Re: [Int-dir] [Last-Call] Intdir telechat review of draft-ietf-masque-connect-ip-10

"touch@strayalpha.com" <touch@strayalpha.com> Wed, 19 April 2023 18:30 UTC

Return-Path: <touch@strayalpha.com>
X-Original-To: int-dir@ietfa.amsl.com
Delivered-To: int-dir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7C13C151B01; Wed, 19 Apr 2023 11:30:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.216
X-Spam-Level:
X-Spam-Status: No, score=-6.216 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NEUTRAL=0.779, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=strayalpha.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SYFIo8GQrhNr; Wed, 19 Apr 2023 11:30:03 -0700 (PDT)
Received: from server217-2.web-hosting.com (server217-2.web-hosting.com [198.54.115.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D4EBFC152D9A; Wed, 19 Apr 2023 11:30:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=strayalpha.com; s=default; h=To:References:Message-Id:Cc:Date:In-Reply-To: From:Subject:Mime-Version:Content-Type:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=a5/MjNSvJterWlqE4ZDkccod8NxXL7Ipx2h0UGC93aY=; b=2xC9KLNkmpBI362KEYi06NDEtz Ke99crDA/ZBUeDL5nHrpWtFr/J2Fyoqfjg59VRqcrl6d0lCoTmddiztWwZjWu/L5bWNT7r7BdwGWV 3r3DVBUx2SDWrtKntJH2UMJdyfYiNNyiZ9LITcs2HOYCnaXKx2khEzI3ggxOO3v3wcj70MiFQDTlP ax/42xoOtkfSijMc0zdMLlzLCybSYW8eIQuwkZIL29a0K+Z/Knvb/rLV7a2bjOnpEcI/876zgB1gY +UPxhUJjyF1tciKmIgOG4oo+8FtHSQNXjX9BKEXfz6Hfl5kzxncaHud1KjUPHIjYigKHYJK9vzUPh d5dzbZag==;
Received: from [172.58.208.248] (port=48791 helo=smtpclient.apple) by server217.web-hosting.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <touch@strayalpha.com>) id 1ppCZ1-001OkR-1M; Wed, 19 Apr 2023 14:30:01 -0400
Content-Type: multipart/alternative; boundary="Apple-Mail=_9B6D52A2-392A-4B26-9D9D-6A4086C2DB9A"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.500.231\))
From: "touch@strayalpha.com" <touch@strayalpha.com>
In-Reply-To: <70EF67A5-7C4D-4E0E-8058-15EBA4A59095@ericsson.com>
Date: Wed, 19 Apr 2023 11:29:43 -0700
Cc: David Schinazi <dschinazi.ietf@gmail.com>, Magnus Westerlund <magnus.westerlund@ericsson.com>, "int-dir@ietf.org" <int-dir@ietf.org>, "draft-ietf-masque-connect-ip.all@ietf.org" <draft-ietf-masque-connect-ip.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "masque@ietf.org" <masque@ietf.org>
Message-Id: <5595EF59-79AF-4952-A2C0-3DD26D02A978@strayalpha.com>
References: <168152936276.58402.12408511926010382248@ietfa.amsl.com> <CAPDSy+5ZOnK02VgJY7giVD0uNM4ao7-gHXUhrf6BG9RWxzC+RQ@mail.gmail.com> <19AB5170-D789-491C-B748-7AD5CE26B58C@strayalpha.com> <DU0PR07MB8970FC2DDE02B2BBB78D6E33959D9@DU0PR07MB8970.eurprd07.prod.outlook.com> <CAPDSy+72wpWzsQur=Bsvf7bUAxCAzq=OnXDS6Uxr7-k-3ZS-0Q@mail.gmail.com> <DA3F26DF-5B5F-4045-AA67-2BDEDCCA7975@strayalpha.com> <CAPDSy+7cf=ONtQw4Sfy4u51i6txk9K7axhyz6nx=_vic35DWtQ@mail.gmail.com> <4F486987-90BB-480A-9A0E-2E09BC4F1B72@strayalpha.com> <70EF67A5-7C4D-4E0E-8058-15EBA4A59095@ericsson.com>
To: Mirja Kuehlewind <mirja.kuehlewind=40ericsson.com@dmarc.ietf.org>
X-Mailer: Apple Mail (2.3731.500.231)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server217.web-hosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - strayalpha.com
X-Get-Message-Sender-Via: server217.web-hosting.com: authenticated_id: touch@strayalpha.com
X-Authenticated-Sender: server217.web-hosting.com: touch@strayalpha.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-From-Rewrite: unmodified, already matched
Archived-At: <https://mailarchive.ietf.org/arch/msg/int-dir/3W7OGQ9N-X4Mw987dYC3-UlwspI>
Subject: Re: [Int-dir] [Last-Call] Intdir telechat review of draft-ietf-masque-connect-ip-10
X-BeenThere: int-dir@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This list is for discussion between the members of the Internet Area directorate." <int-dir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/int-dir>, <mailto:int-dir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/int-dir/>
List-Post: <mailto:int-dir@ietf.org>
List-Help: <mailto:int-dir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/int-dir>, <mailto:int-dir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Apr 2023 18:30:07 -0000

Hi, MIrja,

Agreed it doesn’t apply to all transports, but one of the transports is TCP.

For QUIC, this goes towards any parameters that can be set per connection.

Joe
—
Dr. Joe Touch, temporal epistemologist
www.strayalpha.com

> On Apr 19, 2023, at 10:36 AM, Mirja Kuehlewind <mirja.kuehlewind=40ericsson.com@dmarc.ietf.org> wrote:
> 
> Hi Joe, hi all,
>  
> I would just quickly reply to the following part:
>  
> David: I've seen literature about nested TCP, which is both nested congestion control and nested loss recovery. In my understanding, the majority of the issues come from the two layers retransmitting the same data, not from the nested congestion controllers. 
>  
> Joe: The lower one slams the window down due to loss; the upper one should never really see loss at all (given it’s running over TCP), but every time a loss and retransmit occurs, the RTT measurements at the upper layer take a hit. So the bottom layer does what it can, but the upper layer gets into regimes where it thinks it can send more (RTT BW*delay) than it really can, which then causes process stalls at the upper layer.
>  
> Joe, this is not correct if QUIC datagrams are used as datagrams are no retransmitted and thus losses will be exposed to the tunneled connection without delay avoiding time-outs in the upper layer congestion control. This is what David meant by nested loss recovery. This may also have implications on congestion control but it’s probably less problematic.
>  
> Mirja
>  
>  
>  
>  
> From: "touch@strayalpha.com" <touch@strayalpha.com>
> Date: Wednesday, 19. April 2023 at 19:26
> To: David Schinazi <dschinazi.ietf@gmail.com>
> Cc: Magnus Westerlund <magnus.westerlund@ericsson.com>, "int-dir@ietf.org" <int-dir@ietf.org>, "draft-ietf-masque-connect-ip.all@ietf.org" <draft-ietf-masque-connect-ip.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "masque@ietf.org" <masque@ietf.org>
> Subject: Re: [Last-Call] [Int-dir] Intdir telechat review of draft-ietf-masque-connect-ip-10
> Resent from: <alias-bounces@ietf.org>
> Resent to: <magnus.westerlund@ericsson.com>, <Zaheduzzaman.Sarker@ericsson.com>, <mirja.kuehlewind@ericsson.com>, <achernya@google.com>, <ekinnear@apple.com>, <tpauly@apple.com>, <caw@heapingbits.net>, <dschinazi.ietf@gmail.com>, <martin.h.duke@gmail.com>
> Resent date: Wednesday, 19. April 2023 at 19:25
>  
> Hi, David,
>  
> More below…
>  
> Joe
> —
> Dr. Joe Touch, temporal epistemologist
> www.strayalpha.com <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-9fdeb710e124f19f&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=http%3A%2F%2Fwww.strayalpha.com%2F>
> 
> 
>> On Apr 19, 2023, at 9:46 AM, David Schinazi <dschinazi.ietf@gmail.com> wrote:
>>  
>> Thanks, more discussion inline.
