You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器Socket连接失败:PermissionError权限问题求助

Docker容器中Scapy权限问题排查求助

我正在将一款应用迁移至Docker容器,大部分功能已正常运行,但涉及Socket使用及网络参数配置的权限模块无法工作。

已尝试的操作

  • 添加--privileged参数
  • 添加--cap-add=NET_ADMIN参数
  • 通过--security-opt apparmor=unconfined --security-opt seccomp=unconfined移除安全限制
  • 在Dockerfile中添加用户组与sudo配置
  • 使用--net=host选项
  • 将本地用户加入docker用户组
  • 添加--cap-add=SYS_RAWIO参数
  • 在Dockerfile中通过RUN groupadd -r netdev && usermod -a -G netdev $USER将用户加入netdev组

错误信息

Process Process-2:
Traceback (most recent call last):
  File "/usr/local/lib/python3.9/multiprocessing/process.py", line 315, in _bootstrap
    self.run()
  File "/usr/local/lib/python3.9/multiprocessing/process.py", line 108, in run
    self._target(*self._args, **self._kwargs)
  File "/app/support_files/wizard_configuration_routines.py", line 781, in find_device
    device_list = scan_subnet('192.168.30.0/24',g_interface)
  File "/app/support_files/wizard_configuration_routines.py", line 757, in scan_subnet
    answered, unanswered = scapy.arping(subnet,verbose=False,iface=g_interface)
  File "/usr/local/lib/python3.9/site-packages/scapy/layers/l2.py", line 890, in arping
    ans, unans = srp(
  File "/usr/local/lib/python3.9/site-packages/scapy/sendrecv.py", line 687, in srp
    s = iface.l2socket()(promisc=promisc, iface=iface,
  File "/usr/local/lib/python3.9/site-packages/scapy/arch/linux.py", line 484, in __init__
    self.ins = socket.socket(
  File "/usr/local/lib/python3.9/socket.py", line 232, in __init__
    _socket.socket.__init__(self, family, type, proto, fileno)
PermissionError: [Errno 1] Operation not permitted

相关文件内容

主应用文件

Dockerfile

# Slim version of Python
FROM python:3.9-slim

# Download Package Information
RUN apt update -y

# Install Tkinter
RUN apt install tk -y

# Install fontconfig
RUN apt install fontconfig -y

# Install Pillow
RUN python3 -m pip install Pillow
RUN python3 -m pip install ouster-sdk
RUN python3 -m pip install scapy
RUN python3 -m pip install customtkinter
RUN apt install net-tools -y
RUN fc-cache -f -v

# Commands to run Tkinter application
CMD ["/app/SCOT_wizard.py"]
ENTRYPOINT ["python3"]

build.sh

sudo docker build -t tkinter_in_docker .

run.sh

sudo docker run -u=$(id -u $USER):$(id -g $USER) \
 -e DISPLAY=$DISPLAY \
 -v /tmp/.X11-unix:/tmp/.X11-unix:rw \
 -v $(pwd)/app:/app \
 -v $(pwd)/logs:/logs \
 -v $(pwd)/records:/records \
 -v $(pwd)/fonts:/.fonts\
 -w /app \
 --privileged \
 --net=host \
 --rm \
  tkinter_in_docker

最小可复现示例

为排查问题,我制作了包含出错代码的简易Docker容器,该容器可正常运行,但无法定位大型应用故障原因。

Dockerfile

# Slim version of Python
FROM python:3.9-slim

# Download Package Information
RUN apt update -y
RUN apt install net-tools -y
RUN apt install -y libpcap0.8 

RUN python3 -m pip install scapy
# Commands to run Tkinter application
CMD ["SCOT_wizard.py"]
ENTRYPOINT ["python3"]

run.sh

sudo docker run \
 -v $(pwd)/app:/app \
 -w /app \
 --net=host \
 --rm \
  tkinter_in_docker

/app/SCOT_wizard.py

import scapy.all as scapy
answered, unanswered = scapy.arping('192.168.11.0/24',verbose=False,iface='eno2')
print(answered)

内容的提问来源于stack exchange,提问作者Zico

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 16:25:36