[IPv6]Re: Call for adoption: draft-iurman-6man-eh-occurrences-02 (Ends 2026-05-17)
Tom Herbert <tom@herbertland.com> Thu, 23 April 2026 18:37 UTC
Return-Path: <tom@herbertland.com>
X-Original-To: ipv6@mail2.ietf.org
Delivered-To: ipv6@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 503F1E1E6BDB for <ipv6@mail2.ietf.org>; Thu, 23 Apr 2026 11:37:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776969440; bh=xFZVfsREaMztn1VI0sjDkzeukA4FeWAmT245M3Gsnjw=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=rAFCDFqbOFG6fkIdFV//xkNlDm/erAD9Fszus3Wcfe/zWGoB4WlIwxeQQtylTlxws PV6e4oAiQ5lVKfoXxUD3/osRCBTRgHO3dW2QW0aVMwJSKTFaUnVqRwaOU0IffFkCcj n/MdZ1Df7DoNU0QDsr8Xq0FM0IL4soVIYLR9p5f0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=herbertland.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZuTiPePDNati for <ipv6@mail2.ietf.org>; Thu, 23 Apr 2026 11:37:18 -0700 (PDT)
Received: from mail-lj1-x22f.google.com (mail-lj1-x22f.google.com [IPv6:2a00:1450:4864:20::22f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D0BC1E1E67E9 for <ipv6@ietf.org>; Thu, 23 Apr 2026 11:36:50 -0700 (PDT)
Received: by mail-lj1-x22f.google.com with SMTP id 38308e7fff4ca-38e91416cc0so76063541fa.1 for <ipv6@ietf.org>; Thu, 23 Apr 2026 11:36:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1776969409; cv=none; d=google.com; s=arc-20240605; b=SQfJgy1J7dw32yJ/XdHhh/6aOXQoafmVmvj0QqlSB2b+JjlM1OJXXwj+DyzbiEsRrz zo0O30zd7t8igS7bQGwmLruXkmX1XzBl1Eas0DNH6Ro72IcDmrrxSS1Gdo56xfo7/AaW UOB+myYK4eALKrS6wlYRrrECM8vRiH2o0THILfRfJgUORS5mJckP7wY+VsUSjUzuWk8x RBsvAllrp/9WbpEBzAPOwSig75GjwAO7kXZl7SxcnsW1+i3VHzqfXYihIUH6Kg2sBNFz tbvahQzXbgO6ZgM/0/BlUPeHuLa7sglhlNVIyobznDY4mC32OEHewJY3MPqHtMtLCH3q 6Lkg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=q4q+xHpPIbCYGSxkBu92AfCYzVJBlQbamWYe2cS9kCk=; fh=2Rur/NyL6QA6RPelzZaiKu9FMV65coJS5MhA1LIQwQo=; b=lfm1DBkHr+NnxnK5mHOHq06VDXUv+eOIIqZOtWG2F++3FCt6hTXfQCk1PEVLfQXi83 qT9V4048bXC+X3XiNBWRi9t006sogn4gkvSHksFKf7cfSHsa1ep+GMDyAhXT9fi1quDM MQxlemRBAuEFr4mQc5F/vB9+gw0i5QIeBypvDHEIa+s7KV1RxLrx/M4TXFmewWjbYx0Q oEQoC+e4KbNyDJ4BISBdfH/Oc1lhU115Ad/7CfTWNjcX0a/NZUAOpM8BK926AZlgvZNE +uI+73tzRvHsT2e59l3ZT4dmASgmDChUfArW7kV1Q1lfz/VNnH6bQyeR8ml00kclVgSS Pi3A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=herbertland.com; s=google; t=1776969409; x=1777574209; darn=ietf.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=q4q+xHpPIbCYGSxkBu92AfCYzVJBlQbamWYe2cS9kCk=; b=Ny9JfpgMf84Lw/n9iMRHdSIxq7PV7iiUuJCgg1FxeZJdpWL1AtdsNKFiDTXm4oahux 4sI8vCF3uQTmt5TfjK3okCUW7QKo+bVTrySPo70/fxW3KYs0TrKwtT+kMNsjPxQDto59 pA0POkAT38b7D6CWkkXnFXDodIeU2suN6BE+ZnUfjaYKtNrQEGvXg3Gqigf772BbHGQf tUqsgLtb6DSKPR3D3hPGDQmb6sBu3CPmL+bD4BC6bP7qztMyLfjEb12veODhVxI7SRZh E7pqMxnB94Uiyx6i4S8IJuyGWjSRibeigL5SCr4yDKnDCfhp1tXew71X+QalSy2AE1co D+QQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776969409; x=1777574209; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=q4q+xHpPIbCYGSxkBu92AfCYzVJBlQbamWYe2cS9kCk=; b=CzIsLhPFhkd+A1pTA4NxmRjHDKot8YE7o548xR9POodCsGR55leXZ257RiDGGeiYc0 kpB9fQXBcLOMTkzjL3uKMWY1G6FTSEj326f5kc9sbvmMfmcE+zpdTuywszAwURx7KJ8N 1AOXojYGI1Ldb3sMnlV0hNhBOUnTrTXZpACaQRYpszW1+1NMcMIuhOj+wyznpu+8s1E3 EG1FAzMRo+yI/CM5Wy2yQ0p00rJ3QP8T1NJldzSLRHnI2ShCX2bQMwJEqXcPVtbacyYw 4Rzc3NnqSq2RzsQWsVWr/w+SWGoPaaJbnU7MpDMKk4C9ZV2ZXXoL6vXOqfX4wYdUb4jM CCkw==
X-Forwarded-Encrypted: i=1; AFNElJ+fh2upoQ7tFa92mFPnAxiZWzw7fdxYSzIOAjMdviuTDWFwP67G6N8YPPEOpnPX2eV9gXb9@ietf.org
X-Gm-Message-State: AOJu0YwLGfB/57gk5bwif6FMNzrQJRMBX/kpritTey6RYH43g6r0NSVl yA9n31tR5lPHLKI4QnpA/Y/hOk5HeQnjN1j63gCybQskTxTOuTHq+ewzi9DdptUCZTjftVvgHxT fO5T9SUFZJ6eSclN6BhzvPmd5dOvn9rsD4QGbVLpcP3HHEqbCrCgtDw==
X-Gm-Gg: AeBDieu8sUFSqtz7Lsu2ZpOikQOE4J9dDw1q535gv6vPkVEER4hkM94N62E96GSJ5Xx ezpbd5qAGpLLVqwUNS/kl4sqwUUXd8DaFa4DWLNvy/4V6dFMirK4uVCXSTa4T8gBE3C9at4QWXp iKzKF1ZsoGjy2S71mNC5sZczvxT15trGme17PfiwOezJCI9L81pQ6cnCGTUGoDV24A9WYWw+4TN EnECamoKH+M9fLDhCUIl6FSIK6BPvfyHOQHd99sm+Wz5iLjIeLINmW7PnMk+lgDy/Z+xfMUP98J J0iE5zR61ANnTbXuWKCG1I943jSZqdeiEidPO7VFAXAUq5WeIzk5vu8aEABWIujxZ6ayDDOY23Y 343pPUz0=
X-Received: by 2002:a2e:8e95:0:b0:38f:7fd0:1c5f with SMTP id 38308e7fff4ca-38f7fd01f83mr54073651fa.14.1776969409306; Thu, 23 Apr 2026 11:36:49 -0700 (PDT)
