xen: use libxendevice model to restrict operations