> In AOSP master, external/sepolicy/Android.mk has:
>
> # Force permissive domains to be unconfined+enforcing?
> #
> # During development, this should be set to false.
> # Permissive means permissive.
> #
> # When we're close to a release and SELinux new policy development
> # is frozen, we should flip this to true. This forces any currently
> # permissive domains into unconfined+enforcing.
> #
> FORCE_PERMISSIVE_TO_UNCONFINED ?= false
>
> ifeq ($(TARGET_BUILD_VARIANT),user)
>   # User builds are always forced unconfined+enforcing
>   FORCE_PERMISSIVE_TO_UNCONFINED := true
> endif
>

> When they forked master for Lollipop, at some point they flipped it to
> force permissive to unconfined even in userdebug builds to ensure proper
> testing.  That was this commit on lollipop-dev/lollipop-release:
>

Thank you for explaining! This makes perfect sense now.
_______________________________________________
Seandroid-list mailing list
[email protected]
To unsubscribe, send email to [email protected].
To get help, send an email containing "help" to 
[email protected].

Reply via email to