You may have seen it already, but the CentOS SELinux HOWTO was very useful for me in learning how to interact with it: https://wiki.centos.org/HowTos/SELinux
>Turns out that doing crazy shit like letting users have their html files in ~/public_html/ requires a lot of SELinux configuration
You should just be able to `setsebool httpd_enable_homedirs on`. What trouble did you run in to?
>procmail touching user directories?
This works by default for me in in C6 and C7: I'm using it on a number of production systems. The ~/.procmailrc should have type procmail_home_t but procmail itself can create/modify/delete files in the user's home dir.
>spamassassin?
Again, should just work. You may need to `setsebool spamassassin_can_network on` depending on configuration.
>a tool which tells you what new rules are needed
That would be nice. My usual process if I'm in a situation that needs custom rules is to:
echo '' >/var/log/audit/audit.log # (it would be better to rotate it here, but you get the idea)
setenforce 0
# Do whatever I want to be able to do...
setenforce 1
sealert -a /var/log/audit/audit.log