Repository navigation
Support for SELinux #730
Description
Activity
Hi Jakob. Great point. This seems a JIT executable-memory restriction, very likely imposed by SELinux policy. blosc2.linspace() uses a miniexpr kernel for faster operation, which defaults to compiling native code with bundled TinyCC (libtcc). TinyCC writes the generated code into memory, then calls mprotect() to make it executable. A restrictive SELinux policy can deny that operation, producing this error.
The immediate workaround is to disable JIT for the operation:
uvx --with blosc2 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=False)'Perhaps we would need a graceful interpreter fallback when executable-memory allocation fails. Users shouldn’t need to disable SELinux to run the quickstart. Would you like to provide a PR?
Thank you for a quick and clear response! Before I posted I was looking in the documentation for options regarding the jit but I couldn't find the argument you mention. It indeed makes the function work with SELinux enabled. IMHO there would need to be a global option to turn it off to make the library ergonomic for SELinux users.
I was just having a first look at this library so I'm afraid I'm not commited enough to provide a PR. I wish you the best of luck and I hope the report itself was a positive contribution, although very very minor 🙂
No worries, totally understand. You made a good point about documentation, which can be improved indeed (you are welcome if you prefer to work on that, rather than the code side).
Having said that, I wonder if using the cc backend instead of tcc would help SELinux. Can you run this:
env ME_DSL_TRACE=1 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=True, jit_backend="cc")'and tell me the output?
Something like
jit_backendwas actually what I was looking for in the documentation hoping that another choice would work better with SELinux. It seems to work fine:$ env ME_DSL_TRACE=1 uvx --with blosc2 python -c 'import blosc2; blosc2.linspace(0, 10, 10_000_000, jit=True, jit_backend="cc")' [me-dsl] jit codegen: runtime math bridge enabled (scalar=libm vec=on expr=off if=select) [me-dsl] jit codegen: lowering=scalar vec_ops=- reason=no-vector-lowering-match [me-dsl] jit ir built: fp=strict compiler=cc fingerprint=a8e270a4a2185868 [me-dsl] jit runtime hit: fp=strict source=disk-cache key=e87f69daef8dc186Is there a way to set the jit backend globally for e.g. a script?
I just ran the quickstart example with
git+https://github.com/Blosc/python-blosc2@mainwithout any problems so it's looking great, really nice work @FrancescAlted! I'll make sure to report if I run into any more issues related to SELinux when I explore further. Thanks!Reacted by Francesc Alted
Greetings!
I thought I would give this very interesting library a try this morning but couldn't get past the quickstart example:
The computer I'm using runs RHEL10 with SELinux enabled and from the error message I'm guessing tcc needs to be compiled with a special flag to work with that. Is there a way to make this package work with SELinux enabled?
Regards, Mattias