From cd7249510d5ba80a56e77317402a4028d9f8f4a3 Mon Sep 17 00:00:00 2001 From: Salvo Giangreco Date: Mon, 19 Aug 2024 11:08:34 +0200 Subject: [PATCH] Fix SELinux prop spoofing Signed-off-by: Salvo Giangreco --- module/service.sh | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/module/service.sh b/module/service.sh index 5507926f..f94c9b71 100644 --- a/module/service.sh +++ b/module/service.sh @@ -23,9 +23,7 @@ resetprop_if_match vendor.boot.mode recovery unknown # Hiding SELinux | Permissive status resetprop_if_diff ro.boot.selinux enforcing -if [ -n "$(resetprop ro.build.selinux)" ]; then - resetprop --delete ro.build.selinux -fi +resetprop_if_diff ro.build.selinux 1 # Hiding SELinux | Use toybox to protect *stat* access time reading if [[ "$(toybox cat /sys/fs/selinux/enforce)" == "0" ]]; then