For instance a VMM could choose to only assign devices which never use no-snoop, which describes almost all of what people actually do :) The purpose of S2FWB is to keep that approach working. If the VMM has blocked no-snoop then S2FWB ensures that the VM can't use IOPTE bits to break cachability and it remains safe.