>> David
>>  
>> On Tue, Apr 18, 2023 at 9:36 PM touch@strayalpha.com <mailto:touch@strayalpha.com> <touch@strayalpha.com <mailto:touch@strayalpha.com>> wrote:
>>> On Apr 18, 2023, at 7:00 PM, touch@strayalpha.com <mailto:touch@strayalpha.com> wrote:
>>> 
>>> Hi, David and Magnus,
>>> 
>>> Replies below, cutting to the remaining issues…
>>> (Trying again - I got reports of mail failures)
>>> 
>>> Joe
>>> —
>>> Dr. Joe Touch, temporal epistemologist
>>> www.strayalpha.com <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-9fdeb710e124f19f&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=http%3A%2F%2Fwww.strayalpha.com%2F>
>>> 
>>> > On Apr 18, 2023, at 5:26 PM, David Schinazi <dschinazi.ietf@gmail.com <mailto:dschinazi.ietf@gmail.com>> wrote:
>>> > 
>>> > Thanks Joe and Magnus for the replies.
>>> > Some more responses inline.
>>> > David
>>> > 
>>> > On Tue, Apr 18, 2023 at 1:23 AM Magnus Westerlund <magnus.westerlund@ericsson.com <mailto:magnus.westerlund@ericsson.com>> wrote:
>>> >> Hi,
>>> >>  
>>> >> Please see inline. Prefix with “MW:”
>>> …
> ...
> 
>>> >> It is missing the way in which these ingress/egress
>>> >> components are viewed a their endpoints, e.g., to be useful as an IP tunnel,
>>> >> these need to appear as attached to (possibly virtual) network interfaces,
>>> >> i.e., to appear as a link, which allows them to then be used for local
>>> >> processes (via sockets), packet forwarding, etc. 
>>> >> That's an implementation detail that doesn't belong in this document. Most
>>> >> implementations will indeed use virtual TUN interfaces, but it's not a requirement.
>>> >> There is a known implementation with transport protocols in userspace that doesn't
>>> >> do what you describe. 
>>> >> Whether a TUN interface is used or some other method, there needs to be a method by which these applications (client, server) present something that accepts IP packets.
>>> >>  
>>> >> That aspect of how this is actually used is ignored and needs to be addressed. It does not need to be implementation specific, but it would not hurt to give an example like TUNs.
>>> >>  
>>> >> (The fact that other user-space IP systems ignore this issue is not rationale for this document also ignoring it)
>>> >>  MW: I don’t see how any text can be other than informational. Considering the below discussion. Are you asking for a general discussion of the boundaries between the routing and the link the tunnel that this construct results in, especially as it puts some traffic filtering rules in front of the encapsulation that affects the routing?
>>> I’m asking for both the routing and endpoint behaviors to be described in relation to the tunnel.
>>> >> https://github.com/ietf-wg-masque/draft-ietf-masque-connect-ip/issues/165 <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-d6151ec7d70291ca&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=https%3A%2F%2Fgithub.com%2Fietf-wg-masque%2Fdraft-ietf-masque-connect-ip%2Fissues%2F165>
>>> > I think I now understand what Joe was saying. We didn't make it clear enough that this document specifies a (virtual) link with routers attached to it. The IP proxying endpoints both act as routers that are connected by this virtual link. That's why we talk about having them send ICMP. Adding some text to clarify this should help. We'll cover this in issue 165.
>>> 
>>> If that’s what you’re defining, it is incorrect. It can’t be a router. If it were and traffic were to go from tunnel to real interface, it would have its IP decremented twice, which is inconsistent with RFC1812.
>>> 
>>> This is a tunnel. It should not try to be a router or a host. It can’t issue ICMPs properly esp. because it can’t take into consideration the relation of this tunnel to other interfaces, the endpoint and its rules for ICMP (per RFC1122) or a router and its rules for ICMP (per RFC1812).
