Matthew: Avoiding gaps in IOMMU protection at boot

Matthew has a new security patch which’s been merged with mainline Linux kernel, with a blog post describing it (also see comments in head of patch):

