r/linuxadmin • • 3d ago

X11 - RHEL 10.2 - ISOLATED Passthrough

Hoping someone can help me out with an issue I've been having for a long while.

I'm running RHEL 10.2 Gnome 49, trying to use an X application inside of a podman container with a custom network.

"podman network create --internal pod_dev"

I pass in all the environment variables and files that I know and what AI also says i need. I can not for the life of me get the x application to display.

It works in fedora 44, and Ubuntu, but RHEL 10 is kicking my butt.. if i do --net=host is am able to get the x application to work, but I have to have the container have its own IP.

And advice at all is appreciated, I've probably spent over 100 hours trying different combinations of flags and ways to run.

2 Upvotes

15 comments sorted by

View all comments

3

u/michaelpaoli 3d ago

If you can do ssh, and with X forwarding, and properly set up environment, it should work fine.

First see if you can get it working without even touching container or the like, e.g. host of 127.0.0.1, if you're not getting that to work, it's not going to be easier targeting a container. And once you've got that working, for target host of container, also use -v options as needed on the ssh client, see if you're actually getting the X forwarding to work properly at all ... or not. And probably use both the -X and -Y options for X forwarding.

Anyway, pretty good chance you get all those bits correct and you should be set, but if not, well, update us on how far you got and what you found.

Might also want to try the Red Hat subreddit(s), notably in case there are any particular relevant Red Hat funkiness bits of relevance ... e.g. you may have SELinux enabled by default, and that might take some additional step(s). Thinking of which, don't forget to check relevant firewall configuration bits. Most of that would be handled by forwarding over ssh, but some bits may not be - notably the bits between ssh and X on the client and server side.

3

u/smallcrampcamp 2d ago edited 2d ago

Can you explain something that I am missing with this?

AI also told me this solution, but what i can't wrap my head around is how I ssh into the container when I have a custom network with the --internal flag set.

I will cross post, that is a good idea. se, fa, fwd, and everything else is stopped for now while I figure this out. Its in a test env, so not a big deal.

Thank you for your comment.

3

u/michaelpaoli 2d ago

At least from my quick skim, --internal blocks access beyond the host itself, but not to/from the host itself. So, do the ssh from the host itself to the IP address within the podman container.

And if you need to do it from a client beyond the host, you'll need to use host as intermediary, e.g. by using ProxyCommand option. But probably make sure you can get it working at least from host itself first.

3

u/smallcrampcamp 2d ago

Ah!, you may be on to something.

When podman creates its network with the internal flag, it puts the network in its own namespace, which doesnt allow direct communication when running rootless.. however it may be possible to establish connection between the container and the host. Ill have to further research this!

2

u/Firestorm1820 2d ago

podman unshare might be useful here, if you’ve not poked at the container with it.

Have you checked for selinux denials?

sudo ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent

What’s xorg/x11 log say? Crank up the verbosity and tail it.