[PATCH v3 0/2] Restrict devmem for confidential VMs