[Ntp] Focussing loop detection on loop detection only.

David Venhoek <david@venhoek.nl> Wed, 08 July 2026 07:54 UTC

Return-Path: <david@venhoek.nl>
X-Original-To: ntp@mail2.ietf.org
Delivered-To: ntp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 014B6112BF732 for <ntp@mail2.ietf.org>; Wed, 8 Jul 2026 00:54:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783497253; bh=LxyNrqyS4egnK1vEClKQM7DoYa/HmBF+1QcyjiUF830=; h=From:Date:Subject:To; b=qwxhyr67H9mihCScDaElSCP0c8z+L3HF9Svnuzhct2Z5BTeZVHcUAjjSgI1KlyNDW JBmI19ctKUDrT5uK2hWx/5cSsHFunUgLLyd2NN0e/ahHm+62AGiL09LlW04ulkOxgJ zJHJH47VUpU+2xLDETyjmiQedC5co99DlXb2Wtko=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=venhoek.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pPVLlwHItehd for <ntp@mail2.ietf.org>; Wed, 8 Jul 2026 00:54:12 -0700 (PDT)
Received: from mail-pj1-x1031.google.com (mail-pj1-x1031.google.com [IPv6:2607:f8b0:4864:20::1031]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 49D9F112BF72D for <ntp@ietf.org>; Wed, 8 Jul 2026 00:54:12 -0700 (PDT)
Received: by mail-pj1-x1031.google.com with SMTP id 98e67ed59e1d1-3856d4015e0so30476a91.2 for <ntp@ietf.org>; Wed, 08 Jul 2026 00:54:11 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783497251; cv=none; d=google.com; s=arc-20260327; b=L+sAO38byq2n9PLqJLUFoPJweD/sOIfI8K7aylouBhgED4A0JnLONfpsOpoaFyNXuf r9ksqdo62l3k6oaZK1M6g4v4SwetvN53E13vspEofBl97KZqjpacHG04mjqwpIdapFHe +osbXLANn394zGnNFio7Epw+nwt0SFWPsKznPWkHHO3p3NH0RB2G7eWiTcTbO41x17e7 Z7xDqGuTQFGIjBDUCDQvIgbQFV6ZJFa5XsnVNOkAat+dLhyiPecCqBqMiu72d1x/7vJg SL1Tp/AXsf1qkS73wgjGskpl4QMuaCa7eOXtgDPOXoVaPZOtbQUb6fdqMNz28+X7vJKC q/Bw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; fh=xE8u0ZNrJqEAi3Ihq+/Az0nvUwk65KaNGlZcdjSShQs=; b=pMUHvp6+gHseqZUEO9b0gWJDLJgBMT6CzudTd98xmF5awc7HU80Ovf0ccvV0sYProu EwiRwEVhe2gybiJ6aahR9hyxSIPq31aA/lyXnelr1eZa010+nE5hKylw7fdenQ//q9eh 4IWd+jfZ0c3fAN7rypV/DA/28vqfvmv2RoV791JKyjxGje6SQpJ3aleBzyJDoxiXf1a7 vmC8G0SZpSrXeKz48dZtcHaV+DKScKGFHg1QOIOs7vaswEti1xcrcq2d980utDjIMfHA uhpRgVCPt41wV9/mBfHv2vLIuU9h6CUvrNJl+mHB52KnmgKLteSECt689hYuKXMbhguS QAZg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=venhoek.nl; s=google; t=1783497251; x=1784102051; darn=ietf.