[Ntp] Focussing loop detection on loop detection only.
David Venhoek <david@venhoek.nl> Wed, 08 July 2026 07:54 UTC
Return-Path: <david@venhoek.nl>
X-Original-To: ntp@mail2.ietf.org
Delivered-To: ntp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 014B6112BF732 for <ntp@mail2.ietf.org>; Wed, 8 Jul 2026 00:54:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783497253; bh=LxyNrqyS4egnK1vEClKQM7DoYa/HmBF+1QcyjiUF830=; h=From:Date:Subject:To; b=qwxhyr67H9mihCScDaElSCP0c8z+L3HF9Svnuzhct2Z5BTeZVHcUAjjSgI1KlyNDW JBmI19ctKUDrT5uK2hWx/5cSsHFunUgLLyd2NN0e/ahHm+62AGiL09LlW04ulkOxgJ zJHJH47VUpU+2xLDETyjmiQedC5co99DlXb2Wtko=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=venhoek.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pPVLlwHItehd for <ntp@mail2.ietf.org>; Wed, 8 Jul 2026 00:54:12 -0700 (PDT)
Received: from mail-pj1-x1031.google.com (mail-pj1-x1031.google.com [IPv6:2607:f8b0:4864:20::1031]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 49D9F112BF72D for <ntp@ietf.org>; Wed, 8 Jul 2026 00:54:12 -0700 (PDT)
Received: by mail-pj1-x1031.google.com with SMTP id 98e67ed59e1d1-3856d4015e0so30476a91.2 for <ntp@ietf.org>; Wed, 08 Jul 2026 00:54:11 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783497251; cv=none; d=google.com; s=arc-20260327; b=L+sAO38byq2n9PLqJLUFoPJweD/sOIfI8K7aylouBhgED4A0JnLONfpsOpoaFyNXuf r9ksqdo62l3k6oaZK1M6g4v4SwetvN53E13vspEofBl97KZqjpacHG04mjqwpIdapFHe +osbXLANn394zGnNFio7Epw+nwt0SFWPsKznPWkHHO3p3NH0RB2G7eWiTcTbO41x17e7 Z7xDqGuTQFGIjBDUCDQvIgbQFV6ZJFa5XsnVNOkAat+dLhyiPecCqBqMiu72d1x/7vJg SL1Tp/AXsf1qkS73wgjGskpl4QMuaCa7eOXtgDPOXoVaPZOtbQUb6fdqMNz28+X7vJKC q/Bw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; fh=xE8u0ZNrJqEAi3Ihq+/Az0nvUwk65KaNGlZcdjSShQs=; b=pMUHvp6+gHseqZUEO9b0gWJDLJgBMT6CzudTd98xmF5awc7HU80Ovf0ccvV0sYProu EwiRwEVhe2gybiJ6aahR9hyxSIPq31aA/lyXnelr1eZa010+nE5hKylw7fdenQ//q9eh 4IWd+jfZ0c3fAN7rypV/DA/28vqfvmv2RoV791JKyjxGje6SQpJ3aleBzyJDoxiXf1a7 vmC8G0SZpSrXeKz48dZtcHaV+DKScKGFHg1QOIOs7vaswEti1xcrcq2d980utDjIMfHA uhpRgVCPt41wV9/mBfHv2vLIuU9h6CUvrNJl+mHB52KnmgKLteSECt689hYuKXMbhguS QAZg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=venhoek.nl; s=google; t=1783497251; x=1784102051; darn=ietf.