只能以root身份运行uwsgi

问题描述:

我准备将nginx/uwsgi与烧瓶用于我正在开发的网站,但我遇到了问题。注意网站本身运行良好使用烧瓶的调试:5000端口,但我想现在投入生产。解释我做了什么。只能以root身份运行uwsgi

这是一个的Linode的Ubuntu 12.04LTS服务器,我安装了它这样的:

# install nginx 
sudo apt-get install python-software-properties 
sudo add-apt-repository ppa:nginx/stable 
sudo apt-get update 
sudo apt-get upgrade --show-upgraded 
sudo apt-get install nginx-full 
# installing uwsgi 
sudo apt-get install build-essential python-dev libxml2-dev 
sudo apt-get install libc6 libexpat1 libgd2-xpm libgeoip1 libpam0g libpcre3 libssl1.0.0 libxml2 libxslt1.1 zlib1g 
sudo pip install uwsgi 
# python basics 
sudo apt-get install python-pip build-essential python-dev 
sudo pip install virtualenv 
sudo pip install virtualenvwrapper 
sudo mkdir -p /srv/www/li/ 
cd /srv/www/li/ 
virtualenv venv 
source /srv/www/li/venv/bin/activate 
pip install flask 

然后我开始配置一切,但我已经运行到与uwsgi麻烦(没关系NGINX,这将是。下一步

sudo nano /etc/uwsgi/apps-available/li.xml 

    <uwsgi> 
    <plugin>python</plugin> 
    <socket>/run/uwsgi/app/li.socket</socket> 
    <chmod-socket>666</chmod-socket> 
    <chdir>/srv/www/li</chdir> 
    <pythonpath>/srv/www/li</pythonpath> 
    <virtualenv>/srv/www/li/venv</virtualenv> 
    <module>li</module> 
    <wsgi-file>/srv/www/li/li.py</wsgi-file> 
    <callable>app</callable> 
    <master/> 
    <processes>4</processes> 
    <harakiri>60</harakiri> 
    <reload-mercy>8</reload-mercy> 
    <cpu-affinity>1</cpu-affinity> 
    <stats>/tmp/stats.socket</stats> 
    <max-requests>2000</max-requests> 
    <limit-as>512</limit-as> 
    <reload-on-as>256</reload-on-as> 
    <reload-on-rss>192</reload-on-rss> 
    <no-orphans/> 
    <vacuum/> 
</uwsgi> 

sudo ln -s /etc/uwsgi/apps-available/li.xml /etc/uwsgi/apps-enabled/li.xml 

但是,如果我运行它,我得到:

uwsgi --xml /etc/uwsgi/apps-enabled/li.xml 

[uWSGI] parsing config file /etc/uwsgi/apps-enabled/li.xml 
open("./python_plugin.so"): No such file or directory [core/utils.c line 4755] 
!!! UNABLE to load uWSGI plugin: ./python_plugin.so: cannot open shared object file: No such file or directory !!! 
*** Starting uWSGI 1.4.6 (64bit) on [Thu Feb 28 16:30:53 2013] *** 
compiled with version: 4.6.3 on 28 February 2013 12:38:22 
os: Linux-3.7.10-x86_64-linode30 #1 SMP Wed Feb 27 14:29:31 EST 2013 
nodename: demo 
machine: x86_64 
clock source: unix 
detected number of CPU cores: 4 
current working directory: /run/uwsgi/app 
detected binary path: /usr/local/bin/uwsgi 
your processes number limit is 63594 
limiting address space of processes... 
your process address space limit is 536870912 bytes (512 MB) 
your memory page size is 4096 bytes 
*** WARNING: you have enabled harakiri without post buffering. Slow upload could be rejected on post-unbuffered webservers *** 
detected max file descriptor number: 1024 
lock engine: pthread robust mutexes 
uwsgi socket 0 bound to UNIX address /run/uwsgi/app/li.socket fd 3 
Python version: 2.7.3 (default, Aug 1 2012, 05:25:23) [GCC 4.6.3] 
Set PythonHome to /srv/www/li/venv 
*** Python threads support is disabled. You can enable it with --enable-threads *** 
Python main interpreter initialized at 0xa86e20 
your server socket listen backlog is limited to 100 connections 
mapped 362120 bytes (353 KB) for 4 cores 
*** Operational MODE: preforking *** 
added /srv/www/li/ to pythonpath. 
/srv/www/li/venv/local/lib/python2.7/site-packages/mongoengine/fields.py:744: FutureWarning: ReferenceFields will default to using ObjectId strings in 0.8, set DBRef=True if this isn't desired 
    warnings.warn(msg, FutureWarning) 
WSGI app 0 (mountpoint='') ready in 1 seconds on interpreter 0xa86e20 pid: 14934 (default app) 
*** uWSGI is running in multiple interpreter mode *** 
spawned uWSGI master process (pid: 14934) 
spawned uWSGI worker 1 (pid: 14940, cores: 1) 
mapping worker 1 to CPUs: 0 
spawned uWSGI worker 2 (pid: 14941, cores: 1) 
mapping worker 2 to CPUs: 1 
spawned uWSGI worker 3 (pid: 14942, cores: 1) 
mapping worker 3 to CPUs: 2 
spawned uWSGI worker 4 (pid: 14943, cores: 1) 
unlink(): Operation not permitted [core/socket.c line 109] 
bind(): Address already in use [core/socket.c line 141] 
...brutally killing workers... 
mapping worker 4 to CPUs: 3 
VACUUM: unix socket /run/uwsgi/app/li.socket removed. 

