Ubuntu 20.04环境下Docker拉取镜像或运行容器时卡顿无响应问题求助
Let’s dig into your Docker stall issue on Ubuntu 20.04 — I’ve seen similar problems in enterprise environments, so here’s a breakdown of likely causes and actionable fixes you can test:
1. Fix Overlay2 Filesystem Permissions or Corruption
Your logs show Docker creates the overlay2 diff directory but fails to populate it, which points to either permission issues or underlying filesystem corruption.
- First, check if the
/var/lib/dockerpartition has bad blocks (you’ll need to unmount it or boot into single-user mode to run this safely):sudo fsck /dev/sdX # Replace sdX with your docker partition, e.g., /dev/sda2 - Verify and reset permissions for the overlay2 directory:
# Check current permissions sudo ls -ld /var/lib/docker/overlay2 sudo ls -ld /var/lib/docker/overlay2/91e5944b0c0d34d010b4f28036e29d47213266af5677660edbb00470160fb186/diff # Reset ownership and permissions sudo chown -R root:docker /var/lib/docker sudo chmod -R 775 /var/lib/docker/overlay2
2. Fix Corrupted unpigz Decompression Tool
Your debug logs show Docker uses /usr/bin/unpigz to decompress the image blob — if this tool is corrupted, it can cause hangs during extraction:
- Check if unpigz is working properly:
unpigz --version - Reinstall the pigz package to replace a broken unpigz binary:
sudo apt purge pigz && sudo apt install pigz -y - As a fallback, force Docker to use the default
gzipinstead of unpigz by adding this to/etc/docker/daemon.json:
Then restart Docker:{ "decompressors": { "gzip": "/bin/gzip" } }sudo systemctl daemon-reload sudo systemctl restart docker
3. Resolve Kernel Compatibility Issues
Ubuntu 20.04 kernel updates can sometimes introduce compatibility bugs with Docker’s overlay2 driver. If you’ve updated your kernel recently, try downgrading to a stable 5.4.x release (Ubuntu 20.04’s default):
- Install a stable kernel version:
sudo apt install linux-image-5.4.0-150-generic linux-headers-5.4.0-150-generic -y - Update GRUB and reboot to use the new kernel:
sudo update-grub sudo reboot
4. Check Enterprise Security Interference
In enterprise environments, EDR/antivirus tools often block Docker’s filesystem operations without explicit whitelisting.
- Check your enterprise security software logs for entries blocking
dockerdorunpigzprocesses. - Temporarily disable the security tool (with proper approval) and test running
docker run hello-worldagain.
Post-Fix Verification
After trying any of these fixes, clean up stale resources and test:
# Remove all unused images, containers, and temp files sudo docker system prune -af # Test with hello-world docker run hello-world
Monitor Docker logs in real-time to confirm no stalls:
journalctl -u docker.service -f
内容的提问来源于stack exchange,提问作者nicoh

