Git推送失败:fatal: unable to access连接重置问题排查与修复
问题描述
此前IDE集成的Git与Git Bash均可正常运行,杀毒软件删除系统内若干文件后,执行git push命令返回如下错误:
fatal: unable to access 'https://gitlab.com/60trees/my_project.git/': Send failure: Connection was reset
已尝试重新安装Git但未解决问题,启用GIT_TRACE等调试后的输出信息如下:
$ GIT_TRACE=1 GIT_TRACE_CURL=1 GCM_TRACE=1 git push 15:01:48.426040 exec-cmd.c:244 trace: resolved executable dir: C:/Program Files/Git/mingw64/bin 15:01:48.434036 git.c:463 trace: built-in: git push 15:01:48.434036 run-command.c:659 trace: run_command: GIT_DIR=.git git remote-https origin https://gitlab.com/60trees/my_project.git 15:01:48.468036 exec-cmd.c:244 trace: resolved executable dir: C:/Program Files/Git/mingw64/libexec/git-core 15:01:48.474036 git.c:749 trace: exec: git-remote-https origin https://gitlab.com/60trees/my_project.git 15:01:48.474036 run-command.c:659 trace: run_command: git-remote-https origin https://gitlab.com/60trees/my_project.git 15:01:48.498768 exec-cmd.c:244 trace: resolved executable dir: C:/Program Files/Git/mingw64/libexec/git-core 15:01:48.513496 http.c:870 == Info: Couldn't find host gitlab.com in the .netrc file; using defaults 15:01:48.684367 http.c:870 == Info: Trying 172.65.251.78:443... 15:01:48.826655 http.c:870 == Info: Connected to gitlab.com (172.65.251.78) port 443 15:01:48.826655 http.c:870 == Info: ALPN: curl offers h2,http/1.1 15:01:48.837666 http.c:843 => Send SSL data, 0000000005 bytes (0x00000005) 15:01:48.837666 http.c:858 => Send SSL data: ..... 15:01:48.837666 http.c:870 == Info: TLSv1.3 (OUT), TLS handshake, Client hello (1): 15:01:48.837666 http.c:843 => Send SSL data, 0000000512 bytes (0x00000200) 15:01:48.837666 http.c:858 => Send SSL data: ........C........^....=..l...<.H...H.. }..Z\......9.s}.e.... 15:01:48.837666 http.c:858 => Send SSL data: .h...j.[IV..>.......,.0.........+./...$.(.k.#.'.g.....9..... 15:01:48.837666 http.c:858 => Send SSL data: 3.....=.<.5./.....u.........gitlab.com...................... 15:01:48.837666 http.c:858 => Send SSL data: ...................h2.http/1.1.........1.....*.(............ 15:01:48.837666 http.c:858 => Send SSL data: .............................+........-.....3.&.$... .>2.j.p 15:01:48.837666 http.c:858 => Send SSL data: ..s"l..o$.=V)gwQj[......Z................................... 15:01:48.837666 http.c:858 => Send SSL data: ............................................................ 15:01:48.837666 http.c:858 => Send SSL data: ............................................................ 15:01:48.837666 http.c:858 => Send SSL data: ................................ 15:01:48.837666 http.c:870 == Info: Send failure: Connection was reset 15:01:49.003525 http.c:870 == Info: CAfile: C:/Program Files/Git/mingw64/etc/ssl/certs/ca-bundle.crt 15:01:49.003525 http.c:870 == Info: CApath: none 15:01:49.003525 http.c:870 == Info: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to gitlab.com:443 15:01:49.003525 http.c:870 == Info: Closing connection 15:01:49.003525 http.c:870 == Info: Send failure: Connection was reset 15:01:49.003525 http.c:870 == Info: Send failure: Connection was reset fatal: unable to access 'https://gitlab.com/60trees/my_project.git/': Send failure: Connection was reset
排查与修复方法
从调试日志看,连接已建立但在TLS握手发送Client Hello后被重置,结合杀毒软件删文件的背景,按以下步骤处理:
检查杀毒软件拦截
- 查看杀毒软件隔离区/操作日志,恢复被误删的系统文件(尤其是SSL动态库、系统网络组件)。
- 将Git安装目录(默认
C:/Program Files/Git/)、Git Bash程序加入杀毒软件信任列表,禁止拦截其网络请求和文件访问。
修复系统SSL/TLS组件
- 以管理员身份打开
cmd,执行sfc /scannow扫描修复受损系统文件,重点覆盖网络及SSL相关库。 - 若sfc无法修复,执行
DISM /Online /Cleanup-Image /RestoreHealth修复系统镜像。
- 以管理员身份打开
调整Git网络配置
- 强制Git使用HTTP/1.1而非HTTP/2,执行:
git config --global http.version HTTP/1.1 - 重置Git的SSL证书配置:
若证书文件损坏,从Git安装包中提取替换,或手动替换为可信CA证书链。git config --global http.sslCAinfo "C:/Program Files/Git/mingw64/etc/ssl/certs/ca-bundle.crt"
- 强制Git使用HTTP/1.1而非HTTP/2,执行:
切换至SSH传输协议
若HTTPS持续被拦截,改用SSH协议:- 生成SSH密钥对:
ssh-keygen -t ed25519 -C "your_email@example.com" - 将公钥添加到GitLab账号的SSH密钥设置中
- 修改远程仓库地址:
git remote set-url origin git@gitlab.com:60trees/my_project.git
- 生成SSH密钥对:
清理代理设置
关闭Git及系统的异常代理:git config --global --unset http.proxy git config --global --unset https.proxy同时检查系统控制面板的代理设置,确认未被杀毒软件篡改。
内容的提问来源于stack exchange,提问作者sixtytrees
相关产品推荐
相关产品推荐