,所以我得到不允许取消链接操作,并且绑定地址已经在使用错误(在python_plugin错误旁边,我也没有线索如何解决这个错误!)。如果我作为sudo运行,它似乎工作正常 - >

sudo uwsgi --xml /etc/uwsgi/apps-enabled/li.xml 

[uWSGI] parsing config file /etc/uwsgi/apps-enabled/li.xml 
open("./python_plugin.so"): No such file or directory [core/utils.c line 4755] 
!!! UNABLE to load uWSGI plugin: ./python_plugin.so: cannot open shared object file: No such file or directory !!! 
*** Starting uWSGI 1.4.6 (64bit) on [Thu Feb 28 15:47:41 2013] *** 
compiled with version: 4.6.3 on 28 February 2013 12:38:22 
os: Linux-3.7.10-x86_64-linode30 #1 SMP Wed Feb 27 14:29:31 EST 2013 
nodename: demo 
machine: x86_64 
clock source: unix 
detected number of CPU cores: 4 
current working directory: /run/uwsgi 
detected binary path: /usr/local/bin/uwsgi 
uWSGI running as root, you can use --uid/--gid/--chroot options 
*** WARNING: you are running uWSGI as root !!! (use the --uid flag) *** 
your processes number limit is 63594 
limiting address space of processes... 
your process address space limit is 536870912 bytes (512 MB) 
your memory page size is 4096 bytes 
*** WARNING: you have enabled harakiri without post buffering. Slow upload could be rejected on post-unbuffered webservers *** 
detected max file descriptor number: 1024 
lock engine: pthread robust mutexes 
uwsgi socket 0 bound to UNIX address /run/uwsgi/app/li.socket fd 3 
Python version: 2.7.3 (default, Aug 1 2012, 05:25:23) [GCC 4.6.3] 
Set PythonHome to /srv/www/li/venv 
*** Python threads support is disabled. You can enable it with --enable-threads *** 
Python main interpreter initialized at 0x1fc9d00 
your server socket listen backlog is limited to 100 connections 
mapped 362120 bytes (353 KB) for 4 cores 
*** Operational MODE: preforking *** 
added /srv/www/li/ to pythonpath. 
/srv/www/li/venv/local/lib/python2.7/site-packages/mongoengine/fields.py:744: FutureWarning: ReferenceFields will default to using ObjectId strings in 0.8, set DBRef=True if this isn't desired 
    warnings.warn(msg, FutureWarning) 
WSGI app 0 (mountpoint='') ready in 0 seconds on interpreter 0x1fc9d00 pid: 14755 (default app) 
*** uWSGI is running in multiple interpreter mode *** 
spawned uWSGI master process (pid: 14755) 
spawned uWSGI worker 1 (pid: 14761, cores: 1) 
mapping worker 1 to CPUs: 0 
spawned uWSGI worker 2 (pid: 14762, cores: 1) 
mapping worker 2 to CPUs: 1 
spawned uWSGI worker 3 (pid: 14763, cores: 1) 
mapping worker 3 to CPUs: 2 
spawned uWSGI worker 4 (pid: 14764, cores: 1) 
*** Stats server enabled on /tmp/stats.socket fd: 16 *** 
mapping worker 4 to CPUs: 3 

任何人都可以请帮助我吗?由于WWW的数据是www数据组中,他跑了,我尝试了一些东西:

sudo usermod -a -G www-data $USER 
sudo chown -R $USER:www-data /srv/www/li 
sudo chmod -R g+r+w+x /srv/www/li 
sudo chown -R $USER:www-data /etc/uwsgi/apps-enabled 
sudo chmod -R g+r+w+x /etc/uwsgi/apps-enabled 
sudo chown -R $USER:www-data /run/uwsgi/app 
sudo chmod -R g+r+w+x /run/uwsgi/app 

但真的没有帮助。我也尝试了一个tcp端口,而不是unix/run/uwsgi/app/port,这两个端口没有任何区别... 这让我很疯狂:(我希望有人对这里发生的事情有一点线索

亲切的问候,

岩溶

编辑:

