install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t
メンテナーはふだん 1 日以内に返信
評価
調査の方向性
まず crates/lib/src/install/osconfig.rs と crates/lib/src/lsm.rs 内の atomic_replace_labeled の検索箇所を確認し、この呼び出し元を、ターゲットルートからの相対パスを渡す他の呼び出し元と比較します。インストールコードが /etc/tmpfiles.d/bootc-root-ssh.conf のラベルをどのように決定するかを確認します。インストールされたドロップインが etc_runtime_t ではなく etc_t として解決されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:
# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0
The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.
I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:
ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
-v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
--root-ssh-authorized-keys /out/k.pub /out/a.raw
The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.
inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.
I'd expect the drop-in to be labeled for its full path, which gives etc_t.
- 主要言語
- Rust
- スター
- 2.3k
- フォーク
- 230
- 平均マージ
- 2日 19時間
- マージ済み PR(30日)
- 56
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
bootc-dev/bootc のほかの issue
-
auto-updates fail with `opendir(boot): Operation not permitted` when /boot is a systemd automount that has idled out対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンtriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
bootc-dev/bootc#2402 · コメント 9 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信
-
install: improve error message when systemd-boot is selected without composefs backend対応中かも @ASVLCII が 27 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
メンテナーはふだん 1 日以内に返信
-
composefs: bootc status/upgrade/switch use the first ESP on the disk instead of the one the system booted from (dual-boot with Windows)対応中かも @Johan-Liebert1 が 1 日前に担当しました。 オープンtriaged
bootc-dev/bootc#2554 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
bootc-dev/bootc の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
antithesishq/bombadil#361 ·
メンテナーはふだん 1 日以内に返信
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeオープンtype:debt
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
skaiy/wild_agentos#425 ·
メンテナーはふだん 1 日以内に返信
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信
-
status:needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信