最新国产好看的视频,伊人天堂AV在线,国产Aaaaaa视频,蜜臀视频在线观看一区,人妻av色图,密臀久久久精品影片,青青视频免费观看毛片,久草在线观看视,国产三级精品色情在线

解決docker使用GDB,無法進入斷點的問題

 更新時間:2020年11月18日 09:47:06   作者:mania_yan  
這篇文章主要介紹了解決docker使用GDB,無法進入斷點的問題,具有很好的參考價值,希望對大家有所幫助。一起跟隨小編過來看看吧

問題

docker里運行g(shù)db,打了斷點,卻無法進入斷點

原因

docker為了保證主機安全,docker開了很多安全設(shè)置,其中包括ASLR(Address space layout randomization),即docker里的內(nèi)存地址和主機內(nèi)存地址是不一樣的。

ASLR會導致GDB這種依賴地址的程序無法正常運作。

解決方法

使用docker的超級權(quán)限,加入--privileged(兩個橫線,markdown語法

如:

docker run --privileged ……

GDB即可正常運作

超級權(quán)限會關(guān)閉很多安全設(shè)置,可以更充分的使用docker能力

例如,docker里再開docker都可以了,呵呵。

補充知識:docker ptrace: Operation not permitted. 處理方法

docker中g(shù)db在進行進程debug時,會報錯:

(gdb) attach 30721

Attaching to process 30721

ptrace: Operation not permitted.

原因就是因為ptrace被Docker默認禁止的問題??紤]到應用分析的需要,可以有以下幾種方法解決:

