You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu(RPi4)配置Mercurial+Apache遇403 Forbidden错误求助

树莓派Ubuntu环境下Mercurial Apache 403权限错误排查

在Ubuntu系统的RPi4上搭建Mercurial服务器,访问192.168.5.3/hg时返回403错误,但访问根目录192.168.5.3能正常显示Apache默认页面。此前在多款树莓派设备上使用相同配置可正常运行,新设备配置后卡住。

错误信息

Forbidden

You don't have permission to access this resource.
Apache/2.4.52 (Ubuntu) Server at 192.168.5.3 Port 80

配置文件详情

1. /etc/apache2/hg/main.conf

WSGIScriptAliasMatch ^/hg(.*) /var/hg/script/hgweb.wsgi$1
<Directory /var/hg/script>
    Order deny,allow
    Allow from all
</Directory>

2. /etc/apache2/sites-available/000-default.conf

已添加Include /etc/apache2/hg/main.conf和<Directory /var/hg/>配置段,完整内容:

<VirtualHost *:80>
        # The ServerName directive sets the request scheme, hostname and port that
        # the server uses to identify itself. This is used when creating
        # redirection URLs. In the context of virtual hosts, the ServerName
        # specifies what hostname must appear in the request's Host: header to
        # match this virtual host. For the default virtual host (this file) this
        # value is not decisive as it is used as a last resort host regardless.
        # However, you must set it for any further virtual host explicitly.
        #ServerName www.example.com

        ServerAdmin webmaster@localhost
        DocumentRoot /var/www/html

        # Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
        # error, crit, alert, emerg.
        # It is also possible to configure the loglevel for particular
        # modules, e.g.
        #LogLevel info ssl:warn

        ErrorLog ${APACHE_LOG_DIR}/error.log
        CustomLog ${APACHE_LOG_DIR}/access.log combined

        # For most configuration files from conf-available/, which are
        # enabled or disabled at a global level, it is possible to
        # include a line for only one particular virtual host. For example the
        # following line enables the CGI configuration for this host only
        # after it has been globally disabled with "a2disconf".
        #Include conf-available/serve-cgi-bin.conf
        Include /etc/apache2/hg/main.conf
</VirtualHost>
<Directory /var/hg/>
    Options +ExecCGI
    PassEnv LANG
    AddHandler hgweb .cgi
</Directory>

# vim: syntax=apache ts=4 sw=4 sts=4 sr noet

3. /var/hg/script/hgweb.wsgi(旧设备可正常运行)

# An example WSGI for use with mod_wsgi, edit as necessary
# See https://mercurial-scm.org/wiki/modwsgi for more information

# Path to repo or hgweb config to serve (see 'hg help hgweb')
config = "/var/hg/hgweb.config"

# Uncomment and adjust if Mercurial is not installed system-wide
# (consult "installed modules" path from 'hg debuginstall'):
#import sys; sys.path.insert(0, "/path/to/python/lib")

# Uncomment to send python tracebacks to the browser if an error occurs:
import cgitb; cgitb.enable()

# enable demandloading to reduce startup time
from mercurial import demandimport; demandimport.enable()

from mercurial.hgweb import hgweb
application = hgweb(config)

4. /var/hg/hgweb.config

[paths]
bh0002 = /var/hg/bh0002
sam4sd32c_freertos=/var/hg/sam4sd32c_freertos
sqlforms=/var/hg/sqlforms
..snip..

访问日志(多次GET /hg返回403)

tail -f /var/log/apache2/access.log
192.168.5.43 - - [06/Oct/2024:15:18:14 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:25:16 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:25:18 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:25:23 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:30:41 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:30:43 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:15:49:45 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:16:34:04 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:16:44:15 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
192.168.5.43 - - [06/Oct/2024:16:44:16 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"

排查方向

  • Apache 2.4权限语法更新:旧配置使用的Order deny,allow和Allow from all是Apache 2.2语法,Ubuntu新版本的Apache 2.4需替换为Require all granted。修改/etc/apache2/hg/main.conf的Directory块:
    <Directory /var/hg/script>
        Require all granted
    </Directory>
    
    同时更新/var/hg/的Directory块:
    <Directory /var/hg/>
        Options +ExecCGI
        PassEnv LANG
        AddHandler hgweb .cgi
        Require all granted
    </Directory>
    
  • 文件系统权限检查:确保/var/hg及其子目录、文件的所有者为www-data用户组,执行:
    sudo chown -R www-data:www-data /var/hg
    sudo chmod -R 755 /var/hg
    
  • mod_wsgi模块启用状态:运行sudo a2enmod wsgi确认模块已启用,之后重启Apache:sudo systemctl restart apache2
  • 仓库路径有效性:检查hgweb.config中配置的仓库路径是否实际存在,且www-data用户有访问权限
  • 错误日志分析:查看/var/log/apache2/error.log,里面会记录403错误的具体原因,比如权限不足、模块加载失败等

内容的提问来源于stack exchange,提问作者DiBosco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 13:37:32