使用SSHFS-Win代替SAMBA在Windows上映射Linux网络驱动器
SSHFS-Win,即SSHFS For Windows,是一种比SAMBA更优的,在Windows上映射Linux网络驱动器的方案。
Linux以root用户为例。
Windows实验环境如下
版本 Windows 10 家庭中文版
版本号 22H2
安装日期 2026/4/20
OS 内部版本 19045.6466
一、Windows 装两个组件(顺序不能反)
以普通 PowerShell(不用管理员)运行:
winget install --id WinFsp.WinFsp --exact
winget install --id SSHFS-Win.SSHFS-Win --exact
WinFsp 最新 2.1.25156,SSHFS-Win 最新 3.5.20357。Win10 家庭版 1809 以上自带 winget;若提示找不到命令,去 GitHub 的 winfsp/winfsp 和 winfsp/sshfs-win 发布页手动下 MSI,先装 WinFsp 再装 SSHFS-Win。装完重启一次。
二、第一步先用密码挂载,验证通路
因为远程用户是 root,而 root 的家目录正好就是 /root,所以最简单的 UNC 是:
net use Z: \\sshfs\root@<服务器IP>
四个前缀的含义:
| 前缀 | 起点 | 认证 |
|---|---|---|
\sshfs |
远程用户家目录(root → /root) |
密码 |
\sshfs.r |
服务器根目录 / |
密码 |
\sshfs.k |
家目录 | 密钥 |
\sshfs.kr |
根目录 / |
密钥 |
\\sshfs.r\root@<IP>\root 和上面等价,随便挑一个。弹窗时用户名填 root——不填的话 Windows 会拿你当前登录的微软/本地账户去试,必失败。
看到 Z: 盘出现、能打开 /root 下的文件,就说明通了。先跑这一步再换密钥,能少踩一半坑。
三、换成密钥登录(推荐)
生成密钥(注意:SSHFS-Win 用的是自带的 Cygwin ssh,默认只认 %USERPROFILE%\.ssh\id_rsa,且不支持带口令短语的私钥——带 passphrase 的话 net use 会卡在输入口令那步直到超时报错):
ssh-keygen -t rsa -b 4096 -f $env:USERPROFILE\.ssh\id_rsa
# 口令短语一路回车留空
上传公钥到服务器:
type $env:USERPROFILE\.ssh\id_rsa.pub | ssh root@<服务器IP> "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys"
顺手加固(可选,但强烈建议):给这把钥匙只开 SFTP,禁止它开 shell:
# /root/.ssh/authorized_keys 里,该公钥行首加上:
command="internal-sftp" ssh-rsa AAAAB3...
挂载(sshfs.k 对应家目录即 /root):
net use Z: /delete
net use Z: \\sshfs.k\root@<服务器IP> /persistent:yes
如果 SSH 不是 22 端口,端口用 叹号不是冒号:\\sshfs.k\root@<IP>!2222
四、开机自动挂载(比 /persistent 更靠谱)
/persistent:yes 在开机时常常因为网络还没就绪而失败,盘符变成红叉。更稳的是建个计划任务:
- 把下面存成
C:\Scripts\mount-root.ps1
$ErrorActionPreference = 'SilentlyContinue'
net use Z: /delete /y
Set-Location 'C:\Program Files\SSHFS-Win\bin'
.\sshfs-win.exe svc \sshfs.k\root@<服务器IP> Z:
- 任务计划程序 → 新建任务 → 触发器"用户登录时" → 勾选"使用最高权限运行" → 操作填
powershell.exe -ExecutionPolicy Bypass -File C:\Scripts\mount-root.ps1
想更省事就装 SSHFS-Win-Manager(winget install SSHFS-Win-Manager),图形界面管理连接、可最小化到托盘,也支持带口令的密钥。
几个必知的坑
- 防掉线:闲置久了连接会断。导入 SSHFS-Win 自带的
ServerAliveInterval.reg(30 秒心跳),或在 svc 模式加-o ServerAliveInterval=30。 - 没有回收站:Z: 盘上按 Delete 是真删服务器文件,
rm -rf同理。删之前先确认。 - 权限是假的:Linux 的 700/644 不会映射成 Windows ACL,挂上 root 后所有文件都显示可写,别被"看起来能改"误导。
- 性能:走的是 SFTP 单连接,传大文件、遍历海量小文件都偏慢。日常编辑代码建议直接 VS Code Remote-SSH,比挂载盘符快一个量级。
- 报错 67 / 找不到网络路径:99% 是 UNC 拼错、WinFsp 没装,或密钥带口令;另外去"凭据管理器"把该服务器的旧凭据删掉再试。
需要我把第五步的计划任务脚本按你的实际 IP 和端口填好,或者再做一份"只挂载 /root 下某个子目录(比如 www)"的版本吗?
附录: UNC Syntax
The complete UNC syntax is as follows:
\\sshfs\[LOCUSER=]REMUSER@HOST[!PORT][\PATH]
\\sshfs.r\[LOCUSER=]REMUSER@HOST[!PORT][\PATH]
\\sshfs.k\[LOCUSER=]REMUSER@HOST[!PORT][\PATH]
\\sshfs.kr\[LOCUSER=]REMUSER@HOST[!PORT][\PATH]
REMUSERis the remote user (i.e. the user on the SSHFS host whose credentials are being used for access).HOSTis the SSHFS host.PORTis the remote port on the SSHFS host (optional; default is 22).PATHis the remote path. This is interpreted as follows:- The
sshfsprefix maps toHOST:~REMUSER/PATHon the SSHFS host (i.e. relative toREMUSER's home directory). - The
sshfs.rprefix maps toHOST:/PATHon the SSHFS host (i.e. relative to theHOST's root directory). - The
sshfs.kprefix maps toHOST:~REMUSER/PATHand uses the ssh key in%USERPROFILE%/.ssh/id_rsa(where%USERPROFILE%is the home directory of the local Windows user). To specify a different specific key, define an alias of the HOST with the specific private ssh key you want to use in the ssh config. BEWARE: only keys without a pass phrase are supported. - The
sshfs.krprefix maps toHOST:/PATHand uses the ssh key in%USERPROFILE%/.ssh/id_rsa. To specify a different specific key, define an alias of the HOST with the specific private ssh key you want to use in the ssh config. BEWARE: only keys without a pass phrase are supported.
- The
LOCUSERis the local Windows user (optional;USERNAMEorDOMAIN+USERNAMEformat).- Please note that this functionality is rarely necessary with latest versions of WinFsp.