Merge "Remove system_server and zygote unlabeled execute access."
diff --git a/lmkd.te b/lmkd.te
index 8643d91..a8b52c3 100644
--- a/lmkd.te
+++ b/lmkd.te
@@ -4,7 +4,7 @@
 
 init_daemon_domain(lmkd)
 
-allow lmkd self:capability { dac_override sys_resource };
+allow lmkd self:capability { dac_override sys_resource kill };
 
 ## Open and write to /proc/PID/oom_score_adj
 ## TODO: maybe scope this down?
diff --git a/uncrypt.te b/uncrypt.te
index f62fbbf..265a8b1 100644
--- a/uncrypt.te
+++ b/uncrypt.te
@@ -27,3 +27,4 @@
 # Raw writes to block device
 allow uncrypt self:capability sys_rawio;
 allow uncrypt block_device:blk_file w_file_perms;
+allow uncrypt block_device:dir r_dir_perms;