Re: [AVTCORE] Roman Danyliw's No Objection on draft-ietf-payload-rtp-jpegxs-15: (with COMMENT)

Tim Bruylants <TBR@intopix.com> Thu, 10 June 2021 06:49 UTC

Return-Path: <TBR@intopix.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 056C63A3728; Wed, 9 Jun 2021 23:49:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=intopix.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PmZSQmD3xBNG; Wed, 9 Jun 2021 23:48:57 -0700 (PDT)
Received: from dispatch1-eu1.ppe-hosted.com (dispatch1-eu1.ppe-hosted.com [185.132.181.7]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87AB03A3725; Wed, 9 Jun 2021 23:48:56 -0700 (PDT)
X-Virus-Scanned: Proofpoint Essentials engine
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04lp2056.outbound.protection.outlook.com [104.47.13.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1-eu1.ppe-hosted.com (PPE Hosted ESMTP Server) with ESMTPS id E98579C008C; Thu, 10 Jun 2021 06:48:52 +0000 (UTC)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=C3VAEgGKu6GySDVytfLMEK+WS/GPvSF6R4e3IZyumHEMTQEKQvTXJu20TYiCpzOUBS4SazEAaPR9Mu7mxz3HJikxJ6lR26ctOuvol9l88dm2rkXV0cPch6lER5q1hrO7QuGkLmCGqBjTMxq6wkSXIDofhVGZygfWoHs1VZvvbEBbjtSoF15Aq1HqwqZ434yajiFhn+wM1eyzrZk2nqqXmJcoa3HU946A9W6L5b06WEVIs1siXFtj+TQgptbo0iP/9YiyzaqODJGG5IJeAAJPS7QDKr4aPyDIkwc0JR5yf9IcdreLgLM656xN4rxQFF/H/Wt41x9XOtJ1TiISTRdtPA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=efBHT2iCYy5/33bukQpEY6cdz5GTTyWwOIiTInFKXbc=; b=KqCH+disSeYaArGzHb79RfFfCGeONH+q5PNLjq6Br6Egi9vpMRvpJzligi6aDYdYnQkEU9VP2DAP1vULcQmFyjc3oUdT0bRb6+4SCGc7oI4/UcyS1lV60Gb0twucueu0YHnyKuYOvs6ufRMZac3Qx5vzWRBXlpqUUKMFF4Vi1aE/86pAi5q+FevpzcaYsR/unaTPxjIh3aqpcf7vPuLPIbF1HP65N10PaDDRnQdEhO30a+zDVTXSPcYL/1D5Jdzf8wxyKhfdJKJ2okwcs6bMjSwNBvZiaOtLNZdZT3kmrEnkgj8wDFsRiFcTgA5EebKDpW3v5MJsZpTclIUZRZSDzA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=intopix.com; dmarc=pass action=none header.from=intopix.com; dkim=pass header.d=intopix.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=intopix.onmicrosoft.com; s=selector1-intopix-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=efBHT2iCYy5/33bukQpEY6cdz5GTTyWwOIiTInFKXbc=; b=D2VG/qc9uajo9JT9EBkYfMC3eKvgrMpeGquzjpk3mDrwSksFHQfmeZbuczEwkR/N/NuB1LZU0/rxs7w7y6tz6FVv58y3O7d0hR4ee/73Tk4/+N4gCrk9997rCY0l6j9qoh12gwp0QEjczxlz9gnAkeH2dtZV8LRDGW5hthqy20A=
Received: from PR3P192MB0748.EURP192.PROD.OUTLOOK.COM (2603:10a6:102:4f::24) by PR3P192MB1024.EURP192.PROD.OUTLOOK.COM (2603:10a6:102:a2::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4219.22; Thu, 10 Jun 2021 06:48:50 +0000
Received: from PR3P192MB0748.EURP192.PROD.OUTLOOK.COM ([fe80::841c:3124:d643:9f40]) by PR3P192MB0748.EURP192.PROD.OUTLOOK.COM ([fe80::841c:3124:d643:9f40%3]) with mapi id 15.20.4219.022; Thu, 10 Jun 2021 06:48:50 +0000
From: Tim Bruylants <TBR@intopix.com>
To: Roman Danyliw <rdd@cert.org>, The IESG <iesg@ietf.org>
CC: "draft-ietf-payload-rtp-jpegxs@ietf.org" <draft-ietf-payload-rtp-jpegxs@ietf.org>, "avtcore-chairs@ietf.org" <avtcore-chairs@ietf.org>, "avt@ietf.org" <avt@ietf.org>, Ali Begen <ali.begen@networked.media>, "bernard.aboba@gmail.com" <bernard.aboba@gmail.com>
Thread-Topic: Roman Danyliw's No Objection on draft-ietf-payload-rtp-jpegxs-15: (with COMMENT)
Thread-Index: AQHXXWZ+mAT+JAQdPEKwq0n30H6jqKsMzGnA
