You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级Apache至2.4.58后大文件上传失败(报AH01225错误)求助

问题描述

将Apache HTTP Server从2.4.41升级至2.4.58后,出现大于1GB的文件上传失败问题,小文件上传无异常。上传过程中Apache error.log持续打印以下错误:

[Tue May 07 04:16:35.109777 2024] [cgi:error] [pid 30766] (-102)Unknown error -102: [client 10.140.204.23:64774] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:17:05.919928 2024] [cgi:error] [pid 30768] (-102)Unknown error -102: [client 10.140.204.23:64802] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:17:36.592258 2024] [cgi:error] [pid 30767] (-102)Unknown error -102: [client 10.140.204.23:64849] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:18:07.223293 2024] [cgi:error] [pid 30766] (-102)Unknown error -102: [client 10.140.204.23:64884] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:18:37.928108 2024] [cgi:error] [pid 30767] (-102)Unknown error -102: [client 10.140.204.23:64916] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:19:08.700924 2024] [cgi:error] [pid 30768] (-102)Unknown error -102: [client 10.140.204.23:64950] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:19:39.443934 2024] [cgi:error] [pid 30767] (-102)Unknown error -102: [client 10.140.204.23:64980] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net
[Tue May 07 04:20:10.530056 2024] [cgi:error] [pid 30766] (-102)Unknown error -102: [client 10.140.204.23:65029] AH01225: Error reading request entity data, referer: https://10.105.105.84/cgi-bin/pages.cgi?title=cm_net

已尝试的配置调整:

  • 将httpd.conf和apache2.conf的超时时间调整为600
  • httpd.conf中添加LimitRequestBody 3000000000
  • .htaccess配置如下:
<IfModule mod_rewrite.c>
    RewriteEngine on
    RewriteRule    ^$    webroot/    [L]
    RewriteRule    (.*) webroot/$1    [L]
</IfModule>
<IfModule mod_security.c>
    SecRuleEngine On
    SecRequestBodyAccess On
    SecRequestBodyLimit 2147483648
    SecRequestBodyNoFilesLimit 524288
    SecRequestBodyInMemoryLimit 524288
</IfModule>
<IfModule mod_php7.c>
    php_value upload_max_filesize   15000M
    php_value post_max_size                 15001M
    php_value memory_limit  15000M
</IfModule>
解决建议

1. 同步升级APR及APR-Util

Apache 2.4.58对APR(Apache Portable Runtime)版本有严格兼容性要求,未同步升级可能导致大文件传输时的IO中断错误(-102错误关联APR层的连接问题):

  • 检查当前APR版本:执行apr-1-config --version和apu-1-config --version
  • 确保APR≥1.7.0、APR-Util≥1.6.1,若版本过低,同步升级后重启httpd。

2. 调整CGI专属超时参数

错误日志标记为[cgi:error],需针对CGI环节单独配置超时:

  • 在httpd.conf或虚拟主机配置中添加:
    # CGI脚本执行超时,按大文件上传耗时调整(示例设为1800秒)
    ScriptTimeout 1800
    # 全局超时覆盖连接、接收、发送全流程
    Timeout 1800
    KeepAliveTimeout 1800
    
  • 原600秒超时可能不足以支撑1GB文件上传(取决于带宽),需根据实际传输速度调整。

3. 优化ModSecurity临时存储配置

大文件上传时ModSecurity会将超出内存限制的请求体写入磁盘,需确保临时目录正常:

  • 查找ModSecurity临时目录:grep SecTmpDir /etc/modsecurity/modsecurity.conf(路径依系统而定)
  • 确认目录有足够磁盘空间,且httpd进程拥有读写权限
  • 可适当调整内存缓冲区大小减少磁盘IO压力:
    SecRequestBodyInMemoryLimit 10485760  # 调整为10MB
    

4. 解除操作系统层面限制

  • 文件描述符限制:大文件上传会占用更多描述符,执行ulimit -n查看当前值,若过低则修改/etc/security/limits.conf:
    apache soft nofile 65535
    apache hard nofile 65535
    
    重启httpd生效。
  • TCP连接参数:调整系统TCP配置避免连接中断:
    # 临时生效
    sysctl -w net.ipv4.tcp_keepalive_time=300
    sysctl -w net.ipv4.tcp_keepalive_intvl=60
    sysctl -w net.ipv4.tcp_keepalive_probes=10
    sysctl -w net.core.rmem_max=16777216
    sysctl -w net.core.wmem_max=16777216
    # 永久生效,写入/etc/sysctl.conf
    echo "net.ipv4.tcp_keepalive_time=300" >> /etc/sysctl.conf
    echo "net.ipv4.tcp_keepalive_intvl=60" >> /etc/sysctl.conf
    echo "net.ipv4.tcp_keepalive_probes=10" >> /etc/sysctl.conf
    echo "net.core.rmem_max=16777216" >> /etc/sysctl.conf
    echo "net.core.wmem_max=16777216" >> /etc/sysctl.conf
    sysctl -p
    

5. 检查CGI脚本内部逻辑

确认pages.cgi脚本本身没有限制:

  • 检查是否存在脚本级超时设置(如PHP的set_time_limit())
  • 验证脚本对上传文件的写入目录权限及磁盘空间

内容的提问来源于stack exchange,提问作者Prajwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 10:47:05