[Ntp] ntpd-rs: RefID/LI incorrectly reported for source-less stratum-1 config (root cause + patch); also a draft-ID interop note
Pranutha Sundeep <m.pranutha@gmail.com> Sat, 01 August 2026 08:45 UTC
Return-Path: <m.pranutha@gmail.com>
X-Original-To: ntp@mail2.ietf.org
Delivered-To: ntp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 801A312202DAE for <ntp@mail2.ietf.org>; Sat, 1 Aug 2026 01:45:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785573918; bh=HrwNfaV3qumbHtyo33rJ7l9MOhzHrS7PYyCzHI47o9s=; h=From:Date:Subject:To; b=ICU0J+j56D/1HOxEpOP+4RZeD/7A9Gs0pwOCARsLB41RqcQtkqXVkgemLuc+BYzED zBxN2jfXH0/QGJ2k+R2P6b1dXTsvrHUFbDzVS7vlfq5rdRaMejW5OBdJMZb/djmeoq jtcMYM3XBNU143BLYpAqAt99eAfOwq/rRIMm5VJI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7P5cEf50RSaa for <ntp@mail2.ietf.org>; Sat, 1 Aug 2026 01:45:18 -0700 (PDT)
Received: from mail-oa1-x29.google.com (mail-oa1-x29.google.com [IPv6:2001:4860:4864:20::29]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0FD6C12202DA7 for <ntp@ietf.org>; Sat, 1 Aug 2026 01:45:18 -0700 (PDT)
Received: by mail-oa1-x29.google.com with SMTP id 586e51a60fabf-4591f35aff3so48115fac.2 for <ntp@ietf.org>; Sat, 01 Aug 2026 01:45:18 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785573911; cv=none; d=google.com; s=arc-20260327; b=hIdOgFzQkQg4eeqaGJjVGW00/BuJ8L3jylmu1fQQuu68XuAz82x6q8c8npPPd/QHvq zANjLfW0OR6e9PmAPhVwCE5vuDizCWPd5iiW3Atk7R/M8XbNWIpizW9iRwww8YziP1yI bW/ZV9YcQJF3nclquH3KmAZ0D2UTzfkXs9odAbi8OFv1HhDMMqSWLemE89pvGSjRPxFh NwzQqYuvyNdA7c62nDpukg/6+fLVtakZHu2bfdMz1dHEkt4fsEn3VFdFSRbGe41Vuz6U wuEousGVX/spdhRW7uugpc0lzkveAmvozUAbh97oTbsPl/uegfK67ngmM6VDyiz6zGGL Wifg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=HrwNfaV3qumbHtyo33rJ7l9MOhzHrS7PYyCzHI47o9s=; fh=E3UZjAP9mzC0BX3IMSYMjyYz8tGS1Lti74m7NDiYKq0=; b=Gke6tPqgXZHnlwMASYHHBWP0LBsTiUio0oI1IiLWf2Bg8ZwdRBum/4WGMQNkmASPNJ k7ZJso0gq5ntHHtK35f2et4DGINuQElPEPFb9ZEZj0esi6VoaiB9/b6A3nMX+HQgE1+u guYcIsiQWD9zKxGBRT9fEJrdFR9c8vr64wK1cMLLNaSK+aGkfeGS83Hu6K6M+FBXb1Nx mkqoJn/1grJzrnW4MdQRaTnTAXHQTalWIz97lNCRw27n8RjsAw0l9mpo6W644aj4D3QP 6kw5iUQrbeLKK7Xb6bCRVqIjl7DlkhU2F+5J1RzvuDW/7KTGMaT65RRZh/CUZhdcpaFd U++g==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785573911; x=1786178711; darn=ietf.org; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HrwNfaV3qumbHtyo33rJ7l9MOhzHrS7PYyCzHI47o9s=; b=fFt6PrY0El7MRnTduqG5ntPFwfjqwegp0jcpBnJwKzp28OeReo8J1iLqQz0qinDpFp dP2zx02bKroKs9cgpJFVgLgxt6ViH8oFOlikVLbjG3bYMCYbcRZABVtT3HIt2Fp7ukD6 1NAz7U+kPckNO3J4dioW400R3Po4YpYAfi5plpthFYHzp4pS0KCwlhuN8zlCJ6mvByQq BoFRBkDh5fHp64YGnuhPh2yhH6mQ/Oo5K2WeFIlD0mssWWPNYMnbfVIq6Cegb09cnVzM Rf8rF9weoXShsNzsLZGonR/s6nmyiYCdp1t3CuGmmwf3vpunWgo1cUpYnLOpJ5nfNphm