[PATCH] implement policy_pcr commands to lock NV-indexes behind a PCR