[IPv6]Re: Call for adoption: draft-iurman-6man-eh-occurrences-02 (Ends 2026-05-17)

Justin Iurman <justin.iurman@gmail.com> Wed, 22 April 2026 14:54 UTC

Return-Path: <justin.iurman@gmail.com>
X-Original-To: ipv6@mail2.ietf.org
Delivered-To: ipv6@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id F0ECEE0DEAF1 for <ipv6@mail2.ietf.org>; Wed, 22 Apr 2026 07:54:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776869696; bh=W/NjDQ6ySUv+3BqPnBNd6QBlsCuJZIH5EYOIc1LVfEo=; h=Date:Subject:To:References:From:In-Reply-To; b=X6TMvw1W5lfketcdfk4jlINhfR3RBOI5dwAMqYbmvR83hU5VjKUY1csILIKv5A34E pwrkhyobPYCQHmfj+AyFVXlBytgJ5aEWTyy6kmYwlKPFenP2KEO0LLkneRETg92n0s I/ve2xTHwJ/7XlRVG/zUoz0wg+RfjEMyb2RlrDoc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hxyjS1LTIz_2 for <ipv6@mail2.ietf.org>; Wed, 22 Apr 2026 07:54:55 -0700 (PDT)
Received: from mail-wm1-x32f.google.com (mail-wm1-x32f.google.com [IPv6:2a00:1450:4864:20::32f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BB69DE0DEAE4 for <ipv6@ietf.org>; Wed, 22 Apr 2026 07:54:55 -0700 (PDT)
Received: by mail-wm1-x32f.google.com with SMTP id 5b1f17b1804b1-4891d7164ddso22062345e9.3 for <ipv6@ietf.org>; Wed, 22 Apr 2026 07:54:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1776869695; x=1777474495; darn=ietf.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id:from :to:cc:subject:date:message-id:reply-to; bh=sqnzqAvLVsPEuCSULIqfF18O7MuGh4yx0m15zOI4GJs=; b=BfltA8em+39mmf1AHX7xIGuoYgA71jt5kVvW+4b+fxsxSn4VdVfbIqpX1fXLIRNHzY gHWoc8JUemZSroZfcuEfIbr4UgUHTI4Er679bsNdZ+nEVowvk22soPYhLUnNZYvCb5al GE1zmZPEf/zQdR/L3k0sDuNpzyoA5Ytn2yI/v+XZrsVEUG7AiALaNCFR9YMhM4Ut0Wjk znkNXNVFmaztltDWU/6NOy+RJmnS+qRS+NubFv1NTdackUVA8JXd6pB5YWNOSF3ooCZm mmzhRY0vqE0S4CNUQ0IyA/dypRn3vVSib7QqreufIwUUISbWTtX/2grgtR9XfWDoteDQ heag==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776869695; x=1777474495; h=content-transfer-encoding:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=sqnzqAvLVsPEuCSULIqfF18O7MuGh4yx0m15zOI4GJs=; b=lVwuG/IMBsDN6xf27Vr0eYruEQx4Ws8G2ywHClv/605+EHYq2AFVedgvwll1rH5szI QIaapl9kqZ56QNrl55GvH0qC4Z+tdGLc182ONNcKRPb/tW72KOE1yi9zEGgOIonvxhmV nkkKQAQIRVBk9u5b9FmAkz2DtCW3ZQWPg53ZK1GbdxhR7Zj4sXf4DEJryXnwFRv8Rhi1 nYXf9RTDkxSXWWFIKJD8qrsiIqrEv448HU63mJQH/vfx6We5pnMZ/yCb05/Q1+4xCFih eghtVXpoWiUtiL7tqjGpFP8y0ZQp4vaAxwADKcR2aqYNsb7wdtAxo23eEfLujnJiQrca kluQ==
X-Forwarded-Encrypted: i=1; AFNElJ8zb9p/QJRz+/IbdIH7PY+p1GKraDDKsI8uPk3nS61AlafJ9csX30iYgPcOD6bHLbJk7QBi@ietf.org
X-Gm-Message-State: AOJu0Yz3d99IJIBmIVgKWFANmx0ihPDAmVbnF8PNA781O8y8q65LPg6G 08TLlHkY8AL1/H3YMr73Ti3vHoxFRo31r9EKCyM6Znm4jICweNuNDCJ3njOGzGno
X-Gm-Gg: AeBDievB4Pielf/gTKY/uoIQ8tJnTdAUhsZI4wah+Y2Y4IPSnFyvJlz5gTGqN5oRKlP a9ZADvWzuarC3I6MecQMHNp4bFDl2/fKKNQIYRNW8uUZBHt+FmCT7Ar0C15Csr2f7M1TDFdcUw5 j0WmdRfzBD1JMVICOa6F4IDtRl0pKFVIZY3QtZygltCXv5Z90b5cCQeIIE5kZvse6Pg8n0GC/78 j1nxts+XGLMD4mg8hbbupDGjKSCBwreJsZxmZ5MbjxdZN6QUH3ytXfqRtxrluTtB6HNRlfn25QZ SzjvcEpueohofNMRDj3voxnl4O9LmPeK0YSiOjtJumI2Hijw4+Na1+73RkDrvz1UGMFaurFTlG6 Dd+JgIQIUeBeHgQI1YJSm6L2D1jLfZ/p036K8VHkAytSXf3nzOGJmYaAq10SFPKmzU5ydw9rAB6 B0Ycwb+y/1n8OvmlacNaslHrYgnD+evd34rZwg+NpmiGWSaA==
X-Received: by 2002:a05:600c:3e1a:b0:489:1ca2:eafd with SMTP id 5b1f17b1804b1-4891ca2ee65mr184488335e9.11.1776869694415; Wed, 22 Apr 2026 07:54:54 -0700 (PDT)
Received: from [10.86.0.15] ([185.13.181.2]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43fe4e3a18csm52607336f8f.20.2026.04.22.07.54.53 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 22 Apr 2026 07:54:54 -0700 (PDT)
Message-ID: <a79fe228-cad5-435b-b132-48fff1ec4bcf@gmail.com>
Date: Wed, 22 Apr 2026 16:54:53 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: tom petch <ietfc@btconnect.com>, "ipv6@ietf.org" <ipv6@ietf.org>, "6man-chairs@ietf.org" <6man-chairs@ietf.org>, "draft-iurman-6man-eh-occurrences@ietf.org" <draft-iurman-6man-eh-occurrences@ietf.org>, Jen Linkova <furry13@gmail.com>
References: <177684315758.1032515.10043189142937925605@dt-datatracker-b45949c58-5szpr> <DB9PR07MB7946A6120EBC74D09587DDB7A02D2@DB9PR07MB7946.eurprd07.prod.outlook.com>
Content-Language: en-US
From: Justin Iurman <justin.iurman@gmail.com>
In-Reply-To: <DB9PR07MB7946A6120EBC74D09587DDB7A02D2@DB9PR07MB7946.eurprd07.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Message-ID-Hash: 32IFPQ6UCLKJV3ZWY7W27V4ADEGGGRL4
X-Message-ID-Hash: 32IFPQ6UCLKJV3ZWY7W27V4ADEGGGRL4
X-MailFrom: justin.iurman@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ipv6.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [IPv6]Re: Call for adoption: draft-iurman-6man-eh-occurrences-02 (Ends 2026-05-17)
List-Id: "IPv6 Maintenance Working Group (6man)" <ipv6.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/PP0rJ2s_h2urlPl039vBvKz2aYs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Owner: <mailto:ipv6-owner@ietf.org>
List-Post: <mailto:ipv6@ietf.org>
List-Subscribe: <mailto:ipv6-join@ietf.org>
List-Unsubscribe: <mailto:ipv6-leave@ietf.org>

