Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt

Fernando Gont <fernando.gont@edgeuno.com> Fri, 11 June 2021 19:30 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 62C343A124D for <ipv6@ietfa.amsl.com>; Fri, 11 Jun 2021 12:30:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5qVHdOob1W7J for <ipv6@ietfa.amsl.com>; Fri, 11 Jun 2021 12:30:52 -0700 (PDT)
Received: from NAM04-MW2-obe.outbound.protection.outlook.com (mail-mw2nam08on2097.outbound.protection.outlook.com [40.107.101.97]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 773DA3A1248 for <ipv6@ietf.org>; Fri, 11 Jun 2021 12:30:52 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=asLjwvv0bGom3O1boGg49g8OuG2kb2zXnG4y7/AU3TZuJl59vd1A5M4qHJD8dTLK+IOJpBD6Bj+j0Rur5vGISQfxZ9dxBre2+Yrr5u8DzWYIUUpbHWljNAAsFBN42bjlUcWen4Pr7k40uZ4n4hCL29x4cZCXkxqdQ/EQp/SzjB+m6H0gtqXjaci6OUZHoJtqthk7q0jS4AgnO8BQLwGVNIMSzFirVFvLgZQWPG8rS4BDbmYH7sPob0pUOKwCOsKP14uzl0oL4oLxuPzL8CWD17qpsR0tkXxserkoDwh+RVvFCjmeS46XTZo5kGlt1y0dJRlS7Ov16URgpPpiA4/jsQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gv9kB+EwlKGVaq1O8Uf4KLfcjBZiW0isrJ+9FK9hMYI=; b=VeL6NYFeRAGpeOIowG3DXJ8jhZ/cbzsR5SQZaMo11Cus66W3sGhFa4fo4Ui/Nqw10h7aw2kOjV8rdNevBoQ9/bAwTEhggOuPXm0j62j9WqGnBQoMESiFcS2A/RanZbbKQ/h4SrVfajaI7ZajLhfLXvUB/esrJIhw4QfjQsQqIga7oGlwDp3imF+35xIJpbRVeY5IrboujHI4M0uzD/OCwKGbuXnuXLrMYVqhmen7Z2KyJd4ckQ0vAaIwO2uvPDoDf6YqHBRhMqPAun8MmsQqOIWHie8G4QrhzIeCkTYNI45x7GJAlp48aXpziZfka9ce3+dTGvDMbcqiQWeVPqTpCQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gv9kB+EwlKGVaq1O8Uf4KLfcjBZiW0isrJ+9FK9hMYI=; b=Vk9xoyijF57vm720L2Kf5e0F7MQuo5WHzChIcXsze92LmhHnEW7+OvVrrFvFy2qzI/nzbFIBLiIVFsBUmSvW9bfblIo2YZPd9eGXqs9fWlf6lrCHXo6cYw8qtxygkLjd0jOU2RyHC5TR9bYOG+exGugSeC02nMo7/Wd+JEkUtYw=
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com (2603:10b6:a03:2eb::6) by SJ0PR05MB8808.namprd05.prod.outlook.com (2603:10b6:a03:391::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.11; Fri, 11 Jun 2021 19:30:49 +0000
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148]) by SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148%9]) with mapi id 15.20.4242.013; Fri, 11 Jun 2021 19:30:49 +0000
From: Fernando Gont <fernando.gont@edgeuno.com>
To: "vasilenko.eduard@huawei.com" <vasilenko.eduard@huawei.com>, "tom@herbertland.com" <tom@herbertland.com>
CC: "ipv6@ietf.org" <ipv6@ietf.org>
Subject: Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Topic: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Index: AQHXXn7qO96AsvT4FkS1hVkPsR81LKsORiUAgAAbbICAAEb/gIAAPKiAgAA88ICAAAdsgIAACf0A
Date: Fri, 11 Jun 2021 19:30:49 +0000
Message-ID: <dfe3a4bc1948d8af752e694b3ae50ab755a96272.camel@edgeuno.com>
References: <162265842779.4095.2393609365780372735@ietfa.amsl.com> <E5A31CCD-104D-4B92-9730-4FCFBF191F46@gmail.com> <17adf4b21d428d051e390574e976e3f61aee33c0.camel@edgeuno.com> <CALx6S368ZavS5Ggv28XB1mW41sZML0Vv=DvBPMooFFhbWdpKUg@mail.gmail.com> <4e1c6c6a-1512-755e-a4e5-723e83b74b4c@gmail.com> <d2847bc077d1775b07642587758962dcb80e7690.camel@edgeuno.com> <F6288093-7141-4190-8541-DF96C0DE0CF7@cisco.com> <7c7a73ba2730696e40acd65c44036d2c0a17f9c2.camel@edgeuno.com> <CO1PR11MB48812CF3CB24EC9A3B18C453D8349@CO1PR11MB4881.namprd11.prod.outlook.com> <5f733909279347cbb8bd9de5dec29adf@huawei.com> <CALx6S352C9vag=ivyi7+SpD6Nmqi15hFsEru_i8Z_Hn5OBw6mw@mail.gmail.com> <0d3be0c9c2eb486b820bb3ecd2fd3383@huawei.com> <CALx6S34Gpo673i9oHSzRuF1MzdDt76p2D2PYVvnk3Lk1y7St3Q@mail.gmail.com>
In-Reply-To: <CALx6S34Gpo673i9oHSzRuF1MzdDt76p2D2PYVvnk3Lk1y7St3Q@mail.gmail.com>
Accept-Language: es-AR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Evolution 3.36.5-0ubuntu1
