So this works now, but unfortunately not only the relabel operation breaks, but also some operations after this. I'll try to figure out a way to now have to load the policy in initrd, this will be a permanent pain with this change. If I don't find a way we might have to keep kernel_t unconfined