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; b=Gr9fPC3Kr2aju7XE7QBo+b0uYLpXtGhygkH5taMF3oLFiHrWK7s0q6NC9kxJfHhOm4 iEUA46AsNcu1+ERunOVJ22pvqN9Hl+GBSaB5Ao8dmTOkooPhxLrYpt58NoHJQvqifTaY aMd5pRNzl9GYOtjvvVo1PPj0XznlDOsRVDBhvjvyttUyzxnQDtLIEjf3YFMxgAoF3juT qb26Llt81SCgRUm71AKLHqlDEfboBZSvVpTrIwlNELvhYGSwyAe+ErM76Glo1olIaelx gxLOKK7e0DEsmJouov3k9dAHthQLfqTy0nswWHftecgkUWD43oYo4fW+PjhC7sz2BxX4 knQw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783497251; x=1784102051; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; b=aulcwAZtS4/b3Z2YPp4EN7c4AIvY4s0LGKDslUmt7/viR9HVboQpTcfuecpl/drP81 E6lqe3M+n9ROv1OAJXWRhPygBgi8fMbhwPmbuNR98Tvp9EtEjF9jwFg3IbfS+R9JCxOs LpgropovDu4wTNWmnd+FJMWcFD3JTbbh/6x1LniP1HFkpy2L6MuC94p8sEf5hTf/2cJZ rxs6HCP8/Wr8NXNlt+2GUdVJp5k6jUZLH/+AxWRSwXAvtIrtCq17USZG0FQzIdKHBlzS uJXTxbwV0utk01cKsCKu7s1fs2zbguP9PHAMZ5zzB+svCZkmjas1QQL9l17IilqYhZ6S sVng==
X-Gm-Message-State: AOJu0YzESQfx7mraV9eERQt4rCLvt0pFfNMzo5Xy2BkR12PC+50GShJM Ou2SFMTbzBfKIznzUAnNaV4I7YcMqn0Mzq34c1OtfpqOyUJOh1Jfrt8Ks6p4qm8UO8gYAyAqZmS AaxybpqIaw4w+afJHDqdeOP49LGcLaKwSmay6fZl/9/2hA3IyQwPW9Y0=
X-Gm-Gg: AfdE7cmUHCk5ioQVcTypnMiMc//M3KiRxVONtDYWCy5B46DG8otfDg1mgSxk3yvF8wG HK22bUoKp+82thm7aKmdK6TfMPVR2YV3OjCFJ9PkR1R4GeYNT5xL1i4+k646itLlbQiiQbd/rAH J+Vc19AetRs0k0twJ7Do6lFer0C6gRIGmYDIWcAOvHznY+ZDo4FNgfXm3xIFQbIjZjsXcCOPdjr o6GbLfOEETVoSaNVF+fjKkiyVLewJodAolKoqD4AkLYF36r9Z3th1EHWUAvBIgAp9sOjdV9Vstf EPvTvCWioVds
X-Received: by 2002:a17:90b:57cd:b0:381:77cd:38ca with SMTP id 98e67ed59e1d1-389417e432fmr1208185a91.4.1783497250636; Wed, 08 Jul 2026 00:54:10 -0700 (PDT)
MIME-Version: 1.0
From: David Venhoek <david@venhoek.nl>
Date: Wed, 08 Jul 2026 09:53:59 +0200
X-Gm-Features: AVVi8CebOrWoVs3cP5bD1La3o4e-wxipXxKjzCGpEJDTl1lSizEQJ2EGbnkYBR8
Message-ID: <CAPz_-SUxrGMUy2UJ1vcfX5jb3FSHqXZ3VAuhwSfxTRMrbTj28g@mail.gmail.com>
To: NTP WG <ntp@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: VF4WM3IM5YKSQX63ADXSNWR3HVUEZ2PL
X-Message-ID-Hash: VF4WM3IM5YKSQX63ADXSNWR3HVUEZ2PL
X-MailFrom: david@venhoek.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ntp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ntp] Focussing loop detection on loop detection only.
List-Id: Network Time Protocol <ntp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/5bdqrbzpM8DbZ60f8tshvstkzm0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Owner: <mailto:ntp-owner@ietf.org>
List-Post: <mailto:ntp@ietf.org>
List-Subscribe: <mailto:ntp-join@ietf.org>
List-Unsubscribe: <mailto:ntp-leave@ietf.org>

