You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ProFTPd SFTP服务中"get"命令执行被拒但"put"正常的问题求助

ProFTPd SFTP服务中"get"命令执行被拒但"put"正常的问题求助

我在RHEL 8.6上用ProFTPd 1.3.8a搭建了SFTP服务,给用户IFTPTEST的主目录下创建了in/和out/两个目录,预期是用户能连接后从out/里下载文件。

目前的情况是:用户可以正常进入out/目录、查看文件列表,甚至能往里面上传文件,但执行get命令下载文件时会提示权限拒绝,具体的交互过程如下:

sftp> ls -al
drwxrwxr-x    3 IFTPTEST 1000         4096 Nov  9 10:02 .
drwxrwxr-x    3 IFTPTEST 1000         4096 Nov  9 10:02 ..
drwxrwxr-x    2 IFTPTEST 1000         4096 Nov  9 10:08 in
drwxrwxrwx    2 IFTPTEST 1000         4096 Nov  9 10:05 out
sftp> cd out
sftp> ls -al
drwxrwxrwx    2 IFTPTEST 1000         4096 Nov  9 10:05 .
drwxrwxr-x    3 IFTPTEST 1000         4096 Nov  9 10:02 ..
-rwxrwxrwx    1 IFTPTEST 1000           13 Nov  9 10:05 test
sftp> get test test.txt
Fetching /out/test to test.txt
remote open("/out/test"): Permission denied

从权限来看,out/目录和里面的test文件都已经设置了777权限,用户组和所有者都是IFTPTEST,理论上应该完全有权限操作。

查看sftp.log时看到这条关键提示:

OPEN command for '/out/test' blocked by 'RETR' handler

/var/log/messages里的日志也显示:

RETR /appli_var/XFRF/xfrf_files/ftpusers/IFTPTEST/out/test denied by <Limit> configuration

这就让我很困惑了——我明明在proftpd.conf里给/out目录配置了允许RETR命令啊!以下是我配置文件中相关的目录权限限制部分:

# Directory limits
<Global>
<Directory />
<Limit ALL>
DenyAll
</Limit>
<Limit CDUP CWD LIST MDTM MLSD MLST NLST PWD STAT XCUP XPWD OPENDIR READDIR REALPATH LSTAT FSTAT SETSTAT STOR SITE_CHMOD>
AllowAll
</Limit>
</Directory>

<Directory /in>
<Limit ALL>
DenyAll
</Limit>
<Limit CDUP CWD LIST MDTM MLSD MLST NLST PWD STAT XCUP XPWD RETR SIZE APPE DELE RNFR RNTO STOR STOU SITE_CHMOD SETSTAT FSETSTAT LSTAT FSTAT READ>
AllowAll
</Limit>
</Directory>

<Directory /out>
<Limit ALL>
DenyAll
</Limit>
<Limit CDUP CWD LIST MDTM MLSD MLST NLST PWD STAT XCUP XPWD RETR SIZE DELE SITE_CHMOD SETSTAT FSETSTAT LSTAT FSTAT READ>
AllowAll
</Limit>
</Directory>
</Global>

还有SFTP虚拟主机的配置部分:

LoadModule mod_sftp.c

# SFTP virtual server (user/password authentication)
# ----------------------------------------------------
<VirtualHost 10.19.xx.xxx>
<Limit LOGIN>
AllowAll
</Limit>
ServerName                  "SFTP Server"
Port                        20022
AccessGrantMsg              "Welcome to SFTP %u"
SFTPEngine                  on
SFTPHostKey                 /appli/XFRF/proftpd/etc/ssh/proftpd_dsa_key
SFTPHostKey                 /appli/XFRF/proftpd/etc/ssh/proftpd_rsa_key
SFTPHostKey                 /appli/XFRF/proftpd/etc/ssh/proftpd_ecdsa_key
SFTPAuthMethods             password
SFTPCompression             delayed
SFTPLog                     /appli_var/XFRF/proftpd/sftp.log
ExtendedLog                 /appli_var/XFRF/proftpd/sftp_extended.log
TransferLog                 /appli_var/XFRF/proftpd/sftp_transfer.log
ServerLog                   /appli_var/XFRF/proftpd/sftp_server.log
</VirtualHost>

另外,我还提取了/var/log/messages中更详细的RETR命令处理日志:

dispatching PRE_CMD command 'LSTAT /out/test' to mod_tls
dispatching PRE_CMD command 'LSTAT /out/test' to mod_exec
dispatching PRE_CMD command 'LSTAT /out/test' to mod_core
dispatching PRE_CMD command 'LSTAT /out/test' to mod_core
in dir_check(): setting umask to 0022 (was 0022)
dispatching POST_CMD command 'LSTAT /out/test' to mod_exec
dispatching LOG_CMD command 'LSTAT /out/test' to mod_log
dispatching PRE_CMD command 'STAT /out/test' to mod_tls
dispatching PRE_CMD command 'STAT /out/test' to mod_exec
dispatching PRE_CMD command 'STAT /out/test' to mod_core
dispatching PRE_CMD command 'STAT /out/test' to mod_core
in dir_check(): setting umask to 0022 (was 0022)
dispatching POST_CMD command 'STAT /out/test' to mod_exec
dispatching LOG_CMD command 'STAT /out/test' to mod_log
dispatching PRE_CMD command 'RETR /out/test' to mod_tls
dispatching PRE_CMD command 'RETR /out/test' to mod_exec
dispatching PRE_CMD command 'RETR /out/test' to mod_core
dispatching PRE_CMD command 'RETR /out/test' to mod_core
dispatching PRE_CMD command 'RETR /out/test' to mod_vroot
dispatching PRE_CMD command 'RETR /out/test' to mod_vroot
dispatching PRE_CMD command 'RETR /out/test' to mod_auth
dispatching PRE_CMD command 'RETR /out/test' to mod_xfer
in dir_check_full(): path = '/appli_var/XFRF/xfrf_files/ftpusers/IFTPTEST/out/test', fullpath = '/appli_var/XFRF/xfrf_files/ftpusers/IFTPTEST/out/test'
RETR /appli_var/XFRF/xfrf_files/ftpusers/IFTPTEST/out/test denied by <Limit> configuration
dispatching POST_CMD_ERR command 'RETR /out/test' to mod_exec
dispatching POST_CMD_ERR command 'RETR /out/test' to mod_vroot
dispatching POST_CMD_ERR command 'RETR /out/test' to mod_auth
dispatching LOG_CMD_ERR command 'RETR /out/test' to mod_log
dispatching LOG_CMD_ERR command 'RETR /out/test' to mod_xfer
dispatching POST_CMD_ERR command 'OPEN /out/test' to mod_exec
dispatching LOG_CMD_ERR command 'OPEN /out/test' to mod_log

我已经检查了文件系统权限(都是777)、配置文件的权限规则(明确允许了RETR),但还是找不到问题所在。这是ProFTPd的已知问题吗?还是我的配置哪里有疏漏?

备注:内容来源于stack exchange,提问作者Matt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 09:34:36