此错误消息...
NaCl helper process running without a sandbox!
...暗示您的系统中没有 setuid 沙箱,因此程序无法启动/生成新的浏览上下文,即 Chrome 浏览器 会话。
解决方案
一个快速的解决方案是,如果你想运行 Chrome 并且只使用命名空间沙箱,你可以设置标志:
--disable-setuid-sandbox
此标志将禁用 setuid 沙箱(仅限 Linux)。但是,如果您在没有适当内核支持命名空间沙箱的主机上执行此操作,Chrome 将不会启动。作为替代方案,您也可以使用该标志:
--no-sandbox
此标志将为所有通常被沙盒处理的进程类型禁用沙盒。
例子:
chromeOptions: {
args: ['--disable-setuid-sandbox', '--no-sandbox']
},
您可以在Security Considerations - ChromeDriver - Webdriver for Chrome找到详细讨论
深潜
根据Linux SUID Sandbox Development 中的文档,google-chrome 需要一个SUID 辅助二进制文件才能在 Linux 上打开沙箱。在大多数情况下,您可以使用以下命令为您安装正确的沙箱:
build/update-linux-sandbox.sh
此程序将在/usr/local/sbin 中为您安装正确的沙盒,并告诉您在需要时更新您的.bashrc。
但是,也可能有一些例外,例如,如果您的 setuid 二进制文件已过期,您将收到如下消息:
Running without the SUID sandbox!
或者
The setuid sandbox provides API version X, but you need Y
You are using a wrong version of the setuid binary!
在这些情况下,您需要:
- 在构建 chrome 时构建
chrome_sandbox(ninja -C xxx chrome chrome_sandbox 而不是 ninja -C xxx chrome)
-
构建完成后,执行update-linux-sandbox.sh。
# needed if you build on NFS!
sudo cp out/Debug/chrome_sandbox /usr/local/sbin/chrome-devel-sandbox
sudo chown root:root /usr/local/sbin/chrome-devel-sandbox
sudo chmod 4755 /usr/local/sbin/chrome-devel-sandbox
-
最后,您必须在~/.bashrc(或.zshenv)中包含以下行:
export CHROME_DEVEL_SANDBOX=/usr/local/sbin/chrome-devel-sandbox