brCg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785573911; x=1786178711; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HrwNfaV3qumbHtyo33rJ7l9MOhzHrS7PYyCzHI47o9s=; b=RNKLtREBWhrCMg7LwPaDqXDh5xyFrzw3kcBxC35/BSdB1d6mzO+jKLpW5YyOeppqW3 fEdrt3hVMUqO0iWsFyduhurHx5//YOapYwCJCFA2syS6N3IB12uyfQ1KoikBhhRA40LF v63wIttVctPNhIh+jn62cSnPqiZdz4hv8iKFPuD/0gkdj0DxN5Gp9hZsCv20liDRsWsH FLlDFeoHEPhD4HVjRolfWhgBZMDzzjPjmklHMgl+nTq3E6NvgGtXkd14qNHalgDqkSXy KfEz8UepQRufu/5MH71UcP9y+G3pJ1GFrGqfwWmbR4DDqPeIMZMcCzNGEKzrzi2nUION hKcg==
X-Gm-Message-State: AOJu0YxG6flirGlgFqMWA+H+MNahN54FvT+kLMeN0okop4QqB7CS/1Q/ VmT2ozNrlZQYlu0Ck/tl7OEIBLzj01+B6PKN/u84+BHyIyRxaY/W+HbYosbnAGPsg+SIBP/jYhz /aAg3KY/iBbqbczOxKD5yUCQWuCXOGbGi9Bst
X-Gm-Gg: AR+sD12vua160Vx8fjPJIiG85urV68Tj0dDhJpjqFpGXhKteU3ubNlwSdCSSsG/4hvD 1Se9cfLy6MZ3uv/526m0E4nBTBdyPAM9V3t5AyCp/d0VcvxqdBYyT3WeHL6tGM/VnYZ52/jJfat 0nfLzIcJ/uR/JxQA6q3+pH3Ydey4rEz8Ma21qP91/1O3GXB2Wh/KT0Qf97MTcEnw36urKp4KLsw E8+8hW/0XV+5dOe/7jse/uS8tKEMeLgBQO06Wk9x27NlW7nNIFThyUX/C4rmEFePWFMafuXR3Xn r61//WH8isydy1pQsOp3wcCE8XiBuPl8e8jIh5N/YjUK6zXnPxJ4xsGqEiWyAllgrKTvQEPnVYN VIJ2+o5q2wFvVJf0T/UfHCczZUGuh7lVk4UdOnE+guZLjMBV4ry/FZXNq0iW7mDiO+zdIrazKID Inyg==
X-Received: by 2002:a05:6870:d8c:b0:448:9052:f436 with SMTP id 586e51a60fabf-459059ae6e8mr6628314fac.8.1785573910820; Sat, 01 Aug 2026 01:45:10 -0700 (PDT)
MIME-Version: 1.0
From: Pranutha Sundeep <m.pranutha@gmail.com>
Date: Sat, 01 Aug 2026 03:44:59 -0500
X-Gm-Features: AUfX_mwlVdBv7Cv5GZHOfmv-O81H02rYPBPK-wu9gRB_01SbXxNtSib_b2InwKg
Message-ID: <CAAJYWJEPcGAjpMzbGB0RsG7hhJ4Mb8iqZGVGHr1NaoBQdVYArA@mail.gmail.com>
To: ntp@ietf.org
Content-Type: multipart/alternative; boundary="000000000000acbc6a0657f85203"
Message-ID-Hash: 22FODDTZ7TQIETH2QLF7OD2KLCMF5EBR
X-Message-ID-Hash: 22FODDTZ7TQIETH2QLF7OD2KLCMF5EBR
X-MailFrom: m.pranutha@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ntp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ntp] ntpd-rs: RefID/LI incorrectly reported for source-less stratum-1 config (root cause + patch); also a draft-ID interop note
List-Id: Network Time Protocol <ntp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/NqvfIiTPYUsXRJiwI_omkkcsczU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Owner: <mailto:ntp-owner@ietf.org>
List-Post: <mailto:ntp@ietf.org>
List-Subscribe: <mailto:ntp-join@ietf.org>
List-Unsubscribe: <mailto:ntp-leave@ietf.org>
Hello,
I'm a PhD researcher at the University of Texas at Dallas, working on
cross-protocol time synchronization accuracy (NTPv4, NTPv5, PTP). Through
my work managing a production network, I've had the opportunity to test
this across a fleet of ~90 HPE Aruba AOS-CX switches. As part of that work
I've been running ntpd-rs as an NTPv5-capable reference source (GMR6000
