bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:
# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0
The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.
I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:
ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
-v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
--root-ssh-authorized-keys /out/k.pub /out/a.raw
The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.
inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.
I'd expect the drop-in to be labeled for its full path, which gives etc_t.
bootc install --root-ssh-authorized-keyswrites/etc/tmpfiles.d/bootc-root-ssh.conflabeledetc_runtime_t, while the policy expectsetc_tfor that path. On the installed system, with SELinux enforcing:The file already has
etc_runtime_ton the disk before first boot, and its parent directory isetc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.I saw this with
$IMGbuilt byjust buildfrom main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:The code involved is the same in v1.16.13, which
quay.io/fedora/fedora-bootc:44ships.inject_root_ssh_authorized_keysopensetc/tmpfiles.dand passes the bare file name toatomic_replace_labeled(osconfig.rs L39-L47), which looks up the label for that name joined onto/(lsm.rs L664-L668). The policy is asked about/bootc-root-ssh.conf, which its/[^/]+rule maps toetc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.I'd expect the drop-in to be labeled for its full path, which gives
etc_t.