Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt

Fernando Gont <fernando.gont@edgeuno.com> Fri, 11 June 2021 06:14 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 083CD3A2ABC for <ipv6@ietfa.amsl.com>; Thu, 10 Jun 2021 23:14:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z9Ku1043HJDQ for <ipv6@ietfa.amsl.com>; Thu, 10 Jun 2021 23:14:37 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11on2120.outbound.protection.outlook.com [40.107.223.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 959B63A2AB9 for <ipv6@ietf.org>; Thu, 10 Jun 2021 23:14:37 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=CNuvwLgKWH4ImLUiFm/8ZCj8MW2j9uZSzJ2yPI5TGIt/Ak7C7lZiCCPD+NryQBoWxC/vQdWnu4/DK7HR2rZYCjroNSpVNCLt+bvKoGKpbE5sEhWA+9GGiypVwYHYsaCvPSvIZjqNtL9ashlFOWTWMHlv5f8Rsq/j4PZIGSyBrIKKDV1PwcBtIJ4dq9POFjQ4M9CfFbY1NkvrijSj6e90iWGHD09b1J6esnWOwNDhbS4h0FptGJmNf+IylDfwN6C8wxua+2q8mDfsWUU1HiiBMnH/n4UTQbpsBpdxt+vM3l5HSSge9tGtXRWyj0OuOVomp69TtjMmK0UYDH1v7c2XNg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X3lkV4nK2L7bxDCE9J/1R1AGcRg4OECtrLa2Tlu38ao=; b=mFUOKoHypA+dBP7Drrqe2+pOgCC4PITDVdMuBJ5vAtrFt9+shL5tEGHZOHaBi+KNiZodbLXH82FQzxo13d9EXinORM0fox27hKtbMpVlttMHO4NGzK0i7f9i2d7pO37RBy4QP4xrMHx1/TXkhq8r+UT8FrPphfE5DX/uQ7o5Kdbk6cMmhfskzXjrSLHjfSvO8IHLQoGKZmGJxHdbY+JaWB4a+29wdIhEjJgWhUKEgrhkt/UGON6W86TDi3wyfIqhWafsvJO8YdO1f3SLG4afo7yQkvapPCSKrgT954KlqH8YH5OEUpdOEssErAjbIASNCKm99FMiImkIfMt6hc7H9A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X3lkV4nK2L7bxDCE9J/1R1AGcRg4OECtrLa2Tlu38ao=; b=B8gf/p5KbIrL5gibuFU02WOoN03yDkLpBlaUI60UTN76k0k51bAM4V56DgP2lPQo+gEPYvn6dIBnbHNwS3PmQJGqwd47LWsTr/jhl/e+VDjKOIkFmqdUbWKojVqYdVcft00VL/4T9ZGReoUimPevwEq6OVf601+fxlGnG0rlksg=
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com (2603:10b6:a03:2eb::6) by BYAPR05MB6519.namprd05.prod.outlook.com (2603:10b6:a03:e3::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4219.17; Fri, 11 Jun 2021 06:14:33 +0000
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148]) by SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148%9]) with mapi id 15.20.4242.013; Fri, 11 Jun 2021 06:14:33 +0000
From: Fernando Gont <fernando.gont@edgeuno.com>
To: "tom@herbertland.com" <tom@herbertland.com>
CC: "brian.e.carpenter@gmail.com" <brian.e.carpenter@gmail.com>, "gorry@erg.abdn.ac.uk" <gorry@erg.abdn.ac.uk>, "pthubert=40cisco.com@dmarc.ietf.org" <pthubert=40cisco.com@dmarc.ietf.org>, "bob.hinden@gmail.com" <bob.hinden@gmail.com>, "ipv6@ietf.org" <ipv6@ietf.org>
Subject: Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Topic: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Index: AQHXXn7qO96AsvT4FkS1hVkPsR81LKsORiUAgAAHtgCAAAc8gA==
Date: Fri, 11 Jun 2021 06:14:32 +0000
Message-ID: <2fec5c1c3456d95ed79024359b5326ca2588f89b.camel@edgeuno.com>
References: <162265842779.4095.2393609365780372735@ietfa.amsl.com> <E5A31CCD-104D-4B92-9730-4FCFBF191F46@gmail.com> <17adf4b21d428d051e390574e976e3f61aee33c0.camel@edgeuno.com> <CALx6S368ZavS5Ggv28XB1mW41sZML0Vv=DvBPMooFFhbWdpKUg@mail.gmail.com> <4e1c6c6a-1512-755e-a4e5-723e83b74b4c@gmail.com> <d2847bc077d1775b07642587758962dcb80e7690.camel@edgeuno.com> <F6288093-7141-4190-8541-DF96C0DE0CF7@cisco.com> <7c7a73ba2730696e40acd65c44036d2c0a17f9c2.camel@edgeuno.com> <CALx6S34GVTLRwmqfYfUX+uzdAy9OQge+_r3=2eGwcBivdb0cvQ@mail.gmail.com>
In-Reply-To: <CALx6S34GVTLRwmqfYfUX+uzdAy9OQge+_r3=2eGwcBivdb0cvQ@mail.gmail.com>
Accept-Language: es-AR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Evolution 3.36.5-0ubuntu1
authentication-results: herbertland.com; dkim=none (message not signed) header.d=none;herbertland.com; dmarc=none action=none header.from=edgeuno.com;