authentication-results: huawei.com; dkim=none (message not signed) header.d=none;huawei.com; dmarc=none action=none header.from=edgeuno.com;
x-originating-ip: [186.19.8.47]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 540d99a9-caee-4ac6-e4f3-08d92d0f6b04
x-ms-traffictypediagnostic: SJ0PR05MB8808:
x-microsoft-antispam-prvs: <SJ0PR05MB8808332B33F534E864E30E98E5349@SJ0PR05MB8808.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: KWDpRXk4eMdA007Qxg7NJk9y4bgHAYlZ3t8/adYpMv8+MsIC4TZeF5xMm1MpVDEOsfGHvlH5SbL4WyXAfGKcp/LF52CZI712BHvPC4EgZzjOwEjqVDOgcjUXOH/dLEOxn0OF35XKdEBpEhhlaq6wbjLBWmlbEIiIcqtpJnGxNabcgygPPasOiDrxSyEYxAOHLZnSQlh92P/b5SDvWBE1g70oGJZUhSyjDZSROw9QrOEduOm1MQP18EdDE5f9qAsqFwnKiciW8bvtiXcEl7g/m1130Gte+VXpdaZTn9Wo4J2N1BAYVZJtneNdou20Itp2tggNzdUUj0cRrJXduxtRJly9JAkepd26Z6DOKSQKENmnVXZ/yxZCYshoOt0BCHD6Yx4XhjTWBhjIG0DLbHNsWCu1vojWCZvXtwGaGdkQWMDhel9uJfqV1m3n8JqD2MzZbEjcLzaldidigckaDp04DKd2kHEG+3uY2+xnbCZBw34siXYq86UpXyacNLfDZ70Ya3fI0eIhaGVgNRDS7/b0yFtZj9lY/0IdKt3B1Mv8134U02WHqnGjP4s2dzdMNlhd3jKzla2UqPRv/FG1jLY5HUghEtOORopmJwAMbfut7x+Yuq6NSyTaJlZ9lu+B5LbklozoHLuZEvO93MlgrKwkXAzJ/79VT4Pw4i3DSMYvhJmd6qTk5yT8ufxbO0I113t4zbJ/WPIFO/kz1uhlCe2NXw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR05MB7514.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(396003)(346002)(376002)(136003)(39840400004)(366004)(66556008)(66476007)(66946007)(86362001)(38100700002)(91956017)(8676002)(76116006)(66446008)(8936002)(478600001)(64756008)(83380400001)(6506007)(966005)(2616005)(122000001)(26005)(36756003)(110136005)(5660300002)(2906002)(186003)(71200400001)(44832011)(316002)(6512007)(15650500001)(4326008)(6486002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 5DCmi5hnyVIJvrNaxLran9kxy1z4BWFdaDSXoGoFp3qKk2XfTa3vtMBFbn2eRE0R+G0rwl1uCE8QibS5vcsbIv2aafx9Z/+K7MAWFQtyz7C591s5KY8g6OrRf0tgHi7b7Bz+778FKsAfDNA1G6tY2Cdxxqnt+nXffK07hIka9BuQO2y9woyyMV6hqRY5+SapWLpqiNs4wo1nMxGpqjS4O0m4jHdfSHBCHOLztJdIfjGlNGvGYMKCdy2vQJ0j8Cj6rCj7fRjOktM2PDJcOPCID0gnbkubcxqOtytne29sD+85G3X5ptQm5sTyhswMvYMQmpzLQetUpeppwbp13lzbgHHFZ6YCbpYrODXZtziaAEQPAIATRs5f3F4NufGvN7u0QVjzeGtNL+FomTEv9fEGR+5PSHU5tfY3w/GO2ZOQFZuWYDLq0j0T4Nq+NaioTECqX0bfaKPxgqwiOLXoraZVrD3+h1+QhQ7qBjOBXimR4ISBt3w6k7E86wJbdsZBXXRtZ1TE5T36yJb5IKcT++QyYck/UMMJupVSHEnQjFcleQt75jQXFsdmskhD+4dQkIRsesFn7+aGmXorPessyIPp3UC825fsKjGuYQuChs5GsCEXewAMfqJInKwpvmx8oxC615Dg00ZjrF9A/1POv3U9WEBvtKCI5liQbV937i0YOlpWYwgxj/y0X7DpQUO9+PoBO8DMjNcpO01UidCP4kBVxTCG9RfCc955s8fnk5WDzxi0hlS725/I7ONeG1+b7YmRiTCgLu7oF1JRTo394fnwWC0iqRbjhY8UEwQ+mw5dohiIRxMDugPEHaFYi2HgvBIwheAXz4j647UVBhMrAsbMEaC+nUyQDiCXRdcPMezCvhpQJW9CgSSuQJWSpLVBrbZttGprnBw1rZnnOt8tVhjgknsdjSjn+FjkssXhxDdXw1+yoWTMpjylG5/E+Iat6dBUv3AgXU7wP3rxCbDPpyqxwv5U56/5qhmMnWJTT9ubQFx9HATnMaiG41F1BpN1gIWh+wkHJwffjRUC7jVMYmMdVdosauuAJdx5urtuAoBTmI9lizkCaMWEzUVU8zg4JuEm81yxD43HiIWH48xpsbdmMJqp7/jCVBKcEZnkOjbTyIAxmr5Xcq+KFFQUjEhlL+LCqPI8vV0CVet6TSBt8j+3pVNhZTyM1irkSQhHoNwPaYkMntfPl4WeXFdWTM6GAjjY8pQmcKJBAsAjTBVxPOCEdUsydTwyJi/odDrZCbfpf8M+CYwR6iwXeSIHz9clXsQB1ClBqy0GCjxMxNuXIz6epl15Woa0Kfzu4E+Nb9YriBxl9kGIM09EUf+K9Xcc7acC
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <D646FB00F6DE064399D21BCA7D24456C@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR05MB7514.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 540d99a9-caee-4ac6-e4f3-08d92d0f6b04
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Jun 2021 19:30:49.1364 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: nuJ/dbbchfcdzS5oFuIu0UivPRn9ABE24UtHHlTQaghlbwu5vxaVlpkQ5dtPzuL3am1nRKW07lpZTEZjcrhBSED+nR57sBHOIz5sIBXBnRs=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR05MB8808
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/ljQccK2hHabtXeJnARSnkqhAvW8>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jun 2021 19:30:57 -0000

