[RFC PATCH v2 1/2] tee: add restricted memory allocation