You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SmartGit与Apache httpd:HTTP 403错误排查求助

Alright, let's tackle that HTTP 403 error you're hitting when pushing to your Git HTTP server. Since pull operations work perfectly, we know read access is configured correctly—this is almost certainly a write permission issue, either in your web server setup, Git repository settings, or file system permissions. Let's break this down step by step:

1. First, Fix Git Repository File System Permissions

Your web server user (like www-data for Apache/Nginx on Debian/Ubuntu) needs write access to the Git repository on the server.

  • Run this command to set the correct ownership on your repo:
    sudo chown -R www-data:www-data /path/to/your/git/repo.git
    
  • If your repository isn't a bare repo (ends with .git), you'll want to convert it—Git HTTP servers typically require bare repos for push operations. Do this with:
    git clone --bare /path/to/non-bare/repo /path/to/new/bare/repo.git
    
  • For non-bare repos (if you intentionally use one), enable branch updates with:
    git config receive.denyCurrentBranch updateInstead
    
2. Adjust Your Web Server Virtual Host Config

Since you're using a virtual host, let's cover the two most common servers: Apache and Nginx.

Apache Configuration Fixes

Make sure you have mod_cgi, mod_alias, mod_env, and mod_auth_basic enabled (run sudo a2enmod cgi alias env auth_basic if not). Then update your virtual host config to explicitly allow push access:

<VirtualHost *:80>
    ServerName git.domain.tld
    DocumentRoot /var/www/git

    # Point Git to your repo root
    SetEnv GIT_PROJECT_ROOT /var/www/git
    SetEnv GIT_HTTP_EXPORT_ALL
    # Map Git HTTP requests to the backend script
    ScriptAlias /git/ /usr/lib/git-core/git-http-backend/

    <Directory "/usr/lib/git-core">
        Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
        AllowOverride None
        Require all granted
    </Directory>

    # Restrict push access to authenticated users
    <LocationMatch "^/git/.*/git-receive-pack$">
        AuthType Basic
        AuthName "Git Push Authorization"
        AuthUserFile /etc/apache2/.git-htpasswd
        Require valid-user
    </LocationMatch>
</VirtualHost>
  • Double-check the path to git-http-backend with which git-http-backend (it might vary by OS).
  • Ensure your .git-htpasswd file is readable by the web server:
    sudo chmod 640 /etc/apache2/.git-htpasswd && sudo chown www-data:www-data /etc/apache2/.git-htpasswd
    
  • Restart Apache after changes: sudo systemctl restart apache2

Nginx Configuration Fixes

Nginx needs fcgiwrap to run the Git HTTP backend—install it first with sudo apt install fcgiwrap (Debian/Ubuntu) and start the service: sudo systemctl enable --now fcgiwrap. Then update your virtual host:

server {
    listen 80;
    server_name git.domain.tld;

    root /var/www/git;
    client_max_body_size 0; # Allow large pushes (no size limit)

    location ~ /git(/.*) {
        include fastcgi_params;
        # Point to Git HTTP backend
        fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend;
        fastcgi_param GIT_PROJECT_ROOT /var/www/git;
        fastcgi_param GIT_HTTP_EXPORT_ALL "";
        fastcgi_param PATH_INFO $1;
        # Connect to fcgiwrap socket
        fastcgi_pass unix:/run/fcgiwrap.socket;

        # Require auth only for push operations
        if ($request_uri ~* git-receive-pack$) {
            auth_basic "Git Push Authorization";
            auth_basic_user_file /etc/nginx/.git-htpasswd;
        }
    }
}
  • Verify the fcgiwrap socket path (it might be /var/run/fcgiwrap.socket on some systems).
  • Fix .git-htpasswd permissions:
    sudo chmod 640 /etc/nginx/.git-htpasswd && sudo chown nginx:nginx /etc/nginx/.git-htpasswd
    
  • Restart Nginx: sudo systemctl restart nginx
3. Test the Push Again

First, clear your local Git credential cache to avoid using stale credentials:

git credential-cache exit

Then try pushing again with explicit credentials:

git push http://username@git.domain.tld/git/someRepo/ your-branch-name

If these steps don't resolve the issue, feel free to share the exact lines from your virtual host config, and we can troubleshoot further.

内容的提问来源于stack exchange,提问作者Mutex Morgan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:59:35