audit:backlog limit exceeded

本文记录了一次Linux服务器因audit服务导致的系统崩溃经历。通过重启服务器及调整audit服务配置解决了问题,并介绍了如何设置audit服务参数避免类似故障再次发生。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

今天发现存储服务器业务不可用,服务器能ping通,远程不了!  到机房管理员那里查看服务器状态后,发现显示如下:

显然系统已经崩溃,只能先重启服务器,先恢复业务,然后针对backlog limit exceeded的告警查找原因

 

通过百度查找audit服务是linux的一个审计服务,上述原因是audit服务在繁忙的系统中进行审计事件操作,缓冲瓶颈,导致系统崩溃

在优化audit服务之前要先确保selinx是disabled状态和磁盘正常,否则会出现重启服务器之后输入root密码的那个界面会提示只读等的字样

 

优化audit服务:#auditctl -b 8192(8192是kb单位,但是这个值要根据系统的实际情况设置)

   

以上只是临时生效,重启服务器还是会重置为默认值,可以将auditctl -b 8192写入/etc/rc.local

 

转载于:https://www.cnblogs.com/qfdxxdr/p/8462010.html

安卓APP访问CAN有如下报错05-16 18:09:54.015 8022 8022 D can_test: nCanFd = 67 05-16 18:09:54.015 8022 8022 D can_test: Send can_id 05-16 18:09:54.013 8022 8022 I com.bin.cantest: type=1400 audit(0.0:444): avc: denied { ioctl } for path="socket:[114169]" dev="sockfs" ino=114169 ioctlcmd=0x8933 scontext=u:r:system_app:s0 tcontext=u:r:system_app:s0 tclass=can_socket permissive=1 05-16 18:09:54.015 8022 8022 D can_test: Send Error frame[0] 05-16 18:09:54.013 8022 8022 I com.bin.cantest: type=1400 audit(0.0:445): avc: denied { bind } for scontext=u:r:system_app:s0 tcontext=u:r:system_app:s0 tclass=can_socket permissive=1 05-16 18:09:54.013 8022 8022 I com.bin.cantest: type=1400 audit(0.0:446): avc: denied { write } for path="socket:[114169]" dev="sockfs" ino=114169 scontext=u:r:system_app:s0 tcontext=u:r:system_app:s0 tclass=can_socket permissive=1 05-16 18:09:54.020 0 0 W audit : audit_lost=15 audit_rate_limit=5 audit_backlog_limit=64 05-16 18:09:54.020 0 0 E audit : rate limit exceeded 05-16 18:09:54.060 305 388 W APM::AudioPolicyEngine: getDevicesForStrategy() unknown strategy: -1 05-16 18:09:54.060 459 477 I system_server: oneway function results will be dropped but finished with status OK and parcel size 4 05-16 18:09:54.150 459 1215 E TaskPersister: File error accessing recents directory (directory doesn't exist?). 05-16 18:09:56.930 274 401 D AudioHardwareTiny: do_out_standby,out = 0xea043b70,device = 0x2 05-16 18:09:56.932 274 401 D alsa_route: route_set_controls() set route 24 05-16 18:09:56.941 274 401 D AudioHardwareTiny: close device 05-16 18:09:56.943 459 477 I system_server: oneway function results will be dropped but finished with status OK and parcel size 4 05-16 18:10:00.010 620 620 D KeyguardClockSwitch: Updating clock:
06-13
06-27 14:30:48.756 17487 17487 D UsbDeviceConnectionJNI: close 06-27 14:30:48.756 17487 17487 I MultiCameraClient: disconnect device name/pid/vid:/dev/bus/usb/005/097&8841&7119 06-27 14:30:48.757 17487 17487 D ActivityStackUtils: remove stack: CusCarmerActivity 06-27 14:30:48.757 17487 17487 I CusCarmerActivity22: onDestroy==end 06-27 14:30:48.761 443 516 W InputManager-JNI: Input channel object '8e49df8 com.example.simplecarmer/com.example.simplecarmer.CusCarmerActivity (client)' was disposed without first being removed with the input manager! 06-27 14:30:48.772 17487 17487 I CusCarmerActivity22: CusCarmerActivity stateCLOSED==null 06-27 14:30:48.773 23868 23898 D BufferPoolAccessor2.0: bufferpool2 0xb400007d2ad603d8 : 5(19200 size) total buffers - 4(15360 size) used buffers - 812541/812546 (recycle/alloc) - 2285/1625082 (fetch/transfer) 06-27 14:30:48.798 17487 26435 I RenderManager: camera render frame rate is 7 fps-->gl_render 06-27 14:30:48.804 376 23907 D BufferPoolAccessor2.0: bufferpool2 0xb4000070ae124038 : 4(96000 size) total buffers - 2(48000 size) used buffers - 812540/812544 (recycle/alloc) - 117/812542 (fetch/transfer) 06-27 14:30:48.809 17487 26436 F libc : Fatal signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x780d80e690 in tid 26436 (camera-17510058), pid 17487 (le.simplecarmer) 06-27 14:30:48.930 26448 26448 I crash_dump64: obtaining output fd from tombstoned, type: kDebuggerdTombstoneProto 06-27 14:30:48.933 210 210 I tombstoned: received crash request for pid 26436 06-27 14:30:48.935 26448 26448 I crash_dump64: performing dump of process 17487 (target tid = 26436) 06-27 14:30:49.080 26448 26448 W unwind : Failed to initialize DEX file support: dlopen failed: library "libdexfile.so" not found 06-27 14:30:49.193 26448 26448 I crash_dump64: type=1400 audit(0.0:1451): avc: denied { open } for path="/dev/__properties__/u:object_r:hwservicemanager_prop:s0" dev="tmpfs" ino=11849 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:hwservicemanager_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.193 26448 26448 I crash_dump64: type=1400 audit(0.0:1452): avc: denied { getattr } for path="/dev/__properties__/u:object_r:hwservicemanager_prop:s0" dev="tmpfs" ino=11849 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:hwservicemanager_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.193 26448 26448 I crash_dump64: type=1400 audit(0.0:1453): avc: denied { map } for path="/dev/__properties__/u:object_r:hwservicemanager_prop:s0" dev="tmpfs" ino=11849 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:hwservicemanager_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.197 26448 26448 I crash_dump64: type=1400 audit(0.0:1454): avc: denied { open } for path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=11955 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.197 26448 26448 I crash_dump64: type=1400 audit(0.0:1455): avc: denied { getattr } for path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=11955 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.197 26448 26448 I crash_dump64: type=1400 audit(0.0:1456): avc: denied { map } for path="/dev/__properties__/u:object_r:vendor_default_prop:s0" dev="tmpfs" ino=11955 scontext=u:r:crash_dump:s0:c512,c768 tcontext=u:object_r:vendor_default_prop:s0 tclass=file permissive=1 app=com.example.simplecarmer 06-27 14:30:49.196 0 0 W audit : audit_lost=260 audit_rate_limit=5 audit_backlog_limit=64 06-27 14:30:49.196 0 0 E audit : rate limit exceeded
最新发布
06-28
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值