Merge "Remove system_server and zygote unlabeled execute access."
diff --git a/lmkd.te b/lmkd.te
index 8643d91..a8b52c3 100644
--- a/lmkd.te
+++ b/lmkd.te
@@ -4,7 +4,7 @@
init_daemon_domain(lmkd)
-allow lmkd self:capability { dac_override sys_resource };
+allow lmkd self:capability { dac_override sys_resource kill };
## Open and write to /proc/PID/oom_score_adj
## TODO: maybe scope this down?
diff --git a/uncrypt.te b/uncrypt.te
index f62fbbf..265a8b1 100644
--- a/uncrypt.te
+++ b/uncrypt.te
@@ -27,3 +27,4 @@
# Raw writes to block device
allow uncrypt self:capability sys_rawio;
allow uncrypt block_device:blk_file w_file_perms;
+allow uncrypt block_device:dir r_dir_perms;