[NMOP] Re: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities
Reshad Rahman <reshad@yahoo.com> Tue, 10 March 2026 21:40 UTC
Return-Path: <reshad@yahoo.com>
X-Original-To: nmop@mail2.ietf.org
Delivered-To: nmop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D6453C7D315C for <nmop@mail2.ietf.org>; Tue, 10 Mar 2026 14:40:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aygfQDI0UeZo for <nmop@mail2.ietf.org>; Tue, 10 Mar 2026 14:40:35 -0700 (PDT)
Received: from sonic320-24.consmr.mail.bf2.yahoo.com (sonic320-24.consmr.mail.bf2.yahoo.com [74.6.128.205]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 14170C7D314D for <nmop@ietf.org>; Tue, 10 Mar 2026 14:40:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1773178828; bh=C2oUZWRGQ7tBHDHw3ryCTZY0nq43J6pBTiNFgk5WV1I=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject:Reply-To; b=IfmTt3FkmMaUtt2fWE3GLqM5mhZahlf6ez3A6wGBtvDxLhH5F14BdcEKVewUW/pcJBYw+po6d8AtEgtGOuE6K7cRkB4fC+coqtf0bhRa5ji3oKt4YbLj+Pj2LVl/pHexVv2pjQiI5jmTfwnA1v6DX3zFQzRxOlCH0p1GadYkZiIdeLXI34nMlFt84xXA+ONMZWDmjaehbeb4YT6q8ISxCMkvqVrLc82Mtrwg/e/nKRyJC5P8BqyYVFE0BLhXxawr92GnWDPYdo8+/Zi7Rr/ul0sUlE7xYDwN4NEIvR1cRttrHj52cIq/vomPKulAT5WGTylCyTiRC4hs6Nk+O5gHZw==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1773178828; bh=XpGKw6NrTVfKsJbLhi5wXup8F2UhfXsFoMvdRc5Sqcz=; h=X-Sonic-MF:Date:From:To:Subject:From:Subject; b=ayQqWYZkneGyqwB99op0SeYdYJfBEYZx+vPKf+0mxGPQo0qjrdQu1CBfGD+7vU3joidS96zDbC+7KUuPIn2qbUVZVReSdmUb1jR9x6AP2zYu+aGSLmZ181EaT98KGrAVNmUK5+e6hSSX0W2lCpL2qnOD16xInIso9zenbycElUdoqfBM0hb9Dx//7anXxsB+WgU7J80d9QqB4g19W92knVJp1sxnLBCZLo6qoq8+i1MCZLQj4yDvGrorBH+VaP7daJoH6r0h75eX1hozBlLK5XtwB47pxqzq8BabokuoqaT9IKEjL26Z92G99Ind+rv1kR3yqeX4rsfqci3tdwSJXA==
X-YMail-OSG: cHU2B3MVM1kBKHijGtJoCMrkbr5331qc64NSdQGj1GBJB5iPeE_eyV4igEKmhMF 8Ng2BfOZ3E5VWjLCVZQltm3SI3Z8xMUJEa.rHhcd152VeKJPg78r9POMUrwcETdcM1sjp5HcvTl9 i.1Rk..Wareje2ABYFtWCYfRER817BNoTO1EE98AxCkX8KtUaYzlPeveZGCUvE__Wy55PVSa2lVP QqsHeY4L8tpfz1o0sw4QfRRY7jJGcazfkTXwBUF8DP6acMw8hmPjwHLgUsEn1l3d2.eemdsX9oGG 1lZSBT0G66eHeN_tpyQBUtjdRpnVnVE5AwxN9YPwKoPhymwyINInhyibhCH_58FvNF9fiYtDvZA7 GOXIzAH5bqNuGV480POR39PcftAKYUUlxLnGa1kW9lFUHK5US18sVNH5XQIv2S0oHpdipxbURBiP