x-originating-ip: [186.19.8.47]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 60fa035e-4136-4886-7ee9-08d92ca02e60
x-ms-traffictypediagnostic: BYAPR05MB6519:
x-microsoft-antispam-prvs: <BYAPR05MB651980AF415E17A0E9BC71D2E5349@BYAPR05MB6519.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:4125;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 6uBKwMn7QiTFYLnH9KMcd/bPb8+d/XGnFF7GBi+y5SO4v6l30CipeSF9i/p02BQpmL2xPqPY2gjU/2OJFuvMM3BrqzTj62kgTnQn2II+iTJY0GmVMv1QvJXRkNccOvl7OSX1OFsju4bObkxG+3cQ07lCoGUcjQ4Yj0+oiN93/s+8FdJoMEY0TyOOR8ID2x75V13Wl+qQEGZGHDemcbwSYEC1A/PYVzcXo6sDxbUXnMOG07J36vF7AwAaeZgo7m/GPwoYEzzvaXI9/uYNK/3H4oJ2FjioP4t9le7tQW8ANPkrr9PKp/Prb/qV9PhgDUnV0iCqOh99v6zZej4uF0EDylSM2VOWsGV0I25dqlYXnU+MHUIUKlC6E9opGwJIdReEmlxezD2njrGmnG5G7OweThnSdU69z7bcplDP3UeQYpAgMkyL9twX792Sy+9909X1lcuFE8bpaN57p99NS0Iq3EnQHdIo5aEU8Jj+V2nA7VhfAnXrJHcBQW0KB2Q100CZHI2evri0Mi2nXInzSdIB2nfdUwOpU1Ax81fnOEq2QufMi9MzA+pK+mn2dXkQQZdumzMX+axvKeOZo6e3XtT2LFodUThjZxqnhiXT6wzFofs=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR05MB7514.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(346002)(366004)(136003)(396003)(39840400004)(376002)(66946007)(64756008)(66446008)(5660300002)(76116006)(2616005)(86362001)(66476007)(71200400001)(66556008)(38100700002)(91956017)(478600001)(6486002)(6916009)(2906002)(316002)(8936002)(122000001)(8676002)(186003)(83380400001)(54906003)(36756003)(15650500001)(4326008)(26005)(6506007)(6512007)(44832011); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: GDWScRnwNGuu4LMsWfgKMrOGtmBVfkdY8j5r1FB9yLDhXKbkf1Nc4c8LCOfzoLPGi2eCxTAwNTOJRNGApay0W+RtGD5uDeSZmh9i8pGz2ERKK6OGahcflCu6OSFwLn/RLMzDRbwprlXneJ6DowpCTln0xELTmLicxI5Qxm0iX51UPslJUcdUSZ/2Mrl3o3x5JXQay8NLns5I+o0YmekEaEXbbNdjwDWlPUeByPcXBOAkwpGQJPRJWxEzKePGBXa+Kv9ZP6efwCWP8gxxNZ+xMc5WV4w9ESWDDQtvQ43QAcfH2WKlXGUAxb/YK9epJsU6j54qj6zExHQ4tubiiE4SnBl6/ONpSXic5HF6UlomLVbn+/QE4ed0pfkTvk8RBGg1kOiUO/nZg2UMuwyStut1qKSwxsyx6XXnmZm/fTsnp2O4gt2HdbBYyk5dORSnVdrWanOrhz+4WpsdEUQAwhwEBPape/jefxYk5Acighg9KX8kvrU9sZ+Lm1Jx0JeEXBu4K0GAMTBK3o3oQ6oJiju4q35SCqX0gMoF/ge12mIK4HOyPUvWUhasuzbpIqD5l2DK0SAxtoP8vXN4KypdodnYjM080nCIT1chvgKgw0GyN+HnweEkKN4vSEWl7WcySQ1dJcXsYGFTjjjJlOIg9KBCXvLI5XkkLv4QUKX9NeLgcKTQvtRtbeTZOjz9FzjDo0RRltpDPTwnbbHD1zvv1uZbqmMcddlndy5xNYsNLcEmJzI1ckIq8k78k5m/yKRhsvVkH94cSnlORodhsAlts7F/wXyFcZqTyiVILNfNVS4Tzh5gD64Ak0q714ev7jfzetaxrkHEeWVdxctbO5YIMN5+MZtlj2y8aGz35jtK/PLHJjYLQ8+ESdv8W/LlEWkVPRWbbb5u0XYxBHTkLdQfRK5IthV5gZJilhNxJo+TZAGz/0646Q8tCFQTE50r1gaS5sxF+BfhNiPqHxFz1VR+gccNEGnzwaeo+M70zgG2/I9j/HwqIPfL0ds83ypjvqMgb4EJdxBOP1sOv6/ViEPoLH0zUb0qRmsUConkEAeZMrkAmV4quvseQvM9nE5U9M33ipm2CWoOXtWK1YvtJKt/icWFBrjwISvteZD/1uNGQf/n86QgkWDKvLEfEZlfvJAZhPTq9BRBUe42uZdnLPOO50vcKv1Xe87RiWo+3NQhK1NzFTlnUvhykP5j8uAFgid+fNco2YLlGvipeg4Rn75QFkS0TPDDUb2s5QrWJnBxenVC+m2Ol0+mD36fc8W7aAXUdELnoeGGhW43JnLTqhEwXmLb/WRQ0g2RK2yZ/sgTwP05LkjJody8JwEM4zyTAfqw4snU
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <DAB309665024E6469DA5DD6ED61EBAE7@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR05MB7514.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 60fa035e-4136-4886-7ee9-08d92ca02e60
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Jun 2021 06:14:32.7719 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: VBt3BeB8pzK+ksNVvk9nrUui7hLWh5FE3fxLyxHLdtMsmscWml99WOkjJRlnpeRykJSV0yqkQwQcy2u0ZJHywwccuw7lInu8RAuvyUQumWk=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB6519
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/QkYrvhPs-zCy22pfKNSmEZU9lMU>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jun 2021 06:14:42 -0000

