Merged in changes from the tip of RCL_1 branch which includes fixes for Bug 284, Bug 383, Bug 287. These were wiped out from when the S^3 code drop came in.
# Each constraint is the empty set i.e. allow nothing[device_id_list][sid_list][vid_list][cert_capabilities]