Along the pieces that were determined to have security relevance there are quite a few more fixes / improvements (or so I hope) which were decided to not become part of the XSA itself. Hence also why this is v7 and why several of them already have a Reviewed-by tag. Here we go.
1: check / convert IVMD ranges for being / to be reserved 2: obtain IVHD type to use earlier 3: improve (extended) feature detection 4: check IVMD ranges against host implementation limits 5: also insert IVMD ranges into Dom0's page tables 6: provide function backing XENMEM_reserved_device_memory_map 7: add "ivmd=" command line option 8: respect AtsDisabled device flag Jan