Add policy for /metadata/apex.

This is an area that apexd can use to store session metadata, which
won't be rolled back with filesystem checkpointing.

Bug: 126740531
Test: builds
Change-Id: I5abbc500dc1b92aa46830829be76e7a4381eef91
diff --git a/private/file_contexts b/private/file_contexts
index 33b4e18..9625acc 100644
--- a/private/file_contexts
+++ b/private/file_contexts
@@ -617,6 +617,7 @@
 # Metadata files
 #
 /metadata(/.*)?           u:object_r:metadata_file:s0
+/metadata/apex(/.*)?      u:object_r:apex_metadata_file:s0
 /metadata/vold(/.*)?      u:object_r:vold_metadata_file:s0
 /metadata/gsi(/.*)?       u:object_r:gsi_metadata_file:s0
 /metadata/password_slots(/.*)?    u:object_r:password_slot_metadata_file:s0