!hzgkCxLtCOTmFXGauj:nixos.org

NixOS Gaming

582 Members
Gaming things, my hands are typing words.156 Servers

Load older messages


SenderMessageTime
19 Jun 2026
@magic_rb:matrix.redalder.orgmagic_rbOh so its checking the capability of the thread in the root ns, not the threads ns16:08:15
@magic_rb:matrix.redalder.orgmagic_rb(I mean thats an easy patch :P)16:08:21
@magic_rb:matrix.redalder.orgmagic_rb(Would also solve the gamescope RT issue)16:08:31
@k900:0upti.meK900 It won't no 16:08:40
@k900:0upti.meK900 That's a different issue 16:08:44
@magic_rb:matrix.redalder.orgmagic_rbIs it? If gamescope had valid cap_sys_nice when launched from steam as custom command, it could renice itself16:09:18
@elvishjerricco:matrix.orgElvishJerriccowould relaxing that actually be safe? Like, presumably that cap exists to guard a user against doing these things; being able to bypass it just by entering a userns sounds like probably not something to allow16:09:21
@magic_rb:matrix.redalder.orgmagic_rbI run into that on my desktop16:09:23
@k900:0upti.meK900
In reply to @magic_rb:matrix.redalder.org
Is it? If gamescope had valid cap_sys_nice when launched from steam as custom command, it could renice itself
The global check cannot be changed
16:09:43
@k900:0upti.meK900 The change needs to be local to amdgpu if anything 16:09:50
@k900:0upti.meK900 And then it won't get CAP_SYS_NICE 16:09:57
@marie:marie.cologneMarieso basically our options are apply the kernel patch or wait for valve to solve it because they have the same problem with steamrt3? :(16:09:59
@k900:0upti.meK900 It should really use rtkit for that 16:10:07
@magic_rb:matrix.redalder.orgmagic_rbI mean if i understand it correctly, you cant just give yourself cap_sys_nice even inti a userns16:10:14
@magic_rb:matrix.redalder.orgmagic_rbIt shouldn't be changed :P16:10:23
@k900:0upti.meK900 Like we have an existing mechanism for getting RT priority without capabilities 16:10:28
@magic_rb:matrix.redalder.orgmagic_rb * 16:10:35
@k900:0upti.meK900 On the CPU side 16:10:39
@k900:0upti.meK900And it's rtkit16:10:42
@magic_rb:matrix.redalder.orgmagic_rbAnd its called rtkit, yeah, should probably make a gamescope patch for that one instead16:10:53
@magic_rb:matrix.redalder.orgmagic_rb

https://github.com/ValveSoftware/gamescope/issues/494

Ill open a new issue. What shall i say? If running gamescope in a userns cap_sys_nice wont work, as such the only option is rtkit?

16:12:52
@elvishjerricco:matrix.orgElvishJerricco you can. if you do unshare -U --keep-caps (to be clear, the more useful way to get it is unshare -r but -U --keep-caps moreso tells you what I'm talking about) you'll find that you have CAP_SYS_NICE. So relaxing that capable() call into ns_capable() call would mean that anyone could do it by doing unshare -U --keep-caps 16:13:33
@elvishjerricco:matrix.orgElvishJerriccoso whenever you patch the kernel to do a relaxation like that, you have to find a way to scope things so that whatever can be done in the namespace doesn't escape what the namespace was originally restricted to at its creation16:14:57
@magic_rb:matrix.redalder.orgmagic_rb What is -U? 16:15:05
@elvishjerricco:matrix.orgElvishJerricco --user, make a user namespace 16:15:13
@magic_rb:matrix.redalder.orgmagic_rbAh16:15:16
@k900:0upti.meK900 Honestly I'd probably not submit this without a patch 16:15:19
@magic_rb:matrix.redalder.orgmagic_rbYeah im looking at a patch, reading how to do rtkit16:15:33
@magic_rb:matrix.redalder.orgmagic_rbDoesnt look that hard16:15:35
@magic_rb:matrix.redalder.orgmagic_rbIll write smth and open a draft PR to show i made an effort16:15:46

Show newer messages


Back to Room ListRoom Version: 10