sandbox: Support booting from TPL to SPL