I have a policy fix but it's a bit unfortunate. Due to /var/mail/ I need to give init_t access to mail types. init_t is mighty anyway, but this is whackamole, as the next service will setup a different setup. Daike, please test the new version with home:jsegitz:branches:security:SELinux/selinux-policy that should work. If it does for you then I'll submit this into Factory first to avoid breaking openQA