W04no1_RygLmpMceIasaTHhuIAzLT71PPCIcvIRuXzOQh2alm.cmcpS3D.hJmpErrE07BdiVFeTU hMtT2mRMGDvcO4eznpz4uhyFMrcNSl78S9UKmlB3S.0k7raJhzGdFVlX_B16h5TjAjwh_0rJ3tHx DZXwHpMdy0bNGqqkNgl99_mg_FPHCvrMSuEIjehL2Nt3OnpT.tzbFtapZQiKZiQNOZ14d4rn2pf0 ZtNoqgUKQFsoCA4wA2y1hu4cUAjX5ND79SAag99sG3vAb_OVluDM8kMIpfgnla2Pht3SwqVVAXEY l3fxUuLYCnQfRc75Op4ZEV5UHj56P1V1IEXQmVlTWfSPw4TawNkk511DNNmuzSQnV4Sfsgxvf2o6 vjKkr_ycAlqRyia15kz0voU0zXcYATz9pB55OHKc_xi9ZAMF4nZKi91j7y1Q0.jJbTN7sfyIVKzk LMY.RRM6Y6dPEctvoVPJa6Mbo9RgMuz7WgnpmB7mn_wCQFCNLUlx5jKnLq5V9zspAUXFguqVDCtB .AT.ijcmSVJkvDO4YO8S1_PH0PCJ9hx4rgIZPdYq5_4dkqVoJNp1aebd3eE6z6kB_CeVmmKYo3HJ sxFUy4ZlkTdTrwoDYldi6KesPcqg7jRgHrj1UD5WX9Nn3_C7T0ybRQQR.suZmHoPhGC9nHS0tf7. vU4iIuktno7UPaGhKI3.FUqy9qw2tH3ymoCbNXDeqTMfht3Wuf3FyQjkMyNr3KjeqGCTxVokIyca 0umP1WW7jC9z3XRorW7A7k8m2T81tpWrRFr3t997POZIwqf9c_gW1YdZRGH897ijRikv7A4y5wbe PuDoYkF2fPSp4dCQm89x4e4ZsxV2sRTuHQU_Jq2eHH26f._K5hPnuyzFQM_twhdkSWvRolT57TXT f2La7uZh22Bso41Xn6fZ0qDBIuEOOy_i.j.CcohIiKf3SEMWCPwhPUn1ucb7occBx.5qr7LTXixK oITq81489O2dyDHKmv8tIYjMvjGsnJQgxxmeLwemCfJhXuMVEPpatmo0U5pEMbtUiexyTAqAt3OY ivD51FM_5aijLesHwdJcIGwzptf.EFghvPZUZT9jxJ6S0OtpO13vefGeLCh9xMvjF0bCg5WbUU5s aM1Nawyiqt8T4xVCBje0iSDo0wzdgNoB8FbbF9WfjcOye_KOR9u8TSzbuovNdfzYPL6tWU10pJCF lKNwuz_UVQq5._cn5SXlRyNRnfgYf3syuh4OraxdKpirCJhy9DoUsL4hQAxpsIbGa1FRtBkHFEcn lXlkVDq3v1SrpGZSwmpDWhMFGOMJ_2MyaSn1AcgXKA6cw.VniMl3OpNxtCveZfXXHC5LQre4dYWT nvUIwFxTHgqSXTQFcoM65EEQwT8PGyV4ALU4m.XKqp7NLnr_Iq46Ahhpk8E6CuQCPTRpq7pJ1xR6 At6g7nTFZN_y1dhyWV.ssnfUBXmQ.tUqjAIaabNEwTfJGfPNA8Vme3ft3LhXnhUdKEhlucsNryNU TrPKq0GT4C6lI8EQE_lBCBnlIJ5JIYwiexp5jA9_Xf8jAKTkEhK1QM.9Vum7Dw1jW1mzIKWzrjU5 5S98LNkbEg.x6eziZ15h9ds9hIuRwv35GAX_xUcKUk7e3rQjzeW6jB4Y9v2B5TLnLv.DEW631xYH w69zhOeIHyTAKHIfyEovQYL8N5L0E5ZhAYS0WXdMgbRhEERyI8ghgfLe5fKxYQEM9iD0ngtND4Mb gq6Afu0b19Q8Nw.cjG6gXVnC5L14fc6vo3Y8iIverIlURJvtXC18h6dhvLxdj7PSKJe4EuBkLKkm MSWBA.4OFqoo5WiN6_P__VtgTmJQIupBUoT.oLqvxJHZj3q8Frw--
X-Sonic-MF: <reshad@yahoo.com>
X-Sonic-ID: 846a877d-0445-41bd-a92f-0bdb35e1dbd7
Received: from sonic.gate.mail.ne1.yahoo.com by sonic320.consmr.mail.bf2.yahoo.com with HTTP; Tue, 10 Mar 2026 21:40:28 +0000
Date: Tue, 10 Mar 2026 21:40:22 +0000
From: Reshad Rahman <reshad@yahoo.com>
