Re: Adoption call for draft-schwartz-httpbis-optimistic-upgrade

Willy Tarreau <w@1wt.eu> Sat, 27 January 2024 07:17 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 32A37C14F6F6 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 26 Jan 2024 23:17:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.657
X-Spam-Level:
X-Spam-Status: No, score=-2.657 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EqVWbZSa0xuD for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 26 Jan 2024 23:17:09 -0800 (PST)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D85C6C14F6B5 for <httpbisa-archive-bis2Juki@ietf.org>; Fri, 26 Jan 2024 23:17:09 -0800 (PST)
Received: from lists by lyra.w3.org with local (Exim 4.94.2) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1rTcvx-00Dluo-4w for ietf-http-wg-dist@listhub.w3.org; Sat, 27 Jan 2024 07:16:57 +0000
Resent-Date: Sat, 27 Jan 2024 07:16:57 +0000
Resent-Message-Id: <E1rTcvx-00Dluo-4w@lyra.w3.org>
Received: from titan.w3.org ([128.30.52.76]) by lyra.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <w@1wt.eu>) id 1rTcvv-00Dltn-NQ for ietf-http-wg@listhub.w3.org; Sat, 27 Jan 2024 07:16:55 +0000
Received: from ded1.1wt.eu ([163.172.96.212] helo=1wt.eu) by titan.w3.org with esmtp (Exim 4.94.2) (envelope-from <w@1wt.eu>) id 1rTcvt-009Zdd-1S for ietf-http-wg@w3.org; Sat, 27 Jan 2024 07:16:55 +0000
Received: (from willy@localhost) by pcw.home.local (8.15.2/8.15.2/Submit) id 40R7Gk4X013357; Sat, 27 Jan 2024 08:16:46 +0100
Date: Sat, 27 Jan 2024 08:16:46 +0100
From: Willy Tarreau <w@1wt.eu>
To: Tommy Pauly <tpauly@apple.com>
Cc: HTTP Working Group <ietf-http-wg@w3.org>
Message-ID: <20240127071646.GC13227@1wt.eu>
References: <DC01619C-3B1C-4AE8-B331-56B1CE3E7120@apple.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <DC01619C-3B1C-4AE8-B331-56B1CE3E7120@apple.com>
User-Agent: Mutt/1.10.1 (2018-07-13)
Received-SPF: pass client-ip=163.172.96.212; envelope-from=w@1wt.eu; helo=1wt.eu
X-W3C-Hub-Spam-Status: No, score=-4.9
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, W3C_AA=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: titan.w3.org 1rTcvt-009Zdd-1S cd4998c621cb75d09f4d045bebe1f10d
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Adoption call for draft-schwartz-httpbis-optimistic-upgrade
Archived-At: <https://www.w3.org/mid/20240127071646.GC13227@1wt.eu>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/51744
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

On Tue, Jan 23, 2024 at 09:41:39AM -0800, Tommy Pauly wrote:
> Hello HTTP,
> 
> This email starts a working group adoption call for "Security Considerations
> for Optimistic Use of HTTP Upgrade",
> draft-schwartz-httpbis-optimistic-upgrade. Notably, this updates RFC 9298
> (connect-udp, which was produced by the MASQUE WG) on how to handle HTTP
> Upgrade, including to disallow optimistic data sending for HTTP/1.1.
> 
> The document can be found here:
> 
> https://datatracker.ietf.org/doc/draft-schwartz-httpbis-optimistic-upgrade/
> https://www.ietf.org/archive/id/draft-schwartz-httpbis-optimistic-upgrade-00.html
> 
> This adoption call will last for 3 weeks, until Tuesday, February 13. Please
> reply to this email with your reviews and comments, and whether or not you
> think HTTPBIS should adopt this draft.

I support adoption. Such a work has long been needed, there have been
concerns around the risk of uploading data before the handshake completes
since at least the work that led to WebSocket, where it was decided that
the client had to make use of the server's response in part (but not only)
to make sure it couldn't send before the 101 status was received.

Thanks,
Willy