1、關(guān)閉seccomp

docker run --security-opt seccomp=unconfined

2、采用超級權(quán)限模式

docker run --privileged

3、僅開放ptrace限制

docker run --cap-add sys_ptrace

當然從安全角度考慮,如只是想使用gdb進行debug的話,建議使用第三種。

安全計算模式(secure computing mode,seccomp)是 Linux 內(nèi)核功能,可以使用它來限制容器內(nèi)可用的操作。

Docker 的默認 seccomp 配置文件是一個白名單,它指定了允許的調(diào)用。

下表列出了由于不在白名單而被有效阻止的重要(但不是全部)系統(tǒng)調(diào)用。該表包含每個系統(tǒng)調(diào)用被阻止的原因。

Syscall Description
acct Accounting syscall which could let containers disable their own resource limits or process accounting. Also gated by CAP_SYS_PACCT.
add_key Prevent containers from using the kernel keyring, which is not namespaced.
adjtimex Similar to clock_settime and settimeofday, time/date is not namespaced. Also gated by CAP_SYS_TIME.
bpf Deny loading potentially persistent bpf programs into kernel, already gated by CAP_SYS_ADMIN.
clock_adjtime Time/date is not namespaced. Also gated by CAP_SYS_TIME.
clock_settime Time/date is not namespaced. Also gated by CAP_SYS_TIME.
clone Deny cloning new namespaces. Also gated by CAP_SYS_ADMIN for CLONE_* flags, except CLONE_USERNS.
create_module Deny manipulation and functions on kernel modules. Obsolete. Also gated by CAP_SYS_MODULE.
delete_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE.
finit_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE.
get_kernel_syms Deny retrieval of exported kernel and module symbols. Obsolete.
get_mempolicy Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE.
init_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE.
ioperm Prevent containers from modifying kernel I/O privilege levels. Already gated by CAP_SYS_RAWIO.
iopl Prevent containers from modifying kernel I/O privilege levels. Already gated by CAP_SYS_RAWIO.
kcmp Restrict process inspection capabilities, already blocked by dropping CAP_PTRACE.
kexec_file_load Sister syscall of kexec_load that does the same thing, slightly different arguments. Also gated by CAP_SYS_BOOT.
kexec_load Deny loading a new kernel for later execution. Also gated by CAP_SYS_BOOT.
keyctl Prevent containers from using the kernel keyring, which is not namespaced.
lookup_dcookie Tracing/profiling syscall, which could leak a lot of information on the host. Also gated by CAP_SYS_ADMIN.
mbind Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE.
mount Deny mounting, already gated by CAP_SYS_ADMIN.
move_pages Syscall that modifies kernel memory and NUMA settings.
name_to_handle_at Sister syscall to open_by_handle_at. Already gated by CAP_SYS_NICE.
nfsservctl Deny interaction with the kernel nfs daemon. Obsolete since Linux 3.1.
open_by_handle_at Cause of an old container breakout. Also gated by CAP_DAC_READ_SEARCH.
perf_event_open Tracing/profiling syscall, which could leak a lot of information on the host.
personality Prevent container from enabling BSD emulation. Not inherently dangerous, but poorly tested, potential for a lot of kernel vulns.
pivot_root Deny pivot_root, should be privileged operation.
process_vm_readv Restrict process inspection capabilities, already blocked by dropping CAP_PTRACE.
process_vm_writev Restrict process inspection capabilities, already blocked by dropping CAP_PTRACE.
ptrace Tracing/profiling syscall, which could leak a lot of information on the host. Already blocked by dropping CAP_PTRACE.
query_module Deny manipulation and functions on kernel modules. Obsolete.
quotactl Quota syscall which could let containers disable their own resource limits or process accounting. Also gated by CAP_SYS_ADMIN.
reboot Don't let containers reboot the host. Also gated by CAP_SYS_BOOT.
request_key Prevent containers from using the kernel keyring, which is not namespaced.
set_mempolicy Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE.
setns Deny associating a thread with a namespace. Also gated by CAP_SYS_ADMIN.
settimeofday Time/date is not namespaced. Also gated by CAP_SYS_TIME.
socket, socketcall Used to send or receive packets and for other socket operations. All socket and socketcall calls are blocked except communication domains AF_UNIX, AF_INET, AF_INET6, AF_NETLINK, and AF_PACKET.
stime Time/date is not namespaced. Also gated by CAP_SYS_TIME.
swapon Deny start/stop swapping to file/device. Also gated by CAP_SYS_ADMIN.
swapoff Deny start/stop swapping to file/device. Also gated by CAP_SYS_ADMIN.
sysfs Obsolete syscall.
_sysctl Obsolete, replaced by /proc/sys.
umount Should be a privileged operation. Also gated by CAP_SYS_ADMIN.
umount2 Should be a privileged operation. Also gated by CAP_SYS_ADMIN.
unshare Deny cloning new namespaces for processes. Also gated by CAP_SYS_ADMIN, with the exception of unshare –user.
uselib Older syscall related to shared libraries, unused for a long time.
userfaultfd Userspace page fault handling, largely needed for process migration.
ustat Obsolete syscall.
vm86 In kernel x86 real mode virtual machine. Also gated by CAP_SYS_ADMIN.
vm86old In kernel x86 real mode virtual machine. Also gated by CAP_SYS_ADMIN.

以上這篇解決docker使用GDB,無法進入斷點的問題就是小編分享給大家的全部內(nèi)容了,希望能給大家一個參考,也希望大家多多支持腳本之家。

相關(guān)文章

  • 如何使用docker配置wordpress

    如何使用docker配置wordpress

    本文詳細介紹了如何使用Docker安裝并配置WordPress,包括配置Yum源下載Docker,檢查安裝成功,并設(shè)置開機啟動,還涉及了如何配置MySQL密碼,以及設(shè)置php.ini來增加WordPress的文件上傳大小限制,最后,通過訪問指定IP完成WordPress的配置
    2024-10-10
  • 如何在Docker中設(shè)置容器間通信的權(quán)限和訪問控制策略

