evdenis

selinux_permissive

v3.1guide

Magisk Module that switches SELinux to permissive mode

★273 stars
•Development & Instrumentation•by evdenis•GPL-2.0•Updated Mar 7, 2026
Platforms:
✓ Magisk

Overview

SELinux Permissive, authored by kernel engineer Denis Efremov (@evdenis), is a specialized systemless module designed for developers, ROM porters, and root tool authors. In Android’s standard enforcing mode, Security-Enhanced Linux (SELinux) blocks and audits any system action not explicitly declared in the device’s sepolicy rules.

While invaluable for production device security, enforcing mode frequently blocks new device bring-ups, custom vendor HAL debugging, or complex instrumentation tools. This module switches SELinux to permissive mode on boot—allowing audited calls to proceed rather than failing—while simultaneously masking this status from standard user-space applications to reduce detection flags.

[!WARNING] Permissive mode intentionally lowers the security boundaries of your device. Do not use this module on daily-driver devices containing sensitive banking credentials unless required for specific development or troubleshooting workflows.

Prerequisites & Compatibility

  • Root Framework: Magisk (stable or canary).
  • Kernel Support: The device kernel must allow runtime mode switching.

Documented Incompatibilities

  • Samsung Stock Kernels: The module will not work on stock Samsung kernels compiled with CONFIG_ALWAYS_ENFORCE=y in their kernel configuration. Samsung’s Knox security model prevents changing SELinux mode even when running with full root privileges. On these devices, a custom permissive-capable kernel must be flashed first.

Architecture & Masking Mechanism

Standard permissive toggles simply run setenforce 0. However, banking apps and anti-cheat engines routinely check two common indicators to detect permissive devices:

  1. They read the /sys/fs/selinux/enforce file directly.
  2. They inspect the bootloader property ro.boot.selinux.

SELinux Permissive applies a hardened two-pronged approach:

  1. Permission Restriction: In both post-fs-data.sh and service.sh, it executes chmod 640 /sys/fs/selinux/enforce or reassigns DAC ownership so that unprivileged apps receive a Permission Denied error when querying the node, rather than reading a 0 value.
  2. Property Masking: Uses resetprop to overwrite ro.boot.selinux with enforcing, neutralizing straightforward property inspection checks.

Installation & Verification

  1. Download the latest release from the repository or Magisk repository.
  2. Flash the module within Magisk and reboot.
  3. To verify current SELinux status from a root shell (su):
    getenforce
    # Returns: Permissive
  4. Verify non-root access is restricted by running as a standard shell user without su:
    cat /sys/fs/selinux/enforce
    # Returns: Permission denied

Uninstallation

To remove the module and revert SELinux to default enforcing security:

  1. Uninstall the module via Magisk.
  2. The module’s uninstall.sh automatically restores standard world-read permissions on /sys/fs/selinux/enforce and resets properties before the device reboots.