Description
Termpolis 1.49.4 AppImage does not start correctly on Fedora 44 when launched normally.
The application works correctly when the Chromium/Electron sandbox is completely disabled using --no-sandbox.
The issue appears to be related to Electron/Chromium sandbox initialization. Chromium reports a /dev/shm permissions problem, although /dev/shm permissions and write access have been verified and are correct.
Steps to Reproduce
- Download
Termpolis-1.49.4.AppImage.
- Make the AppImage executable.
- Start it normally:
LANG=C ./Termpolis-1.49.4.AppImage
- Termpolis starts its backend/MCP components, but the Electron/Chromium frontend fails to start correctly.
- Start it again with:
LANG=C ./Termpolis-1.49.4.AppImage --no-sandbox
- Termpolis starts and works correctly.
Expected Behavior
Termpolis should start and work normally on Fedora 44 without requiring the Chromium/Electron sandbox to be disabled.
Actual Behavior
Without --no-sandbox, Chromium/Electron reports:
ERROR:platform_shared_memory_region_posix.cc(214)]
Creating shared memory in /dev/shm/.org.chromium.Chromium.* failed: No such process (3)
ERROR:platform_shared_memory_region_posix.cc(217)]
Unable to access(W_OK|X_OK) /dev/shm: No such process (3)
FATAL:platform_shared_memory_region_posix.cc(219)]
This is frequently caused by incorrect permissions on /dev/shm.
Try 'sudo chmod 1777 /dev/shm' to fix.
However, /dev/shm is configured correctly:
$ ls -ld /dev/shm
drwxrwxrwt. 2 root root ... /dev/shm
$ findmnt /dev/shm
TARGET SOURCE FSTYPE OPTIONS
/dev/shm tmpfs tmpfs rw,nosuid,nodev,seclabel,inode64,usrquota
$ stat -c '%a %U %G %n' /dev/shm
1777 root root /dev/shm
$ touch /dev/shm/test-$USER && rm /dev/shm/test-$USER && echo OK
OK
SELinux does not appear to be blocking anything:
$ getenforce
Permissive
$ sudo ausearch -m AVC,USER_AVC -ts recent
<no matches>
User namespaces are also available:
$ sysctl user.max_user_namespaces
user.max_user_namespaces = 255555
$ unshare -Ur true
$ echo $?
0
Tested Chromium/Electron options:
Result: only a black window.
Result: does not resolve the problem.
Result: Termpolis starts and works correctly.
Currently, --no-sandbox is the only workaround I have found.
Environment
- OS: Fedora Linux 44, Wayland
- Termpolis version: 1.49.4
- Package: x86_64 AppImage
- Shell: Bash
- SELinux: Permissive
- Display server: Wayland
Screenshots
Not applicable. The relevant Chromium/Electron error output is included above.
Additional Context
The Termpolis backend appears to start successfully before the Chromium/Electron failure. For example:
[workflow] orchestrator IPC registered (0 trigger(s) armed)
[agents] claude: update MCP server
[agents] codex: update MCP server
[agents] gemini: update MCP server
Termpolis MCP server listening on http://127.0.0.1:9315
[termpolis][memory] store is OFF the main thread
[termpolis][memory] brain is OFF the main thread (mode=host)
Since the application works correctly with --no-sandbox, while /dev/shm, SELinux, and unprivileged user namespaces have been verified, this looks like an Electron/Chromium sandbox compatibility issue rather than an actual /dev/shm permissions problem.
I would be happy to provide additional logs or test a debug build/fix on Fedora 44.
Description
Termpolis 1.49.4 AppImage does not start correctly on Fedora 44 when launched normally.
The application works correctly when the Chromium/Electron sandbox is completely disabled using
--no-sandbox.The issue appears to be related to Electron/Chromium sandbox initialization. Chromium reports a
/dev/shmpermissions problem, although/dev/shmpermissions and write access have been verified and are correct.Steps to Reproduce
Termpolis-1.49.4.AppImage.Expected Behavior
Termpolis should start and work normally on Fedora 44 without requiring the Chromium/Electron sandbox to be disabled.
Actual Behavior
Without
--no-sandbox, Chromium/Electron reports:However,
/dev/shmis configured correctly:SELinux does not appear to be blocking anything:
User namespaces are also available:
Tested Chromium/Electron options:
Result: only a black window.
Result: does not resolve the problem.
Result: Termpolis starts and works correctly.
Currently,
--no-sandboxis the only workaround I have found.Environment
Screenshots
Not applicable. The relevant Chromium/Electron error output is included above.
Additional Context
The Termpolis backend appears to start successfully before the Chromium/Electron failure. For example:
Since the application works correctly with
--no-sandbox, while/dev/shm, SELinux, and unprivileged user namespaces have been verified, this looks like an Electron/Chromium sandbox compatibility issue rather than an actual/dev/shmpermissions problem.I would be happy to provide additional logs or test a debug build/fix on Fedora 44.