MIME-Version: 1.0
References: <177684315758.1032515.10043189142937925605@dt-datatracker-b45949c58-5szpr> <DB9PR07MB7946A6120EBC74D09587DDB7A02D2@DB9PR07MB7946.eurprd07.prod.outlook.com> <a79fe228-cad5-435b-b132-48fff1ec4bcf@gmail.com> <DB9PR07MB7946C8579623E92C84A800B9A02A2@DB9PR07MB7946.eurprd07.prod.outlook.com> <e27b6b5d-656b-40e8-8604-4d776ffac8df@gmail.com>
In-Reply-To: <e27b6b5d-656b-40e8-8604-4d776ffac8df@gmail.com>
From: Tom Herbert <tom@herbertland.com>
Date: Thu, 23 Apr 2026 11:36:37 -0700
X-Gm-Features: AQROBzBbUpR6wS3IOnI6z8iBmQtPX05EtDO4JJt51Trh2BotAz50f4b3feSIrs0
Message-ID: <CALx6S35Ca6RK3xjvAcdto2KZMc3NpX17G=KkviLCB6JZR34jcQ@mail.gmail.com>
To: Justin Iurman <justin.iurman@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: 2WFUQYNMDOHJYPT5QDNUPDU64THQOVFM
X-Message-ID-Hash: 2WFUQYNMDOHJYPT5QDNUPDU64THQOVFM
X-MailFrom: tom@herbertland.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipv6.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tom petch <ietfc@btconnect.com>, "ipv6@ietf.org" <ipv6@ietf.org>, "6man-chairs@ietf.org" <6man-chairs@ietf.org>, "draft-iurman-6man-eh-occurrences@ietf.org" <draft-iurman-6man-eh-occurrences@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPv6]Re: Call for adoption: draft-iurman-6man-eh-occurrences-02 (Ends 2026-05-17)
List-Id: "IPv6 Maintenance Working Group (6man)" <ipv6.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/5YAGsof5GI6dNMK-gWgC5SqNZYo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Owner: <mailto:ipv6-owner@ietf.org>
List-Post: <mailto:ipv6@ietf.org>
List-Subscribe: <mailto:ipv6-join@ietf.org>
List-Unsubscribe: <mailto:ipv6-leave@ietf.org>
On Thu, Apr 23, 2026 at 10:23 AM Justin Iurman <justin.iurman@gmail.com> wrote: > > Hi Tom, > > On 4/23/26 12:57, tom petch wrote: > > From: Justin Iurman <justin.iurman@gmail.com> > > Sent: 22 April 2026 15:54 > > > > Hi Tom, > > > > As Tom (the other one :D) mentioned, ICMPv6 errors are the indication. > > The draft says: "[...] MAY send an ICMP Parameter Problem message > > [...]". Yes, it is only a "MAY", but "SHOULD" or "MUST" would probably > > be too strong here. OTOH, RFC8200 recommends (although without normative > > language) to respect the specified ordering and number of occurrences. I > > don't have data to support what I'm about to say, but, I'm pretty sure > > there is no legitimate packet out there with out-of-order or > > more-than-allowed Extension Headers. Such packets should be flagged as > > suspicious, and dropping them seems reasonable anyway. > > > > <tp> > > It is the 'MAY' that catches my attention and drives me to respond. I find that too vague for an update to IPv6. By now we should be nailing IPv6 down much tighter IMHO. > > [JI] We'll have plenty of time to discuss s/MAY/SHOULD (or are you > thinking MUST?) after the adoption. Actually, looking at RFC8883 the ICMP errors for reporting packet drops by routers are a SHOULD to send. Probably, it makes sense to use SHOULD here as well. > > > And as I said in my other post. if there is no such legitimate packet out there, then is it worth the effort of creating an RFC which updates the existing IPv6 ones? IMHO, no; if it is worth doing, then we should do it more thoroughly. It depends on what you mean by "legitimate". If someone launches a DOS attack on a host by packing 700 Destination Option headers into single MTU sized packet is that a legitimate packet? :-) Tom > > [JI] IMHO, hosts need to be allowed to protect themselves against > abusive use of EHs. Right now, it's too permissive, as RFC8200 expects > them to process pretty much anything. Not having such legitimate packet > out there (theoretically) does not mean that malicious ones do not exist. > > Justin > > > Cheers, > > Justin > > > > On 4/22/26 13:26, tom petch wrote: > >> So packets may vanish into a black hole without any warning and with no indication what is going on. > >> > >> It sounds like an idea that needs more thinking through. How can I tell that this is why my packets are vanishing and what