[coreboot-gerrit] Change in coreboot[master]: sb/intel/*: add option to lockdown chipset on normal boot path