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; b=Gr9fPC3Kr2aju7XE7QBo+b0uYLpXtGhygkH5taMF3oLFiHrWK7s0q6NC9kxJfHhOm4 iEUA46AsNcu1+ERunOVJ22pvqN9Hl+GBSaB5Ao8dmTOkooPhxLrYpt58NoHJQvqifTaY aMd5pRNzl9GYOtjvvVo1PPj0XznlDOsRVDBhvjvyttUyzxnQDtLIEjf3YFMxgAoF3juT qb26Llt81SCgRUm71AKLHqlDEfboBZSvVpTrIwlNELvhYGSwyAe+ErM76Glo1olIaelx gxLOKK7e0DEsmJouov3k9dAHthQLfqTy0nswWHftecgkUWD43oYo4fW+PjhC7sz2BxX4 knQw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783497251; x=1784102051; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YdCnt3h5MpdKJWxhG8+pIZ8EuA6J17Q6SUyQr4UY79g=; b=aulcwAZtS4/b3Z2YPp4EN7c4AIvY4s0LGKDslUmt7/viR9HVboQpTcfuecpl/drP81 E6lqe3M+n9ROv1OAJXWRhPygBgi8fMbhwPmbuNR98Tvp9EtEjF9jwFg3IbfS+R9JCxOs LpgropovDu4wTNWmnd+FJMWcFD3JTbbh/6x1LniP1HFkpy2L6MuC94p8sEf5hTf/2cJZ rxs6HCP8/Wr8NXNlt+2GUdVJp5k6jUZLH/+AxWRSwXAvtIrtCq17USZG0FQzIdKHBlzS uJXTxbwV0utk01cKsCKu7s1fs2zbguP9PHAMZ5zzB+svCZkmjas1QQL9l17IilqYhZ6S sVng==
X-Gm-Message-State: AOJu0YzESQfx7mraV9eERQt4rCLvt0pFfNMzo5Xy2BkR12PC+50GShJM Ou2SFMTbzBfKIznzUAnNaV4I7YcMqn0Mzq34c1OtfpqOyUJOh1Jfrt8Ks6p4qm8UO8gYAyAqZmS AaxybpqIaw4w+afJHDqdeOP49LGcLaKwSmay6fZl/9/2hA3IyQwPW9Y0=
X-Gm-Gg: AfdE7cmUHCk5ioQVcTypnMiMc//M3KiRxVONtDYWCy5B46DG8otfDg1mgSxk3yvF8wG HK22bUoKp+82thm7aKmdK6TfMPVR2YV3OjCFJ9PkR1R4GeYNT5xL1i4+k646itLlbQiiQbd/rAH J+Vc19AetRs0k0twJ7Do6lFer0C6gRIGmYDIWcAOvHznY+ZDo4FNgfXm3xIFQbIjZjsXcCOPdjr o6GbLfOEETVoSaNVF+fjKkiyVLewJodAolKoqD4AkLYF36r9Z3th1EHWUAvBIgAp9sOjdV9Vstf EPvTvCWioVds
X-Received: by 2002:a17:90b:57cd:b0:381:77cd:38ca with SMTP id 98e67ed59e1d1-389417e432fmr1208185a91.4.1783497250636; Wed, 08 Jul 2026 00:54:10 -0700 (PDT)
MIME-Version: 1.0
From: David Venhoek <david@venhoek.nl>
Date: Wed, 08 Jul 2026 09:53:59 +0200
X-Gm-Features: AVVi8CebOrWoVs3cP5bD1La3o4e-wxipXxKjzCGpEJDTl1lSizEQJ2EGbnkYBR8
Message-ID: <CAPz_-SUxrGMUy2UJ1vcfX5jb3FSHqXZ3VAuhwSfxTRMrbTj28g@mail.gmail.com>
To: NTP WG <ntp@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: VF4WM3IM5YKSQX63ADXSNWR3HVUEZ2PL
X-Message-ID-Hash: VF4WM3IM5YKSQX63ADXSNWR3HVUEZ2PL
X-MailFrom: david@venhoek.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ntp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ntp] Focussing loop detection on loop detection only.