Date: Thu, 10 Jun 2021 06:48:50 +0000
Message-ID: <PR3P192MB0748FDFA32628F85514F2EA2AC359@PR3P192MB0748.EURP192.PROD.OUTLOOK.COM>
References: <162326727198.29714.11233454715669304814@ietfa.amsl.com>
In-Reply-To: <162326727198.29714.11233454715669304814@ietfa.amsl.com>
Accept-Language: en-US, nl-NL
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: cert.org; dkim=none (message not signed) header.d=none;cert.org; dmarc=none action=none header.from=intopix.com;
x-originating-ip: [2a02:1810:1dbd:e901:1cd3:ed4a:ff56:9137]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 77ab33fd-4b58-45ef-13b7-08d92bdbce32
x-ms-traffictypediagnostic: PR3P192MB1024:
x-microsoft-antispam-prvs: <PR3P192MB102473DB6E1959EDAD570931AC359@PR3P192MB1024.EURP192.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ziPo/eS2IGn7ag4oEki15Eu+5eZVx8lhYMwDi+BCcyaUOJTVhPV2siEcpUGOn0dAamkIbwfyF15Isd+YVMWYc5xs06B3UPMIaUwxouSjSJEPFc/T/xHWCSKoklM0hQqub3mvYickoO6PdOuYRZ+IV9d6FOhK41J01r92GcbQ9rNRLcD9OvbKaaeh3wqkChPVfzQBV02mLG8sd26bzJDRnLVatex3vXR9lL2HKmsok3UYruhByxq6lQAgsOT1oyU7hQMepTx/WR5BimaE2RELzzsaHLIPOzCS0OlmAGXrL5kb5O0Lr4Tw5MkIDaiVLe084lZaB9v9uJ4XlU3uwXFDEmc+otngn7sMLOkZdKurvCbaCO1OA1mPtYHW+BCB+i96Aw35f202uIjGXrLpmJ9itG2k+wxvv6Njh0Is3fYJsCjFsT3TpUXvmH2vEvUoggCJYDYOlNZiSwLnE9s75LzpuY+DtoVIGTrz2u4SCErvB4yyCMw0EGYkJrkT8x2NpDoe+rQiiW/kXCoMWxSohAPn35RbLbrHJ4KWV7rVCd9hgRU72QszMfw+mV/eDzr0h6pv10d1VkXf56aBnIz2Q3LXjUj08A8wI2sgp0C+7O4FH9U=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PR3P192MB0748.EURP192.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(366004)(376002)(346002)(396003)(136003)(39830400003)(6506007)(55016002)(52536014)(316002)(2906002)(38100700002)(478600001)(4326008)(9686003)(64756008)(71200400001)(66946007)(8676002)(66476007)(76116006)(66446008)(186003)(83380400001)(5660300002)(8936002)(33656002)(7696005)(54906003)(122000001)(110136005)(86362001)(66556008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: =?utf-8?B?M20yZE9nYlRrOTBDUk5GNmxiNGJsTVJEWHUrZHo0M2tZT1ZrSnl0MzZ3aldS?= =?utf-8?B?TE90Q2pUeEQ2MmtQQVp2SW1Dc1BjMmRnbms1ZysyeXVWa3dYaENqUkIzOFp0?= =?utf-8?B?b1hYczRldE9BUWZvYVF3RHhMdVc3NHlRMW1Oak5xa1B5S0NhUE52SGd5V1NT?= =?utf-8?B?OS8zZVRoNVV1YWR3bWYxUDRXaDRjSmo2aXlwSEFHc2V1UmYzekZLSlpzeHdQ?= =?utf-8?B?UndPRGt4TUJvam13SVo1cWZBVTV5OEhoY1pSM2p3UWhQVHZwUHBlMFlIdW5K?= =?utf-8?B?QmttQUkyS3ZmN2VRdTJRYlloWlZsSUEwOVh0NzlUVzFDSkxjL3lucExjOEhW?= =?utf-8?B?Qm1GK3pYbHFMRjQ2Q2NBKzBwMTk4R24zb0Rlc1V1VFhmL3M4VWI4R0VZVklG?= =?utf-8?B?MFlVRmU2R3JYdHhicHFMYUwwY04wdTBNV2FQUTdlWDl6TFdBN0FqaXIwa1k0?= =?utf-8?B?TytNYjZFdmdBMGRQaEp3MkNsVkR0VGxmOFZHTWg0Z2E2eGhSbkFNZmJTQTJ6?= =?utf-8?B?Nll0WjlNVllGQ1g4TWZBeE9NS3hOWHlzVmFOaHMwNDMyTmVHUDVIK2FTQnVQ?= =?utf-8?B?dzJkZTZKbk9IMGZ1UkN0TU42TWRRT1I2UjlRanRzejlmK0JxZlRVeGt1bnVo?= =?utf-8?B?Sisrc1Zrb1R5cXBYQ1JjN1B6TzQxNEJ1Sk9WMi80b3dDVzRRR1dLT1luYUxQ?= =?utf-8?B?cFYyOWdCRnkrM29LNGw3RWtVc0lzb2ZPQm9pM0dLbVBqQmFzOVZXZU5TMzBP?= =?utf-8?B?Kzg1WnVOWjNvVkxsb29tb2lHV01zekRra29yMGNCeWJWWUN2MUNyU01kUXMw?= =?utf-8?B?U1dhR0NIZjVkU1VRdCt1eWpuamx4SmpNZzEyUXdVN2gyNmFWSnZOL05mUTRn?= =?utf-8?B?bCsrWG1CN0x5ZERMUG1jMXNwMml2TXl3NW16c3FTNTFadUttbmVodFJVN3hz?= =?utf-8?B?L1RnSG1LTFp4Nm5nOHNmZ3ZqS3NPbGtmMTBjVjFGQ29CWFBQOXEzVnF2dWxN?= =?utf-8?B?b3B6d0hjMHYvREI0a0cxWm1KbzhHc2l3TkV0bWFrZ3J1eUh2TW5naUhiZ3oz?