[NMOP] Re: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities

Thomas.Graf@swisscom.com Tue, 05 May 2026 07:17 UTC

Return-Path: <Thomas.Graf@swisscom.com>
X-Original-To: nmop@mail2.ietf.org
Delivered-To: nmop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A76A7E9295F9; Tue, 5 May 2026 00:17:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777965462; bh=LZe9nZ/JTzXH5uLWwg0SnZsC/FowQYX1WUL9YV7rttM=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=pzdE57zDRRLUIKV2IuOVX7vPN9ET6BZ5yXp4YpOpQLY5HIkR1WDWN8Gllehl3aJq9 WcNi2D7kR/asOM044DxAlcsRtqes3qa3+FNDxoovGWSC3rm7RtQtkZg11YFw9uwUWN Ktp2jhh8w0L1CTgzijLO++7XueCrLhgZvYQfYNgI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.396
X-Spam-Level:
X-Spam-Status: No, score=-4.396 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=swisscom.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 65NZCRZl6Dtf; Tue, 5 May 2026 00:17:39 -0700 (PDT)
Received: from mail.swisscom.com (mailout120.swisscom.com [138.188.166.120]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id AF4F6E9295EB; Tue, 5 May 2026 00:17:35 -0700 (PDT)
Received: by mail.swisscom.com; Tue, 5 May 2026 09:17:11 +0200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=swisscom.com; s=iscm; t=1777965432; bh=tBKh31thIkdUyoLNi89ebXly0OnW+HdUfFriPklytEc=; h=MIME-Version:Content-Type:From:To:CC:Subject:Date:Message-ID: References:In-Reply-To; b=LVYTZFVgBFVd7n7zhWLgw4mAmBpCncZdXqSS/MEOWZgSKJprcbi/5ZiTu/eCoY+rr Mf5uhtx0dXMA8WX8cG02bdKOvinpANoEoNWiCbTX5+8bjw1+rB1NF0zB1LqgGzkU9q 1X2nyEl54y1od8kIrBwTP/Iee/AK5zXO5a7byGZuVA2q40M2eJfEGSl4yGiMILe/8W nMJmfvAyIJcaqXptwgExZD8Ht4fw3GzVNkZmjjiOiyyGfYJHmvwuBpWbKVznkk1IPJ G8a6xCXaaDJtgHC0TQJBUkONAk2PRLhDnChT1/6B/Pb6qWTEclucYeZ4mIX4POl96B ALY0txSdhhARQ==
MIME-Version: 1.0
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="----=_Part_759657_1298551076.1777965431407"
X-Mailer: Totemo_TrustMail_(Notification)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=O4pMXlMBDlnLsQqePt0nQeZYm3d0GDyv/IhKeK2KuUFFblEpUiZ/hRUq+2EKGJ5G3SEcnfUXO4TNPH2gsc3Xj1Eo3yvekwXJmIe1f1RArdvPucgQZA0ipoCRDg0lCPNgECCadB9zy+z6pfviJHItT5nhn/+HkF+bzx8b8dTzY4Psa6Adt7AgJxcS0495eJQVOkmCDhH862YIDe9AupUOiOGO2TYes3VJFOL3RhGrjghSJLTTfGR8b4k7i3vSB8Djuachi0Fq5at6Dc1qTUcMNVoztARDevtqzfzX3UQ78ni+CCout6MAvxCUSqdxxfgMUXvtKGX96QjSg+2ad4Acaw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=zJ5QOkPIeFncoGedIPJvDzQFxcUCSeTIO9nN80fMVF4=; b=oKWPDAX6TzHV2378vWKwCS8ThIN9szp/o0DA+3earyE0S3koGZkqM1xuWwMays53EaVM5UFNy4U10tm3kLOvWC1WZ9XUmKfIb0A/mHTbxpVZxle+NkQJmVfw5FwGpIxFDSJmsYruLmdv2+2mCeWNa6Dr6Sw46wfL+KunFspGAgqQ+JqVwe0A23EwxmcdW9BVvn4g9f20CxC5/iF0OagHCBt9t2kB/bN49P6s8Z6z9Ow+9rm804aF7COKG3FgdoJ9z0s6LvKMSFqZknULKwECFXgdh3CS21M0CEM5tthgSp+k29HmfjUZkR7tFo3Bk1mLLttLj1UE8UjDNAe2vciS8w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=swisscom.com; dmarc=pass action=none header.from=swisscom.com; dkim=pass header.d=swisscom.com; arc=none
From: Thomas.Graf@swisscom.com
To: benoit.claise@huawei.com, ludwig=40clemm.org@dmarc.ietf.org, balazs.lengyel=40ericsson.com@dmarc.ietf.org
