Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t

Aperta Adatta ai principianti
#2,538 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@andrewdunndev ci sta già lavorando.

Dal 5/10/2026.

  • #2543 di @andrewdunndev — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
82/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
security

Direzione di ricerca

Inizia da crates/lib/src/install/osconfig.rs e dalla ricerca di atomic_replace_labeled in crates/lib/src/lsm.rs; confronta questo chiamante con gli altri chiamanti che passano percorsi relativi alla radice di destinazione. Verifica come il codice di installazione determina l’etichetta di /etc/tmpfiles.d/bootc-root-ssh.conf. Il lavoro è completo quando il drop-in installato viene risolto come etc_t anziché etc_runtime_t.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:

# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf	system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0

The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.

I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:

ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
  -v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
  bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
  --root-ssh-authorized-keys /out/k.pub /out/a.raw

The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.

inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.

I'd expect the drop-in to be labeled for its full path, which gives etc_t.

Lingua principale
Rust
Stelle
2.3k
Fork
230
Merge medio
2g 21h
PR unite (30g)
45

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di bootc-dev/bootc

Tutte le issue di bootc-dev/bootc

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.