Re: [babel] [Babel-users] Babel MAC auth fails due to packet reordering

Juliusz Chroboczek <jch@irif.fr> Fri, 13 May 2022 20:57 UTC

Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A06F6C1850D3 for <babel@ietfa.amsl.com>; Fri, 13 May 2022 13:57:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jTsCwtozSL7E for <babel@ietfa.amsl.com>; Fri, 13 May 2022 13:57:14 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8BE78C1850D9 for <babel@ietf.org>; Fri, 13 May 2022 13:57:13 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/82085) with ESMTP id 24DKv5TA011770; Fri, 13 May 2022 22:57:05 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 5F2ECD0B5A; Fri, 13 May 2022 22:57:05 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id jfRIkU0rCV5B; Fri, 13 May 2022 22:57:03 +0200 (CEST)
Received: from pirx.irif.fr (82-64-141-196.subs.proxad.net [82.64.141.196]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 48746D0B58; Fri, 13 May 2022 22:57:03 +0200 (CEST)
Date: Fri, 13 May 2022 22:57:02 +0200
Message-ID: <871qwx178h.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Daniel Gröber <dxld@darkboxed.org>
Cc: Toke Høiland-Jørgensen <toke@toke.dk>, babel-users@alioth-lists.debian.net, babel@ietf.org
In-Reply-To: <20220513185419.dxhmkyfjmnbgub53@House>
References: <8735hj23pq.fsf@toke.dk> <87sfpi4uwh.wl-jch@irif.fr> <20220513185419.dxhmkyfjmnbgub53@House>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/27.1 Mule/6.0
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset="US-ASCII"
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Fri, 13 May 2022 22:57:05 +0200 (CEST)
X-Miltered: at korolev with ID 627EC621.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 627EC621.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 627EC621.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/IyDuuLZ7K7DY9TiJHFSsA5DcHaU>
Subject: Re: [babel] [Babel-users] Babel MAC auth fails due to packet reordering
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 May 2022 20:57:16 -0000

Thanks a lot, Daniel.

> I'm having some trouble establishing a baseline using babeld. Using
> babeld-1.11 as both the sending and receiving side I'm not observing any
> errors

You need to run babeld with the "-d2" flag to see MAC and PC validation errors.

> and the session seems to come up perfectly

It looks to me like you were lucky.  There's some reordering going on in
your trace, but it's never severe enough to cause association failures.
I'll try to reproduce your issue locally, you've given me all the hints
I need.

At any rate, your results seem to indicate that we've successfully solved
the issue, which means we can try to push the Internet-Draft through the
working group.  I'm very grateful for your report and for your help with
understanding the issue.

-- Juliusz