Thread-Topic: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities
Thread-Index: AQHcYQVr6ELdL0i1HEKTlHTdi5cGx7Wo6vMAgFcNE2A=
Date: Tue, 05 May 2026 07:17:05 +0000
Message-ID: <ZR1P278MB1170AD65D888A46F1F590AC5893E2@ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM>
References: <1387624537.1157475.1761751369707.ref@mail.yahoo.com> <1387624537.1157475.1761751369707@mail.yahoo.com> <ZR1P278MB1170CE6C1F4D9633A5CE3BBE89DDA@ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM> <288123420.4898609.1773178822999@mail.yahoo.com>
In-Reply-To: <288123420.4898609.1773178822999@mail.yahoo.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_ActionId=61cf8573-9859-4135-a138-e5b65c02da21;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_ContentBits=0;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Enabled=true;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Method=Standard;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Name=C2 Internal;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_SetDate=2026-05-05T07:01:45Z;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_SiteId=364e5b87-c1c7-420d-9bee-c35d19b557a1;MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Tag=10, 3, 0, 1;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=swisscom.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: ZR1P278MB1170:EE_|ZR0P278MB1154:EE_
x-ms-office365-filtering-correlation-id: 34648828-aefd-4da0-c7b3-08deaa764fa5
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|22082099003|8096899003|56012099003|18002099003|13003099007|38070700021;
x-microsoft-antispam-message-info: X4qxnVnHLMgmTJOuoVNMN8RBgWfKXCKLM45GOIF+Yf6Fg0FPedBmxY1ZlyMHQPzIwgB5V+u4U61qsEwZg1Ukqw2FzNmaz4fwoJ2u5mzbyX6OFPWBWYcloQixPqjUydqzVXEqtcdZYWuGlwgLGuJa2synXG1nIKRLM5achbt/hIz6v9D3QjxttjADzLtZFwlGRzmySZJcbwyDd7RVtBPVb2CZkr9ktF9LPh5TpKNEUfHjPDzK54L8k2aZL+KSCCOzE2MfDh4oWpox0BmS2m714cgzWCTZkfRYjqwvZTkoyX+bdA2OeKkzykgGq+DI97zHhtojYelnL4mmv8AnEHgszFe3MI/V4WGrgcDkTNWPskyHMVbxDyRMENy27z+wSOaMpWbO2MoLVgnRpv9uRtJyQgAqlRDDlqsjXQdds6yNlUpJRCWbnN9R08QjUiAsET2wtCRONl1s/zoHcbtRy3+Usi58JWsDe0vyqW6zHwM/Eq9EWAYFqZivAcOx496JooIxE0gO1wXBCwKsR6ta9vhmUslIX4fsy+0ZhbHKS52rXHZtFH/t//AirbPSBui9L+E9EtpQFpcpIa+W6VI5/gXerDp6lScq4HCTWXF98bkbCby5DL1g5yDqtRyUdFNxEjl1cZ8rnLvfuBSqlp1HVjoH5ERcbWB+T9aIm/i9y2jm7eCDsXnKtzAuT7Vz/7dCq3dGtB4rEpMXdb+NE9iinRyoww==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(22082099003)(8096899003)(56012099003)(18002099003)(13003099007)(38070700021);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 2kNg0+lJ428UoHxvc0WWKF8sKh5/2bH9W59MtiXoeprxSIw1/WmvpgME76I7lplBgqWPEmYY0tf7BwH6eMpVWqXAqGJzr0InsrmqV2RyqcY5Acza+swP6pB/Gdr4Wd8eDuk1JGRlnPPDSzs/MnMYPKQNNDtfs/3felYDVy+XPVajJPaEEsMDd+Z1FYyavm/iSMR1uttP5qnqeEskcjX7ULcPJSdCtCsjHQeZlYoqo4VFYxZrnKKirsekJ1tZK/zhkGGjw/3y2aPiD1tzyxjtIqOQrcj3qWpV3zuVx8VqT6xLM7Qs6nhfgQWe/LklgQ49en3j8PbqFEiJGQ2TT6iyzzI4bxZVWGBlS9O30wnNrbsD+adD+4JvXPhhIp5SypMKRi61/0gmPvFeUKoSx+MBq8IgU+obftkHArrd6nB/tSMP8N9H7TvUkiSBAMduWAbVSxz/alQSS2nqdp8+Wbj/csmwG7sZ4Sm88c1ZZtSSIs/57XYtgjCypA2zyHhQ7C1E4uMKRI1E+cfwurisqSklYVOWVC+51AtxuRYwnbOfgjO1LYI1ena77pH1tq3E2u2epJBcrYvaaAXBr33Bm6KrwAfjRPOggeA82HDaUIoXUaAZT1q862ZpMM4oWk79CeajvHKmynaDPshwN0u1F+uvNNbolWH7w1lYu2lnK0sCdlDJX/ZTxgVJGEVIKDLt8bQlHi3wl2911Ghb0nhp2L2144/m8h89+rN8Lva2+Gq+uVc1wAiMwWz7g5yKKh5uc16i2SjFcrwkruKZLim4E26Rf5TixVqtq5PABSylVtQQ5tZFEcrCMni0GkXHfmvdEc1v2l7Fd4cBamSmAJz4Fv1PIOp5uLcPf6ohrR+8XaNls8N+526wfre5SsSJidlVBjgX3VoLsPz8oOVtrWUWFR19NBPVqEKhCxGqmnao/MJqC2EpaHaL78bvYwsYRIhCTvsbMZ5CYg+OvXEnaNi786ozL6WChrEVmV+RkjdiITT9RTLE5k9N2+Cy435MeYS3Z2yqJCFW3krteoM9BAH/lK55GlgqmIgPRqFN3EBugcrN2aPdybVSTnpHnIvntciBDwNDnNcS610vPkoBrYDGq2zQT6bWqfbsAE4C7Uyp2FKInrj2/hCNzjluGRoi+cLURYa1sKPAI5nLA5J0FmtCWnZf9BZa/kN2pwbtQCMWF3sdbkZPcHi9D1bvawrF0AjJ0EY37Hxv8/rGFvmtN58vE+NEGBzvJqWjY2N2Lkfna74Vt/yXkPVj5LFNySWaDNghhVcncht6BV+KtDnvxJPGiKAC8582N9j9M7icGvCZ4s5dhvmcMQN54hwDK08FtOsanRCwZ57/Vmagkuawvpmy/G/n7+wYQWd3LUPDkakkXYVyjkiIhieOKKkHMMeRaqEowRMbTzVWF/Hon+Vp/zwengB1mXSjSkh3ZpKZekbTjCRkE+KN0Crjfy0Yt+OtLHU/GGWT8zpdwqUAe3Nc+U0n0y9wXGuhPwTr6+gYOsCuPfvHqNxkhEN7ZnvEqI/o4sPQEreTWhdCNOy2vfdROnlg0uaoDFU8/EFQrD/bTPsrY+ATYnLqXfO31POm2jQRfdmaeU3Dy1SNRepplq+VX+4ZF3oSfhi9KvYCq48fMPEyhrMfss+GJ0EzPnTvLMPHoi8uY3ce2aZfE242iTjgbhPsPbghPVSuexPlL0QRyONL/NId4m8555PW9JzIF4qlTZ518R8X1J0+c35jxzeqp3qlRPQLwg==
X-Exchange-RoutingPolicyChecked: Z7FU47DT4mhTvgJ+6OlHqH17+8u1BnDwFmVymR4Z+ss5ESmmF1OP1NnED6lJtaObpdWx+WJALdT4uDnornMcosXWWvsxlpenidmdcCSZHFg/qDT24umkWNxqiFnW6+VesCwRER07lheSyZ+hd/DcAvbX+toWusn2ODIF/rEgXOP66yU/GDl4RaVy0HgRRBqdxyn1gmKKhJ0auhH80v1i+na42HJ7A+hbIBJPCfs2JTkrFgNCo5aiJdMFKS+XygGBEYWSByvRdwfzSmsBkQE/RXFhwNbHGJaAS/3T+ixez2N4Rhc1VjYrSbIU3boY1UYL7cxhLJpjC42pZPOujkwPoA==
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 34648828-aefd-4da0-c7b3-08deaa764fa5
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 May 2026 07:17:05.1661 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 364e5b87-c1c7-420d-9bee-c35d19b557a1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ITRe2b9EeXlM9dM0RUtAbxJWvkQWGOA35Oz3WEhmxarbFh5EnSiAvoUw+ztMKGFC04QejY6SUh+sSg3w83iQnrTE4kSxkB2RwFXexIDEjWw=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: ZR0P278MB1154
X-OriginatorOrg: swisscom.com
X-CFilter-Loop: Reflected
X-Trustmail: processed
Message-ID-Hash: N3UPQVG7EH6BI5QH7TWFV4G72LYAACWQ
X-Message-ID-Hash: N3UPQVG7EH6BI5QH7TWFV4G72LYAACWQ
X-MailFrom: Thomas.Graf@swisscom.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: reshad@yahoo.com, nmop@ietf.org, draft-ietf-nmop-yang-message-broker-integration@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [NMOP] Re: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities
List-Id: "Network Management Operations (NMOP) Working Group" <nmop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/nmop/8f8_w3B_bzzKVIa_9W-gVdEj1z4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nmop>
List-Help: <mailto:nmop-request@ietf.org?subject=help>
List-Owner: <mailto:nmop-owner@ietf.org>
List-Post: <mailto:nmop@ietf.org>
List-Subscribe: <mailto:nmop-join@ietf.org>
List-Unsubscribe: <mailto:nmop-leave@ietf.org>

