Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t

オープン 初心者向け
#2,538 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@andrewdunndev がすでに取り組んでいます。

2026年10月5日 から。

  • #2543 @andrewdunndev による — オープン

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
82/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
rust
領域
security

調査の方向性

まず crates/lib/src/install/osconfig.rs と crates/lib/src/lsm.rs 内の atomic_replace_labeled の検索箇所を確認し、この呼び出し元を、ターゲットルートからの相対パスを渡す他の呼び出し元と比較します。インストールコードが /etc/tmpfiles.d/bootc-root-ssh.conf のラベルをどのように決定するかを確認します。インストールされたドロップインが etc_runtime_t ではなく etc_t として解決されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:

# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf	system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0

The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.

I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:

ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
  -v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
  bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
  --root-ssh-authorized-keys /out/k.pub /out/a.raw

The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.

inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.

I'd expect the drop-in to be labeled for its full path, which gives etc_t.

主要言語
Rust
スター
2.3k
フォーク
230
平均マージ
2日 19時間
マージ済み PR(30日)
56

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

bootc-dev/bootc のほかの issue

bootc-dev/bootc の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。