Description of problem: sabayon is creating the lockdown.zip file in /tmp. This gets labeled unconfined_tmp_t, When it is complete, it "mv"s it to /etc/desktop-profiles But it does not fix the labeling. It needs to do a restorecon. If you login with a user type that is not allowed to read unconfined_tmp_t like xguest_t, it will fail.
Created attachment 226051 [details] Patch to fix selinux file contexts.
Looks fine to me.