gui-libs/greetd has a line of policy (insignificant, but still relevant) in the hardened refpolicy: ./policy/modules/services/xserver.fc:80:/usr/bin/greetd -- gen_context(system_u:object_r:xdm_exec_t,s0) This likely means that sec-policy/selinux-xserver should be pulled in for selinux systems. As for how, I'm not entirely too sure how the small files policy would affect this, but I would think maybe a selinux use flag would work?