Processes running as portage_t or openrc_cgroup_release_t don't have access to /run/nscd/socket. This doesn't look like a security gain, so they should be granted either nscd_socket_use() or auth_use_nsswitch().
Fixed in repository and will be in rev 12.
Also, openrc now depends on selinux-openrc if USE="selinux"
rev 12 in main tree, ~arch'ed