The targeted policy runs the xserver unconfined, but the selinux configuration page in firstboot still shows the allow_xshm boolean (and it appears to be off, since the boolean is not in the policy, which is confusing. I thought I had to turn it on!). The page should show only exisiting booleans.
*** This bug has been marked as a duplicate of 160895 ***