Skip to content

install: Label root SSH drop-in by its full path - #2543

Open
andrewdunndev wants to merge 1 commit into
bootc-dev:mainfrom
andrewdunndev:fix/tmpfiles-dropin-label
Open

andrewdunndev wants to merge 1 commit into
bootc-dev:mainfrom
andrewdunndev:fix/tmpfiles-dropin-label

Conversation

@andrewdunndev

@andrewdunndev andrewdunndev commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The tmpfiles.d drop-in for --root-ssh-authorized-keys is written relative to the /etc/tmpfiles.d directory fd, but atomic_replace_labeled looks up the label for its destination joined onto /, so it expects to be handed the root. The policy is asked about /bootc-root-ssh.conf, which on Fedora and CentOS is etc_runtime_t, so restorecon on the installed system wants to relabel the file to etc_t. The composefs injection in #2536 goes through the same call.

This writes the drop-in as etc/tmpfiles.d/bootc-root-ssh.conf relative to the root, as the fstab and shadow callers already do, and documents on atomic_replace_labeled that it expects the root. test_inject_root_ssh_label checks the injected file's label against the host policy's label for /etc/tmpfiles.d/bootc-root-ssh.conf, and returns early where SELinux reads as disabled, which includes the containerized just unit-tests run.

Testing: make validate passes, and cargo test -p bootc-lib reports 287 passed and 1 ignored. With SELinux enforcing, the new test fails when the call goes back to the tmpfiles.d directory (left: "system_u:object_r:etc_runtime_t:s0", right: "system_u:object_r:etc_t:s0"). In a test VM, installs with --root-ssh-authorized-keys on this version label the drop-in etc_t, and restorecon -n -v finds nothing to relabel. That holds on ostree, and with --composefs-backend when merged with #2536. Main on ostree, and #2536 alone, give etc_runtime_t.

There's no integration assertion: both install tests that pass --root-ssh-authorized-keys, the alongside install in tests-integration and the check #2536 adds, run with SELinux disabled.

Closes: #2538

@github-actions github-actions Bot added the area/install Issues related to `bootc install` label Oct 5, 2026
@bootc-bot
bootc-bot Bot requested a review from jeckersb October 5, 2026 10:37
@cgwalters

Copy link
Copy Markdown
Collaborator

I think the problem here is the atomic_replace_labeled was expecting the passed Dir to be a root - and arguably that's a cleaner fix, change everything using that to pass the root?

@andrewdunndev
andrewdunndev force-pushed the fix/tmpfiles-dropin-label branch from ffcb2a0 to 4f75f6d Compare October 5, 2026 16:56
@andrewdunndev

Copy link
Copy Markdown
Contributor Author

Agreed, that's cleaner. The drop-in was the only caller passing a subdirectory, so it now passes the root like the others, as_path is gone, and the doc comment on atomic_replace_labeled now says it expects the root. That puts this in conflict with #2536 in osconfig.rs, so once either merges I'll rebase the other.

cgwalters
cgwalters previously approved these changes Oct 5, 2026
@jeckersb
jeckersb enabled auto-merge (rebase) October 6, 2026 17:58
atomic_replace_labeled looks up the label for its destination joined
onto /, so it expects the directory it is given to be the root. The
tmpfiles.d drop-in for --root-ssh-authorized-keys passed the
/etc/tmpfiles.d directory instead, so the policy was asked about
/bootc-root-ssh.conf. On Fedora and CentOS that is etc_runtime_t
instead of etc_t, and restorecon wants to relabel the file.

Write the drop-in relative to the root, as the other callers already
do, and note the expectation on atomic_replace_labeled.

Assisted-by: AI
Closes: bootc-dev#2538
Signed-off-by: Andrew Dunn <andrew@dunn.dev>
auto-merge was automatically disabled October 9, 2026 03:02

Head branch was pushed to by a user without write access

@andrewdunndev
andrewdunndev force-pushed the fix/tmpfiles-dropin-label branch from 4f75f6d to 9e82720 Compare October 9, 2026 03:02
@andrewdunndev

Copy link
Copy Markdown
Contributor Author

Rebased onto main after #2536, which gave inject_root_ssh_authorized_keys a separate dest directory for the drop-in. The full-path write now goes against dest, the directory the ensure_dir_labeled call above it already treats as the root, and the new label test passes root as both directories. The ostree path passes the deployment root for both, so it's unchanged from the approved version, and the composefs path now gets the full-path lookup as well.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/install Issues related to `bootc install`

Projects

None yet

Development

Successfully merging this pull request may close these issues.

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t

2 participants