Repository navigation
composefs: Inject root SSH keys at install - #2536
Conversation
`bootc install --root-ssh-authorized-keys` writes a tmpfiles.d drop-in that provisions root's authorized_keys on first boot, but only the ostree install path called the helper. With the composefs backend the option was accepted and silently dropped: the install succeeded and root key login failed on the booted system. A composefs deployment keeps its /etc in state/deploy/<id>/etc, apart from the image that holds the /root symlink the helper resolves. Let the helper take the directory that receives etc/tmpfiles.d separately from the root it reads, and call it once the deployment's /etc exists. The /etc merge carries the drop-in across upgrades like any other locally added file. Assisted-by: AI Signed-off-by: Andrew Dunn <andrew@dunn.dev>
|
|
||
| if let Some(contents) = state.root_ssh_authorized_keys.as_deref() { | ||
| osconfig::inject_root_ssh_authorized_keys(&root, sepolicy, contents)?; | ||
| osconfig::inject_root_ssh_authorized_keys(&root, &root, sepolicy, contents)?; |
There was a problem hiding this comment.
For followup, I think this should be moved out into a common place that's "post image layout"
There was a problem hiding this comment.
Makes sense, I'll move it in a follow-up once this lands.
Only the ostree-only install tests in tests-integration covered --root-ssh-authorized-keys, so the composefs backend could drop it unnoticed. test-install-composefs-native already installs to disk with both backends; pass a key on every install there and check the deployment's bootc-root-ssh.conf content and mode. The drop-in is read with decode utf-8 because nushell 0.99.1, which Fedora 44 and EPEL 9 ship, drops the trailing newline when an open --raw stream is collected into a string. Without the previous commit the composefs installs fail this check. Assisted-by: AI Signed-off-by: Andrew Dunn <andrew@dunn.dev>
56cfee0 to
18b0253
Compare
|
The plan-60 failures were in the new drop-in check, and the Rust side is unchanged. Fedora 44 and EPEL 9 ship nushell 0.99.1, which drops the trailing newline when the |
|
Yeah this is not the first time we've been bit by a nushell behavioral change. I now mostly regret using it, filed #2547 which summarizes some thoughts. |
bootc install --root-ssh-authorized-keysis accepted with the composefs backend, but the keys never reach the installed system. Only the ostree path callsinject_root_ssh_authorized_keys(frominstall_container), andsetup_composefs_bootnever does, so the install succeeds and root key login fails after boot.A composefs deployment keeps its
/etcinstate/deploy/<id>/etc, apart from the image that holds the/rootsymlink the helper resolves. The helper now takes the directory that receivesetc/tmpfiles.dseparately from the root it reads, andsetup_composefs_bootcalls it oncewrite_composefs_statehas created the deployment's/etc. The ostree call passes the same directory for both, so its behaviour is unchanged.test-install-composefs-nativenow passes a key on every install and checks the drop-in's content and mode for whichever backend installed.Testing:
make validateandcargo test -p bootc-lib osconfigpass. In a VM, a Fedora 44 bootc image built from this branch and installed with--composefs-backend --root-ssh-authorized-keyswritesstate/deploy/<id>/etc/tmpfiles.d/bootc-root-ssh.conf, and root SSH login with the key works after boot with SELinux enforcing. The same install from main writes no drop-in and the login is refused.just test-tmt install-composefs-nativepasses with this change and, with thesetup_composefs_boothunk reverted, fails at the new drop-in check on the first composefs install.Fixes #2535