[DNSOP] Re: New Version Notification for draft-bortzmeyer-dnsop-poisonlicious-05.txt

Ben Schwartz <bemasc@meta.com> Wed, 05 August 2026 15:33 UTC

Return-Path: <prvs=6677b029fc=bemasc@meta.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8E9D01242CD62 for <dnsop@mail2.ietf.org>; Wed, 5 Aug 2026 08:33:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785944031; bh=78lv0b0v+lyoVT7xYroRWDdxAV5+1eDiuAhKHPdr2y8=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=CcRBdf3tMKkuysylnLMXzdsWg6n6pExiCQz4znmaphfNYHxIPaiHXyKoSIQ4h+TRb DuV/cmP7zhs0g8FmUsbW35C1+2t+hMrpr9IMb6k6/M1cxf2c6G5Z8hB22hd5lAL30Y Dt6hC0+X3QXWiIXH508p8gA068ebPQ464Z5QZQRw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.794
X-Spam-Level:
X-Spam-Status: No, score=-2.794 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=meta.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L-TNh1E9Opp3 for <dnsop@mail2.ietf.org>; Wed, 5 Aug 2026 08:33:51 -0700 (PDT)
Received: from mx0b-00082601.pphosted.com (mx0b-00082601.pphosted.com [67.231.153.30]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1EA5A1242CD54 for <dnsop@ietf.org>; Wed, 5 Aug 2026 08:33:50 -0700 (PDT)
Received: from pps.filterd (m0528004.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 675FWLLg3436953 for <dnsop@ietf.org>; Wed, 5 Aug 2026 08:33:49 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=meta.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s= pps82601-s2048-2026-q3; bh=91TwWCHejT2QpWNXjbin/UPN3YRwlXVUevKof QUNrhE=; b=ILTNlgXZiK+QCWYePULnAkEEBL5KAofpR5wPD8GcDvdSZA9TSDLzf JwyCs4t+BNNYYHw2vlYd3G34B9vGN5khSvXYwt/j7melQz6WTu3YXoiTeF/kuaiZ 5ciz8BgNS4nUyHd/A6O3A4IX2JMAqDkJweCvLEcXYFPMvkYNe3ar3+MmsJpBI5xw L55u21vKRgI4gHcXA/ul701WmTY3StWSq8IGyXEuEvxbkdXhRkU/GANqJYv+kewq SKqnEGWnRc3H38/F9lNhZUA/VK2HZcGoFxluhbRqY7aNWNvx7EGfc/kimaJv9SoG Elrkq7hQ5BCpXjVG9VCdpQDjzwZ8pyqAw==
Received: from mail-yx1-f71.google.com (mail-yx1-f71.google.com [74.125.224.71]) by mx0a-00082601.pphosted.com (PPS) with ESMTPS id 4funcfxmjm-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for <dnsop@ietf.org>; Wed, 05 Aug 2026 08:33:49 -0700 (PDT)
Received: by mail-yx1-f71.google.com with SMTP id 956f58d0204a3-66931a828c0so1590229d50.0 for <dnsop@ietf.org>; Wed, 05 Aug 2026 08:33:49 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785944029; cv=none; d=google.com; s=arc-20260327; b=mbPg6OGD7Mnqu8HhiSR9WS42neFDqKnGlJvR0PQq3KR5eQnBl4THP1iPoDPSVwp6Ce wNaUs+OgJLjyzdvB/Qjw1v0yPW0FPvN3EZwOX3NCM/IeuLoOUGGwYe4dtH4PRDUYdskR Jbw3QMgFS08v4fVyf3QHoWEJYpGLukjrA3kFGvh5rKrwiGRvLywI2FEWja3l6155Tgc1 /uNEfYTtywrRaZ4GZ+NJ7joOVugH3PXMXrC9s+ErYs2pV1DkmmNeRe4uzXW5whmfm4pI oimV+imx5Ms/XgOVgtXAjLX5B+j6oRE5BQ+zq4EUosJE9yNw3wsXOnxj8ntTCP2myZBI s+zQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version; bh=91TwWCHejT2QpWNXjbin/UPN3YRwlXVUevKofQUNrhE=; fh=e4RQJIrsIbZoijS+xpVc82iz+yajnMqdsASiWnbBmb4=; b=pHRiSm5kYoXW9uxxjZE1wGMWYyYurpD+DGUbuzGQ0soCROI4DaUdPthfvC+j6IQRyJ /rmUMk281Xpzb7i+HrQDatlwa2qXddfgQbrbAl/NhiTXUtgxBMbKIKkvH492MtF44Ih1 h4zEJXml0FJUR+TsX+fAUMr7RVng0qO5EBBURMeMiVbCt+iI/p/mEk5mu1qN3yDTTBlF neapEnZEtqs/4FKggR88FfnNo22BbPOasFAtpU90Muqeyikq9opkmuSdeAKwovRUs/yW lLjZrX1Qr+3H1UKiIQH7rSm5dAM82Dwbtv3+/Og/NB6VmW/gyPA9fj9ATuHySA2HuAHM lTKA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785944029; x=1786548829; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=91TwWCHejT2QpWNXjbin/UPN3YRwlXVUevKofQUNrhE=; b=HU53oeRZzrjkmiyuAJaa5RO6RwWsIDxR8FvlmvKFx6xZD7+v7rMrALtOXcu9LrQtAD AaxqHdegXUCkRzWvjLnF4PSCDj76Ag+/kC5ZTEaTKkv2gtdrgefhKzGOVU5TF0E0aNoQ 8yzQUrZJS6VBChEIg4asYRe3BNfcKKB3n2KJtfA1sjqyO/D1bWNy9RMEpyxiZuUxcHpQ LwyXY7Qzn3uySqsCpiQRPQSeCLw3H9kgeloD0wRUQT0y9CWcbnpBuBmxsDQ9K+eQNneg SAQ20s0m8I3yXKHmt176jua8SrfIMK6uNQ8geT4Sw3RzK8lfs2A4hyB/D4/OW3pXHLDH QllA==