Hi All,

As an alternative to Miroslav's weighted list idea for loop detection,
I want to propose we improve the capacity of the bloom filter by
removing a lot of the unnecessary sources from the bloom filter
itself. Removing the need for stratum 1 servers to put anything in the
bloom filter removes a large number of identifiers, reducing the
number of ids in miroslav's 5 strata example from 3906 back down to a
much more managable 626.

The desire to provide information on where the time is coming from
primarily can be solved separately by including something similar (but
a bit more robust) to the ntpv4 reference id. This can provide
information on the primary source of the server, IF the server is
willing to share it. Making it optional allows servers which want to
have a more defensive posture to not provide such information without
having to mess with the loop detection mechanism and becoming
non-compliant.

Patches to the specification providing these changes are included
below, and in the following PR on github:
https://github.com/ietf-wg-ntp/draft-ietf-ntp-ntpv5/pull/32

Kind regards,
David Venhoek

>From 685bd47204650e2be7fc132de1d1c15fec9cb204 Mon Sep 17 00:00:00 2001
From: David Venhoek <david@tweedegolf.com>
Date: Wed, 8 Jul 2026 09:18:08 +0200
Subject: [PATCH 1/2] Remove information on non-ntpv5 sources from bloom
 filter.

This provides more room in the bloom filter for sources for which loop
detection is actually needed, extending the useful capacity of the
filter.
---
 ntp-ntpv5.xml | 14 +++++---------
 1 file changed, 5 insertions(+), 9 deletions(-)

diff --git a/ntp-ntpv5.xml b/ntp-ntpv5.xml
index 0c51aef..ead2c3d 100644
--- a/ntp-ntpv5.xml
+++ b/ntp-ntpv5.xml
@@ -769,15 +769,11 @@
           sources selected for synchronization and the server's own reference
           ID.</t>

-        <t>If the server uses a previous version of NTP for some of its
-          sources, the reference IDs added to the filter are generated from
-          their IP addresses as the first 120 bits of the
-          <xref target="RFC1321">MD5</xref> sum of the address in network
-          order. If the server uses a reference clock, the reference ID is the
-          first 120 bits of the MD5 sum of the 4-octet zero-padded ASCII
-          string from the NTP Reference Identifier Codes registry maintained by
-          IANA, or a string beginning with the uppercase letter X, which are
-          reserved for private and experimental use.</t>
+        <t>Sources the server uses that are not using NTPv5 shall not
be included
+          in the bloom filter. Furthermore, a server not considering any NTPv5
+          server as a potential source may choose to send an empty bloom filter
+          to its clients. This provides more room in the bloom filter
for downstream
+          clients, lowering the probability of false positives.</t>

         <t>A client checking whether the server's set of reference IDs contains
           the client's own reference ID checks whether the bits at the 10
-- 
2.47.3

>From 59095c3a611cea5791c6a10d25c1235f02302526 Mon Sep 17 00:00:00 2001
From: David Venhoek <david@tweedegolf.com>
Date: Wed, 8 Jul 2026 09:19:15 +0200
Subject: [PATCH 2/2] Provide an optional mechanism for indicating the primary
 time source.

This allows servers to provide insight into what their primary source of
synchronization is, without having to use valuable space in the bloom
filter and without risks of false positives.
---
 ntp-ntpv5.xml | 97 +++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 97 insertions(+)

diff --git a/ntp-ntpv5.xml b/ntp-ntpv5.xml
index ead2c3d..608c349 100644
--- a/ntp-ntpv5.xml
+++ b/ntp-ntpv5.xml
@@ -881,6 +881,56 @@
           to other NTP servers (i.e. they can be in a synchronization
loop).</t>
       </section>