    如何在Docker中設(shè)置容器間通信的權(quán)限和訪問控制策略

    文章介紹了使用Docker網(wǎng)絡(luò)進行訪問控制的方法,包括自定義Bridge網(wǎng)絡(luò)、基于容器名稱的訪問控制和使用網(wǎng)絡(luò)策略(如Calico)進行更精細的控制
    2024-11-11
  • Docker容器中的Postgresql備份腳本異常解決

    Docker容器中的Postgresql備份腳本異常解決

    本文基于K8S中Docker容器對postgres數(shù)據(jù)庫進行備份的操作,但是提示報錯,報錯信息為kubectl command not found,本文就來介紹一下報錯信息的分析及其解決辦法,感興趣的可以了解一下
    2023-08-08
  • Centos7下安裝與卸載docker應用容器引擎的方法

    Centos7下安裝與卸載docker應用容器引擎的方法

    這篇文章主要介紹了Centos7下安裝與卸載docker應用容器引擎的方法,小編覺得挺不錯的,現(xiàn)在分享給大家,也給大家做個參考。一起跟隨小編過來看看吧
    2018-07-07
  • Docker安裝基礎(chǔ)鏡像服務的步驟

    Docker安裝基礎(chǔ)鏡像服務的步驟

    外部機器不能直接訪問容器,網(wǎng)是不通的,但可以訪問宿主機,只要將容器的端口與宿主機進行映射后,訪問宿主機的端口就相當于訪問了容器的端口,本文介紹Docker如何安裝基礎(chǔ)鏡像服務,感興趣的朋友一起看看吧
    2024-01-01
  • Docker容器時區(qū)調(diào)整操作

    Docker容器時區(qū)調(diào)整操作

    這篇文章主要介紹了Docker容器時區(qū)調(diào)整操作,具有很好的參考價值,希望對大家有所幫助。一起跟隨小編過來看看吧
    2020-11-11
  • 詳解docker進行數(shù)據(jù)掛載的三種模式

    詳解docker進行數(shù)據(jù)掛載的三種模式

    Docker?提供了三種方式將數(shù)據(jù)從宿主機掛載到?Docker容器中:?volumes、bind?mounts、tmpfs?,這篇文章主要介紹了docker進行數(shù)據(jù)掛載的三種模式,需要的朋友可以參考下
    2022-05-05
  • 使用Docker部署Dashdot服務器儀表盤的步驟

    使用Docker部署Dashdot服務器儀表盤的步驟

    Dashdot是一款簡單、實用的開源服務器儀表盤,設(shè)計時考慮到了玻璃形態(tài),它旨在用于較小的?VPS?和私人服務器,這篇文章主要介紹了使用Docker部署Dashdot服務器儀表盤,需要的朋友可以參考下
    2022-12-12
  • 使用docker-compose部署mysql的完整步驟

    使用docker-compose部署mysql的完整步驟

    Compose是用于定義和運行多容器Docker應用程序的工具,通過Compose可以使用YAML文件來配置應用程序的服務,下面這篇文章主要給大家介紹了關(guān)于使用docker-compose部署mysql的相關(guān)資料,需要的朋友可以參考下
    2022-08-08
  • docker容器啟動失敗如何查看日志

    docker容器啟動失敗如何查看日志

    這篇文章主要介紹了docker容器啟動失敗如何查看日志問題,具有很好的參考價值,希望對大家有所幫助。如有錯誤或未考慮完全的地方,望不吝賜教
    2023-05-05

最新評論

雷波县| 营口市| 公安县| 南和县| 绥化市| 赤峰市| 博野县| 金昌市| 阿瓦提县| 永定县| 天水市| 扎赉特旗| 华容县| 宜丰县| 双峰县| 武定县| 邵武市| 乐东| 河东区| 清涧县| 阳朔县| 自贡市| 兴国县| 巢湖市| 讷河市| 浦县| 阳春市| 临西县| 长寿区| 肥东县| 定襄县| 夏津县| 泗洪县| 米泉市| 青田县| 芦山县| 阳泉市| 无棣县| 梓潼县| 漯河市| 林西县|