When we run a confidential container via nerdctl or ctr with GPUs, we supply the VFIO device at the command line. The sandbox has all needed information at sandbox (VM) creation time and we can create ...