Real-Time SELinux Compiler

magiskpolicy CLI Reference Manual

Developer reference for magiskpolicy, the native Magisk utility that compiles, modifies, and injects live SELinux access vectors directly into the running Linux kernel, enabling root daemons to function in Enforcing mode without triggering audit denials.

Live SELinux Policy Patching Explained

Historically, rooting tools required setting SELinux to Permissive mode (disabling all security controls system-wide). magiskpolicy parses Android's compiled binary policy (/sys/fs/selinux/load) in kernel memory, adds targeted allow rules specifically for Magisk and module domains, and reloads the policy dynamically while keeping the system in secure Enforcing mode.

Command Modes & CLI Syntax

magiskpolicy Usage Syntax
# 1. Live In-Memory Injection (Directly affects running kernel): $magiskpolicy --live "<rules>" # 2. Offline Binary Policy Patching (Compile infile -> outfile): $magiskpolicy --load sepolicy_in --save sepolicy_out "<rules>" # 3. Apply built-in Magisk default ruleset: $magiskpolicy --magisk "<additional_rules>"

SEPolicy Rule Syntax Reference

magiskpolicy supports the full standard SELinux statement syntax:

Statement Syntax Description Example
allow src tgt class perm Grants access permissions between domains allow magisk su_daemon process { fork signal }
permissive type Sets specific type/domain to permissive mode permissive custom_daemon_t
type type_name [attr] Declares a new SELinux type and optional attributes type my_service_t domain
attribute attr_name Declares a new SELinux attribute attribute my_domain_attr
typeattribute type attr Associates an existing type with an attribute typeattribute custom_t domain

Practical Example: Granting Daemon File Access

CLI Policy Injection Example
# Grant magisk domain permission to read/write custom socket: $magiskpolicy --live "allow magisk self unix_stream_socket { create bind listen }"

Remediating SELinux Audit Denials (avc: denied) with magiskpolicy

When developing custom root daemons, privileged background services, or complex Zygisk companion processes, the Linux kernel's SELinux subsystem will log audit denials whenever an undeclared access vector is attempted. Under default Android behavior in Enforcing mode, these denied operations cause process terminations or silent I/O failures.

Instead of disabling system security by running setenforce 0 (which triggers immediate detection by banking frameworks and SafetyNet/Play Integrity), developers can inspect the kernel log via dmesg | grep "avc: denied" and inject precise, minimal allow rules on the fly:

Live Dynamic SELinux Patching Example
# Extract denial from dmesg and convert to live rule: # Example denial: avc: denied { read } for scontext=u:r:magisk:s0 tcontext=u:object_r:userdata_block_device:s0 class=blk_file $magiskpolicy --live "allow magisk userdata_block_device blk_file { read open ioctl }"

The Rule Compiler Pipeline

magiskpolicy embeds an optimized C++ compiler that parses standard policy statement grammar directly into binary kernel policy structures. When --live is specified, the tool writes the patched binary policy directly to /sys/fs/selinux/load. The kernel atomically reloads its security context lookup tables without interrupting currently running threads or processes.

Source & Verification Standard

Verified with Android 16 QPR2 binary SEPolicy compatibility on Magisk v30.7 (February 23, 2026).