Provide alternate SE RoT provisioning path.

On some devices it is infeasible to provision the KeyMint RoT bits in
the Android Bootloader.  This provides an alternate path to provision
them from the TEE during early boot.

Bug: 219076736
Test: VtsAidlKeyMintTargetTest
Change-Id: Id7bf6a309f53ad8219ce1d3754d9c2211182b89f
Merged-In: Id7bf6a309f53ad8219ce1d3754d9c2211182b89f
2 files changed