Dear RFC 9196 authors,

Reshad and I have a different understanding on wherever through NACM YANG node permissions are inherited or not. Or in other words if a Netconf/Restconf client has certain permissions to access a certain YANG node defined by NACM, depending on those permission only subscribe able YANG nodes would be shown.

I understood that Reshad interprets below text that all YANG nodes regardless would be shown.

Can you clarify this for us?

Best wishes
Thomas

https://datatracker.ietf.org/doc/html/rfc9196#section-4.2
      list per-node-capabilities {
        description
          "Each list entry specifies capabilities for the selected
           data nodes.  The same capabilities apply to the data nodes
           in the subtree below the selected nodes.
           The system SHALL order the entries according to their
           precedence. The order of the entries MUST NOT change
           unless the underlying capabilities also change.
           Note that the longest patch matching can be achieved
           by ordering more specific matches before less
           specific ones.";
        choice node-selection {
          description
            "A method to select some or all nodes within a
             datastore.";
          leaf node-selector {
            type nacm:node-instance-identifier;
            description
              "Selects the data nodes for which capabilities are
               specified. The special value '/' denotes all data
               nodes in the datastore, consistent with the path
               leaf node on page 41 of [RFC8341].";
            reference
              "RFC 8341: Network Configuration Access Control Model";
          }
        }
https://datatracker.ietf.org/doc/html/rfc8341#section-3.5.2
     typedef node-instance-identifier {
       type yang:xpath1.0;
       description
         "Path expression used to represent a special
          data node, action, or notification instance-identifier
          string.
          A node-instance-identifier value is an
          unrestricted YANG instance-identifier expression.
         All the same rules as an instance-identifier apply,
          except that predicates for keys are optional.  If a key
          predicate is missing, then the node-instance-identifier
          represents all possible server instances for that key.
          This XML Path Language (XPath) expression is evaluated in the
          following context:
             o  The set of namespace declarations are those in scope on
                the leaf element where this type is used.
             o  The set of variable bindings contains one variable,
                'USER', which contains the name of the user of the
                current session.
             o  The function library is the core function library, but
                note that due to the syntax restrictions of an
                instance-identifier, no functions are allowed.
             o  The context node is the root node in the data tree.
          The accessible tree includes actions and notifications tied
          to data nodes.";
     }



Thomas Graf
____________________________________________________________________________
Distinguished Network Engineer
Network Analytics Architect
Telefon +41-58-223 84 01
Mobile  +41-79-728 80 12
thomas.graf@swisscom.com<mailto:thomas.graf@swisscom.com>
____________________________________________________________________________
Swisscom (Schweiz) AG
IT, Network & Infrastructure
Datacenter Functions
Binzring 17
8045 Zürich
www.swisscom.com<http://www.swisscom.com/>
Postadresse:
Binzring 17
8045 Zürich


From: Reshad Rahman <reshad@yahoo.com>
Sent: Tuesday, March 10, 2026 10:40 PM
To: nmop@ietf.org; draft-ietf-nmop-yang-message-broker-integration@ietf.org; Graf Thomas, SCS-INI-NET-VNC-E2E <Thomas.Graf@swisscom.com>
Cc: benoit.claise@huawei.com; ludwig=40clemm.org@dmarc.ietf.org; balazs.lengyel=40ericsson.com@dmarc.ietf.org
Subject: Re: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities

Be aware: This is an external email.

Hi Thomas,

Even bigger apologies from me, that RTT doesn't match the SLO :-( Unfortunately, your email somehow ended up in the wrong folder, and only when I was going through the archive for threads on this document I noticed that you replied...

I don't interpret RFC9196 and RFC8341's node-instance-identifier the same way as you do. I also don't see how RFC9196's implementation-time use case works if the data in per-node-capabilities is user-specific. But I can very well be mistaken.

