Apparently, BusyBox's `cp` does NOT copy SELinux contexts when the `-a` argument is specified. This differs from GNU coreutils's `cp`, and explains why the files copied from the rootfs image to the persistent storage volume were not being labelled correctly. The `-c` argument is required. Now that files are labelled correctly when they are copied, the step to run `restorecon` is no longer necessary. |
||
---|---|---|
.. | ||
auditd.service.d | ||
sysinit.target.wants | ||
factory-reset.service | ||
init-storage.service | ||
ssh-keygen.target | ||
ssh-keygen@.service |