Are there any cryptographic proof systems that rewind the prover to argue soundness but are not proofs of knowledge? In particular, I would be very curious to see examples of proof systems where rewinding is useful for arguing soundness but does not seem to suffice for witness extraction.
To give some nonexamples, Schnorr's discrete log proof of knowledge rewinds the prover to extract the discrete log, proving soundness. The classic 3-coloring ZK does not rewind to prove soundness and also does not extract the witness (I think it is possible to rewind and extract the witness, although it is not entirely trivial).