Fedora 27上Phabricator SSH(端口2222)配置故障求助
Hey there, let’s work through your Phabricator setup problems step by step. I’ve gone through all the details you shared, and here’s what’s off and how to fix it:
1. Patch Up Phabricator SSH Configuration Gaps
First, your diffusion.ssh-host setting is unset—Phabricator needs to know which host its SSH service is running on. Fix that with:
config set diffusion.ssh-host localhost
Next, let’s make sure the SSH hook script has the right permissions and access. Your /usr/libexec/phabricator-ssh-hook.sh needs to be executable, owned by the phssh user, and the Phabricator directory must be accessible to phssh:
sudo chmod +x /usr/libexec/phabricator-ssh-hook.sh sudo chown phssh:phssh /usr/libexec/phabricator-ssh-hook.sh sudo chmod -R 755 /var/www/phabricator/phabricator
You’ve got a dedicated sshd_config.phabricator file, but you need to make sure SSHD is using it. On Fedora, you can drop it into the sshd_config.d directory for automatic loading, or start a separate SSHD instance:
# Option 1: Use the config.d directory (recommended) sudo cp /etc/ssh/sshd_config.phabricator /etc/ssh/sshd_config.d/phabricator.conf sudo systemctl restart sshd # Option 2: Start a standalone SSHD instance for Phabricator sudo /usr/sbin/sshd -f /etc/ssh/sshd_config.phabricator
Double-check that port 2222 isn’t being used by another service:
sudo ss -tulpn | grep 2222
2. Clean Up SSH Authorized Keys Setup
You added your public key to myuseraccount’s authorized_keys, but that’s unnecessary for Phabricator’s SSH workflow. The phssh user uses the AuthorizedKeysCommand hook to validate keys directly from Phabricator’s database—you don’t need a .ssh directory or authorized_keys file for phssh. Remove that extra file to avoid confusion:
rm ~/.ssh/authorized_keys
Your step of adding the public key via Phabricator’s UI (Settings > SSH) is correct, so leave that as-is.
3. Fix Local Git Repository Recognition (Permission Issues)
For Phabricator to see your local Git repos, the web server user (usually apache on Fedora) needs read access to the repo directories. Let’s fix that:
# Replace /var/repos/myrepo.git with your actual repo path sudo chown -R apache:apache /var/repos/myrepo.git sudo chmod -R 755 /var/repos/myrepo.git
Also, make sure Phabricator knows where the git binary lives:
# First find the git path which git # Set it in Phabricator config config set diffusion.git.path /usr/bin/git
When adding the repo in Phabricator’s UI, always use the absolute path to the repo.
4. Test the SSH Connection
Now let’s verify the SSH setup works. Run this command from your myuseraccount terminal:
ssh -p 2222 phssh@localhost
If everything’s configured right, you’ll see a Phabricator shell welcome message. If you get a Permission denied error:
- Check if the Phabricator SSHD instance is running:
ps aux | grep sshd(look for a process listening on port 2222) - Enable SSH logging in Phabricator to debug further:
Re-run the SSH test, then checkconfig set log.ssh.path /var/log/phabricator/ssh.log sudo mkdir -p /var/log/phabricator sudo chown phssh:phssh /var/log/phabricator/var/log/phabricator/ssh.logfor specific errors.
5. Final Configuration Check
Make sure all your diffusion SSH settings are consistent:
config set diffusion.ssh-host localhost config set diffusion.ssh-port 2222 config set diffusion.ssh-user phssh
Then restart your web server to apply changes:
sudo systemctl restart httpd
内容的提问来源于stack exchange,提问作者RJ Cole