[email protected]:~$ uwsgi --xml /etc/uwsgi/apps-enabled/li.xml 
[uWSGI] parsing config file /etc/uwsgi/apps-enabled/li.xml 
*** Starting uWSGI 1.4.6 (64bit) on [Thu Feb 28 18:47:36 2013] *** 
compiled with version: 4.6.3 on 28 February 2013 12:38:22 
os: Linux-3.7.10-x86_64-linode30 #1 SMP Wed Feb 27 14:29:31 EST 2013 
nodename: demo 
machine: x86_64 
clock source: unix 
detected number of CPU cores: 4 
current working directory: /home/geoadmin 
detected binary path: /usr/local/bin/uwsgi 
your processes number limit is 63594 
limiting address space of processes... 
your process address space limit is 536870912 bytes (512 MB) 
your memory page size is 4096 bytes 
*** WARNING: you have enabled harakiri without post buffering. Slow upload could be rejected on post-unbuffered webservers *** 
detected max file descriptor number: 1024 
lock engine: pthread robust mutexes 
bind(): No such file or directory [core/socket.c line 141] 

好,后来编辑后,我检查的目录和插座:在服务器重新启动它仍然给了埃罗但不同的一个后目录不存在(不再);我瘦k它必须使用原始apt-get安装与我以后的pip安装...仍然有问题与python插件,但会检查是否需要为nginx或如果它将工作没有它... 8小时的工作在复位,德哦;)

@bearrito: 在我把插座的tmp目录结束,以避免*问题:

<uwsgi> 
     <uid>www-data</uid> 
     <gid>www-data</gid> 
    <plugin>python</plugin> 
    <socket>/tmp/li.socket</socket> 
    <chmod-socket>666</chmod-socket> 
    <chdir>/srv/www/li</chdir> 
    <pythonpath>/srv/www/li</pythonpath> 
    <virtualenv>/srv/www/li/venv</virtualenv> 
    <module>li</module> 
    <wsgi-file>/srv/www/li/li.py</wsgi-file> 
    <callable>app</callable> 
    <master/> 
    <processes>2</processes> 
    <pidfile>/tmp/li.pid</pidfile> 
    <harakiri>120</harakiri> 
    <reload-mercy>8</reload-mercy> 
    <cpu-affinity>1</cpu-affinity> 
    <stats>/tmp/stats.socket</stats> 
    <max-requests>2000</max-requests> 
    <limit-as>2048</limit-as> 
    <reload-on-as>2048</reload-on-as> 
    <reload-on-rss>1024</reload-on-rss> 
    <no-orphans/> 
    <vacuum/> 
</uwsgi> 

我希望这有助于!

+1

后小评:蟒插件(这是在每个一派示例)在新版本中似乎不再需要。所以最终它确实比我以前想象的更容易和开箱即用! – Carst 2013-03-03 21:02:38

+0

你能更清楚地知道你的修补程序需要什么吗?我的情况完全相同,但我无法破译我的案例中可重现的内容。 – bearrito 2013-03-06 05:30:38

+0

用我所做的来编辑它!另外:我的工作者的内存限制是真的,所以不要复制:)(与一个沉重的分析过程有关) – Carst 2013-03-06 19:11:39

这一直是我在google上的第一个结果,而且这个页面对我来说相对没有帮助,所以我会添加我的答案,即使它在回顾过程中显而易见。

我的问题是我的统计套接字的权限问题。如果您更改了uWSGI配置的uid或gid参数,请确保您或者chmod或rm所有旧套接字/ pid,以及它们的父文件夹

+0

嗨,很抱歉听到它没有帮助你。这就是我的意思是“最终我把套接字放在tmp目录中以避免版权问题”的评论,但你说得对,它可能会少一点隐密。这个问题也是由于我同时有两个问题,另一个问题造成的:http://*.com/questions/15936413/pip-installed-uwsgi-python-plugin-so-error – Carst 2013-10-04 08:15:40

+3

对不起,并不意味着攻击你的答案,只是在下一次我加入到这个页面时才加入它。恕我直言,来自uWSGI的日志消息在处理这个问题上完全没有帮助。 – pnovotnak 2013-10-04 15:21:33

+1

别担心,没有看到它那样。我会编辑答案,以帮助人们更好。基本上问题是,你可以同时有两个单独的问题(python插件问题+权利套接字问题),这也给我一个头痛的原因,因此上面的原始答案如此广泛 – Carst 2013-10-07 10:32:15

对我来说,解决办法是删除/var/run/uwsgi/.sock和

chmod 775 /var/run/uwsgi 
chmod 777 /var/log/uwsgi 

或任何你uwsgi文件。

在我来说,我是想放置.sock文件中/vagrant目录,这是虚框的一台机器安装文件夹,不利于远远超过读取和写入。

放置.sock文件的virtualbox以外挂载点优选在/tmpFHS说:/var/run

价: https://*.com/a/7580524/1695680

+0

这对我来说真的很有用。 – cjauvin 2016-10-10 18:57:24

+0

这里的权利应该是答案 – Jeremy 2016-12-01 19:54:01