They are not good enough to do a full device, when we did d2 we still had to override a lot of them and write out own, just put androidboot.selinux=permissive and you bypass selinux for now until you can create policies, which BTW not everything shows in audit.log , you will have to grep kmsg...