To: "nmop@ietf.org" <nmop@ietf.org>, "draft-ietf-nmop-yang-message-broker-integration@ietf.org" <draft-ietf-nmop-yang-message-broker-integration@ietf.org>, "thomas.graf@swisscom.com" <thomas.graf@swisscom.com>
Message-ID: <288123420.4898609.1773178822999@mail.yahoo.com>
In-Reply-To: <ZR1P278MB1170CE6C1F4D9633A5CE3BBE89DDA@ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM>
References: <1387624537.1157475.1761751369707.ref@mail.yahoo.com> <1387624537.1157475.1761751369707@mail.yahoo.com> <ZR1P278MB1170CE6C1F4D9633A5CE3BBE89DDA@ZR1P278MB1170.CHEP278.PROD.OUTLOOK.COM>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_4898608_1765459880.1773178822993"
X-Mailer: WebService/1.1.25198 YMailNorrin
Message-ID-Hash: CXA4FQZ5FLKFXYFTKERVEYJYZFNAK2GD
X-Message-ID-Hash: CXA4FQZ5FLKFXYFTKERVEYJYZFNAK2GD
X-MailFrom: reshad@yahoo.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "benoit.claise@huawei.com" <benoit.claise@huawei.com>, "ludwig=40clemm.org@dmarc.ietf.org" <ludwig=40clemm.org@dmarc.ietf.org>, "balazs.lengyel=40ericsson.com@dmarc.ietf.org" <balazs.lengyel=40ericsson.com@dmarc.ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: Reshad Rahman <reshad@yahoo.com>
Subject: [NMOP] Re: Question on draft-ietf-nmop-yang-message-broker-integration - ietf-system-capabilities
List-Id: "Network Management Operations (NMOP) Working Group" <nmop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/nmop/xKAABB23QANGzr8qmm36rdBAZ84>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nmop>
List-Help: <mailto:nmop-request@ietf.org?subject=help>
List-Owner: <mailto:nmop-owner@ietf.org>
List-Post: <mailto:nmop@ietf.org>
List-Subscribe: <mailto:nmop-join@ietf.org>
List-Unsubscribe: <mailto:nmop-leave@ietf.org>
Hi Thomas,
Even bigger apologies from me, that RTT doesn't match the SLO :-( Unfortunately, your email somehow ended up in the wrong folder, and only when I was going through the archive for threads on this document I noticed that you replied...
I don't interpret RFC9196 and RFC8341's node-instance-identifier the same way as you do. I also don't see how RFC9196's implementation-time use case works if the data in per-node-capabilities is user-specific. But I can very well be mistaken.
Regards,Reshad.
