A Secure and Formally Verified Linux KVM Hypervisor