Pull security layer fixes from James Morris:
 "A fix for SELinux policy processing (regression introduced by
  commit fa1aa143ac4a: "selinux: extended permissions for ioctls"), as
  well as a fix for the user-triggerable oops in the Keys code"

  KEYS: Fix handling of stored error in a negatively instantiated user key
  selinux: fix bug in conditional rules handling