cpu/intel/model_{2065x,206ax}: fix AES-NI locking

MSR_FEATURE_CONFIG, which is used for locking AES-NI, is core-scoped,
not package-scoped. Thus, move locking from SMM to core init, where the
code gets executed once per core.

Change-Id: I3a6f7fc95ce226ce4246b65070726087eb9d689c
Signed-off-by: Michael Niewöhner <foss@mniewoehner.de>
Reviewed-on: https://review.coreboot.org/c/coreboot/+/46535
Tested-by: build bot (Jenkins) <no-reply@coreboot.org>
Reviewed-by: Nico Huber <nico.h@gmx.de>
diff --git a/src/cpu/intel/model_206ax/model_206ax_init.c b/src/cpu/intel/model_206ax/model_206ax_init.c
index cd828e8..d23772a 100644
--- a/src/cpu/intel/model_206ax/model_206ax_init.c
+++ b/src/cpu/intel/model_206ax/model_206ax_init.c
@@ -470,6 +470,12 @@
 	/* Thermal throttle activation offset */
 	configure_thermal_target();
 
+	if (!intel_ht_sibling()) {
+		/* Lock AES-NI only if supported */
+		if (cpuid_ecx(1) & (1 << 25))
+			msr_set(MSR_FEATURE_CONFIG, BIT(0));
+	}
+
 	/* Enable Direct Cache Access */
 	configure_dca_cap();