Jenkins Pipeline执行nohup失败:spawn helper异常排查求助
Jenkins Pipeline执行命令时nohup报错:Failed to exec spawn helper问题排查与解决建议
问题现象
Jenkins Pipeline执行git ls-remote、curl等命令时,均出现无法运行nohup的错误,提示信息为:Failed to exec spawn helper: pid: xxx, exit value: 1。报错命令示例如下:
Jenkins pipeline failed on command:`curl -H 'X-JFrog-Art-Api: ****' -H 'Content-Type: text/plain' --data-raw 'items.find( [2024-12-08T18:21:14.465Z] { [2024-12-08T18:21:14.465Z] "repo":{"$eq":"art-generic-dev-local"}, [2024-12-08T18:21:14.465Z] "path":{"$match":"int.game.amatic/*"}, [2024-12-08T18:21:14.465Z] "name":{"$nmatch":"*-tests.zip"} [2024-12-08T18:21:14.465Z] "name":{"$nmatch":"*.pdf"} [2024-12-08T18:21:14.465Z] }Error is same, can't run program "nohup". After several restart of jenkins agents, It cleare on that stage and on different stage it fails: git ls-remote --tags | grep '2cb8d2db1980450cceaf4111a0459fa62edebda1' || true— Identify Git tags<1sCannot run program "nohup" (in directory "/mnt/jenkins/workspace/servicedir"): error=0, Failed to exec spawn helper: pid: 1224283, exit value: 1`
已尝试的排查步骤
- 在Jenkins master添加JVM参数
-Djdk.lang.Process.launchMechanism=vfork并重启服务,当前配置:Environment="JAVA_OPTS=-Djava.awt.headless=true \ -Djdk.lang.Process.launchMechanism=vfork " - 从UI断开并重新连接Jenkins代理
- 在Jenkins代理上以jenkins用户登录,执行
which nohup返回/usr/bin/nohup,工作区目录权限为755 - 重启Jenkins代理与master服务
- 在Groovy流水线中添加调试步骤(
which nohup、ls -ld、echo $PATH),均报相同错误 - 更新coreutils至最新版本
下一步调试与解决建议
降级Java版本到17
Java 21在进程启动机制上有较多变更,与Jenkins代理的兼容性可能存在问题。将代理节点的Java从21降级到Jenkins官方支持的LTS版本17,重启代理后重新运行流水线验证。检查JDK的spawn helper文件权限
该错误核心是JDK无法执行jspawnhelper工具,检查代理节点JDK安装目录下的$JAVA_HOME/lib/jspawnhelper文件权限,确保其为755(所有者可读写执行,组和其他用户可读执行),若权限异常,执行chmod 755 $JAVA_HOME/lib/jspawnhelper修正。验证运维补丁的影响
针对运维补丁操作的怀疑,可做以下检查:- 对比补丁前后的系统库(如
libc.so)更新记录,确认是否影响Java进程启动机制 - 检查
/etc/sudoers、PAM配置,确认是否限制了jenkins用户的进程创建权限 - 查看系统日志(
/var/log/messages、/var/log/syslog),搜索jspawnhelper、nohup相关的错误或拦截记录
- 对比补丁前后的系统库(如
修改流水线shell执行方式
尝试在sh步骤中显式指定shell路径,规避默认nohup调用问题:sh script: 'curl -H ...', executable: '/bin/bash'或设置环境变量调整shell执行逻辑:
withEnv(['BUILD_SHELL=/bin/bash']) { sh 'git ls-remote --tags | grep ...' }检查安全模块限制
查看代理节点是否启用SELinux或AppArmor,这类安全模块可能拦截jenkins用户的进程执行操作:- 临时关闭SELinux:
setenforce 0,验证流水线是否恢复正常 - 查看AppArmor状态:
aa-status,检查是否存在针对jenkins或Java的限制规则
- 临时关闭SELinux:
内容的提问来源于stack exchange,提问作者davit k
相关产品推荐
相关产品推荐

