SmartGit与Apache httpd:HTTP 403错误排查求助
Alright, let's tackle that HTTP 403 error you're hitting when pushing to your Git HTTP server. Since pull operations work perfectly, we know read access is configured correctly—this is almost certainly a write permission issue, either in your web server setup, Git repository settings, or file system permissions. Let's break this down step by step:
Your web server user (like www-data for Apache/Nginx on Debian/Ubuntu) needs write access to the Git repository on the server.
- Run this command to set the correct ownership on your repo:
sudo chown -R www-data:www-data /path/to/your/git/repo.git - If your repository isn't a bare repo (ends with
.git), you'll want to convert it—Git HTTP servers typically require bare repos for push operations. Do this with:git clone --bare /path/to/non-bare/repo /path/to/new/bare/repo.git - For non-bare repos (if you intentionally use one), enable branch updates with:
git config receive.denyCurrentBranch updateInstead
Since you're using a virtual host, let's cover the two most common servers: Apache and Nginx.
Apache Configuration Fixes
Make sure you have mod_cgi, mod_alias, mod_env, and mod_auth_basic enabled (run sudo a2enmod cgi alias env auth_basic if not). Then update your virtual host config to explicitly allow push access:
<VirtualHost *:80> ServerName git.domain.tld DocumentRoot /var/www/git # Point Git to your repo root SetEnv GIT_PROJECT_ROOT /var/www/git SetEnv GIT_HTTP_EXPORT_ALL # Map Git HTTP requests to the backend script ScriptAlias /git/ /usr/lib/git-core/git-http-backend/ <Directory "/usr/lib/git-core"> Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch AllowOverride None Require all granted </Directory> # Restrict push access to authenticated users <LocationMatch "^/git/.*/git-receive-pack$"> AuthType Basic AuthName "Git Push Authorization" AuthUserFile /etc/apache2/.git-htpasswd Require valid-user </LocationMatch> </VirtualHost>
- Double-check the path to
git-http-backendwithwhich git-http-backend(it might vary by OS). - Ensure your
.git-htpasswdfile is readable by the web server:sudo chmod 640 /etc/apache2/.git-htpasswd && sudo chown www-data:www-data /etc/apache2/.git-htpasswd - Restart Apache after changes:
sudo systemctl restart apache2
Nginx Configuration Fixes
Nginx needs fcgiwrap to run the Git HTTP backend—install it first with sudo apt install fcgiwrap (Debian/Ubuntu) and start the service: sudo systemctl enable --now fcgiwrap. Then update your virtual host:
server { listen 80; server_name git.domain.tld; root /var/www/git; client_max_body_size 0; # Allow large pushes (no size limit) location ~ /git(/.*) { include fastcgi_params; # Point to Git HTTP backend fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; fastcgi_param GIT_PROJECT_ROOT /var/www/git; fastcgi_param GIT_HTTP_EXPORT_ALL ""; fastcgi_param PATH_INFO $1; # Connect to fcgiwrap socket fastcgi_pass unix:/run/fcgiwrap.socket; # Require auth only for push operations if ($request_uri ~* git-receive-pack$) { auth_basic "Git Push Authorization"; auth_basic_user_file /etc/nginx/.git-htpasswd; } } }
- Verify the
fcgiwrapsocket path (it might be/var/run/fcgiwrap.socketon some systems). - Fix
.git-htpasswdpermissions:sudo chmod 640 /etc/nginx/.git-htpasswd && sudo chown nginx:nginx /etc/nginx/.git-htpasswd - Restart Nginx:
sudo systemctl restart nginx
First, clear your local Git credential cache to avoid using stale credentials:
git credential-cache exit
Then try pushing again with explicit credentials:
git push http://username@git.domain.tld/git/someRepo/ your-branch-name
If these steps don't resolve the issue, feel free to share the exact lines from your virtual host config, and we can troubleshoot further.
内容的提问来源于stack exchange,提问作者Mutex Morgan

