Package ebuild should contain 'selinux' USE flag so that it can pull sec-policy/selinux-shorewall automatically on selinux-enabled hardened systems. Reproducible: Always
Looks like this was gone when we moved from a split packages back to an all-in-one package. Re-added via https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=20a634de3881aebc5cd63e45d6972dc920da7bce Please report back if this fixes the problem for you.