Debian12下启动OSS Beats遇pthread_create失败问题求助
Debian 12下OSS Beats启动报错:pthread_create failed: Operation not permitted
在Debian 12系统中启动任意OSS Beats(包括Filebeat、Metricbeat等,版本7.12.1及7.13.1)时,频繁触发pthread_create failed: Operation not permitted错误,仅偶尔能正常运行。此前为Suricata配置过pf_ring,暂不确定该操作是否引发系统性能配置变更导致此问题。
已尝试以下操作但未解决问题:
- 重启系统
- 卸载pf_ring模块
- 停止Suricata进程
附Metricbeat报错日志
2023-09-14T16:17:32.355-0500 INFO instance/beat.go:468 metricbeat start running. 2023-09-14T16:17:32.357-0500 INFO filesystem/filesystem.go:57 Ignoring filesystem types: sysfs, tmpfs, bdev, proc, cgroup, cgroup2, cpuset, devtmpfs, debugfs, tracefs, securityfs, sockfs, bpf, pipefs, ramfs, hugetlbfs, devpts, mqueue, pstore, autofs, efivarfs, configfs, fuse, fusectl, binfmt_misc 2023-09-14T16:17:32.357-0500 INFO [system.fsstat] fsstat/fsstat.go:57 Ignoring filesystem types: %ssysfs, tmpfs, bdev, proc, cgroup, cgroup2, cpuset, devtmpfs, debugfs, tracefs, securityfs, sockfs, bpf, pipefs, ramfs, hugetlbfs, devpts, mqueue, pstore, autofs, efivarfs, configfs, fuse, fusectl, binfmt_misc 2023-09-14T16:17:32.358-0500 INFO cfgfile/reload.go:164 Config reloader started runtime/cgo: pthread_create failed: Operation not permitted SIGABRT: abort PC=0x7f839ff97d3c m=5 sigcode=18446744073709551610 goroutine 0 [idle]: runtime: unknown pc 0x7f839ff97d3c stack: frame={sp:0x7f836b7fd900, fp:0x0} stack=[0x7f836affe268,0x7f836b7fde68) 00007f836b7fd800: 0000000000000000 0000000000000000 00007f836b7fd810: 0000000000000000 00007f836b7fdae8 00007f836b7fd820: 00000000014fffb5 <runtime.gentraceback+4501> 00007f836b7fda90 00007f836b7fd830: 00007f836b7fdb80 0000000001512d01 <runtime.return0+1> 00007f836b7fd840: 00007f836b7fd908 0000000000000000 00007f836b7fd850: 0000000000000000 0000000000000000
附ulimit -a输出结果
ulimit -a real-time non-blocking time (microseconds, -R) unlimited core file size (blocks, -c) 0 data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 95881 max locked memory (kbytes, -l) 3074064 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 95881 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited
解决方案
问题根源在于glibc >=2.35版本新增了rseq系统调用,而该调用不在Beats默认允许的seccomp系统调用列表中,导致线程创建失败。需在Beats的配置文件中添加以下seccomp配置:
seccomp: default_action: allow syscalls: - action: allow names: - rseq
内容的提问来源于stack exchange,提问作者Juan A
相关产品推荐
相关产品推荐

