pebenito has just merged my policy for sys-boot/tboot. The next time you update the gentoo policy, please add a sec-policy/selinux-tboot ebuild.
Merged the policy from upstream and sec-policy/selinux-tboot-9999 is in the tree now
in ~arch
stable back in -r4