加了--cap-add SYS_ADMIN,禁用了沙盒,cpu 内存充足,还是报错怎么排查.egre...
# ask-ai
a
加了--cap-add SYS_ADMIN,禁用了沙盒,cpu 内存充足,还是报错怎么排查.egress@1b5a010ed964:/$ chrome --version Trace/breakpoint trap (core dumped) egress@1b5a010ed964:/$ chrome --headless=new --disable-gpu --no-sandbox --dump-dom https://www.baidu.com2 Trace/breakpoint trap (core dumped) 执行测试命令,打印下面内容,是什么问题
t
Thanks for reaching out, 徐旭. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
I understand encountering the error "Trace/breakpoint trap (core dumped)" when running Chrome in headless mode with
--no-sandbox
and
--cap-add SYS_ADMIN
can be frustrating. This often happens due to conflicting security settings or missing system call permissions. Let’s walk through some steps together to help you resolve this: 1. Try to avoid using `--no-sandbox`: Instead, it’s better to enable Chrome’s sandboxing by setting
enable_chrome_sandbox: true
in your Egress configuration. This helps keep things more secure and stable. 2. Use the right seccomp profile: Chrome needs specific system calls like
clone
and
unshare
. Make sure to use the provided seccomp profile to allow these calls:
Copy code
docker run --rm \
  -e EGRESS_CONFIG_FILE=/out/config.yaml \
  -v ~/egress-test:/out \
  --security-opt seccomp=chrome-sandboxing-seccomp-profile.json \
  livekit/egress
3. Check Docker capabilities: When you’re not using
--no-sandbox
, remember to include
--cap-add=SYS_ADMIN
to ensure proper permissions. 4. Enable debug logging: Adding
log_level: debug
to your Egress configuration can give you more detailed logs to help pinpoint any issues. 5. Verify system-level settings: It’s also a good idea to check kernel parameters like
vm.max_map_count
and make sure they’re set correctly (for example, 524288). Just a quick note: disabling the sandbox with
--no-sandbox
isn’t recommended because it can reduce security and cause instability. If you’re still running into trouble, please make sure you’re using Egress v1.7.6 or later and that your configuration matches the updated security model. We’re here to help you every step of the way! Sources: Self-hosting the Egress Service | LiveKit Docs | chrome-sandboxing-seccomp-profile.json | steam-headless/overlay/etc/cont-init.d/11-setup_sysctl_values.sh | Getting Help | livekit/livekit_composite | DeepWiki