Skip to content

install: Label root SSH drop-in by its full path - #2543

Open
andrewdunndev wants to merge 1 commit into
bootc-dev:mainfrom
andrewdunndev:fix/tmpfiles-dropin-label
Open

andrewdunndev wants to merge 1 commit into
bootc-dev:mainfrom
andrewdunndev:fix/tmpfiles-dropin-label

Conversation

@andrewdunndev

@andrewdunndev andrewdunndev commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The tmpfiles.d drop-in for --root-ssh-authorized-keys is written relative to the /etc/tmpfiles.d directory fd, but atomic_replace_labeled looks up the label for its destination joined onto /, so it expects to be handed the root. The policy is asked about /bootc-root-ssh.conf, which on Fedora and CentOS is etc_runtime_t, so restorecon on the installed system wants to relabel the file to etc_t. The composefs injection in #2536 goes through the same call.

This writes the drop-in as etc/tmpfiles.d/bootc-root-ssh.conf relative to the root, as the fstab and shadow callers already do, and documents on atomic_replace_labeled that it expects the root. test_inject_root_ssh_label checks the injected file's label against the host policy's label for /etc/tmpfiles.d/bootc-root-ssh.conf, and returns early where SELinux reads as disabled, which includes the containerized just unit-tests run.

Testing: make validate passes, and cargo test -p bootc-lib reports 287 passed and 1 ignored. With SELinux enforcing, the new test fails when the call goes back to the tmpfiles.d directory (left: "system_u:object_r:etc_runtime_t:s0", right: "system_u:object_r:etc_t:s0"). In a test VM, installs with --root-ssh-authorized-keys on this version label the drop-in etc_t, and restorecon -n -v finds nothing to relabel. That holds on ostree, and with --composefs-backend when merged with #2536. Main on ostree, and #2536 alone, give etc_runtime_t.

There's no integration assertion: both install tests that pass --root-ssh-authorized-keys, the alongside install in tests-integration and the check #2536 adds, run with SELinux disabled.

Closes: #2538

@github-actions github-actions Bot added the area/install Issues related to `bootc install` label Oct 5, 2026
@bootc-bot
bootc-bot Bot requested a review from jeckersb October 5, 2026 10:37
@cgwalters

Copy link
Copy Markdown
Collaborator

I think the problem here is the atomic_replace_labeled was expecting the passed Dir to be a root - and arguably that's a cleaner fix, change everything using that to pass the root?

atomic_replace_labeled looks up the label for its destination joined
onto /, so it expects the directory it is given to be the root. The
tmpfiles.d drop-in for --root-ssh-authorized-keys passed the
/etc/tmpfiles.d directory instead, so the policy was asked about
/bootc-root-ssh.conf. On Fedora and CentOS that is etc_runtime_t
instead of etc_t, and restorecon wants to relabel the file.

Write the drop-in relative to the root, as the other callers already
do, and note the expectation on atomic_replace_labeled.

Assisted-by: AI
Closes: bootc-dev#2538
Signed-off-by: Andrew Dunn <andrew@dunn.dev>
@andrewdunndev
andrewdunndev force-pushed the fix/tmpfiles-dropin-label branch from ffcb2a0 to 4f75f6d Compare October 5, 2026 16:56
@andrewdunndev

Copy link
Copy Markdown
Contributor Author

Agreed, that's cleaner. The drop-in was the only caller passing a subdirectory, so it now passes the root like the others, as_path is gone, and the doc comment on atomic_replace_labeled now says it expects the root. That puts this in conflict with #2536 in osconfig.rs, so once either merges I'll rebase the other.

@jeckersb
jeckersb enabled auto-merge (rebase) October 6, 2026 17:58

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/install Issues related to `bootc install`

Projects

None yet

Development

Successfully merging this pull request may close these issues.

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t

2 participants