File cleanoldsepoldir.service of Package selinux-policy
[Unit]
Description=Run SELinux Script on boot to check if it is safe to delete /var/lib/selinux after migration to /etc
After=local-fs.target
Conflicts=shutdown.target
# do not run if file exists
ConditionPathExists=!/etc/selinux/tmpselipoldir_deleted
[Service]
Type=oneshot
RemainAfterExit=no
User=root
ExecStart=/usr/libexec/selinux/cleanoldsepoldir.sh
TimeoutSec=300
StandardOutput=journal
StandardError=journal
KillMode=mixed
# Sandboxing directives
WorkingDirectory=/
ReadOnlyPaths=/
ReadWritePaths=/etc /var/lib/
[Install]
WantedBy=multi-user.target