Theettam Kernel — peridot 6.1.175. All 7 flavors green.
New in 2.6 — SELinux DirtySepolicy spoofs (SukiSU flavors)
selinux_hide now reports these VoltageOS device-policy edges as denied to detection apps (Duck Detector's DirtySepolicy canaries), while the live rules stay intact:
fsck_untrusted → self:capability sys_admin— hardened (context-based match; the 2.5 version used aSECCLASS_CAPABILITYconstant that could silently no-op)adbd → adbroot:binder call— new (the Lineage adb-root edge)
Together these clear the two "Allowed" DirtySepolicy edges → fully-green SELinux card on the SukiSU-Ultra and Premium SukiSU flavors, without turning off USB debugging. (KSUN/ReSukiSU/APatch don't ship SukiSU selinux_hide, so this doesn't apply to them.)
If you flashed 2.5 and
fsck_untrustedstill read allowed — that was theSECCLASSno-op. Flash a SukiSU-Ultra 2.6 build to get the working masks.
Flavors: KSUN3.3.0 · KSUN+SUSFS · KSUN+SUSFS+DroidSpaces · SukiSU-Ultra+SUSFS (masks) · Premium SukiSU+SUSFS+DroidSpaces (masks) · ReSukiSU+SUSFS · APatch/KPM.
Companion: VoltageOS users → ROM Prop Hide module. Remaining Custom-ROM warning (libstagefright/hal_lineage) needs a ROM rebuild.
Base: peridot 6.1.175 (ACK android14-6.1-lts + BORE + ADIOS).