Repository navigation
install: Label root SSH drop-in by its full path - #2543
andrewdunndev wants to merge 1 commit into
Conversation
|
I think the problem here is the |
ffcb2a0 to
4f75f6d
Compare
|
Agreed, that's cleaner. The drop-in was the only caller passing a subdirectory, so it now passes the root like the others, |
atomic_replace_labeled looks up the label for its destination joined onto /, so it expects the directory it is given to be the root. The tmpfiles.d drop-in for --root-ssh-authorized-keys passed the /etc/tmpfiles.d directory instead, so the policy was asked about /bootc-root-ssh.conf. On Fedora and CentOS that is etc_runtime_t instead of etc_t, and restorecon wants to relabel the file. Write the drop-in relative to the root, as the other callers already do, and note the expectation on atomic_replace_labeled. Assisted-by: AI Closes: bootc-dev#2538 Signed-off-by: Andrew Dunn <andrew@dunn.dev>
Head branch was pushed to by a user without write access
4f75f6d to
9e82720
Compare
|
Rebased onto main after #2536, which gave |
The tmpfiles.d drop-in for
--root-ssh-authorized-keysis written relative to the/etc/tmpfiles.ddirectory fd, butatomic_replace_labeledlooks up the label for its destination joined onto/, so it expects to be handed the root. The policy is asked about/bootc-root-ssh.conf, which on Fedora and CentOS isetc_runtime_t, sorestoreconon the installed system wants to relabel the file toetc_t. The composefs injection in #2536 goes through the same call.This writes the drop-in as
etc/tmpfiles.d/bootc-root-ssh.confrelative to the root, as the fstab and shadow callers already do, and documents onatomic_replace_labeledthat it expects the root.test_inject_root_ssh_labelchecks the injected file's label against the host policy's label for/etc/tmpfiles.d/bootc-root-ssh.conf, and returns early where SELinux reads as disabled, which includes the containerizedjust unit-testsrun.Testing:
make validatepasses, andcargo test -p bootc-libreports 287 passed and 1 ignored. With SELinux enforcing, the new test fails when the call goes back to the tmpfiles.d directory (left: "system_u:object_r:etc_runtime_t:s0",right: "system_u:object_r:etc_t:s0"). In a test VM, installs with--root-ssh-authorized-keyson this version label the drop-inetc_t, andrestorecon -n -vfinds nothing to relabel. That holds on ostree, and with--composefs-backendwhen merged with #2536. Main on ostree, and #2536 alone, giveetc_runtime_t.There's no integration assertion: both install tests that pass
--root-ssh-authorized-keys, the alongside install in tests-integration and the check #2536 adds, run with SELinux disabled.Closes: #2538