Interesting discussion. I look at things a bit differently. I see this as one of the pitfalls of going for the whole "WLAN Overlay" idea from Controller vendors. If you design the network to extend trunk ports to every AP (which is not exceptionally difficult on many networks), then it allows clients to access their VLAN without the extra network strain involved in tunneling back to the controller. The point about switches being unable to read DSCP only adds to this position.