x86/bugs, kvm: Introduce boot-time control of L1TF mitigations