My backups in docker Gitlab 18.2.4-ee starting taking an extra hour or two recently, and I’m not sure why. My scripted backup begins at 4:05 AM and today ended after 8:30AM. Usually, they’re done before 7AM. The backup file size has been constant, around 80GB.
I am seeing the following messages in the host messages file, although my system is set to be permissive. And checking older logs, it seems like they’ve shown up before, so it might not be the reason for the current slowness.
I am concerned that some of the messages say “access on the file /(null)”. That sounds like a bad thing.
Assistance and advice appreciated.
S. Westmoreland.
Sep 8 04:12:06 local1 setroubleshoot[3247657]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from write access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l bd48bb3b-4f3f-48f8-bae2-a68d12771164
Sep 8 04:12:09 local1 setroubleshoot[3247657]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from add_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 48e49245-d84b-4748-8f3f-32cff6343d06
Sep 8 04:12:11 local1 setroubleshoot[3247657]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from create access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 28a84ac1-8fcb-4791-96bb-76c3b56e860d
Sep 8 04:12:14 local1 setroubleshoot[3247657]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from remove_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 69d05c29-ba26-4109-bc72-20df4f9796d3
Sep 8 04:22:09 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from write access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l bd48bb3b-4f3f-48f8-bae2-a68d12771164
Sep 8 04:22:12 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from remove_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 69d05c29-ba26-4109-bc72-20df4f9796d3
Sep 8 04:22:16 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from add_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 48e49245-d84b-4748-8f3f-32cff6343d06
Sep 8 04:22:19 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from create access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 28a84ac1-8fcb-4791-96bb-76c3b56e860d
Sep 8 04:22:23 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from rename access on the file /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l cc23c457-f527-41c8-8506-05f7cbaec00a
Sep 8 04:22:26 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from create access on the file /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l d5e809c1-0b50-4a2a-b371-41b7735488f6
Sep 8 04:22:29 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from 'read, write, open' accesses on the file /var/opt/gitlab/backups/repositories/manifests/default/@hashed/ab/79/ab79acbdd62e9f9bb4194491b855d057fef36952420149088cb158c3bcb96a62.git/1757318798_2025_09_08_18.2.4-ee.toml.186340fcbe235006.tmp. For complete SELinux messages run: sealert -l 53500ee3-59e7-4e37-9a23-d3432361c6cd
Sep 8 04:22:31 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from write access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l bd48bb3b-4f3f-48f8-bae2-a68d12771164
Sep 8 04:22:34 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from remove_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 69d05c29-ba26-4109-bc72-20df4f9796d3
Sep 8 04:22:37 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from add_name access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 48e49245-d84b-4748-8f3f-32cff6343d06
Sep 8 04:22:40 local1 setroubleshoot[3285995]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from create access on the directory /opt/gitlab/embedded/service/gitlab-rails/(null). For complete SELinux messages run: sealert -l 28a84ac1-8fcb-4791-96bb-76c3b56e860d
Sep 8 08:02:20 local1 setroubleshoot[3458785]: SELinux is preventing /usr/bin/find from read access on the directory d50d8ea32d67d5120a3ac346c952311f36c8375979ba7ac7a2c6fd0ca7388357.wiki.git. For complete SELinux messages run: sealert -l ee0d57a0-e519-4675-a0e0-f413d87aaf6b
Sep 8 08:02:23 local1 setroubleshoot[3458785]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from read access on the file 001.refs. For complete SELinux messages run: sealert -l 63893ca5-d516-4611-8cbe-bbca6f962310
Sep 8 08:02:26 local1 setroubleshoot[3458785]: SELinux is preventing /usr/bin/tar from open access on the file /var/opt/gitlab/backups/repositories/default/@hashed/d5/41/d54123de468bd42ea00dafbd777f85fe5fa1ff6404d9838c007953c25c92a1c5.git/1757318798_2025_09_08_18.2.4-ee/001.refs. For complete SELinux messages run: sealert -l 1545204e-7d9b-4787-bb3b-ec0fa960bd2c
Sep 8 08:32:13 local1 setroubleshoot[3532883]: SELinux is preventing /opt/gitlab/embedded/bin/gitaly-backup from rename access on the file /(null). For complete SELinux messages run: sealert -l cc23c457-f527-41c8-8506-05f7cbaec00a
Sep 8 08:32:16 local1 setroubleshoot[3532883]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from create access on the file /(null). For complete SELinux messages run: sealert -l d5e809c1-0b50-4a2a-b371-41b7735488f6
Sep 8 08:32:20 local1 setroubleshoot[3532883]: SELinux is preventing /usr/bin/tee from 'append, open' accesses on the file /var/opt/gitlab/backups/successful_backup. For complete SELinux messages run: sealert -l b0d6880b-3b20-479b-8480-e9617ba68795
Sep 8 08:32:26 local1 setroubleshoot[3532883]: SELinux is preventing /usr/bin/tar from write access on the file secrets_files.tar.gz. For complete SELinux messages run: sealert -l 91b6cf7e-8acf-41b2-a8cc-995879f18747
Sep 8 08:32:30 local1 setroubleshoot[3532883]: SELinux is preventing /usr/bin/tar from open access on the file /var/opt/gitlab/backups/secrets_files.tar.gz. For complete SELinux messages run: sealert -l 1545204e-7d9b-4787-bb3b-ec0fa960bd2c
Sep 8 08:32:33 local1 setroubleshoot[3532883]: SELinux is preventing /usr/bin/gzip from ioctl access on the file /var/opt/gitlab/backups/secrets_files.tar.gz. For complete SELinux messages run: sealert -l 710945f9-44d5-4418-8bf9-830ce37ddade
Sep 8 08:32:37 local1 setroubleshoot[3532883]: SELinux is preventing /opt/gitlab/embedded/bin/ruby from read access on the file toAl. For complete SELinux messages run: sealert -l 63893ca5-d516-4611-8cbe-bbca6f962310
# sestatus
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: permissive
Mode from config file: permissive
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
#