dispatch-conf with the current policy (selinux-base-policy-20041123) fails if there are any file updates in (for example) /usr/lib, where sysadm_t has no write permissions. Simple fix is to label dispatch-conf (and probably etc-update too) as portage_exec_t, though it's possible that that gives more permission that is desirable...