Re: Proposal: a new WRAP UP capsule
David Schinazi <dschinazi.ietf@gmail.com> Wed, 10 July 2024 16:17 UTC
Received: by ietfa.amsl.com (Postfix) id 6CD06C1930D8; Wed, 10 Jul 2024 09:17:11 -0700 (PDT)
Delivered-To: ietfarch-httpbisa-archive-bis2juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B787C18DBB3 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 10 Jul 2024 09:17:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.356
X-Spam-Level:
X-Spam-Status: No, score=-7.356 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLACK=0.5, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org header.b="ZOQamkeP"; dkim=pass (2048-bit key) header.d=w3.org header.b="pZhrDulZ"; dkim=pass (2048-bit key) header.d=gmail.com header.b="Sdm21F+3"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id peLEX8LuFUxP for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 10 Jul 2024 09:17:07 -0700 (PDT)
Received: from mab.w3.org (mab.w3.org [IPv6:2600:1f18:7d7a:2700:d091:4b25:8566:8113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B31AEC18DBBA for <httpbisa-archive-bis2Juki@ietf.org>; Wed, 10 Jul 2024 09:17:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:Content-Type:Cc:To:Message-ID:Date:From:In-Reply-To: References:MIME-Version:Reply-To; bh=WuaEVcJeCjsrIXJb36NFrJgkLPbZ3PvW32q1dtWimI8=; b=ZOQamkePntqDcWi/2LQLdtoPNu FfnzsLz0dpmJyr03AOxeOCiD+s3S1kINAUwoh9x3DzjW2kueQI8JQYAPemA6veaL+01paQgezRene 3pMjM+HGO3iSQ2a4Dk415CpqD9IIGW6tFhUjCDpHuk1FRGm6WhFpE8a12BP4TS+QkbyLeprwTBx8B zvtMMr/MV1EfiJoAcpJd/fZyTEDiwWG/RutnfbGGFNxSZq+CAqy/nsRbEqgq/9pkNPHNYT2XFbMOf CJWNUoLS/b5JKx/JBbWeEyUxf1QOtnUL4pfKfWC+81NgMKgCodks2x7RFEMBQ7fPzuXFrEP1l3sLS Lf9YifCQ==;
Received: from lists by mab.w3.org with local (Exim 4.96) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1sRZzI-00Gttq-0N for ietf-http-wg-dist@listhub.w3.org; Wed, 10 Jul 2024 16:16:12 +0000
Resent-Date: Wed, 10 Jul 2024 16:16:12 +0000
Resent-Message-Id: <E1sRZzI-00Gttq-0N@mab.w3.org>
Received: from ip-10-0-0-224.ec2.internal ([10.0.0.224] helo=puck.w3.org) by mab.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <dschinazi.ietf@gmail.com>) id 1sRZzE-00Gtsr-2W for ietf-http-wg@listhub.w3.internal; Wed, 10 Jul 2024 16:16:08 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Content-Type:Cc:To:Subject:Message-ID:Date:From:In-Reply-To: References:MIME-Version:Reply-To; bh=WuaEVcJeCjsrIXJb36NFrJgkLPbZ3PvW32q1dtWimI8=; t=1720628168; x=1721492168; b=pZhrDulZbbYwRtu7rjNFOZwZwuW4/rYNsDk+HDP7SRpsWR7GtaA1oT8/SBCOmIsfCHa9oGZzbfk DlZCq8jk3jrQUr6gUI7vVYB1RARSJW9tsom1QtV3OEXKVGNSCmPz2H581yNLdQ1VGnm+UjYRK404B IsZ9Ffyij8NNGf1Ev6SGGNiG43QbGTeugB8rbSL55h3cfOiGIvaTPP/6XjCpytx660jAMMFHgWObI Ss5aBmcI3KIZTSYy3kyKDfmV68lLmjeaa2RNyFfoW1SN17yxQ6VVv4adCVvRyUDAYMFZRK0qdxkVw J3F+UQpxGla84l2HyB+uLda8bVJivWzwx9VQ==;
Received-SPF: pass (puck.w3.org: domain of gmail.com designates 2a00:1450:4864:20::52d as permitted sender) client-ip=2a00:1450:4864:20::52d; envelope-from=dschinazi.ietf@gmail.com; helo=mail-ed1-x52d.google.com;
Received: from mail-ed1-x52d.google.com ([2a00:1450:4864:20::52d]) by puck.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from <dschinazi.ietf@gmail.com>) id 1sRZzE-00Gmw6-0B for ietf-http-wg@w3.org; Wed, 10 Jul 2024 16:16:08 +0000
