【问题标题】:NaCl helper process running without a sandbox! error when running npm testsNaCl 辅助进程在没有沙箱的情况下运行!运行 npm 测试时出错
【发布时间】:2018-04-26 10:41:01
【问题描述】:

我在运行一些 npm 测试时遇到了问题。我收到的错误是:“NaCl helper process running without a sandbox!”,这是真的,因为我正在使用“--no-sandbox”选项运行浏览器。由于浏览器以 root 身份运行,因此我必须运行此选项,而且我根本没有选择以不同的用户运行它(它是一个 docker 映像)。 谁能帮我解决一下?

P.S 我是通过以下方式安装浏览器的:

RUN apt-get update
RUN apt-get install -y nodejs npm
RUN wget -q -O - https://dl-ssl.google.com/linux/linux_signing_key.pub | apt-key add -
RUN sh -c 'echo "deb https://dl.google.com/linux/chrome/deb/ stable main" >> /etc/apt/sources.list.d/google.list'
RUN apt-get install -y apt-transport-https
RUN apt-get update
RUN apt-get install -y google-chrome-stable

提前致谢!

【问题讨论】:

    标签: google-chrome docker npm


    【解决方案1】:

    如果您使用 karma 运行测试,请确保您使用 ChromeHeadless 作为 karma.conf.js 上的浏览​​器

    【讨论】:

      【解决方案2】:

      此错误消息...

      NaCl helper process running without a sandbox!
      

      ...暗示您的系统中没有 setuid 沙箱,因此程序无法启动/生成新的浏览上下文,即 Chrome 浏览器 会话。


      解决方案

      一个快速的解决方案是,如果你想运行 Chrome 并且只使用命名空间沙箱,你可以设置标志:

      --disable-setuid-sandbox
      

      此标志将禁用 setuid 沙箱(仅限 Linux)。但是,如果您在没有适当内核支持命名空间沙箱的主机上执行此操作,Chrome 将不会启动。作为替代方案,您也可以使用该标志:

      --no-sandbox
      

      此标志将为所有通常被沙盒处理的进程类型禁用沙盒。

      例子:

      chromeOptions: {
            args: ['--disable-setuid-sandbox', '--no-sandbox']
      },
      

      您可以在Security Considerations - ChromeDriver - Webdriver for Chrome找到详细讨论


      深潜

      根据Linux SUID Sandbox Development 中的文档, 需要一个SUID 辅助二进制文件才能在 Linux 上打开沙箱。在大多数情况下,您可以使用以下命令为您安装正确的沙箱:

      build/update-linux-sandbox.sh
      

      此程序将在/usr/local/sbin 中为您安装正确的沙盒,并告诉您在需要时更新您的.bashrc。

      但是,也可能有一些例外,例如,如果您的 setuid 二进制文件已过期,您将收到如下消息:

      Running without the SUID sandbox! 
      

      或者

      The setuid sandbox provides API version X, but you need Y
      You are using a wrong version of the setuid binary!
      

      在这些情况下,您需要:

      • 在构建 chrome 时构建 chrome_sandbox(ninja -C xxx chrome chrome_sandbox 而不是 ninja -C xxx chrome)
      • 构建完成后,执行update-linux-sandbox.sh。

        # needed if you build on NFS!
        sudo cp out/Debug/chrome_sandbox /usr/local/sbin/chrome-devel-sandbox
        sudo chown root:root /usr/local/sbin/chrome-devel-sandbox
        sudo chmod 4755 /usr/local/sbin/chrome-devel-sandbox
        
      • 最后,您必须在~/.bashrc(或.zshenv)中包含以下行:

        export CHROME_DEVEL_SANDBOX=/usr/local/sbin/chrome-devel-sandbox
        

      【讨论】:

      • 在哪里可以获得这个 update-linux-sandbox.sh?我也没有使用 docar
      • @dpkrai96 从这里得到它chromium.googlesource.com/chromium/src/+/b05c228f0b14/build/… 但是如何构建 .sh 文件?我运行了命令build/update-linux-sandbox.sh,但它显示:# build/update-linux-sandbox.sh -bash: build/update-linux-sandbox.sh: No such file or directory
      猜你喜欢
      • 2013-10-23
      • 2020-06-18
      • 2015-07-01
      • 2023-01-09
      • 2010-12-06
      • 1970-01-01
      • 2014-07-29
      • 2015-03-01
      • 2023-04-04
      相关资源
      最近更新 更多