On Fri, Aug 30, 2024 at 07:52:41AM +0000, Tian, Kevin wrote: > But according to above description S2FWB cannot 100% guarantee it > due to PCI No Snoop. Does it suggest that we should only allow nesting > only for CANWBS, or disable/hide PCI No Snoop cap from the guest > in case of S2FWB? ARM has always had an issue with no-snoop and VFIO. The ARM expectation is that VFIO/VMM would block no-snoop in the PCI config space.