Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t

Đang mở Phù hợp với người mới
#2,538 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@andrewdunndev đang làm issue này rồi.

Từ ngày 5/10/2026.

  • #2543 của @andrewdunndev — đang mở

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
82/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu với crates/lib/src/install/osconfig.rs và phần tra cứu atomic_replace_labeled trong crates/lib/src/lsm.rs; so sánh bên gọi này với các bên gọi khác truyền đường dẫn tương đối với thư mục gốc đích. Kiểm tra cách mã cài đặt xác định nhãn cho /etc/tmpfiles.d/bootc-root-ssh.conf. Công việc hoàn tất khi drop-in đã cài đặt được phân giải thành etc_t thay vì etc_runtime_t.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:

# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf	system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0

The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.

I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:

ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
  -v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
  bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
  --root-ssh-authorized-keys /out/k.pub /out/a.raw

The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.

inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.

I'd expect the drop-in to be labeled for its full path, which gives etc_t.

Ngôn ngữ chính
Rust
Star
2.3k
Fork
230
Merge trung bình
2 ngày 20 giờ
Pull request đã merge (30 ngày)
48

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của bootc-dev/bootc

Tất cả issue của bootc-dev/bootc

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.