Ubuntu(RPi4)配置Mercurial+Apache遇403 Forbidden错误求助
树莓派Ubuntu环境下Mercurial Apache 403权限错误排查
在Ubuntu系统的RPi4上搭建Mercurial服务器,访问192.168.5.3/hg时返回403错误,但访问根目录192.168.5.3能正常显示Apache默认页面。此前在多款树莓派设备上使用相同配置可正常运行,新设备配置后卡住。
错误信息
Forbidden
You don't have permission to access this resource.
Apache/2.4.52 (Ubuntu) Server at 192.168.5.3 Port 80
配置文件详情
1. /etc/apache2/hg/main.conf
WSGIScriptAliasMatch ^/hg(.*) /var/hg/script/hgweb.wsgi$1 <Directory /var/hg/script> Order deny,allow Allow from all </Directory>
2. /etc/apache2/sites-available/000-default.conf
已添加Include /etc/apache2/hg/main.conf和<Directory /var/hg/>配置段,完整内容:
<VirtualHost *:80> # The ServerName directive sets the request scheme, hostname and port that # the server uses to identify itself. This is used when creating # redirection URLs. In the context of virtual hosts, the ServerName # specifies what hostname must appear in the request's Host: header to # match this virtual host. For the default virtual host (this file) this # value is not decisive as it is used as a last resort host regardless. # However, you must set it for any further virtual host explicitly. #ServerName www.example.com ServerAdmin webmaster@localhost DocumentRoot /var/www/html # Available loglevels: trace8, ..., trace1, debug, info, notice, warn, # error, crit, alert, emerg. # It is also possible to configure the loglevel for particular # modules, e.g. #LogLevel info ssl:warn ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined # For most configuration files from conf-available/, which are # enabled or disabled at a global level, it is possible to # include a line for only one particular virtual host. For example the # following line enables the CGI configuration for this host only # after it has been globally disabled with "a2disconf". #Include conf-available/serve-cgi-bin.conf Include /etc/apache2/hg/main.conf </VirtualHost> <Directory /var/hg/> Options +ExecCGI PassEnv LANG AddHandler hgweb .cgi </Directory> # vim: syntax=apache ts=4 sw=4 sts=4 sr noet
3. /var/hg/script/hgweb.wsgi(旧设备可正常运行)
# An example WSGI for use with mod_wsgi, edit as necessary # See https://mercurial-scm.org/wiki/modwsgi for more information # Path to repo or hgweb config to serve (see 'hg help hgweb') config = "/var/hg/hgweb.config" # Uncomment and adjust if Mercurial is not installed system-wide # (consult "installed modules" path from 'hg debuginstall'): #import sys; sys.path.insert(0, "/path/to/python/lib") # Uncomment to send python tracebacks to the browser if an error occurs: import cgitb; cgitb.enable() # enable demandloading to reduce startup time from mercurial import demandimport; demandimport.enable() from mercurial.hgweb import hgweb application = hgweb(config)
4. /var/hg/hgweb.config
[paths] bh0002 = /var/hg/bh0002 sam4sd32c_freertos=/var/hg/sam4sd32c_freertos sqlforms=/var/hg/sqlforms ..snip..
访问日志(多次GET /hg返回403)
tail -f /var/log/apache2/access.log 192.168.5.43 - - [06/Oct/2024:15:18:14 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:25:16 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:25:18 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:25:23 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:30:41 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:30:43 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:15:49:45 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:16:34:04 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:16:44:15 +0000] "GET /hg HTTP/1.1" 403 493 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0" 192.168.5.43 - - [06/Oct/2024:16:44:16 +0000] "GET /hg HTTP/1.1" 403 492 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
排查方向
- Apache 2.4权限语法更新:旧配置使用的
Order deny,allow和Allow from all是Apache 2.2语法,Ubuntu新版本的Apache 2.4需替换为Require all granted。修改/etc/apache2/hg/main.conf的Directory块:
同时更新<Directory /var/hg/script> Require all granted </Directory>/var/hg/的Directory块:<Directory /var/hg/> Options +ExecCGI PassEnv LANG AddHandler hgweb .cgi Require all granted </Directory> - 文件系统权限检查:确保
/var/hg及其子目录、文件的所有者为www-data用户组,执行:sudo chown -R www-data:www-data /var/hg sudo chmod -R 755 /var/hg - mod_wsgi模块启用状态:运行
sudo a2enmod wsgi确认模块已启用,之后重启Apache:sudo systemctl restart apache2 - 仓库路径有效性:检查
hgweb.config中配置的仓库路径是否实际存在,且www-data用户有访问权限 - 错误日志分析:查看
/var/log/apache2/error.log,里面会记录403错误的具体原因,比如权限不足、模块加载失败等
内容的提问来源于stack exchange,提问作者DiBosco
相关产品推荐
相关产品推荐