= =?utf-8?B?aVNLcFpGUXZrdTVpYkVHVWlRYi9yZmIxbTJPS3djVzdvU2xtUVFma29vYTN1?= =?utf-8?B?RVdDN3JnaitnN0lCcEFENzNiVUhQMDdSQmZMS1B6RU1ZMnkzbG5tK3hOVzhm?= =?utf-8?B?bUZBREVSRlZQS21HY0JrOEJKZjVLYU9VRFN0WlRLMlBhNmZKQXgwS1lzT1d6?= =?utf-8?B?S0F3Sm9SNVRTU2ZkbU5sbnFDcHJUaFdCSUVhOXdyV21mVzJobWFES1VCUWZk?= =?utf-8?B?S2lBSFNPb3hhdUVxcHZHbFhsUmRva2JvWHpzOEl5T3A4UU5wRzcvWHdWSVJk?= =?utf-8?B?elR5YU1PU0NGUjRaK04yQWhMRFYrV3BlQVJMbjlTWGR3c3JRVHNhTzdraTNR?= =?utf-8?B?M25vekVKSXlwNDI2c1lYem1DejJLZnlOcGFaaUlXS1lxMFREVG54TWE5VjF5?= =?utf-8?B?Y3pNSFdWa1d4ZUJjMXptaGNnSk1penNLWTlRVXpLTVJjdmMzYlRZakttSW5R?= =?utf-8?B?em5mVFNDZ1RQYitRVFllcVFxbnphNFRQUS9TVnJBY0pYYVhoVmpOVUNvWDVw?= =?utf-8?B?L2wvOUdpamlIMDFUUTk5Y2pMcCtzYmxMNlo4ODBRTUpBZDFDUzZ0dWRTNFlu?= =?utf-8?B?SS9pM0FTOHUvS2xjL0FvUHM5QnlKa09LSVQxNmVwa2FINkd3ZEpZR1h4QTBK?= =?utf-8?B?U3ViNElacDZNVS9oajNZVGppRHZOa2xrb3JCK1ZNbGYzN0FKWjdsYldWUDVq?= =?utf-8?B?WjJtNklSNzIzTG1zY0NYVGtaa0FhVklhY200UEVEOGluODZiMXczWEFpbytv?= =?utf-8?Q?moCMhNZ3IfDyb?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: intopix.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PR3P192MB0748.EURP192.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 77ab33fd-4b58-45ef-13b7-08d92bdbce32
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Jun 2021 06:48:50.5522 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5f9168c7-cdac-4b23-9509-c278399e3c1f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Jbvy828aEk8Z5i6nYfLEwtbzLH77Lk8yqRwdDun+iH1/EDSYVObs9rGeUbaqUUWt
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PR3P192MB1024
X-MDID: 1623307733-IHpISKK6Fb_y
Archived-At: <https://mailarchive.ietf.org/arch/msg/avt/sefp7oWcHv4mTRH1jwAaCiTUagc>
Subject: Re: [AVTCORE] Roman Danyliw's No Objection on draft-ietf-payload-rtp-jpegxs-15: (with COMMENT)
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/avt/>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jun 2021 06:49:00 -0000

Thank you for the review and feedback.

I have prepared a new draft document that addresses your comments.

> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------

> ** Section 4.1. Typo. s/preceeded/preceded/

Fixed.

> ** Section 10.  . Thanks for mentioning the possibility of a denial of service
> due computational complexity.   Please considering adding a comment about
> processing untrusted input (similar to the language in other RTP payload drafts
> like: draft-ietf-payload-vp9 and draft-ietf-cellar-ffv1).  Roughly:
>
> OLD
>    This payload format and the JPEG XS encoding do not exhibit any
>    substantial non-uniformity, ...
>
> NEW
>
> Implementations of this RTP payload format need to take appropriate security considerations into account.  It is important for the decoder to be robust
> against malicious or malformed payloads and     ensure that they do not cause
> the decoder to overrun its allocated memory or otherwise misbehave.  An overrun in allocated memory could lead to arbitrary code execution by an attacker.  The same applies to the > encoder, even though problems in encoders are typically rarer.
>
> This payload format and the JPEG XS encoding do not exhibit any substantial non-uniformity, ...

Indeed, this is very useful to explain. Somehow it seems so obvious that we did not think about writing it down. Thanks for the suggestion.