[PATCH v5] Restrict devmem for confidential VMs