I should do about it? You really need something somewhere to tell users about these boxes which have a built-in black hole that you cannot detect (like most black holes). > >> > >> Tom Petch > >> > >> ________________________________________ > >> From: Jen Linkova via Datatracker <noreply@ietf.org> > >> Sent: 22 April 2026 08:32 > >> > >> This message starts a 6man WG Call for Adoption of: > >> draft-iurman-6man-eh-occurrences-02 > >> > >> This Working Group Call for Adoption ends on 2026-05-17 > >> > >> Abstract: > >> Operational experience has demonstrated that permitting multiple > >> occurrences of the same IPv6 Extension Header can create parsing > >> ambiguity, complicate packet processing, and increase potential > >> security risks. Although RFC 8200 recommends that senders follow a > >> specific order of appearance and limit the occurrences of Extension > >> Headers, receivers cannot assume that these recommendations have been > >> followed. This document updates RFC 8200 by allowing an IPv6 > >> destination node, namely a host (i.e., the final destination of an > >> IPv6 packet) or an intermediate destination node addressed by an > >> entry in a Routing header list other than the final one, to enforce > >> strict ordering and limits on the occurrence of Extension Headers. > >> > >> Please reply to this message and indicate whether or not you support adoption > >> of this Internet-Draft by the 6man WG. Comments to explain your preference > >> are greatly appreciated. Please reply to all recipients of this message and > >> include this message in your response. > >> > >> Authors, and WG participants in general, are reminded of the Intellectual > >> Property Rights (IPR) disclosure obligations described in BCP 79 [2]. > >> Appropriate IPR disclosures required for full conformance with the provisions > >> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. > >> Sanctions available for application to violators of IETF IPR Policy can be > >> found at [3]. > >> > >> Thank you. > >> [1] https://datatracker.ietf.org/doc/bcp78/ > >> [2] https://datatracker.ietf.org/doc/bcp79/ > >> [3] https://datatracker.ietf.org/doc/rfc6701/ > >> > >> The IETF datatracker status page for this Internet-Draft is: > >> https://datatracker.ietf.org/doc/draft-iurman-6man-eh-occurrences/ > >> > >> There is also an HTMLized version available at: > >> https://datatracker.ietf.org/doc/html/draft-iurman-6man-eh-occurrences-02 > >> > >> A diff from the previous version is available at: > >> https://author-tools.ietf.org/iddiff?url2=draft-iurman-6man-eh-occurrences-02 > >> > >> -------------------------------------------------------------------- > >> IETF IPv6 working group mailing list > >> ipv6@ietf.org > >> List Info: https://mailman3.ietf.org/mailman3/lists/ipv6@ietf.org/ > >> -------------------------------------------------------------------- > > >
- [IPv6]Call for adoption: draft-iurman-6man-eh-occ… Jen Linkova via Datatracker
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Brian E Carpenter
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… xiao.min2
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… jordi.palet@consulintel.es
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Tom Herbert
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Justin Iurman
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Tim Chown
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Justin Iurman
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Mark Smith
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Nick Hilliard
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… tom petch
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… tom petch
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… tom petch
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Jeremy Duncan
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Justin Iurman
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Tom Herbert
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… tom petch
- [IPv6]Re: Call for adoption: draft-iurman-6man-eh… Tom Herbert