X-Gm-Message-State: AOJu0YxCRneUgX9actr8cB9QLBYkdpF1fyvUks2zJc3CFIva+jIXv0vJ rGxUKt0pDG6lXhINi7iziDbkRQWZGjqOBHWft24Lc9lT3BhgDOIJLryZoSKzZ1Xh7ani+5kz05e smkEHeFWWmV+jUMRmNos3iHCHvGFRLqWQcjgnHYe531VF25C1xFeomMjZ7a8nbQQxXizMoMnLtf 9Wznvu1VZu4+B9VdPzqvbW
X-Gm-Gg: AR+sD10KQ7ZSVztyWNd9OIDhTYVOu1VgvDfYrk7lgp9rraSf8cwLe9x5VFd9qf57ujm UG/CbNi/hn9XKLaaoOMJOU548DwO3ADZq9TFNw/ifwfD6vq5gSbIF44htNHpcWnR3hN+UIZQ8XY RhvvVzXKNhi4LdEyybgCi1/LZPKyv1cOnSSUJBTnT+u1r39/gNUcd8ebF+C1mon2cj46m3GWoV
X-Received: by 2002:a05:690e:23c9:b0:667:ba5f:e32e with SMTP id 956f58d0204a3-6699a8a00c9mr3261258d50.14.1785944028990; Wed, 05 Aug 2026 08:33:48 -0700 (PDT)
X-Received: by 2002:a05:690e:23c9:b0:667:ba5f:e32e with SMTP id 956f58d0204a3-6699a8a00c9mr3261232d50.14.1785944028553; Wed, 05 Aug 2026 08:33:48 -0700 (PDT)
MIME-Version: 1.0
References: <178586655868.1998675.29436192776087871@dt-datatracker-d4d6ff9d9-ql5mb> <m2zez1em7l.fsf@farrokhi.net> <CAOdQrVO3iAvuV5NShtKtEzt2RpVD8Ha9dTA_5ewPLJJDfefJMg@mail.gmail.com> <29BE1056-4230-42CD-936E-96321F5E4C53@pch.net> <CAOdQrVOQbOvqF8tE6nNGEtJwCB4+yrpX0BbHCPs00VNe=fuapw@mail.gmail.com> <e13c6813-7985-40ef-a6dd-b143d940bd2f@isc.org>
In-Reply-To: <e13c6813-7985-40ef-a6dd-b143d940bd2f@isc.org>
From: Ben Schwartz <bemasc@meta.com>
Date: Wed, 05 Aug 2026 11:33:37 -0400
X-Gm-Features: AUfX_mwipHa3qXUOfUUv-TRPTMKqwAi40oc8LblouI1qpIb02l3qDoYkAdMCq1A
Message-ID: <CAOdQrVPUTwZ_1Hq6JW4g_Z3NpWJ2P9sr0zBEPE6N-AQUtGLhQg@mail.gmail.com>
To: Petr Špaček <pspacek@isc.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Authority-Analysis: v=2.4 cv=cKDQdFeN c=1 sm=1 tr=0 ts=6a7357dd cx=c_pps a=ngMg22mHWrP7m7pwYf9JkA==:117 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=7x6HtfJdh03M6CCDgxCd:22 a=GbPsI2Ihf5RTnMjR_gZv:22 a=SCo1hh1FAAAA:8 a=t3M6Oha4aWn0Rb7Ru94A:9 a=QEXdDO2ut3YA:10 a=yHXA93iunegOHmWoMUFd:22 a=nwb-CePKZZm3gL-ai9HY:22
X-Proofpoint-ORIG-GUID: h4MZEYBpAxWwoo9HgRDPq2QtLopnOyHQ
X-Proofpoint-GUID: h4MZEYBpAxWwoo9HgRDPq2QtLopnOyHQ
X-Proofpoint-Spam-Info: AW1haW4tMjYwODA1MDEyNSBTYWx0ZWRfX2vZ2amdZvpbk AYhULHGED5pUXlqDej24A11dpBXy1TlknB9iJOnLlD2adNoqMybz6FUz323P0EBcFFDGulJ/muu eeF6GjN6onMraIIr2ngv6GoVZnJdgBA=
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA1MDEyNSBTYWx0ZWRfXyF1+BdwwI7oB hqgX2/WZ23mtXO9oxzhJ5QX2Fx/MmpqoHE6wI6RgeBlpqUnPSKQ0VEsz1uNbLjHpcsciYNmCh9T xeWOvm87hbpBau8UcWAIR9pZ5U8k+vbc/xSGFKn6MdHnlprZ4vD/dDZsUus3jrnQFsVq2ykyVx3 SNpc/J6jd5W1QK8lhlh16BzEYZbh1bG0pjnoG9K9Ubw5PE/bOq77zMBluy9sb5UPYFHQnxsAq2g Ay3kVLYah0f5NuzRLbQto/YOh0/H896B3jCIXWrVcYbRbkHFzJdZaKBvn/sKVq0+VWU4iMCvqsw hgpBTQeSjaZdiRKlTvr4Vl0b7eKgCVUhU38eXpwhrStiG6UWmM1wZ5z8lmLy58udzOteou3PbqU 7ZIYOMCdo1cXYfzCPpwdgpBwOrzqjAYqHALCRQRfiYH+XBMLM6a3TLmjK+e3AiJcSuv70DZCx2d B236hWpPBbJQq0tyD6Q==
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-05_04,2026-08-04_02,2025-10-01_01
Message-ID-Hash: BZ62DDA2TAXSBKGXLRFQW4DS5SWFQRIM
X-Message-ID-Hash: BZ62DDA2TAXSBKGXLRFQW4DS5SWFQRIM
X-MailFrom: prvs=6677b029fc=bemasc@meta.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: New Version Notification for draft-bortzmeyer-dnsop-poisonlicious-05.txt
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/QoUWGr6GiXF4QnfLT7oxyo4-OpU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

