SElinux is only permissive / Security / Mandatory Access Control
As stated here [1] the SElinux framework is shipped with SFOS. The blog post also says "with SELinux ... enabled". While taking a look at a Xperia 10 device with the latest SFOS I was surprised that SElinux is not enabled (enforcing). The current mode is "permissive" with a "minimum" policy loaded. The latter is due to the first implementation, though but the permissive mode downgrades this security feature to just log violations. Effectively it does not provide better security compared to older SFOS versions.
I would like to discuss the current security model of SFOS here.
Does any 3rd party has done an audit of SFOS already?