sepolicy: address some nvram_daemon denials