Hi Tom,

As Tom (the other one :D) mentioned, ICMPv6 errors are the indication. 
The draft says: "[...] MAY send an ICMP Parameter Problem message 
[...]". Yes, it is only a "MAY", but "SHOULD" or "MUST" would probably 
be too strong here. OTOH, RFC8200 recommends (although without normative 
language) to respect the specified ordering and number of occurrences. I 
don't have data to support what I'm about to say, but, I'm pretty sure 
there is no legitimate packet out there with out-of-order or 
more-than-allowed Extension Headers. Such packets should be flagged as 
suspicious, and dropping them seems reasonable anyway.

Cheers,
Justin

On 4/22/26 13:26, tom petch wrote:
> So packets may vanish into a black hole without any warning and with no indication what is going on.
> 
> It sounds like an idea that needs more thinking through.  How can I tell that this is why my packets are vanishing and what I should do about it?  You really need something somewhere to tell users about these boxes which have a built-in black hole that you cannot detect (like most black holes).
> 
> Tom Petch
> 
> ________________________________________
> From: Jen Linkova via Datatracker <noreply@ietf.org>
> Sent: 22 April 2026 08:32
> 
> This message starts a 6man WG Call for Adoption of:
> draft-iurman-6man-eh-occurrences-02
> 
> This Working Group Call for Adoption ends on 2026-05-17
> 
> Abstract:
>     Operational experience has demonstrated that permitting multiple
>     occurrences of the same IPv6 Extension Header can create parsing
>     ambiguity, complicate packet processing, and increase potential
>     security risks.  Although RFC 8200 recommends that senders follow a
>     specific order of appearance and limit the occurrences of Extension
>     Headers, receivers cannot assume that these recommendations have been
>     followed.  This document updates RFC 8200 by allowing an IPv6
>     destination node, namely a host (i.e., the final destination of an
>     IPv6 packet) or an intermediate destination node addressed by an
>     entry in a Routing header list other than the final one, to enforce
>     strict ordering and limits on the occurrence of Extension Headers.
> 
> Please reply to this message and indicate whether or not you support adoption
> of this Internet-Draft by the 6man WG. Comments to explain your preference
> are greatly appreciated. Please reply to all recipients of this message and
> include this message in your response.
> 
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [2].
> Appropriate IPR disclosures required for full conformance with the provisions
> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
> 
> Thank you.
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-iurman-6man-eh-occurrences/
> 
> There is also an HTMLized version available at:
> https://datatracker.ietf.org/doc/html/draft-iurman-6man-eh-occurrences-02
> 
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-iurman-6man-eh-occurrences-02
> 
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> List Info: https://mailman3.ietf.org/mailman3/lists/ipv6@ietf.org/
> --------------------------------------------------------------------