mobicore: Add sepolicy for trustonic HALs
[GitHub/LineageOS/android_device_samsung_slsi_sepolicy.git] / tee / mobicore / common / hal_tee_default.te
diff --git a/tee/mobicore/common/hal_tee_default.te b/tee/mobicore/common/hal_tee_default.te
new file mode 100644 (file)
index 0000000..11c19f3
--- /dev/null
@@ -0,0 +1,17 @@
+type hal_tee_default, domain;
+type hal_tee_default_exec, exec_type, vendor_file_type, file_type;
+
+init_daemon_domain(hal_tee_default)
+
+hal_client_domain(hal_tee_default, hal_allocator)
+hal_server_domain(hal_tee_default, hal_tee)
+
+binder_call(hal_tee_client, hal_tee_server)
+binder_call(hal_tee_server, hal_tee_client)
+
+add_hwservice(hal_tee_server, hal_tee_hwservice)
+allow hal_tee_client hal_tee_hwservice:hwservice_manager find;
+
+allow hal_tee_default hidl_memory_hwservice:hwservice_manager find;
+
+allow hal_tee_default tee_device:chr_file rw_file_perms;