Merge "Explicitly call restorecon_recursive on /metadata/apex"

This commit is contained in:
Nikita Ioffe 2020-06-24 16:40:52 +00:00 committed by Gerrit Code Review
commit 5b2457ed34

View file

@ -520,6 +520,13 @@ on post-fs
mkdir /metadata/apex 0700 root system
mkdir /metadata/apex/sessions 0700 root system
# On some devices we see a weird behaviour in which /metadata/apex doesn't
# have a correct label. To workaround this bug, explicitly call restorecon
# on /metadata/apex. For most of the boot sequences /metadata/apex will
# already have a correct selinux label, meaning that this call will be a
# no-op.
restorecon_recursive /metadata/apex
on late-fs
# Ensure that tracefs has the correct permissions.
# This does not work correctly if it is called in post-fs.