[PATCH v2 0/3] Restrict devmem for confidential VMs