Well, this is an instructive mailing list. :)
The issue is that the file context list used by restorecon isn't really integrated into the rest of policy. Doing the look up when doing all file creations would be very expensive.
I understand. Thanks for telling.
However down the road the final part of of the pathname may become usable which would help in cases like this. See: http://lwn.net/Articles/419161/
Good article. Such a feature would solve a number of headaches in our environment (independently of the correct way to implement it).
Cheers.