When we looked at this together, we figured out that it is because selinux-policy-targeted was not installed yet, thus restorecond failed. Simple patch attached. I would just build it, but acls got in the way...
Created attachment 161071 [details] patch
Ah, you already fixed this, thanks.