>>> 
>>> What you are describing is not a convenience. It’s *incorrect*. I’ve noted that in the text deleted between here and the next issue (see past emails for that detail).
>>  
>> Perhaps another way to present this is that connect-ip is a virtual link with a half router on each side, but that gets harder to reason about.
>  
> Yes, and it should ;-)
> 
> 
>> In practice, we do need some router functionality here to ensure that a packet that loops between virtual connect-ip links will have its TTL decremented to prevent infinite loops.
>  
> But you do not. You should not be doing any forwarding at all - tunnels are links, not routers or half-routers. Links don’t decrement the TTL. If they did, they’d give the wrong answer to traceroute, etc.
> 
> 
>> That can be implemented by sending packets through the kernel, but some implementations might want to handle that all in the connect-ip process to improve performance - and we need to make sure those implementers don't forget to decrement the TTL.
>  
> That’s up to the user but outside the scope of a tunnel. This tunnel should be something that both can be to a TUN device, a user router, etc.
>  
> All devices and processes that relay packets *between* interfaces need to make sure they decrement and check the TTL - that’s already in RFC1812. It is not the job of the tunnel to make sure that happens.
>  
>>  
>>> >> As other reviewers have noted, Sec 10 on nested congestion control is quitethin. The current statement is equivalent to “if you KNOW congestion is nested,
>>> >> turn it off” – it should be the opposite, i.e., “turn congestion ON only if you
>>> >> KNOW congestion is NOT nested”. 
>>> >> Fair enough. We're tweaking that section to be more permissive:
>>> >> https://github.com/ietf-wg-masque/draft-ietf-masque-connect-ip/pull/162It <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-0bda028fcb666bc9&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=https%3A%2F%2Fgithub.com%2Fietf-wg-masque%2Fdraft-ietf-masque-connect-ip%2Fpull%2F162It>’s not about allowing congestion control to be disabled; that needs to be a SHOULD, with the caveat that when it is not, performance can suffer in ways that are difficult to predict.
>>> >> MW: I agree, and we could actually say SHOULD in that text under those constraints rather than MAY. However, doing this disabling first of all requires support of the DATAGRAM extension and will require changes to the QUIC stack that might not be possible in all deployment scenarios. And it can’t be done in general as some usage of this tunnel specification might happen over other HTTP versions than HTTP/3 that uses TCP.
>>> >>  https://github.com/ietf-wg-masque/draft-ietf-masque-connect-ip/issues/164 <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-207846dd839cd796&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=https%3A%2F%2Fgithub.com%2Fietf-wg-masque%2Fdraft-ietf-masque-connect-ip%2Fissues%2F164>
>>> “It can’t be done” in some cases - that can be used as a rationale for implementers not following the SHOULD (i.e., the reason for an exception). 
>>> 
>>> > I personally don't think a SHOULD is reasonable here. We don't have enough data to demonstrate that this advice is always sound. My personal experience is that nested congestion control loops work fine in practice. (Note that this is nested congestion control, not nested loss recovery.) Whether this should be done or not is very dependent on the deployment environment. Adding some text warning of the risks is always good, but a normative recommendation is a step too far.
>>> 
>>> This isn’t an issue for anecdotal discussion; it’s been proven in the literature. Nested control loops are never stable unless they’re specifically designed to do so, and two instances of the same control with the same parameters (TCP on TCP, esp. if the same variant) is particularly bad.
>>> 
>>> I’m suggesting normative SHOULD with specific exceptions that can include places where it can’t be done.
>>  
>> I've seen literature about nested TCP, which is both nested congestion control and nested loss recovery. In my understanding, the majority of the issues come from the two layers retransmitting the same data, not from the nested congestion controllers.
>  
> The lower one slams the window down due to loss; the upper one should never really see loss at all (given it’s running over TCP), but every time a loss and retransmit occurs, the RTT measurements at the upper layer take a hit. So the bottom layer does what it can, but the upper layer gets into regimes where it thinks it can send more (RTT BW*delay) than it really can, which then causes process stalls at the upper layer.