List-Id: Network Time Protocol <ntp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/5bdqrbzpM8DbZ60f8tshvstkzm0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Owner: <mailto:ntp-owner@ietf.org>
List-Post: <mailto:ntp@ietf.org>
List-Subscribe: <mailto:ntp-join@ietf.org>
List-Unsubscribe: <mailto:ntp-leave@ietf.org>
Hi All, As an alternative to Miroslav's weighted list idea for loop detection, I want to propose we improve the capacity of the bloom filter by removing a lot of the unnecessary sources from the bloom filter itself. Removing the need for stratum 1 servers to put anything in the bloom filter removes a large number of identifiers, reducing the number of ids in miroslav's 5 strata example from 3906 back down to a much more managable 626. The desire to provide information on where the time is coming from primarily can be solved separately by including something similar (but a bit more robust) to the ntpv4 reference id. This can provide information on the primary source of the server, IF the server is willing to share it. Making it optional allows servers which want to have a more defensive posture to not provide such information without having to mess with the loop detection mechanism and becoming non-compliant. Patches to the specification providing these changes are included below, and in the following PR on github: https://github.com/ietf-wg-ntp/draft-ietf-ntp-ntpv5/pull/32 Kind regards, David Venhoek >From 685bd47204650e2be7fc132de1d1c15fec9cb204 Mon Sep 17 00:00:00 2001 From: David Venhoek <david@tweedegolf.com> Date: Wed, 8 Jul 2026 09:18:08 +0200 Subject: [PATCH 1/2] Remove information on non-ntpv5 sources from bloom filter. This provides more room in the bloom filter for sources for which loop detection is actually needed, extending the useful capacity of the filter. --- ntp-ntpv5.xml | 14 +++++--------- 1 file changed, 5 insertions(+), 9 deletions(-) diff --git a/ntp-ntpv5.xml b/ntp-ntpv5.xml index 0c51aef..ead2c3d 100644 --- a/ntp-ntpv5.xml +++ b/ntp-ntpv5.xml @@ -769,15 +769,11 @@ sources selected for synchronization and the server's own reference ID.</t> - <t>If the server uses a previous version of NTP for some of its - sources, the reference IDs added to the filter are generated from - their IP addresses as the first 120 bits of the - <xref target="RFC1321">MD5</xref> sum of the address in network - order. If the server uses a reference clock, the reference ID is the - first 120 bits of the MD5 sum of the 4-octet zero-padded ASCII - string from the NTP Reference Identifier Codes registry maintained by - IANA, or a string beginning with the uppercase letter X, which are - reserved for private and experimental use.</t> + <t>Sources the server uses that are not using NTPv5 shall not be included + in the bloom filter. Furthermore, a server not considering any NTPv5 + server as a potential source may choose to send an empty bloom filter + to its clients. This provides more room in the bloom filter for downstream + clients, lowering the probability of false positives.</t> <t>A client checking whether the server's set of reference IDs contains the client's own reference ID checks whether the bits at the 10 -- 2.47.3 >From 59095c3a611cea5791c6a10d25c1235f02302526 Mon Sep 17 00:00:00 2001 From: David Venhoek <david@tweedegolf.com> Date: Wed, 8 Jul 2026 09:19:15 +0200 Subject: [PATCH 2/2] Provide an optional mechanism for indicating the primary time source. This allows servers to provide insight into what their primary source of synchronization is, without having to use valuable space in the bloom filter and without risks of false positives. --- ntp-ntpv5.xml | 97 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 97 insertions(+) diff --git a/ntp-ntpv5.xml b/ntp-ntpv5.xml index ead2c3d..608c349 100644 --- a/ntp-ntpv5.xml +++ b/ntp-ntpv5.xml @@ -881,6 +881,56 @@ to other NTP servers (i.e. they can be in a synchronization loop).</t> </section> + <section title="Primary Source Extension Field" + anchor="primary-source-extension-field"> + <t>This extension filed provides a method for clients to query a server + about what its most important source of time synchronization is. It consists + of a Kind field describing the kind of identifier, together with the actual + value of the source identifier.</t> + + <t>The format of the Primary Source Extension Field is shown in Figure <xref + format="counter" target="primary-source-ext-field"/>.