[coreboot-gerrit] Change in coreboot[master]: soc/intel/xeon_sp/cpx: Add locking of IA32_FEATURE_CONTROL and VMX