Skip to content

install: root SSH tmpfiles.d drop-in is labeled etc_runtime_t instead of etc_t #2538

Description

@andrewdunndev

bootc install --root-ssh-authorized-keys writes /etc/tmpfiles.d/bootc-root-ssh.conf labeled etc_runtime_t, while the policy expects etc_t for that path. On the installed system, with SELinux enforcing:

# matchpathcon /etc/tmpfiles.d/bootc-root-ssh.conf
/etc/tmpfiles.d/bootc-root-ssh.conf	system_u:object_r:etc_t:s0
# restorecon -n -v -R /etc/tmpfiles.d
Would relabel /etc/tmpfiles.d/bootc-root-ssh.conf from system_u:object_r:etc_runtime_t:s0 to system_u:object_r:etc_t:s0

The file already has etc_runtime_t on the disk before first boot, and its parent directory is etc_t. It happens with the ostree backend, and with the composefs backend once #2536 writes the drop-in there. systemd-tmpfiles still reads the file and root key login works, so the visible effect is the relabel.

I saw this with $IMG built by just build from main at 66d4e4d (the centos-bootc stream10 base), installing like this and then booting the disk:

ssh-keygen -t ed25519 -N '' -f k
truncate -s 20G a.raw
podman run --rm --privileged --pid=host --security-opt label=type:unconfined_t \
  -v /dev:/dev -v /var/lib/containers:/var/lib/containers -v $PWD:/out $IMG \
  bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe \
  --root-ssh-authorized-keys /out/k.pub /out/a.raw

The code involved is the same in v1.16.13, which quay.io/fedora/fedora-bootc:44 ships.

inject_root_ssh_authorized_keys opens etc/tmpfiles.d and passes the bare file name to atomic_replace_labeled (osconfig.rs L39-L47), which looks up the label for that name joined onto / (lsm.rs L664-L668). The policy is asked about /bootc-root-ssh.conf, which its /[^/]+ rule maps to etc_runtime_t. The other callers pass a path relative to the target root, so their lookups are right.

I'd expect the drop-in to be labeled for its full path, which gives etc_t.

Activity

  1. added 2 commits that reference this issue on Oct 5, 2026
    4f75f6d
    9e82720
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions