sepolicy: recovery: Allow data file write
Needed to preserve /data/.layout_version (aka nesting bug fix).
Change-Id: Iaae982223e80ad10479cf1ca3db09da7ada5663e
diff --git a/sepolicy/recovery.te b/sepolicy/recovery.te
index 4446bba..cf230f7 100644
--- a/sepolicy/recovery.te
+++ b/sepolicy/recovery.te
@@ -33,7 +33,7 @@
allow recovery file_type:notdevfile_class_set { unlink getattr };
# wipe saves and restores the layout version
allow recovery install_data_file:file create_file_perms;
-allow recovery system_data_file:file create;
+allow recovery system_data_file:file create_file_perms;
# /cache/recovery things: command and logs
allow recovery recovery_cache_file:dir create_dir_perms;