Secure and fast GPU acceleration in VMs (via virtio-GPU native contexts) requires the ability to handle guest-generated page faults. There is no feasible workaround I know of, and I tried to find one for years because Xen has the same limitation. That will eventually have to be fixed in Xen.