[PATCH v8 3/8] iommu/vt-d: Add helper for nested domain allocation