Some SELinux changes have just been merged upstream, which include a bump in the SELinux policy version to support dynamic querying of policy capabilities.
The new maximum supported policy version is 22, so we need this in .config:
CONFIG_SECURITY_SELINUX_POLICYDB_VERSION_MAX_VALUE=22