>  
>> I haven't seen literature about nested congestion control without nested loss recovery.
>  
> See above; it’s not nested loss recovery because that won’t happen.The issue is that the parameters that determine the combined flow/congestion control windows interact very badly.
> 
> 
>> If you squint hard enough, any IP router connected to heterogeneous links is a congestion controller because if the input link is getting more packets in than the output link can handle, the router will drop some of them. In that world view, almost every TCP connection on the Internet involves nested congestion controllers, and it's working quite well.
>  
> An IP router that changes paths a lot will impact TCP, yes. But the drops are also why we use RED-like (non-tail) drops and ECN; that doesn’t happen with TCP over TCP. They’re not equivalent.
> 
> 
>>  
>>> >> Section 11.1 refers to fragmented packets; it should refer to them as not being
>>> >> able to be “re-fragmented”; source-generated fragments are still fragmented and
>>> >> can cross the tunnel subject to the tunnel MTU. 
>>> >> The use of "fragmented" in that section refers to QUIC datagram frames, which
>>> >> cannot be fragmented - this isn't about IP fragmentation. 
>>> >> The section talks about whether IP packets can fit inside QUIC datagram frames.
>>> >>  
>>> >> Fragmentation of those packets can - and will - happen when those packets are generated on the host where the packets enter the tunnel, unless the host decides to force “don’t fragment” on those packets. That’s a decision that happens (could happen or should happen, depending on your viewpoint) before the packets ever get to the tunnel ingress.
>>> >>  
>>> >> On-path fragmentation of IPv4 packets relayed to the IP proxy happens (could happen or should happen, again depending on your viewpoint) before those packets ever get to the tunnel ingress.
>>> >>  
>>> >> Either of those can happen - even if QUIC datagrams sit inside IP packets with DF=1 (or IPv6) that are also not source fragmented.
>>> >>  
>>> >> MW: So I think this may need a bit of wording clean up and also clarification of the conceptual model. If I understand Joe correct here a reasonable way of looking on this is that when a packet arrive at the router part with this tunnel as one of its interfaces, the router part will have some knowledge of the current tunnel MTU. The tunnel itself will not refragement the data, but it will support a particular MTU. Thus, the router part can actually fragment an IPv4 packet that doesn’t have the DF bit set and send it into the tunnel. And in relation to discussion about ICMP generation. It will be the router part that generates the ICMP when the routing decision says send it over the tunnel, but the tunnel MTU is too small for the packet to fit. 
>>> And, FWIW, that’s another reason why the routing part belongs outside of the tunnel. It’s not just routing, it’s also endpoint (source) behavior. The tunnel has no business trying to replicate this behavior when it’s already part of the endpoint system (if it weren’t, then HTTP over X over IP wouldn’t be available as a tunnel mechanism).
>>> >> https://github.com/ietf-wg-masque/draft-ietf-masque-connect-ip/issues/165 <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-d6151ec7d70291ca&q=1&e=25fc5d7d-7043-473a-8286-0a3d32303711&u=https%3A%2F%2Fgithub.com%2Fietf-wg-masque%2Fdraft-ietf-masque-connect-ip%2Fissues%2F165>
>>> > I agree with Magnus, if we clarify the split between link and router then this becomes natural.
>>> 
>>> I agree with the split, but the router cannot be part of this mechanism.
>>  
>> In practice, implementers of connect-IP will often implement part of the router function, so it's useful to mention it so folks don't forget important parts. Phrasing it as not a part of the mechanism and instead as a part of the overall environment is reasonable.
>  
> I appreciate that this discussion talks a lot about not including implementation details - I’ll use that justification here.
>  
> Whether users commonly implement user-level routers or not, that doesn’t belong in the spec for a tunnel.
>  
> ---
>  
> _______________________________________________
> Int-dir mailing list
> Int-dir@ietf.org
> https://www.ietf.org/mailman/listinfo/int-dir