Overview
SELinux Permissive, authored by kernel engineer Denis Efremov (@evdenis), is a specialized systemless module designed for developers, ROM porters, and root tool authors. In Android’s standard enforcing mode, Security-Enhanced Linux (SELinux) blocks and audits any system action not explicitly declared in the device’s sepolicy rules.
While invaluable for production device security, enforcing mode frequently blocks new device bring-ups, custom vendor HAL debugging, or complex instrumentation tools. This module switches SELinux to permissive mode on boot—allowing audited calls to proceed rather than failing—while simultaneously masking this status from standard user-space applications to reduce detection flags.
[!WARNING] Permissive mode intentionally lowers the security boundaries of your device. Do not use this module on daily-driver devices containing sensitive banking credentials unless required for specific development or troubleshooting workflows.
Prerequisites & Compatibility
- Root Framework: Magisk (stable or canary).
- Kernel Support: The device kernel must allow runtime mode switching.
Documented Incompatibilities
- Samsung Stock Kernels: The module will not work on stock Samsung kernels compiled with
CONFIG_ALWAYS_ENFORCE=yin their kernel configuration. Samsung’s Knox security model prevents changing SELinux mode even when running with full root privileges. On these devices, a custom permissive-capable kernel must be flashed first.
Architecture & Masking Mechanism
Standard permissive toggles simply run setenforce 0. However, banking apps and anti-cheat engines routinely check two common indicators to detect permissive devices:
- They read the
/sys/fs/selinux/enforcefile directly. - They inspect the bootloader property
ro.boot.selinux.
SELinux Permissive applies a hardened two-pronged approach:
- Permission Restriction: In both
post-fs-data.shandservice.sh, it executeschmod 640 /sys/fs/selinux/enforceor reassigns DAC ownership so that unprivileged apps receive aPermission Deniederror when querying the node, rather than reading a0value. - Property Masking: Uses
resetpropto overwritero.boot.selinuxwithenforcing, neutralizing straightforward property inspection checks.
Installation & Verification
- Download the latest release from the repository or Magisk repository.
- Flash the module within Magisk and reboot.
- To verify current SELinux status from a root shell (
su):getenforce # Returns: Permissive - Verify non-root access is restricted by running as a standard shell user without
su:cat /sys/fs/selinux/enforce # Returns: Permission denied
Uninstallation
To remove the module and revert SELinux to default enforcing security:
- Uninstall the module via Magisk.
- The module’s
uninstall.shautomatically restores standard world-read permissions on/sys/fs/selinux/enforceand resets properties before the device reboots.
