sepolicy: allow recovery to setenforce

Change-Id: Ie33b247180116e8bc40c29884bc6734d8b1a54b2
diff --git a/common/private/recovery.te b/common/private/recovery.te
index f7dbcd5..6e5e33a 100644
--- a/common/private/recovery.te
+++ b/common/private/recovery.te
@@ -47,4 +47,9 @@
 
 # Read fbe encryption info
 r_dir_file(recovery, unencrypted_data_file)
+
+# setenforce
+userdebug_or_eng(`
+permissive recovery;
+')
 ')