Hello, Tom,

On Thu, 2021-06-10 at 22:48 -0700, Tom Herbert wrote:
> Aside from a bunch of other evil details:
> > 
> > WHat if, say, you employ this solution at, say, connection-
> > establishment time, find that EHs actually "work" towards your
> > destination, but them, sometime later, the path to your
> > destinationchanges, and you find out that EHs no longer work?
> > 
> 
> That scenario isn't all that much different than rerouting causing a
> flow to not hit the same stateful middlebox, or a NAT state times
> out,
> or any other instances of something in the network rendering a
> connection too no longer viable. In all these cases, the application
> just restarts the failed connection.

There are multiple differences here:

* Packet drops can happen all over the place, whreas e.g. transit ASes
won't usually do the kind of stateful operations you're referring to.

* Issues arising from EHs can be avoided, while the other ones cannot.



> >      Abort the transaction/connections?
> >      "Migrate" from EH-based mechansim to the fall back mechanism?
> >      Anything else?
> > 
> > What about the impact on e.g. RTT for connection-establishment?
> > What
> > about the complexity of the mechanism? How many bugs/vulns before
> > every
> > implementation gets it right?
> > 
> All the more reason we need to establish some guidelines as to what
> the host can send in terms of extension headers and correspondingly
> what intermediate nodes should support.

The problem is not establishing guidelines, but rather establishing
guidelines that folks find that there's a compelling reason to follow.



>  Since RFC8200 allows
> intermediate nodes to skip over HBH options, then the pertinent limit
> would seem to be how long the IPv6 header chain is (solely for the
> benefit of those routers that require parsing of the transport
> header). I believe at least 128 byte parsing buffers are well
> supported by vendors, and assuming 16 bytes for L2, and first 8 bytes
> of transport header might need to be accessed by intermediate nodes,
> then that implies a minimum default of 104 bytes and subtracting
> forty
> bytes for IPv6 header gives nice round number of sixty four bytes for
> extension headers. Hence, I suggest the requirements should be:
> routers MUST forward IPv6 packets with sixty-four bytes or less of
> extension headers, and correspondingly hosts MUST NOT send packets
> with more than sixty-four bytes of extension headers unless they have
> knowledge that the path supports a greater number.

Note: the "64 bytes" should accommodate the upper layer header. -- at
the very least, that part with the port numbers.


Thanks,
-- 
Fernando Gont
Director of Information Security
EdgeUno, Inc.
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531