Environment: FusionPBX [5.5/5.6] on Proxmox LCX Debian 13, PHP 8.4, fresh install with fusionpbx-install.sh
Symptom:
Following the official password reset procedure (https://docs.fusionpbx.com/en/latest/additional_information/password_reset.html), the page ends with:
Check permissions /etc/fusionpbx/ must be writable.
Findings (verified on the affected system):
ReadWritePaths=/tmp /etc/freeswitch /usr/share/freeswitch /var/lib/freeswitch /var/cache/fusionpbx /usr/share/fusionpbx
/etc/fusionpbx is not included. That list is generated by update_php_fpm() in core/upgrade/upgrade.php.
Since /etc is read-only for the PHP-FPM service, is_writable() returns false regardless of the folder's ownership, so changing permissions alone is not enough.
Workaround: [confirm after testing]
bash
V=$(php -r 'echo PHP_MAJOR_VERSION.".".PHP_MINOR_VERSION;')
mkdir -p /etc/systemd/system/php${V}-fpm.service.d
printf '[Service]\nReadWritePaths=/etc/fusionpbx\n' > /etc/systemd/system/php${V}-fpm.service.d/fusionpbx-etc.conf
systemctl daemon-reload && systemctl restart php${V}-fpm
chown -R www-data:www-data /etc/fusionpbx
then run the reset, then restore root:root and remove the drop-in.
Suggested fix: either add /etc/fusionpbx to $read_write_paths in update_php_fpm(), or update the documented reset procedure to mention this requirement.
Symptom:
Following the official password reset procedure (https://docs.fusionpbx.com/en/latest/additional_information/password_reset.html), the page ends with:
Check permissions /etc/fusionpbx/ must be writable.
Findings (verified on the affected system):
- The message comes from core/install/resources/classes/install.php (line 97), triggered by if (!is_writable($config_path)).
- /etc/fusionpbx is root:root, mode 755.
- The PHP-FPM unit has ProtectSystem=full and this list:
ReadWritePaths=/tmp /etc/freeswitch /usr/share/freeswitch /var/lib/freeswitch /var/cache/fusionpbx /usr/share/fusionpbx
/etc/fusionpbx is not included. That list is generated by update_php_fpm() in core/upgrade/upgrade.php.
Since /etc is read-only for the PHP-FPM service, is_writable() returns false regardless of the folder's ownership, so changing permissions alone is not enough.
Workaround: [confirm after testing]
bash
V=$(php -r 'echo PHP_MAJOR_VERSION.".".PHP_MINOR_VERSION;')
mkdir -p /etc/systemd/system/php${V}-fpm.service.d
printf '[Service]\nReadWritePaths=/etc/fusionpbx\n' > /etc/systemd/system/php${V}-fpm.service.d/fusionpbx-etc.conf
systemctl daemon-reload && systemctl restart php${V}-fpm
chown -R www-data:www-data /etc/fusionpbx
then run the reset, then restore root:root and remove the drop-in.
Suggested fix: either add /etc/fusionpbx to $read_write_paths in update_php_fpm(), or update the documented reset procedure to mention this requirement.