Received: by mail-ed1-x52d.google.com with SMTP id 4fb4d7f45d1cf-58b447c519eso8266876a12.3 for <ietf-http-wg@w3.org>; Wed, 10 Jul 2024 09:16:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1720628164; x=1721232964; darn=w3.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=WuaEVcJeCjsrIXJb36NFrJgkLPbZ3PvW32q1dtWimI8=; b=Sdm21F+3+7ZREWIcPpQJIRqYW1+FHUnDWjEIHN1W+774lqXnNufX73xcrhz1tqpaHT e6dypakHifQzYI9EbU/yq4ZWfdiprKOSeOAc8uTZ5xvhuJQoFMhhCtiP1PmcFGpEIazB w0qouTYX5ZC5LhN2eCu/FkahqXMy6CzUwRAENiheYKXc+4LqPbLpDDsE8Ro3x+txViqz O1CJz2K6jRi6dgR3Agl1TldFDDNxbjq12Kz8j9ZBgWtpwu5IaEMBxp9LBuqPkAXLTnMS 3/jjFZd5Hsv2Cs9sh6ht/NYKtpW6m3Zt22RB618I8MjzWZDqeT1GOsYor045an8vK72g 0bng==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1720628164; x=1721232964; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=WuaEVcJeCjsrIXJb36NFrJgkLPbZ3PvW32q1dtWimI8=; b=ocTYHMW3CbrzDZuWgBHYv0/QAdnf48leGfWHwzunh7wlxT3/h1N0X669SbsAM8mgRR L8NJyd3RTn2nL+vAOZJQBUSbol2m137OxE3oggzHj2E32CpZVRRVm1ctXatCEYOtIDoy teHNFNnk7Qij3rBq8lJvx9bdcoJVnXNgQ9bDJQFBWeoFpFUlrmcMXNGg7ELUupDxHuiF /Be1+NVz/fylkmBmL3+c9e2zJsYsqipw0CxQkuAXfM9c0zU8GebDSjxKs5NyuN6yUmyc zi95g9JZeHpwSB95U6VYFyNFoXQSL4ffeBGu+xXm5O5aZDeXVzDzKxm8veFZgPabXkwW BFQg==
X-Forwarded-Encrypted: i=1; AJvYcCVmaarjhRfHkRTbrkIl2KcBZ82FdxLKkdXRvluBRKJrimZIXMEUk6kHJBcyvYqY3Hxz5Nw/2slS+8Wltm13rNwuCSyJ
X-Gm-Message-State: AOJu0Yzz9wnqAplIYPPqrrLfw0cHeBytyqQn1U3+YDuOq9Yng+T8BFBU XVHyehjyo62ZjS1Pax9ENXCDoqy06i/nGAwnH6Z506sz0E4/GXZeOPbSTPPlAGSzJ2xliMFWRlS nuWDHPanWIozWyxlXVnJYbXw7A/4=
X-Google-Smtp-Source: AGHT+IEt5k88jMQa9jz8wd2Il8RYEVhbQ4WjjkVvekUXunzoCnJmwJIhF2RsfKUx3VUXDShr9P//Ph1flWHXqw6eHJY=
X-Received: by 2002:a17:906:6c93:b0:a75:2387:7801 with SMTP id a640c23a62f3a-a780b885f65mr339740666b.61.1720628163838; Wed, 10 Jul 2024 09:16:03 -0700 (PDT)
MIME-Version: 1.0
References: <CAPDSy+5UU=GSFWTdrkHW7RXNL8pr5KWtLfp8zjExsZvvGczfEw@mail.gmail.com> <7e87de98-6b21-433f-a56f-456557c64a86@betaapp.fastmail.com> <EB88DA6B-0691-4A0D-93A4-8CE23472E9DC@apple.com>
In-Reply-To: <EB88DA6B-0691-4A0D-93A4-8CE23472E9DC@apple.com>
From: David Schinazi <dschinazi.ietf@gmail.com>
Date: Wed, 10 Jul 2024 09:15:52 -0700
Message-ID: <CAPDSy+7De+oFXsecR64X-scUnCMx8v+owHLXhZ14XyyBgpSk1w@mail.gmail.com>
To: Tommy Pauly <tpauly@apple.com>
Cc: Martin Thomson <mt@lowentropy.net>, HTTP Working Group <ietf-http-wg@w3.org>
Content-Type: multipart/alternative; boundary="0000000000007f0b60061ce6f669"
X-W3C-Hub-DKIM-Status: validation passed: (address=dschinazi.ietf@gmail.com domain=gmail.com), signature is good
X-W3C-Hub-Spam-Status: No, score=-4.4
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, DMARC_PASS=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLACK=1.7, URIBL_DBL_BLOCKED_OPENDNS=0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: puck.w3.org 1sRZzE-00Gmw6-0B 3ddf112fbb0f38447ef746461db99c7b
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Proposal: a new WRAP UP capsule
Archived-At: <https://www.w3.org/mid/CAPDSy+7De+oFXsecR64X-scUnCMx8v+owHLXhZ14XyyBgpSk1w@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/52070
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
