Move restorecon of /data earlier in boot sequence.
A future early-boot daemon (on-device signing) needs to access /data/misc before fs-verity keys are locked. Therefore, move the restorecon of /data up a bit, to make sure the labels are correct. To be safe, only run it after init_user0, since that function is responsible for loading DE keys. Also move early boot keys and fs-verity key locking a bit later, since the on-device signing daemon needs to use both of these, but it also needs the restorecon to function correctly. Bug: 174740982 Test: manual Change-Id: I9b6e44d9b547d420e1c6ba01fb3d3accc0625e20
Loading
Please register or sign in to comment