systemd-coredump 服务填充 /run/systemd/propagate 直到 inode 耗尽

systemd-coredump 服务填充 /run/systemd/propagate 直到 inode 耗尽

在我的 SUSE Linux 上,在 下观察到了大量的 coredump 服务目录/run/systemd/propagate/,示例如下,到目前为止,/run这些文件夹已完全被这些文件夹填满,根本没有任何空闲 inode。

drw------- 2 root root 40 Nov 22 13:07 [email protected]
drw------- 2 root root 40 Nov 22 13:07 [email protected]
drw------- 2 root root 40 Nov 22 13:07 [email protected]
drw------- 2 root root 40 Nov 22 13:07 [email protected]
drw------- 2 root root 40 Nov 22 13:07 [email protected]

理想情况下,这些文件夹应该由systemd.

我怎样才能阻止他们留在这里?

  • 服务单位:
    # cat /usr/lib/systemd/system/[email protected] 
    
    [Unit]
    Description=Process Core Dump
    Documentation=man:systemd-coredump(8)
    DefaultDependencies=no
    Conflicts=shutdown.target
    After=systemd-journald.socket
    Requires=systemd-journald.socket
    Before=shutdown.target
    
    [Service]
    ExecStart=-/usr/lib/systemd/systemd-coredump
    IPAddressDeny=any
    LockPersonality=yes
    MemoryDenyWriteExecute=yes
    Nice=9
    NoNewPrivileges=yes
    OOMScoreAdjust=500
    PrivateDevices=yes
    PrivateNetwork=yes
    PrivateTmp=yes
    ProtectControlGroups=yes
    ProtectHome=yes
    ProtectHostname=yes
    ProtectKernelModules=yes
    ProtectKernelTunables=yes
    ProtectKernelLogs=yes
    ProtectSystem=strict
    RestrictAddressFamilies=AF_UNIX
    RestrictNamespaces=yes
    RestrictRealtime=yes
    RestrictSUIDSGID=yes
    RuntimeMaxSec=5min
    StateDirectory=systemd/coredump
    SystemCallArchitectures=native
    SystemCallErrorNumber=EPERM
    SystemCallFilter=@system-service
    

相关内容