The permission mentioned in the title is needed for the firefox build system. I can't attach patches right now (firefox bug), so please refer to the URL or to the aranea/portage-tmpfs branch in my policy repo.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=34a5c9f83485ba36ea21940a6ecc3932636f51f3 commit 34a5c9f83485ba36ea21940a6ecc3932636f51f3 Author: Luis Ressel <aranea@aixah.de> AuthorDate: 2017-10-25 00:37:05 +0000 Commit: Jason Zaman <jason@perfinion.com> CommitDate: 2017-10-29 13:57:28 +0000 portage: Allow portage compile domains to map portage_tmpfs_t files This is required by a python script in the firefox build system. Bug: https://bugs.gentoo.org/635384 policy/modules/contrib/portage.if | 1 + 1 file changed, 1 insertion(+)}
Fixed in 2.20170805-r3.