Skip to content

Support for SELinux #730

Description

@mjakob

Greetings!

I thought I would give this very interesting library a try this morning but couldn't get past the quickstart example:

$ uvx --with blosc2 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000)' 
tcc: error: mprotect failed (did you mean to configure --with-selinux?)

The computer I'm using runs RHEL10 with SELinux enabled and from the error message I'm guessing tcc needs to be compiled with a special flag to work with that. Is there a way to make this package work with SELinux enabled?

Regards, Mattias

Activity

  1. FrancescAlted commented on Oct 3, 2026

    @FrancescAlted
    Member

    Hi Jakob. Great point. This seems a JIT executable-memory restriction, very likely imposed by SELinux policy. blosc2.linspace() uses a miniexpr kernel for faster operation, which defaults to compiling native code with bundled TinyCC (libtcc). TinyCC writes the generated code into memory, then calls mprotect() to make it executable. A restrictive SELinux policy can deny that operation, producing this error.

    The immediate workaround is to disable JIT for the operation:

    uvx --with blosc2 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=False)'
    

    Perhaps we would need a graceful interpreter fallback when executable-memory allocation fails. Users shouldn’t need to disable SELinux to run the quickstart. Would you like to provide a PR?

  2. mjakob commented on Oct 4, 2026

    @mjakob
    Author

    Thank you for a quick and clear response! Before I posted I was looking in the documentation for options regarding the jit but I couldn't find the argument you mention. It indeed makes the function work with SELinux enabled. IMHO there would need to be a global option to turn it off to make the library ergonomic for SELinux users.

    I was just having a first look at this library so I'm afraid I'm not commited enough to provide a PR. I wish you the best of luck and I hope the report itself was a positive contribution, although very very minor 🙂

  3. FrancescAlted commented on Oct 4, 2026

    @FrancescAlted
    Member

    No worries, totally understand. You made a good point about documentation, which can be improved indeed (you are welcome if you prefer to work on that, rather than the code side).

    Having said that, I wonder if using the cc backend instead of tcc would help SELinux. Can you run this:

    env ME_DSL_TRACE=1 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=True, jit_backend="cc")'

    and tell me the output?

  4. mjakob commented on Oct 4, 2026

    @mjakob
    Author

    Something like jit_backend was actually what I was looking for in the documentation hoping that another choice would work better with SELinux. It seems to work fine:

    $ env ME_DSL_TRACE=1 uvx --with blosc2 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=True, jit_backend="cc")'
    [me-dsl] jit codegen: runtime math bridge enabled (scalar=libm vec=on expr=off if=select)
    [me-dsl] jit codegen: lowering=scalar vec_ops=- reason=no-vector-lowering-match
    [me-dsl] jit ir built: fp=strict compiler=cc fingerprint=a8e270a4a2185868
    [me-dsl] jit runtime hit: fp=strict source=disk-cache key=e87f69daef8dc186
    

    Is there a way to set the jit backend globally for e.g. a script?

  5. FrancescAlted commented on Oct 5, 2026

    @FrancescAlted
    Member

    PR #732 should provide better SELinux compatibility and a way to set the jit backend globally. @mjakob give it a spin and tell me how it goes.

  6. mjakob commented on Oct 10, 2026

    @mjakob
    Author

    I just ran the quickstart example with git+https://github.com/Blosc/python-blosc2@main without any problems so it's looking great, really nice work @FrancescAlted! I'll make sure to report if I run into any more issues related to SELinux when I explore further. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions