如何授权Tomcat 9访问其他文件

5

Tomcat 9被沙盒化了。

我想读取一个日志文件的数据。

该文件位于“/opt/zigbee2mqtt/data/

我已经阅读了这个线程并尝试了它。 如何允许Tomcat war应用程序写入文件夹

我编辑了文件,并执行了 systemctl daemon-reloadsystemctl restart tomcat9

然后我编写了一个Java类,应该从日志文件中读取数据。但是我遇到了一个异常。

java.io.FileNotFoundException: /opt/zigbee2mqtt/data/configuration.yaml (Permission denied)
        at java.base/java.io.FileOutputStream.open0(Native Method)
        at java.base/java.io.FileOutputStream.open(FileOutputStream.java:298)
        at java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:237)
        at java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:187)
        at com.fasterxml.jackson.dataformat.yaml.YAMLFactory.createGenerator(YAMLFactory.java:437)
        at com.fasterxml.jackson.databind.ObjectMapper.createGenerator(ObjectMapper.java:1156)
        at com.fasterxml.jackson.databind.ObjectMapper.writeValue(ObjectMapper.java:3570)
        at zigbee.main.doupdateconfiguration(main.java:81)
        at Servlet.configuration.doPost(configuration.java:72)
        at javax.servlet.http.HttpServlet.service(HttpServlet.java:660)
        at javax.servlet.http.HttpServlet.service(HttpServlet.java:741)
        at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)
        at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
        at org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)
        at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
        at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
        at org.apache.catalina.filters.ExpiresFilter.doFilter(ExpiresFilter.java:1226)
        at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)
        at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)
        at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:200)
        at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)
        at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:490)
        at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)
        at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:92)
        at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:668)
        at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)
        at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)
        at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:408)
        at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66)
        at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:834)
        at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1415)
        at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)
        at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128)
        at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628)
        at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
        at java.base/java.lang.Thread.run(Thread.java:834)

我认为如果我使用chmod或chown更改某些内容,可能会导致Zigbee服务无法正常工作?但我不是Linux专家。我不想做出任何错误或不安全的事情。

root@raspberrypi:/opt/zigbee2mqtt/data# ls -halt
total 24K
drwxr-xr-x  6 pi pi 4.0K May 12 09:17 log
drwxr-xr-x  3 pi pi 4.0K May 10 18:31 .
-rw-r--r--  1 pi pi 4.0K May 10 18:31 database.db
-rw-rw-r--  1 pi pi  360 May 10 18:31 state.json
-rw-rw-r--  1 pi pi  330 May 10 17:23 configuration.yaml
drwxr--r-- 12 pi pi 4.0K May 10 11:16 ..


Tomcat 9如何读取文件并让Zigbee进行更新是最佳解决方案?
更新:
root@raspberrypi:/opt/zigbee2mqtt/data# ll
total 24K
-rw-rw-r--  1 pi webservice  360 May 13 22:03 state.json
drwxrw-r-x  6 pi webservice 4.0K May 12 09:17 log
drwxr-xr-x  3 pi pi         4.0K May 10 18:31 .
-rw-rw-r--  1 pi webservice 4.0K May 10 18:31 database.db
-rw-rw-r--  1 pi webservice  330 May 10 17:23 configuration.yaml
drwxr--r-- 12 pi pi         4.0K May 10 11:16 ..
root@raspberrypi:/opt/zigbee2mqtt/data# id tomcat
uid=1001(tomcat) gid=1001(tomcat) groups=1001(tomcat),1002(webservice)

文件提取自:/etc/systemd/system/tomcat9.service.d/override.conf

[Service]
ReadWritePaths=/usr/local/jakarta-tomcat/webapps/smartzig/_x_logs/
ReadWritePaths=/opt/zigbee2mqtt/data/
ReadWritePaths=/opt/zigbee2mqtt/
ReadWritePaths=/opt/
2个回答

4

将Tomcat添加到一个组中,并授予该组对文件所需的访问权限,例如您可以创建一个名为webserver的组。然后重新启动Tomcat并重试。


步骤

$ sudo groupadd webserver

$ sudo usermod -a -G webserver tomcat9

$ sudo chgrp webserver configuration.yaml

$ sudo chmod g=rw configuration.yaml

$ sudo systemctl restart tomcat9

通过添加权限,更新包含文件的目录的群组所有权

$ sudo chgrp webserver /opt/zigbee2mqtt/data/
$ sudo chgrp webserver /opt/zigbee2mqtt/ 

$ sudo chmod g=rwx /opt/zigbee2mqtt/data/
$ sudo chmod g=rwx /opt/zigbee2mqtt/

评论不适合进行长时间的讨论;此对话已被移至聊天室 - Samuel Liew

0

yaml文件的权限为“-rw-rw-r--”,从左到右读取

  • 文件所有者可以读取和写入(不可执行)
  • 文件所有者所在的组可以读取和写入(不可执行)
  • 其他所有人可以读取该文件

因此,如果您想要写入该文件,则取决于运行tomcat进程的用户。但是每个人都应该能够读取该文件。如果您无法读取该文件,则可能是以读/写模式而不是读模式打开该文件

您可以使用chmod 666更改文件的权限为“-rw-rw-rw-”


网页内容由stack overflow 提供, 点击上面的
可以查看英文原文,
原文链接