Ok, it's running better:
Code:
C:\>adb shell
Poke5P:/ # id
uid=0(root) gid=0(root) groups=0(root) context=u:r:su:s0
Poke5P:/ # getenforce
Enforcing
It took a bunch of compiling sepolicy and patching super.
I've got to get this down to a simpler procedure.
Edit: I deleted all that useless USB config stuff.
Now the device is always in ADB mode and nothing else.
I can lock it down to specific machines if I like without the chance to authorize.