Tom,

On Fri, 2021-06-11 at 11:55 -0700, Tom Herbert wrote:
> 
> 
> It really depends on what you mean by "activate anything from EHs".
> There are at least two possible interpretations: 1) Process the EHs
> like HBH 2) Forward packets containing EHs without doing anything
> with
> them. For the viability of EHs, including future use cases, we mostly
> care about interpretation #2. This really just means we want nodes to
> ignore packets with extension headers instead of dropping them.
> According to the data in RFC7872 that mostly is already happening
> (e.g. 90% of packets with Destination Options we're being
> successfully
> delivered at least five years ago). 

RFC7872 doesn't convey everything that we measured: the number get
uglier as you increase the size of EHs (DO8 vs DO16 vs DO32 vs DO64,
etc.).




> RFC8200 has already relaxed the
> requirement that all nodes in the path need to process HBH, so so
> aside from an explicit policy, the biggest impediment is in
> implementation for those intermediate nodes that need to access the
> transport layer and if the necessary headers don't fit in the parsing
> buffer they may drop the packet. The solution to that, I believe, is
> to set a requirement specifying the maximum length IP header chain
> (e.g. 104 bytes including IPv6 header) that nodes must support if
> they are accessing the transport layer.

This is indeed as much as we (6man( can probably do.


For the amusement of participants, almost ten years ago I proposed to
limit the IPv6 header chain to 1280 bytes, and the idea didn't fly (
https://datatracker.ietf.org/doc/html/draft-gont-6man-oversized-header-chain-00
). :-)

Thanks,
-- 
Fernando Gont
Director of Information Security
EdgeUno, Inc.
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531