I think 1 and 2 aren't a great option. 1 due to the unnecessary duplication and 2 due to needing to keep a core dependency up-to-date As for the force replace param, that's a parameter needing to be defined at RPM install time?
We could keep providing the container policy in /usr (maybe not /usr/etc) and symlink it, rather than removing the file? But I also don't mind the force replace option