Signed-off-by: Ian Jackson <Ian.Jackson@eu.citrix.com>
Reported-by: Roger Pau Monné <roger.pau@citrix.com>
Acked-by: Wei Liu <wei.liu2@citrix.com>
=item B<dm_restrict=BOOLEAN>
-Restrict the HVM device model after startup,
+Restrict the device model after startup,
to limit the consequencese of security vulnerabilities in qemu.
With this feature enabled,
=item
+This is not likely to work at all for PV guests
+nor guests using qdisk backends for their block devices.
+
+=item
+
You must have a new enough qemu.
In particular,
if your qemu does not have the commit