Guarantee L1TF immunity
L1TF is unconditionally handled on Linux by inverting address bits if PRESENT is cleared. On FreeBSD, it is handled by always reserving page zero, and ensuring the address bits are zeroed for non-PRESENT pages.
RMM probably does this already, but that needs to be properly ensured.