loader: fix efi binary loading via -kernel loader: support secure boot verification with direct kernel boot