TPM: Verify PCR0 matches the bootmode if it is already initialized

Refuse to boot in case of a mismatch

Google-Bug-Id: 24814315

Change-Id: I6bd5abba7583eae95968fba4a63dd56f85497727
1 file changed