Вот что добавлялось в готевой xml
<hostdev mode='subsystem' type='pci' managed='yes'>
<source>
<address domain='0x0000' bus='0x02' slot='0x00' function='0x0'/>
</source>
<address type='pci' domain='0x0000' bus='0x08' slot='0x02' function='0x0'/> <= прилетело автоматом
</hostdev>
При старте гостевой ВМ:
error: Failed to start domain test
error: internal error: qemu unexpectedly closed the monitor: 2019-06-03 23:16:49.853+0000: Domain id=1 is tainted: host-cpu
2019-06-03T23:16:50.071319Z qemu-kvm: -device vfio-pci,host=02:00.0,id=hostdev0,bus=pci.8,addr=0x2: vfio error: 0000:02:00.0: failed to setup container for group 7: failed to set iommu for container: Device or resource busy