Regards,
Reshad.

On Friday, November 28, 2025 at 11:55:16 PM PST, <thomas.graf@swisscom.com<mailto:thomas.graf@swisscom.com>> wrote:



Dear Reshad,



Apologies for late reply. I believe my reply https://mailarchive.ietf.org/arch/msg/netconf/ByHjCK3UEmNaWiKoJsciA_-qAVs/ back then was a bit too short and thanks for giving me a nudge.😊



My understanding is as following, and please correct/challenge me, I might have misunderstood something. I put the RFC 9196 authors in CC. They might want to jump in and comment.



The leaf "node-selector" in ietf-system-capabilities@2022-02-17.yang<mailto:ietf-system-capabilities@2022-02-17.yang> is using a type reference to nacm:node-instance-identifier in ietf-netconf-acm@2018-02-14.yang<mailto:ietf-netconf-acm@2018-02-14.yang>. According to typedef node-instance-identifier definition, the YANG node permissions are inherited. See below for references.



Therefor I believe RFC 9196 does it correctly. The netconf client user who discovers the capabilities sees only the xpaths which he can subscribe in YANG-Push.



https://datatracker.ietf.org/doc/html/draft-ietf-nmop-yang-message-broker-integration-09#section-4.1 implies that the netconf client user who discovers is also the one which subscribes. Let me know wherever it is worth to detail in the document that discovery and subscription have the same access rights when the same user is used.



Best wishes

Thomas





https://datatracker.ietf.org/doc/html/rfc9196#section-4.2

      list per-node-capabilities {

        description

          "Each list entry specifies capabilities for the selected

           data nodes.  The same capabilities apply to the data nodes

           in the subtree below the selected nodes.



           The system SHALL order the entries according to their

           precedence. The order of the entries MUST NOT change

           unless the underlying capabilities also change.



           Note that the longest patch matching can be achieved

           by ordering more specific matches before less

           specific ones.";

        choice node-selection {

          description

            "A method to select some or all nodes within a

             datastore.";

          leaf node-selector {

            type nacm:node-instance-identifier;

            description

              "Selects the data nodes for which capabilities are

               specified. The special value '/' denotes all data

               nodes in the datastore, consistent with the path

               leaf node on page 41 of [RFC8341].";

            reference

              "RFC 8341: Network Configuration Access Control Model";

          }

        }



https://datatracker.ietf.org/doc/html/rfc8341#section-3.5.2

     typedef node-instance-identifier {

       type yang:xpath1.0;

       description

         "Path expression used to represent a special

          data node, action, or notification instance-identifier

          string.



          A node-instance-identifier value is an

          unrestricted YANG instance-identifier expression.

         All the same rules as an instance-identifier apply,

          except that predicates for keys are optional.  If a key

          predicate is missing, then the node-instance-identifier

          represents all possible server instances for that key.



          This XML Path Language (XPath) expression is evaluated in the

          following context:



             o  The set of namespace declarations are those in scope on

                the leaf element where this type is used.



             o  The set of variable bindings contains one variable,

                'USER', which contains the name of the user of the

                current session.



             o  The function library is the core function library, but

                note that due to the syntax restrictions of an

                instance-identifier, no functions are allowed.



             o  The context node is the root node in the data tree.



          The accessible tree includes actions and notifications tied

          to data nodes.";

     }



From: Reshad Rahman <reshad@yahoo.com<mailto:reshad@yahoo.com>>
Sent: Wednesday, October 29, 2025 4:23 PM
To: Nmop <nmop@ietf.org<mailto:nmop@ietf.org>>; draft-ietf-nmop-yang-message-broker-integration@ietf.org<mailto:draft-ietf-nmop-yang-message-broker-integration@ietf.org>
Subject: Question on draft-ietf-nmop-yang-message-broker-integration



Be aware: This is an external email.



Hi,



Going through the broker-integration document<https://datatracker.ietf.org/doc/draft-ietf-nmop-yang-message-broker-integration>, it reminded me of this thread<https://mailarchive.ietf.org/arch/msg/netconf/L0Z7UeVrICoKq0NSOdMH8MyMIow/>. Looking at sections 4 and 4.1, specifically steps (1) and (2): user A reads the RFC9196 capabilities and sees that /interfaces/interface/ifstate supports on-change (meaning user A has NACM access to the capabilities data). But that doesn't imply that user A can e.g. dynamically subscribe on-change to /interfaces/interface/ifstate? i.e maybe user A does not have access to /interfaces/interface/ifstate?



Regards,

Reshad.