+      <section title="Primary Source Extension Field"
+          anchor="primary-source-extension-field">
+        <t>This extension filed provides a method for clients to query a server
+          about what its most important source of time
synchronization is. It consists
+          of a Kind field describing the kind of identifier, together
with the actual
+          value of the source identifier.</t>
+
+        <t>The format of the Primary Source Extension Field is shown
in Figure <xref
+          format="counter" target="primary-source-ext-field"/>.</t>
+
+        <figure align="center" anchor="primary-source-ext-field"
+            title="Format of Primary Source Extension Field">
+          <artwork><![CDATA[
+ 0                   1                   2                   3
+ 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
+| Type = [[TBD]] (draft 0xF50A) |             Length            |
++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
+|      Kind     |    Reserved   |                               |
++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+                               +
+.                                                               .
+.                   Source Identifier (variable)                .
+.                                                               .
++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
+          ]]></artwork>
+        </figure>
+
+        <t>The client requests information on the primary source of a server by
+          including the Primary Source Extension Field in its
request, with special None kind (0)
+          and a identifier 16 bytes long consisting of all 0s. The
dummy value is provided to
+          ensure there is room for the identifier in the response
regardless of its kind.</t>
+
+        <t>If supported by the server, and if the identifier is
shorter or equal in length to the
+          None identifier provided by the client, the server SHALL
include a Primary Source Extension
+          Field in its response containing the source identifier of
the source which most
+          contributes to its estimate of the current time. The server
SHALL NOT send a Primary Source
+          Extension Field in its response which is larger than the
Primary Source Extension Field in the
+          client's request.</t>
+
+        <t>If the servers primary source is an NTP source reached
over IpV4, it shall use the IpV4 kind (1)
+          and provide the IpV4 address of the source as the source
identifier.</t>
+
+        <t>If the servers primary source is an NTP source reached
over IpV6, it shall use the IpV6 kind (2)
+          and provide the IpV6 address of the source as the source
identifier.</t>
+
+        <t>If the servers primary source cannot reasonably be
described by any of the other kinds known to
+          the server, it may use the NTP Reference Identifer kind
(3), and provide an entry from the IANA NTP Reference
+          Identifier Codes table to describe the source.</t>
+      </section>
+
       <section title="Server Information Extension Field"
           anchor="server-information-extension-field">
         <t>This field provides clients with information about which NTP
@@ -1732,6 +1782,10 @@ Tx  | 0  |    | t3'|      | 0  |    | t3 |
| 0  |    |t11'|
         <c>Reference IDs Request</c>
         <c><xref target="reference-ids-extension-fields">[[this
memo]]</xref></c>

+        <c>[[TBD]]</c>
+        <c>Primary Source</c>
+        <c><xref target="primary-source-extension-field">[[this
memo]]</xref></c>
+
         <c>[[TBD]]</c>
         <c>Reference IDs Response</c>
         <c><xref target="reference-ids-extension-fields">[[this
memo]]</xref></c>
@@ -1774,6 +1828,49 @@ Tx  | 0  |    | t3'|      | 0  |    | t3 |
| 0  |    |t11'|
         <c>Network Time Protocol version 5 (NTPv5)</c>
         <c><xref target="network-time-security">[[this memo]]</xref></c>
       </texttable>
+
+      <t>IANA is requested to create a new registry entitled "Network Time
+        Protocol Source Identifier Types". Its entries SHALL have the following
+        fields:
+        <list>
+          <t>Number (REQUIRED): An integer in the range 0&ndash;255
inclusive.</t>
+          <t>Description (REQUIRED): A short text description of the
identifier type.</t>
+          <t>Reference document (REQUIRED): A reference to the relevant
+            specification document.</t>
+        </list>
+        The policy for allocation of new entries in this registry SHALL vary by
+        their Number, as follows:
+        <list>
+          <t> 0&ndash;247: IETF Review</t>
+          <t> 248&ndash;255: Private and Experimental Use</t>
+        </list>
+      </t>
+
+      <t> The initial contents of the Network Time Protocol Source
Identifier Types
+        Registry SHALL be as follows:
+      </t>
+
+      <texttable>
+        <ttcol>Number</ttcol>
+        <ttcol>Description</ttcol>
+        <ttcol>Reference</ttcol>
+
+        <c>0</c>
+        <c>None</c>
+        <c><xref target="primary-source-extension-field">[[this
memo]]</xref></c>
+
+        <c>1</c>
+        <c>IpV4</c>
+        <c><xref target="primary-source-extension-field">[[this
memo]]</xref></c>
+
+        <c>2</c>
+        <c>IpV6</c>
+        <c><xref target="primary-source-extension-field">[[this
memo]]</xref></c>
+
+        <c>3</c>
+        <c>NTP Reference Identifier</c>
+        <c><xref target="primary-source-extension-field">[[this
memo]]</xref></c>
+      </texttable>
     </section>

     <section title="Implementation Status - RFC EDITOR: REMOVE BEFORE
PUBLICATION">
-- 
2.47.3