Not really. I mean, yes, in the sense that the IOMMU has to be configured to allow it, but after that, it's fair game. Any PCI device can read within the inbound translation window.
I just want to play video games and I use linux - in order to play multiplayer video games I need anticheat and this means giving that up.
I would also argue that other than a minority of vocal users no one wakes up in the morning looking forward to tinker with their system, we just sometimes have to, doesn't mean we like it.
I can already tell this is very likely not going to work fully, or even work for a sizeable chunk of Linux installations out there. Many platforms don't have TPMs, or have TPMs from unknown CAs. Or firmware that you're not aware of. Or even worse, people might just be running a Linux distribution that you don't know about. Or a patched kernel. Or a bootloader that doesn't measure the next stage into TPM. Not to mention, even the most popular distributions allow you to do anything with root access, things that you just won't be able to measure, but that might allow people to cheat.
TPMs really only make sense for _very_ controlled environments if you want to prevent hardware tampering at this level. The diversity of Linux distributions (and PCs in general) truly works against you here.
The rootkit, driver signing enforcement, driver ACLing of anything it doesn't like, vulnerable drivers, all forms of emulation detection, failing any of those = permanent ban is a whole other problem.
My bigger concern would be a permanent ban on an indie game.
Ultimately anti-cheat within the application itself, I find, should be considered acceptable whereas Riot's Vanguard/rootkit solution is an ugly hack. Valve seem to be showing it's possible via both automation (ML) and community judgement to make achieve results - the aim needs to ensure all players look "normal", not stop all cheats (the latter aim is impossible).