This one is suspect. Can you reproduce with a kernel booted with audit=1 enabled so that we can also get the syscall auditing information for this denial? Also, possibly run it under strace and collect the output?
Uhhh..I came home, put libjavaplugin_oji.so back into /usr/mozilla/plugins (I had moved it into /usr/mozilla), and rebooted with audit=1 as your suggested.
I know this is going to sound crazy, but it no longer fails as before. I'm running selinux-policy-strict-1.20.1-3 now (was running earlier policy when I filed the report).
I see that mozilla_macros.te has allow $1_mozilla_t self:process { execmem setrlimit setsched };
Could this have 'fixed' this?
tom