Optionally enable NS IRQ handling during service execution
Add configuration option to enable NS IRQ handling during service execution.
Turn off by default in keeping with earlier prototype limitations.

Based on @gyuri-szing's comment on the review I split the change to two parts:
https://review.trustedfirmware.org/#/c/174/ only fixes the upstream to keep NS exceptions disabled during secure execution by default as is the current assumption for TF-M.
Change https://review.trustedfirmware.org/#/c/183/ introduces the switch. Gyorgy's comment can be debated separately this way without blocking the fix.