Honor semanage fcontext equivalences when labeling GitLab paths (EL10)

What does this MR do and why?

On AlmaLinux/RHEL/CentOS Stream 10, gitlab-ctl reconfigure aborts in gitlab::selinux:

bash[Set proper security context on ssh files for selinux] (gitlab::selinux line 88) had an error
STDERR: ValueError: File spec /var/opt/gitlab/.ssh(/.*)? conflicts with equivalency rule
'/var/opt /opt'; Try adding '/opt/gitlab/.ssh(/.*)?' instead

EL10's selinux-policy ships a /var/opt = /opt file-context equivalency in file_contexts.subs_dist. semanage refuses to register an fcontext spec that falls under an equivalency source, so SELinuxHelper.commands fails on the first semanage fcontext -a -t gitlab_shell_t '/var/opt/gitlab/.ssh(/.*)?'. context_set? also looked for the literal /var/opt/gitlab/... patterns, which can never be registered on EL10 — so the step could neither succeed nor be detected as already done, and ran (and failed) on every reconfigure.

This MR makes SELinuxHelper honor semanage equivalencies:

  • Parse the equivalence pairs from semanage fcontext -l.
  • When a GitLab path falls under an equivalency source, register and check the substituted (target) path (e.g. /opt/gitlab/.ssh(/.*)?) — exactly what semanage's own error message suggests.
  • restorecon still runs against the real on-disk path; the equivalency makes the label apply there.

On distros without the equivalency (EL8/EL9), the parsed list never matches the GitLab paths, so the generated commands are unchanged.

Closes #9940 (closed).

Reproduction

# EL10 ships this by default:
semanage fcontext -l | grep '/var/opt = /opt'

# which makes the reconfigure command fail:
semanage fcontext -a -t gitlab_shell_t '/var/opt/gitlab/.ssh(/.*)?'
# ValueError: ... conflicts with equivalency rule '/var/opt /opt'; Try adding '/opt/gitlab/.ssh(/.*)?' instead

Testing

bundle exec rspec spec/chef/cookbooks/package/libraries/helpers/selinux_helper_spec.rb — 24 examples, 0 failures (new cases cover the EL10 equivalence in commands and context_set?, plus the parse_equivalences/equivalent_spec helpers). spec/chef/cookbooks/gitlab/recipes/selinux_spec.rb still green; rubocop clean.

Checklist

  • Tests added for new functionality
  • Existing tests still pass
  • Documentation (no user-facing config change)

Merge request reports

Loading
Loading