On Wed, Aug 5, 2026 at 10:54 AM Petr Špaček <pspacek@isc.org> wrote:
> On 04. 08. 26 22:00, Ben Schwartz wrote:
...
> >  My question is whether we should be pursuing this
> > architecture (an O(N) response "broadcast" for cache sharing), as
> > opposed to some other architecture (such as a multilayer cache
> > architecture).  Are you running broadcast-style cache sharing in
> > production?
>
> It does not have to be broadcast, does it? Generally it is discretion of
> the sender to whom it will get delivered, and I would expect great
> variety in strategies here. E.g. not sending NXDOMAINs unless they pass
> some heuristic etc.

Filtering which responses are shared seems plausible.  Delivering
different responses to subsets of the fleet in a useful way seems much
more difficult.

If I were trying to use poisonlicious in a highly optimized
architecture, it would look like this:

1. The stub issues a query.
2. The query hits a dispatcher (dnsdist), which routes it to a
resolver instance based on hash(qname)
3. The resolver starts working, encountering some cache misses along
the way.  On cache miss, it sends an RD=0 (i.e. cache snooping) query
back to the dispatcher, which forwards it to the responsible instance
by hash(qname).
4. If the cache snooping query fails, the resolver queries upstream,
and copies the response to the dispatcher via poisonlicious.
5. The dispatcher forwards the poisonlicious response to the instance
responsible for hash(qname), which adds it to the cache.

If an architecture like this is in scope for poisonlicious, then I
think it would be useful.  I don't see any technical impediment within
the present draft, but perhaps the operational considerations could be
expanded to note the possibility of a dispatcher and "lookaside
snooping" behavior.

--Ben Schwartz