The main use-case I have in mind is the one where the client sends connect-udp to a proxy, and through that the client establishes an h3 connection to an origin, and then the client sends multiple proxied requests to that origin. If the proxy needs to close this particular connect-udp stream after some number of bytes exchanged, it'll first send WRAP_UP to the client, so that the client can finish its in-flight proxied requests to the origin, but not start any new proxied requests to the origin. David On Tue, Jul 9, 2024 at 6:22 PM Tommy Pauly <tpauly@apple.com> wrote: > > > > On Jul 9, 2024, at 6:10 PM, Martin Thomson <mt@lowentropy.net> wrote: > > > > Hi David, > > > > I think that this is reasonable - if your goal is to suggest that > clients terminate a single CONNECT flow, rather than the entire > connection. This could also be achieved with GOAWAY, but it will affect > multiple flows. The draft doesn't say this, so maybe I'm missing something > important. > > > > How common is it to establish multiple flows through a single proxy? > That might depend on use case (CONNECT-IP might be more profligate than > CONNECT-UDP, say). > > I think you'd generally see the most for CONNECT-TCP and CONNECT-UDP, when > you’re proxying an application like a web browser. CONNECT-IP would > generally be much more limited, and in some cases just be a big VPN tunnel. > > Tommy > > > > > Cheers, > > Martin > > > > On Sat, Jul 6, 2024, at 08:29, David Schinazi wrote: > >> Hi HTTP enthusiasts, > >> > >> Over in MASQUE land, as we're deploying our two-hop proxies, we decided > >> we needed to put a cap on how many bytes we'd allow per > >> token-authenticated connect-udp tunnel. Enforcing a hard limit is easy, > >> but the issue is that if the proxy aborts the tunnel halfway through, > >> the web browser could be halfway through a proxied request. Since the > >> browser doesn't know if the half-finished request was acted on or not, > >> it can't retry it, so it has to surface the error to the user. Instead, > >> we want the proxy to be able to warn the browser that this will happen > >> soon, so that the browser can establish a new tunnel with a new token, > >> and start sending new requests there. Conceptually this is a little > >> like GOAWAY, but instead of "please wrap up this connection", it's > >> "please wrap up this tunnel stream". It uses capsules, since this is a > >> message from proxy to client. Here's a draft with diagrams: > >> > >> https://datatracker.ietf.org/doc/draft-schinazi-httpbis-wrap-up/ > >> > https://davidschinazi.github.io/draft-schinazi-httpbis-wrap-up/draft-schinazi-httpbis-wrap-up.html > >> > >> I'd love to hear your thoughts. > >> > >> Thanks, > >> David > > > > >
- Proposal: a new WRAP UP capsule David Schinazi
- Re: Proposal: a new WRAP UP capsule Martin Thomson
- Re: Proposal: a new WRAP UP capsule Ben Schwartz
- Re: Proposal: a new WRAP UP capsule Valentin Gosu
- Re: Proposal: a new WRAP UP capsule Lucas Pardue
- Re: Proposal: a new WRAP UP capsule David Schinazi
- Re: Proposal: a new WRAP UP capsule Dustin Mitchell
- Re: Proposal: a new WRAP UP capsule Ben Schwartz
- Re: Proposal: a new WRAP UP capsule Lucas Pardue
- Re: Proposal: a new WRAP UP capsule David Schinazi
- Re: Proposal: a new WRAP UP capsule Tommy Pauly
- Re: Proposal: a new WRAP UP capsule David Schinazi