r/linuxadmin • • 3d ago

X11 - RHEL 10.2 - ISOLATED Passthrough

Hoping someone can help me out with an issue I've been having for a long while.

I'm running RHEL 10.2 Gnome 49, trying to use an X application inside of a podman container with a custom network.

"podman network create --internal pod_dev"

I pass in all the environment variables and files that I know and what AI also says i need. I can not for the life of me get the x application to display.

It works in fedora 44, and Ubuntu, but RHEL 10 is kicking my butt.. if i do --net=host is am able to get the x application to work, but I have to have the container have its own IP.

And advice at all is appreciated, I've probably spent over 100 hours trying different combinations of flags and ways to run.

1 Upvotes

15 comments sorted by

3

u/michaelpaoli 3d ago

If you can do ssh, and with X forwarding, and properly set up environment, it should work fine.

First see if you can get it working without even touching container or the like, e.g. host of 127.0.0.1, if you're not getting that to work, it's not going to be easier targeting a container. And once you've got that working, for target host of container, also use -v options as needed on the ssh client, see if you're actually getting the X forwarding to work properly at all ... or not. And probably use both the -X and -Y options for X forwarding.

Anyway, pretty good chance you get all those bits correct and you should be set, but if not, well, update us on how far you got and what you found.

Might also want to try the Red Hat subreddit(s), notably in case there are any particular relevant Red Hat funkiness bits of relevance ... e.g. you may have SELinux enabled by default, and that might take some additional step(s). Thinking of which, don't forget to check relevant firewall configuration bits. Most of that would be handled by forwarding over ssh, but some bits may not be - notably the bits between ssh and X on the client and server side.

3

u/smallcrampcamp 2d ago edited 2d ago

Can you explain something that I am missing with this?

AI also told me this solution, but what i can't wrap my head around is how I ssh into the container when I have a custom network with the --internal flag set.

I will cross post, that is a good idea. se, fa, fwd, and everything else is stopped for now while I figure this out. Its in a test env, so not a big deal.

Thank you for your comment.

3

u/michaelpaoli 2d ago

At least from my quick skim, --internal blocks access beyond the host itself, but not to/from the host itself. So, do the ssh from the host itself to the IP address within the podman container.

And if you need to do it from a client beyond the host, you'll need to use host as intermediary, e.g. by using ProxyCommand option. But probably make sure you can get it working at least from host itself first.

3

u/smallcrampcamp 2d ago

Ah!, you may be on to something.

When podman creates its network with the internal flag, it puts the network in its own namespace, which doesnt allow direct communication when running rootless.. however it may be possible to establish connection between the container and the host. Ill have to further research this!

2

u/Firestorm1820 2d ago

podman unshare might be useful here, if you’ve not poked at the container with it.

Have you checked for selinux denials?

sudo ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent

What’s xorg/x11 log say? Crank up the verbosity and tail it.

2

u/apparentlyunoriginal 2d ago

I'd check the X cookie first. With a custom network podman gives the container its own hostname, and an Xauthority entry written for the host's hostname won't match it.

Run xauth list inside the container and compare the hostname in the entry with the output of hostname there. The quickest test is adding --hostname $(hostname) to your run command. If that fixes it and you need the container's own hostname, write a wildcard cookie with xauth nlist $DISPLAY | sed -e 's/^..../ffff/' | xauth -f /tmp/.podman.xauth nmerge -, mount that file, and set XAUTHORITY to its path in the container.

Drafted with AI, reviewed by me.

1

u/smallcrampcamp 2d ago

I did this another way, and it didnt work, but I will try your way on Monday!!

Thank you for taking your time to try and help.

1

u/metux-its 2d ago

No idea how to do it with podman specifically, but all you need is mounting the X socket inside the container and copy over xauthority file.

1

u/smallcrampcamp 2d ago

Yeah, thats exactly right. I have been trying every combination of passing both -e and -v for anything related to X11 that I could think of or what AI says.

Thanks!

1

u/metux-its 1d ago

Did you also copy in the xauthority file into the container ?

1

u/smallcrampcamp 1d ago

I did, no work.

Me sad.

1

u/bobtheboberto 2d ago

Does X11 need to be running on the host system? I ask because gnome on rhel 10 uses wayland by default. You might need to change it to x11, assuming gnome 49 supports x11 at all. I don't know which version but they are taking it out soon.

1

u/smallcrampcamp 2d ago

X11 is fully deprecated on 10. However, Xwayland still allows X processes to work, and for the most part I haven't had issues with Xwayland.

I believe gnome removed support in 48 or 49.

1

u/bobtheboberto 2d ago

Yeah. I know about xwayland. I was just curious if this works with it. It wouldn't be the first time I've seen an X application not run right with it.

1

u/tuxsmouf 1d ago

I know there is a wayland command we can use to export the gui with ssh. I used it only once and was quite straitforward. A quick google search should help you find it if you want to try.