src/security/tpm: query recovery mode from Cr50