install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 82/100
Hướng nghiên cứu
Bắt đầu với crates/lib/src/install/osconfig.rs và phần tra cứu atomic_replace_labeled trong crates/lib/src/lsm.rs; so sánh bên gọi này với các bên gọi khác truyền đường dẫn tương đối với thư mục gốc đích. Kiểm tra cách mã cài đặt xác định nhãn cho /etc/tmpfiles.d/bootc-root-ssh.conf. Công việc hoàn tất khi drop-in đã cài đặt được phân giải thành etc_t thay vì etc_runtime_t.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:
# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0
The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.
I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:
ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
-v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
--root-ssh-authorized-keys /out/k.pub /out/a.raw
The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.
inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.
I'd expect the drop-in to be labeled for its full path, which gives etc_t.
- Ngôn ngữ chính
- Rust
- Star
- 2.3k
- Fork
- 230
- Merge trung bình
- 2 ngày 20 giờ
- Pull request đã merge (30 ngày)
- 48
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của bootc-dev/bootc
-
auto-updates fail with `opendir(boot): Operation not permitted` when /boot is a systemd automount that has idled outCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởtriaged
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
bootc-dev/bootc#2402 · 9 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
install: improve error message when systemd-boot is selected without composefs backendCó thể đã có người làm @ASVLCII đã nhận 25 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
tests: Port away from nushellĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
bootc-dev/bootc#2547 · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
install: --stateroot is silently ignored with --composefs-backendCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của bootc-dev/bootc
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 5 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
tauri-apps/tauri#16219 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
state:triage-needed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
ktuner keeps a stale ledger path and can never restore that entryCó thể đã có người làm @Frun1na đã nhận hôm nay. Đang mởcomponent:ktuner
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
agentic-os-org/ANOLISA#6483 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày