Thanks a lot for this summary. A question about the requirement: do we ordo we not have plan to support assigned device to the protected VM?Good question, I assume that is stuff for the far far future.
It is in principle possible with the current TDX, but not secure. But someone might decide to do it. So it would be good to have basic support at least.
-Andi