grandmaster -> ptp4l/phc2sys -> ntpd-rs, source-less, local-stratum=1), and
identified and fixed a bug that seems worth sharing with the group.
*Symptom: *a correctly configured source-less ntpd-rs instance
(local-stratum=1, clock authority is phc2sys, not an upstream NTP/NTS
source) correctly reports Stratum=1 to clients, but always emits LI=3
(Unsynchronized) and RefID="XNON", regardless of the configured
reference-id. This matches upstream issue #1718.
*Root cause:* in ntp-proto/src/system.rs, NtpSnapshot::from_used_sources()
unconditionally initializes reference_id = ReferenceId::NONE, only
overwriting it if used_sources.peek() finds an active source. It never
falls back to synchronization_config.reference_id when the source list is
legitimately empty (i.e., stratum-1 with an external clock authority).
Separately, update_used_sources() overwrites the entire snapshot on every
call, clobbering any one-time fix applied at startup in NtpManager::new().
The LI bug is a related but separate path, in update_time_snapshot().
*Proposed Fix:* thread a configured_reference_id parameter into
from_used_sources(); when used_sources is empty and local_stratum == 1,
initialize reference_id from synchronization_config.reference_id instead of
ReferenceId::NONE. A parallel fix gates the LI value the same way.
*Verification: *patched, rebuilt, and confirmed at the wire level -- 8
captured NTPv4 response packets to a production AOS-CX switch all show LI=0
(NoWarning), Stratum=1, RefID='PTP ' as expected. On the switch itself, the
NTP association went from a permanent reach=0/.INIT. state to reach=7
(climbing) with REF-ID=.PTP.. -- its first successful NTP association in
this deployment. Zero regressions observed.
I'm happy to open a PR against ntpd-rs with this if useful.
And on a separate note, a smaller observation regarding draft ID
mismatch. While
testing against a real ntpd-rs NTPv5 server, I found it identifies as
"draft-ietf-ntp-ntpv5-08". A client sending a non-matching draft ID (e.g.
-09) has its packets silently dropped, with the only trace being a
TRACE-level log line ("Mismatched draft ID ignoring packet!"). From an
interop-robustness standpoint this seems worth a note somewhere (e.g. a
louder log level, or a response/rejection rather than a silent drop), since
it's easy for an operator or implementer to mistake for a network issue.
Happy to share more detail, packet captures, or the patch itself if useful.
Best,
Pranutha Malickal
PhD Researcher, Computer Engineering, University of Texas at Dallas
Network and Security Manager, Dallas Theological Seminary, Dallas
- [Ntp] ntpd-rs: RefID/LI incorrectly reported for … Pranutha Sundeep
- [Ntp] Re: ntpd-rs: RefID/LI incorrectly reported … Danny Mayer