cannot start jstatd due to permission error

后端 未结 11 1072
野的像风
野的像风 2020-12-12 10:59

I try to run jstatd jvm monitoring tool on linux machine

jboss@hostAddr:/usr/java/jdk1.6.0_18/bin> uname -a
Linux hostAddr 2.6.16.60-0.34-smp #1 SMP Fri J         


        
相关标签:
11条回答
  • 2020-12-12 11:17

    @michael nesterenko 's answer is all right.

    But if sometimes you can't connect the server even if you have get the Jstatd up, u may try to assign the 'rmi.server.hostname'

    #!/bin/sh
    policy=${HOME}/.jstatd.all.policy
    [ -r ${policy} ] || cat >${policy} <<'POLICY'
    grant codebase "file:${java.home}/../lib/tools.jar" {
    permission java.security.AllPermission;
    };
    POLICY
    
    jstatd -J-Djava.security.policy=${policy} -J-Djava.rmi.server.hostname=192.168.x.x &
    

    the hostname shoule be assigned as the public ip if you want to connect via public network.

    0 讨论(0)
  • 2020-12-12 11:18

    This is what worked for me:

    1. Make sure that tools.jar file exists and the user running the jstatd command has permissions to read it.

    2. Make sure that the URL in the jstatd.all.policy that points to the tools.jar is correct and declares the protocol (file in this case). For example, depending on where the java.home variable points to, you may need to remove the ../ part in the path just like this (I had to):

      grant codebase "file:${java.home}/lib/tools.jar" {
         permission java.security.AllPermission;
      };
      
    3. Starting from Java 1.4 the policy file needs to be encoded in UTF-8 without BOM. The EOL (CRLF vs LF) shouldn't really matter. Please see "Default Policy Implementation and Policy File Syntax" document from Oracle, under "Changes" section for more information (link not provided because I don't have enough reputation points to post more than 2 links, but I'm sure you'll be able to find that document).

    4. Use an absolute path to the policy file when running the jstatd command, e.g.

      jstatd -p 12345 -J-Djava.security.policy=/absolute-path-to/jstatd.all.policy
      

      EDIT: The -J parameter may no longer be required or supported in Java 1.8 so this command would be instead:

      jstatd -p 12345 -Djava.security.policy=/absolute-path-to/jstatd.all.policy
      

      (thanks @lisak for pointing this out)

    5. Finally, once you pass this point you may find other problems (I did) and these posts pointed me in the right direction: Using VisualVM to monitor a remote JBoss instance and Remote Profiling of JBoss using VisualVM. Basically you may need to use the -p parameter to use a different port if 1099 is already in use and add some java options in the JBoss run.conf via JAVA_OPTS (assuming you are monitoring JBoss instance). All explained in more detail in the links provided.

    EDIT: - Pointed dead link Using VisualVM to monitor a remote JBoss instance to another page with the same content.

    0 讨论(0)
  • 2020-12-12 11:18

    A one liner using process substitution (though bashism):

    jstatd -p 1099 -J-Djava.security.policy=<(echo 'grant codebase "file:${java.home}/../lib/tools.jar" {permission java.security.AllPermission;};')
    

    Wrapped:

    jstatd -p 1099 -J-Djava.security.policy=<(echo 'grant codebase "file:${java.home}/../lib/tools.jar" {permission java.security.AllPermission;};')

    As of jdk1.8.0_92, the java launcher option prefix -J is still required.

    Note:

    The original problem is more likely due to the tilde ~, in ~/jstatd.all.policy, isn't expanded hence not understood by java, meanwhile either absolute path or using ${HOME} instead should work.

    0 讨论(0)
  • 2020-12-12 11:20

    in addition to LightDye's answer, you can open required ports in your netfilter with this command :

    for port in `netstat -nlp | grep jstatd | sed -r 's/^.*\:([0-9]{4,}).*$/\1/'`; do iptables -I INPUT 1 -p tcp --dport $port -j ACCEPT -m comment --comment jstatd; done
    
    0 讨论(0)
  • 2020-12-12 11:21

    if you are using Java 11, you need view this answer:Starting jstatd in Java 9+ - Stack Overflow
    policy file is like this:

    grant codebase "jrt:/jdk.jstatd" {    
       permission java.security.AllPermission;    
    };
    
    0 讨论(0)
  • 2020-12-12 11:26

    Are you specifying your path wrong (i was)?

    Try putting the policy in /tmp/jstatd.all.policy and then running:

    jstatd -J-Djava.security.policy=/tmp/jstatd.all.policy
    
    0 讨论(0)
提交回复
热议问题