</t> + + <figure align="center" anchor="primary-source-ext-field" + title="Format of Primary Source Extension Field"> + <artwork><![CDATA[ + 0 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 ++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +| Type = [[TBD]] (draft 0xF50A) | Length | ++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +| Kind | Reserved | | ++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + +. . +. Source Identifier (variable) . +. . ++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ]]></artwork> + </figure> + + <t>The client requests information on the primary source of a server by + including the Primary Source Extension Field in its request, with special None kind (0) + and a identifier 16 bytes long consisting of all 0s. The dummy value is provided to + ensure there is room for the identifier in the response regardless of its kind.</t> + + <t>If supported by the server, and if the identifier is shorter or equal in length to the + None identifier provided by the client, the server SHALL include a Primary Source Extension + Field in its response containing the source identifier of the source which most + contributes to its estimate of the current time. The server SHALL NOT send a Primary Source + Extension Field in its response which is larger than the Primary Source Extension Field in the + client's request.</t> + + <t>If the servers primary source is an NTP source reached over IpV4, it shall use the IpV4 kind (1) + and provide the IpV4 address of the source as the source identifier.</t> + + <t>If the servers primary source is an NTP source reached over IpV6, it shall use the IpV6 kind (2) + and provide the IpV6 address of the source as the source identifier.</t> + + <t>If the servers primary source cannot reasonably be described by any of the other kinds known to + the server, it may use the NTP Reference Identifer kind (3), and provide an entry from the IANA NTP Reference + Identifier Codes table to describe the source.</t> + </section> + <section title="Server Information Extension Field" anchor="server-information-extension-field"> <t>This field provides clients with information about which NTP @@ -1732,6 +1782,10 @@ Tx | 0 | | t3'| | 0 | | t3 | | 0 | |t11'| <c>Reference IDs Request</c> <c><xref target="reference-ids-extension-fields">[[this memo]]</xref></c> + <c>[[TBD]]</c> + <c>Primary Source</c> + <c><xref target="primary-source-extension-field">[[this memo]]</xref></c> + <c>[[TBD]]</c> <c>Reference IDs Response</c> <c><xref target="reference-ids-extension-fields">[[this memo]]</xref></c> @@ -1774,6 +1828,49 @@ Tx | 0 | | t3'| | 0 | | t3 | | 0 | |t11'| <c>Network Time Protocol version 5 (NTPv5)</c> <c><xref target="network-time-security">[[this memo]]</xref></c> </texttable> + + <t>IANA is requested to create a new registry entitled "Network Time + Protocol Source Identifier Types". Its entries SHALL have the following + fields: + <list> + <t>Number (REQUIRED): An integer in the range 0–255 inclusive.</t> + <t>Description (REQUIRED): A short text description of the identifier type.</t> + <t>Reference document (REQUIRED): A reference to the relevant + specification document.</t> + </list> + The policy for allocation of new entries in this registry SHALL vary by + their Number, as follows: + <list> + <t> 0–247: IETF Review</t> + <t> 248–255: Private and Experimental Use</t> + </list> + </t> + + <t> The initial contents of the Network Time Protocol Source Identifier Types + Registry SHALL be as follows: + </t> + + <texttable> + <ttcol>Number</ttcol> + <ttcol>Description</ttcol> + <ttcol>Reference</ttcol> + + <c>0</c> + <c>None</c> + <c><xref target="primary-source-extension-field">[[this memo]]</xref></c> + + <c>1</c> + <c>IpV4</c> + <c><xref target="primary-source-extension-field">[[this memo]]</xref></c> + + <c>2</c> + <c>IpV6</c> + <c><xref target="primary-source-extension-field">[[this memo]]</xref></c> + + <c>3</c> + <c>NTP Reference Identifier</c> + <c><xref target="primary-source-extension-field">[[this memo]]</xref></c> + </texttable> </section> <section title="Implementation Status - RFC EDITOR: REMOVE BEFORE PUBLICATION"> -- 2.47.3
- [Ntp] Focussing loop detection on loop detection … David Venhoek
- [Ntp] Re: [EXT] [EXT] Focussing loop detection on… Windl, Ulrich
- [Ntp] Re: [EXT] [EXT] Focussing loop detection on… Miroslav Lichvar
- [Ntp] Re: [EXT] Re: Re: [EXT] [EXT] Focussing loo… Windl, Ulrich
- [Ntp] Re: [EXT] [EXT] Focussing loop detection on… David Venhoek
- [Ntp] Re: [EXT] [EXT] Focussing loop detection on… Miroslav Lichvar
- [Ntp] Re: [EXT] Re: Re: [EXT] [EXT] Focussing loo… Hal Murray
- [Ntp] Re: [EXT] Re: Re: [EXT] Re: Re: [EXT] [EXT]… Windl, Ulrich
- [Ntp] Re: [EXT] Re: Re: [EXT] Re: Re: [EXT] [EXT]… Hal Murray
- [Ntp] Re: [EXT] Re: Re: [EXT] Re: Re: [EXT] [EXT]… Miroslav Lichvar
- [Ntp] Re: [EXT] Re: [EXT] Re: Re: [EXT] Re: Re: [… Windl, Ulrich
- [Ntp] Re: [EXT] Re: [EXT] Re: Re: [EXT] Re: Re: [… David Venhoek