Docker容器Socket连接失败:PermissionError权限问题求助
Docker容器中Scapy权限问题排查求助
我正在将一款应用迁移至Docker容器,大部分功能已正常运行,但涉及Socket使用及网络参数配置的权限模块无法工作。
已尝试的操作
- 添加
--privileged参数 - 添加
--cap-add=NET_ADMIN参数 - 通过
--security-opt apparmor=unconfined --security-opt seccomp=unconfined移除安全限制 - 在Dockerfile中添加用户组与sudo配置
- 使用
--net=host选项 - 将本地用户加入docker用户组
- 添加
--cap-add=SYS_RAWIO参数 - 在Dockerfile中通过
RUN groupadd -r netdev && usermod -a -G netdev $USER将用户加入netdev组
错误信息
Process Process-2: Traceback (most recent call last): File "/usr/local/lib/python3.9/multiprocessing/process.py", line 315, in _bootstrap self.run() File "/usr/local/lib/python3.9/multiprocessing/process.py", line 108, in run self._target(*self._args, **self._kwargs) File "/app/support_files/wizard_configuration_routines.py", line 781, in find_device device_list = scan_subnet('192.168.30.0/24',g_interface) File "/app/support_files/wizard_configuration_routines.py", line 757, in scan_subnet answered, unanswered = scapy.arping(subnet,verbose=False,iface=g_interface) File "/usr/local/lib/python3.9/site-packages/scapy/layers/l2.py", line 890, in arping ans, unans = srp( File "/usr/local/lib/python3.9/site-packages/scapy/sendrecv.py", line 687, in srp s = iface.l2socket()(promisc=promisc, iface=iface, File "/usr/local/lib/python3.9/site-packages/scapy/arch/linux.py", line 484, in __init__ self.ins = socket.socket( File "/usr/local/lib/python3.9/socket.py", line 232, in __init__ _socket.socket.__init__(self, family, type, proto, fileno) PermissionError: [Errno 1] Operation not permitted
相关文件内容
主应用文件
Dockerfile
# Slim version of Python FROM python:3.9-slim # Download Package Information RUN apt update -y # Install Tkinter RUN apt install tk -y # Install fontconfig RUN apt install fontconfig -y # Install Pillow RUN python3 -m pip install Pillow RUN python3 -m pip install ouster-sdk RUN python3 -m pip install scapy RUN python3 -m pip install customtkinter RUN apt install net-tools -y RUN fc-cache -f -v # Commands to run Tkinter application CMD ["/app/SCOT_wizard.py"] ENTRYPOINT ["python3"]
build.sh
sudo docker build -t tkinter_in_docker .
run.sh
sudo docker run -u=$(id -u $USER):$(id -g $USER) \ -e DISPLAY=$DISPLAY \ -v /tmp/.X11-unix:/tmp/.X11-unix:rw \ -v $(pwd)/app:/app \ -v $(pwd)/logs:/logs \ -v $(pwd)/records:/records \ -v $(pwd)/fonts:/.fonts\ -w /app \ --privileged \ --net=host \ --rm \ tkinter_in_docker
最小可复现示例
为排查问题,我制作了包含出错代码的简易Docker容器,该容器可正常运行,但无法定位大型应用故障原因。
Dockerfile
# Slim version of Python FROM python:3.9-slim # Download Package Information RUN apt update -y RUN apt install net-tools -y RUN apt install -y libpcap0.8 RUN python3 -m pip install scapy # Commands to run Tkinter application CMD ["SCOT_wizard.py"] ENTRYPOINT ["python3"]
run.sh
sudo docker run \ -v $(pwd)/app:/app \ -w /app \ --net=host \ --rm \ tkinter_in_docker
/app/SCOT_wizard.py
import scapy.all as scapy answered, unanswered = scapy.arping('192.168.11.0/24',verbose=False,iface='eno2') print(answered)
内容的提问来源于stack exchange,提问作者Zico
相关产品推荐
相关产品推荐

