--- /dev/null
+attribute hal_tee_client;
+attribute hal_tee_server;
+attribute hal_tee;
+attribute hal_teeregistry_client;
+attribute hal_teeregistry_server;
+attribute hal_teeregistry;
/dev/t-base-tui u:object_r:tee_device:s0
/(vendor|system/vendor)/app/mcRegistry(/.*)? u:object_r:mobicore_vendor_file:s0
+
+/(vendor|system/vendor)/bin/hw/vendor\.trustonic\.tee@[0-9]\.[0-9]-service u:object_r:hal_tee_default_exec:s0
+/(vendor|system/vendor)/bin/hw/vendor\.trustonic\.teeregistry@[0-9]\.[0-9]-service u:object_r:hal_teeregistry_default_exec:s0
--- /dev/null
+type hal_tee_default, domain;
+type hal_tee_default_exec, exec_type, vendor_file_type, file_type;
+
+init_daemon_domain(hal_tee_default)
+
+hal_client_domain(hal_tee_default, hal_allocator)
+hal_server_domain(hal_tee_default, hal_tee)
+
+binder_call(hal_tee_client, hal_tee_server)
+binder_call(hal_tee_server, hal_tee_client)
+
+add_hwservice(hal_tee_server, hal_tee_hwservice)
+allow hal_tee_client hal_tee_hwservice:hwservice_manager find;
+
+allow hal_tee_default hidl_memory_hwservice:hwservice_manager find;
+
+allow hal_tee_default tee_device:chr_file rw_file_perms;
--- /dev/null
+type hal_teeregistry_default, domain;
+type hal_teeregistry_default_exec, exec_type, vendor_file_type, file_type;
+
+init_daemon_domain(hal_teeregistry_default)
+
+hal_client_domain(hal_teeregistry_default, hal_allocator)
+hal_server_domain(hal_teeregistry_default, hal_teeregistry)
+
+binder_call(hal_teeregistry_client, hal_teeregistry_server)
+binder_call(hal_teeregistry_server, hal_teeregistry_client)
+
+add_hwservice(hal_teeregistry_server, hal_teeregistry_hwservice)
+allow hal_teeregistry_client hal_teeregistry_hwservice:hwservice_manager find;
+
+allow hal_teeregistry_default hidl_memory_hwservice:hwservice_manager find;
+
+allow hal_teeregistry_default tee_device:chr_file rw_file_perms;
+
+allow hal_teeregistry_default mobicore_vendor_data_file:dir create_dir_perms;
+allow hal_teeregistry_default mobicore_vendor_data_file:file create_file_perms;
+allow hal_teeregistry_default mobicore_vendor_file:file r_file_perms;
--- /dev/null
+type hal_tee_hwservice, hwservice_manager_type;
+type hal_teeregistry_hwservice, hwservice_manager_type;
--- /dev/null
+vendor.trustonic.tee::ITee u:object_r:hal_tee_hwservice:s0
+vendor.trustonic.tee.tui::ITui u:object_r:hal_tee_hwservice:s0
+vendor.trustonic.teeregistry::ITeeRegistry u:object_r:hal_teeregistry_hwservice:s0