ec2: avoid deleting security groups if we can.
It takes ages to delete a security group if an
instance has been using it, so this change
adjusts the old group to have the required
permissions instead.
R=fwereade, niemeyer
CC=
https://codereview.appspot.com/5671086