We *badly* need to have some sort of check run against the policy to ensure that it's sane that's run as a %check in the package. Otherwise, we continue to get broken policies being built that then hose installs (bug 129943 is the most recent incarnation of such).
selinux-policy-*-1.17.1 now verifies the file_context file against the policy file. Dan
Fixed in current release