1 binder_call(hal_gatekeeper_client, hal_gatekeeper_server) 2 3 add_hwservice(hal_gatekeeper_server, hal_gatekeeper_hwservice) 4 allow hal_gatekeeper_client hal_gatekeeper_hwservice:hwservice_manager find; 5 6 # TEE access. 7 allow hal_gatekeeper tee_device:chr_file rw_file_perms; 8 allow hal_gatekeeper ion_device:chr_file r_file_perms; 9