On Friday, November 28, 2025 at 11:55:16 PM PST, <thomas.graf@swisscom.com> wrote:
Dear Reshad,
Apologies for late reply. I believe my replyhttps://mailarchive.ietf.org/arch/msg/netconf/ByHjCK3UEmNaWiKoJsciA_-qAVs/ back then was a bit too short and thanks for giving me a nudge.😊
My understanding is as following, and please correct/challenge me, I might have misunderstood something. I put the RFC 9196 authors in CC. They might want to jump in and comment.
The leaf "node-selector" in ietf-system-capabilities@2022-02-17.yang is using a type reference to nacm:node-instance-identifier in ietf-netconf-acm@2018-02-14.yang. According to typedef node-instance-identifier definition, the YANG node permissions are inherited. See below for references.
Therefor I believe RFC 9196 does it correctly. The netconf client user who discovers the capabilities sees only the xpaths which he can subscribe in YANG-Push.
https://datatracker.ietf.org/doc/html/draft-ietf-nmop-yang-message-broker-integration-09#section-4.1 implies that the netconf client user who discovers is also the one which subscribes. Let me know wherever it is worth to detail in the document that discovery and subscription have the same access rights when the same user is used.
Best wishes
Thomas
https://datatracker.ietf.org/doc/html/rfc9196#section-4.2
list per-node-capabilities {
description
"Each list entry specifies capabilities for the selected
data nodes. The same capabilities apply to the data nodes
in the subtree below the selected nodes.
The system SHALL order the entries according to their
precedence. The order of the entries MUST NOT change
unless the underlying capabilities also change.
Note that the longest patch matching can be achieved
by ordering more specific matches before less
specific ones.";
choice node-selection {
description
"A method to select some or all nodes within a
datastore.";
leaf node-selector {
type nacm:node-instance-identifier;
description
"Selects the data nodes for which capabilities are
specified. The special value '/' denotes all data
nodes in the datastore, consistent with the path
leaf node on page 41 of [RFC8341].";
reference
"RFC 8341: Network Configuration Access Control Model";
}
}
https://datatracker.ietf.org/doc/html/rfc8341#section-3.5.2
typedef node-instance-identifier {
type yang:xpath1.0;
description
"Path expression used to represent a special
data node, action, or notification instance-identifier
string.
A node-instance-identifier value is an
unrestricted YANG instance-identifier expression.
All the same rules as an instance-identifier apply,
except that predicates for keys are optional. If a key
predicate is missing, then the node-instance-identifier
represents all possible server instances for that key.
This XML Path Language (XPath) expression is evaluated in the
following context:
o The set of namespace declarations are those in scope on
the leaf element where this type is used.
o The set of variable bindings contains one variable,
'USER', which contains the name of the user of the
current session.
o The function library is the core function library, but
note that due to the syntax restrictions of an
instance-identifier, no functions are allowed.
o The context node is the root node in the data tree.
The accessible tree includes actions and notifications tied
to data nodes.";
}
From: Reshad Rahman <reshad@yahoo.com>
Sent: Wednesday, October 29, 2025 4:23 PM
To: Nmop <nmop@ietf.org>; draft-ietf-nmop-yang-message-broker-integration@ietf.org
Subject: Question on draft-ietf-nmop-yang-message-broker-integration
| |
Be aware: This is an external email.
|
Hi,
Going through the broker-integrationdocument, it reminded me of this thread. Looking at sections 4 and 4.1, specifically steps (1) and (2): user A reads the RFC9196 capabilities and sees that /interfaces/interface/ifstate supports on-change (meaning user A has NACM access to the capabilities data). But that doesn't imply that user A can e.g. dynamically subscribe on-change to /interfaces/interface/ifstate? i.e maybe user A does not have access to /interfaces/interface/ifstate?
Regards,
Reshad.
- [NMOP] Question on draft-ietf-nmop-yang-message-b… Reshad Rahman
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Thomas.Graf
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Reshad Rahman
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Thomas.Graf
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Reshad Rahman
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Per Andersson
- [NMOP] Re: Question on draft-ietf-nmop-yang-messa… Andy Bierman