You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FreeBSD下普通用户git clone性能远逊于root的问题排查求助

FreeBSD下普通用户git clone性能远低于root的问题排查与解决

问题现象

在FreeBSD系统中,以root身份执行git clone的性能远优于普通用户(普通用户耗时约92秒,root仅需1.4秒),该问题未在其他操作系统中出现。

普通用户执行日志

16:29:18.541291 git.c:462               trace: built-in: git rev-list --objects --stdin --not --all --quiet --alternate-refs '--progress=Checking connectivity'
16:29:18.541545 trace.c:415             performance: 0.000462180 s: git command: /usr/local/libexec/git-core/git rev-list --objects --stdin --not --all --quiet --alternate-refs '--progress=Checking connectivity'
16:30:49.264916 packfile.c:1659         /usr/home/***/***/.git/objects/pack/****.pack ***
16:30:49.266021 chdir-notify.c:70       setup: chdir from '/usr/home/***' to '/usr/home/***/***'
...
16:30:49.267952 trace.c:415  performance: 92.112003993 s: git command: git clone http://*****************.git

root用户执行日志

16:39:25.639364 git.c:462               trace: built-in: git rev-list --objects --stdin --not --all --quiet --alternate-refs '--progress=Checking connectivity'
16:39:25.639652 trace.c:415             performance: 0.000523483 s: git command: /usr/local/libexec/git-core/git rev-list --objects --stdin --not --all --quiet --alternate-refs '--progress=Checking connectivity'
16:39:25.640623 packfile.c:1659         /usr/home/***/***/.git/objects/pack/****.pack ***
16:39:25.641093 chdir-notify.c:70       setup: chdir from '/usr/home/***' to '/usr/home/***/***'
16:39:25.642753 trace.c:415             performance: 1.451267882 s: git command: git clone http://***********.git

可能的原因

从日志对比来看,两者核心命令rev-list的耗时几乎一致,但普通用户在该步骤后到处理packfile之间存在90秒左右的延迟,问题大概率和FreeBSD系统的以下机制有关:

  • 文件系统ACL/权限异常:普通用户的home目录或克隆目标目录可能存在冗余ACL规则,导致git在创建、访问对象文件时频繁触发权限校验,拖慢操作速度;root不受普通ACL限制,操作流程更顺畅。
  • 用户资源限制:login.conf中可能对普通用户设置了CPU、IO或内存上限,导致git无法充分利用系统资源完成克隆。
  • git配置差异:普通用户的git配置可能开启了自动gc、自定义钩子等耗时选项,而root的配置更简洁。
  • 强制访问控制(MAC):若系统启用了MAC框架(如FreeBSD自带的MAC),普通用户的git进程可能受到额外安全检查,增加操作耗时。

解决步骤

  1. 检查目录权限与ACL

    • 查看目标目录基础权限:ls -ld /usr/home/***/***
    • 检查ACL规则:getfacl /usr/home/***/***,若存在多余ACL项,可通过setfacl -b /usr/home/***/***清空,确保普通用户对目标目录有完整的读写执行权限。
  2. 核查用户资源限制

    • 对比普通用户与root的资源限制:
      su - <普通用户名> -c 'ulimit -a'
      ulimit -a
      
    • 若普通用户存在不合理限制,编辑/etc/login.conf调整对应用户类别的资源参数,执行cap_mkdb /etc/login.conf使配置生效。
  3. 对比并调整git配置

    • 导出普通用户与root的git配置:
      su - <普通用户名> -c 'git config --list' > user_git_config.txt
      git config --list > root_git_config.txt
      
    • 禁用普通用户配置中可能耗时的选项,比如关闭自动gc:su - <普通用户名> -c 'git config --global gc.auto 0',同时检查.git/hooks目录是否存在自定义钩子脚本。
  4. 排查强制访问控制机制

    • 查看MAC框架状态:sysctl security.mac.status
    • 若MAC启用且疑似影响git,可临时关闭测试:sysctl security.mac.enabled=0,确认问题后再调整MAC规则放行git操作。

内容的提问来源于stack exchange,提问作者DizirEx

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 10:55:31