able to open a shell and `chown` to that group manually? I suspect you can’t.

Here’s the relevant block of code where we attempt to chown, but rescue and log the failure to do so.

> <https://github.com/OSC/ondemand/blob/6361dd77bc99f28efe9f6b5fcc907277a2785a49/apps/dashboard/app/models/posix_file.rb#L154-L159>

---

<div class="post-metadata">

**Author:** ![samagids](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/samagids/32/2445_2.png) [@samagids](https://discourse.openondemand.org/u/samagids)\
**Post date:** [October 18, 2024, 3:40pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/3 "2024-10-18T15:40:06Z")

</div>

The error shows operation not permitted.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 18, 2024, 3:43pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/4 "2024-10-18T15:43:49Z")

</div>

> [@samagids](#):
>
> The error shows operation not permitted.

Are you able to open a shell and `chown` the file to the group you’d expect?

---

<div class="post-metadata">

**Author:** ![burmek](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/burmek/32/2534_2.png) [@burmek](https://discourse.openondemand.org/u/burmek)\
**Post date:** [December 18, 2024, 2:40pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/5 "2024-12-18T14:40:13Z")

</div>

Hi @jeff.ohrstrom. Picking this up from my colleague…

Your assumption is correct, users uploading files do not have the necessary permission to `chown` to the group, which is intended.

Based on the findings from another recent issue  
([File upload and posix acl support - updated](https://discourse.openondemand.org/t/file-upload-and-posix-acl-support-updated/3783))  
related to `FileUtils.mv` versus `FileUtils.cp`, for the `handle_upload` function in `posix_file.rb`, I’ve achieved the desired behavior by enabling `setgid` on all home directories and switching `mv` to `cp`.

What are your thoughts on this approach?

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [December 18, 2024, 2:44pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/6 "2024-12-18T14:44:42Z")

</div>

Hi and welcome!

To `cp` we’d need to `rm` the temp file as well I think. I’ll have to look into `FileUtils.mv` as the other topic seems to suggest it’s doing a chown by itself.

---

<div class="post-metadata">

**Author:** ![burmek](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/burmek/32/2534_2.png) [@burmek](https://discourse.openondemand.org/u/burmek)\
**Post date:** [January 6, 2025, 7:10pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/7 "2025-01-06T19:10:38Z")

</div>

One other thing worth mentioning: after making the change from `mv` to `cp`, uploads to a `/scratch` directory that is in an AWS FSx for Lustre filesystem throw an error for upload failed, but still successfully complete the upload

Edit: with the above behavior, the file is present within the filesystem, but is not shown within the OOD console

---

<div class="post-metadata">

**Author:** ![burmek](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/burmek/32/2534_2.png) [@burmek](https://discourse.openondemand.org/u/burmek)\
**Post date:** [January 21, 2025, 7:26pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/8 "2025-01-21T19:26:42Z")

</div>

@jeff.ohrstrom, any idea why the change would have the resulting behavior on the`/scratch` FSx Lustre directory?

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 21, 2025, 9:22pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/9 "2025-01-21T21:22:51Z")

</div>

> [@burmek](#):
>
> Edit: with the above behavior, the file is present within the filesystem, but is not shown within the OOD console

This is the behavior you’re referring to?

Do you use the allowlist on your files? This could cause it to not show up, if the file is actually a symlink that points outside of the allowlist paths.

Another issue could be non-utf8 characters. You’d see errors in `/var/log/ondemand-nginx/$USER/error.log` if this were the case.

---

<div class="post-metadata">

**Author:** ![burmek](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/burmek/32/2534_2.png) [@burmek](https://discourse.openondemand.org/u/burmek)\
**Post date:** [January 22, 2025, 9:30pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/10 "2025-01-22T21:30:28Z")

</div>

Indeed, that behavior. We aren’t using the allowlist on file paths so wouldn’t be that. Oddly not getting any errors in the `/var/log/ondemand-nginx/$USER/error.log` files, but do see `403` responses for uploads to the `/scratch` directory from the `/var/log/ondemand-nginx/$USER/access.log`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [July 21, 2025, 9:32pm UTC](https://discourse.openondemand.org/t/set-file-upload-to-inherit-permission-of-parent-directory/3819/11 "2025-07-21T21:32:48Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
