SELinux Permissiver is a minimal debugging module that runs setenforce 0 during boot to request global SELinux permissive mode.
A Diagnostic Switch, Not a Policy Fix
Use it temporarily to confirm whether SELinux denials cause a problem, then replace it with narrowly scoped policy rules.
Single Command
Its service script executes setenforce 0; it does not ship an SELinux policy database or per-domain allow rules.
Diagnostic Use
Permissive mode records denials without blocking them, which can help isolate a policy-related failure during development.
Reversible Module
Disabling or removing it and rebooting allows the firmware's normal enforcing behavior to return, when the kernel supports it.
Behavior and Verification
The module targets Android 5.1 and newer and relies entirely on the kernel and root environment accepting a runtime enforcement change. After boot, run getenforce from a root shell. A result of Permissive confirms the request; Enforcing means the kernel, firmware, or another service rejected or reverted it.
Because the repository contains only the module metadata and scripts, no broader device-compatibility matrix is documented. Treat support labels as packaging compatibility, not proof that every production kernel permits the state change.
Significant Security Trade-Off
Permissive mode disables SELinux enforcement across the entire operating system. Processes remain logged when they violate policy, but the policy no longer blocks those actions. This widens the impact of a compromised application or service and can also cause integrity-sensitive software to reject the device.
Do not use this module as a permanent workaround. Capture the relevant AVC denials, create the smallest correct policy rule, restore enforcing mode, and confirm that the original issue remains resolved.