This graph also show clearly the logic of authorization policy management in tpm2sh:
tpm2-tpmkey reads and writes keys in the TPM 2.0 ASN.1 format. Those bound with a policy have a pre-compiled list of policy commands.tpm2-policy-language compiles policy expressions into command lists.tpm2sh post-processes [*] and executes the command lists in a policy session.[*] At minimum, tpm2sh writes handle of the temporal session to the command buffer.