diff --git a/public/init.te b/public/init.te
index b36a00201b26b74e074cd4ce75d230670d0c0d35..f81f85e3c80ada405232bb15cf11a6798f4905ce 100644
--- a/public/init.te
+++ b/public/init.te
@@ -85,6 +85,7 @@ allow init cpuctl_device:dir { create mounton };
 # /config
 allow init configfs:dir mounton;
 allow init configfs:dir create_dir_perms;
+allow init configfs:{ file lnk_file } create_file_perms;
 
 # Use tmpfs as /data, used for booting when /data is encrypted
 allow init tmpfs:dir relabelfrom;