--- /dev/null
+type hal_tee_default, domain;
+type hal_tee_default_exec, exec_type, vendor_file_type, file_type;
+
+init_daemon_domain(hal_tee_default)
+
+hal_client_domain(hal_tee_default, hal_allocator)
+hal_server_domain(hal_tee_default, hal_tee)
+
+binder_call(hal_tee_client, hal_tee_server)
+binder_call(hal_tee_server, hal_tee_client)
+
+add_hwservice(hal_tee_server, hal_tee_hwservice)
+allow hal_tee_client hal_tee_hwservice:hwservice_manager find;
+
+allow hal_tee_default hidl_memory_hwservice:hwservice_manager find;
+
+allow hal_tee_default tee_device:chr_file rw_file_perms;