Repository navigation
install: Label root SSH drop-in by its full path - #2543
Open
andrewdunndev wants to merge 1 commit into
Open
andrewdunndev wants to merge 1 commit into
andrewdunndev wants to merge 1 commit into
Conversation
Collaborator
|
I think the problem here is the |
atomic_replace_labeled looks up the label for its destination joined onto /, so it expects the directory it is given to be the root. The tmpfiles.d drop-in for --root-ssh-authorized-keys passed the /etc/tmpfiles.d directory instead, so the policy was asked about /bootc-root-ssh.conf. On Fedora and CentOS that is etc_runtime_t instead of etc_t, and restorecon wants to relabel the file. Write the drop-in relative to the root, as the other callers already do, and note the expectation on atomic_replace_labeled. Assisted-by: AI Closes: bootc-dev#2538 Signed-off-by: Andrew Dunn <andrew@dunn.dev>
andrewdunndev
force-pushed
the
fix/tmpfiles-dropin-label
branch
from
October 5, 2026 16:56
ffcb2a0 to
4f75f6d
Compare
Contributor
Author
|
Agreed, that's cleaner. The drop-in was the only caller passing a subdirectory, so it now passes the root like the others, |
cgwalters
approved these changes
Oct 5, 2026
jeckersb
enabled auto-merge (rebase)
October 6, 2026 17:58
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The tmpfiles.d drop-in for
--root-ssh-authorized-keysis written relative to the/etc/tmpfiles.ddirectory fd, butatomic_replace_labeledlooks up the label for its destination joined onto/, so it expects to be handed the root. The policy is asked about/bootc-root-ssh.conf, which on Fedora and CentOS isetc_runtime_t, sorestoreconon the installed system wants to relabel the file toetc_t. The composefs injection in #2536 goes through the same call.This writes the drop-in as
etc/tmpfiles.d/bootc-root-ssh.confrelative to the root, as the fstab and shadow callers already do, and documents onatomic_replace_labeledthat it expects the root.test_inject_root_ssh_labelchecks the injected file's label against the host policy's label for/etc/tmpfiles.d/bootc-root-ssh.conf, and returns early where SELinux reads as disabled, which includes the containerizedjust unit-testsrun.Testing:
make validatepasses, andcargo test -p bootc-libreports 287 passed and 1 ignored. With SELinux enforcing, the new test fails when the call goes back to the tmpfiles.d directory (left: "system_u:object_r:etc_runtime_t:s0",right: "system_u:object_r:etc_t:s0"). In a test VM, installs with--root-ssh-authorized-keyson this version label the drop-inetc_t, andrestorecon -n -vfinds nothing to relabel. That holds on ostree, and with--composefs-backendwhen merged with #2536. Main on ostree, and #2536 alone, giveetc_runtime_t.There's no integration assertion: both install tests that pass
--root-ssh-authorized-keys, the alongside install in tests-integration and the check #2536 adds, run with SELinux disabled.Closes: #2538