Re: [pim] [MBONED] IGMPv3 backward compatibility issue killing SSM

Brian Haberman <brian@innovationslab.net> Tue, 16 April 2024 12:31 UTC

Return-Path: <brian@innovationslab.net>
X-Original-To: pim@ietfa.amsl.com
Delivered-To: pim@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 505C8C14F70B for <pim@ietfa.amsl.com>; Tue, 16 Apr 2024 05:31:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.886
X-Spam-Level:
X-Spam-Status: No, score=-1.886 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SPF_HELO_TEMPERROR=0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=innovationslab-net.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p1-YMlV1yXAB for <pim@ietfa.amsl.com>; Tue, 16 Apr 2024 05:31:28 -0700 (PDT)
Received: from mail-oo1-xc30.google.com (mail-oo1-xc30.google.com [IPv6:2607:f8b0:4864:20::c30]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E8E09C14CEFE for <pim@ietf.org>; Tue, 16 Apr 2024 05:31:12 -0700 (PDT)
Received: by mail-oo1-xc30.google.com with SMTP id 006d021491bc7-5aa2551d33dso2703164eaf.0 for <pim@ietf.org>; Tue, 16 Apr 2024 05:31:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=innovationslab-net.20230601.gappssmtp.com; s=20230601; t=1713270672; x=1713875472; darn=ietf.org; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:from:to:cc:subject :date:message-id:reply-to; bh=2qNWPqgLTVkOmPHs27/GPliMQQ7vW0QuSsVrqJItda8=; b=C1b3LT0o6mUn2RAVRyHzhamowACeuxgDWoCDRYm85lzNOZFCtbmVZ5872lt21VPcx7 TlpgwoGpjm8DrHr18qOn38E/6jhjIYuH9Ei/tGulahytPvl0QTDy+QRpELHdqZbUMbP2 P4eNpzTqeJprSvl40jZNiVY9HXo1yhkfUiNbBdP54wflpo7aBeZmiAFaoBPmAUHsLToy DyEYS6HFkWCmdXZD35NRj/LoNVLoEX1yBDQe0R9WG65IMfhVt8S04ezKOMiKsXDeA2Lh DF76GATM/0VjCHWZJlEAM1nod7nf33gjn/eO5ilFTsuVoMz0M7r7NrNrLU5v1z7gxkMY mbBg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713270672; x=1713875472; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=2qNWPqgLTVkOmPHs27/GPliMQQ7vW0QuSsVrqJItda8=; b=V0uKP3z+HdaSD5dq4sDnrpspcjCwHYuLJPCgC2LxeBfzwYB3KZe/E62KL7wHd0cA1I bNWTjuDVFM+yQc4n3MB2w/z8XNUk50KVmmoB9fZGOEft7YZHXg93NdZ68xyXn0e/nzwL ueE3YqqNNLi/YfVPbNgade9aUg7yIdztztrNfDzt9tl4Cmu/rcqOeS0u8L0fpxTZw1j2 sm/fnnJa6+nTEn+BDbeRcmYalTt6/ruClLWM+pkT/s4acHpfXFV8Xat9vhcOUbP66FNw UXOlt4gTV4Wbr5ONA6pZIJz/6tqTpKxrLZdO/758/SaZfEqDkhPcxJSrnReG/8hP4uNU jlkQ==
X-Gm-Message-State: AOJu0YyGTHCS6HC7cDPCVYdQZJrcgjNroVXB2r8MSMtgm8Y7+x6vwBcU iRkhmOdQLe4S50KHh6ADcd2Ayr65dB9rsKsD2iA3Jk+UNfui0PCW0RZHXvuGHKLZzEPEl9GaBiX L+aE=
X-Google-Smtp-Source: AGHT+IEudpr2lmVyYAPm/wz7gktXJjwC/Uc2V0gwSRRz0mY2Y5y1LPcN2dtOGw9Qq3PZTax1sKsfjw==
X-Received: by 2002:a05:6871:205:b0:235:489d:cea2 with SMTP id t5-20020a056871020500b00235489dcea2mr301006oad.7.1713270671951; Tue, 16 Apr 2024 05:31:11 -0700 (PDT)
Received: from [192.168.1.4] ([172.59.113.110]) by smtp.gmail.com with ESMTPSA id wz2-20020a0568707ec200b0022e9ffdb5a5sm2733391oab.24.2024.04.16.05.31.10 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 16 Apr 2024 05:31:11 -0700 (PDT)
Message-ID: <fd72716a-0a41-4854-aabf-163ca67d5918@innovationslab.net>
Date: Tue, 16 Apr 2024 08:31:09 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Stig Venaas <stig@venaas.com>
Cc: pim@ietf.org
References: <CAHANBtKf03ukXH4sgwN0WVdkaVXnbRYdAGBDmQK56YXrS-z6yA@mail.gmail.com> <CAHANBtKdfS0cPceqv8_R+ToeGOBdUksH7gArKqegqSt_Q0Sf0Q@mail.gmail.com> <ZXtzwBljE45Og27f@faui48e.informatik.uni-erlangen.de> <EDE809A0-E672-4A3B-9F46-E08ECD3D4C23@akamai.com> <edc9d539-4b6c-f238-54c6-210c152e2065@juniper.net> <e9ed1779-4f43-4f71-b8c3-d813bcea81d1@innovationslab.net> <CAHANBtJ0S8RfVvfcMHO5XKeDMpzN0O4Jn3MFPJXecNpBVNs6gQ@mail.gmail.com> <8c620ad0-2174-4cc4-9df9-5940e1225fac@innovationslab.net> <cd8cbc0b-a69d-3bcd-c107-9cc1c4435feb@juniper.net> <CAHANBtL_-Sd-iLV4TjvX+WwrkQHAU3m6w5dNiniqvWYuZjWtvA@mail.gmail.com> <85877FB7-A7E1-4EA2-9A15-80E1262ED956@ieee.org> <8f3b0fba-4dac-41b3-851e-21ab94c660db@innovationslab.net> <CAHANBtLPuGUAqKeJF_H86_N6RnzYitugHNBV0tgVb6cTMTq_xw@mail.gmail.com>
Content-Language: en-US
From: Brian Haberman <brian@innovationslab.net>
Autocrypt: addr=brian@innovationslab.net; keydata= xsFNBGFCWtIBEAC2FIgMIrH27l4L1Uu+vxCBakOv0Y1nxsu61+aulA78two2kCl7OCF+myP8 KQHEFMoZSn+ZvR+QDFyhsHe7qDK0CVf1K3n97PptXG5kvbnDJdwVJV0w9zYC17/VDgGAKLqj 0iNDVc9mYg/zCYdPn616UAj7hNpFgc9f982gLokyR/xbMNvtOwOpToysK+7Oc25oOam0xuUx CHcE4BfzJHO2VmUgWHeTvxervtIeMcn5PUlQ4XhzYH88mLlI1Uno7W5Dfx8FjXLNNAq4aNBM 6QND2LRekYi75pSTFXNpYIZvmgVT/VB6SHpsyJ3Hkio4YqGkPiqCEcB6U1lArT2FmXnzsTOt 6ydx6ONClxtcOmoEWrES+8tU+knaCEo1/XOrWtivTFMzn3Mahf726XxQBG55FkhqQ/Mir70e mTtpm8MDf+Qj4o5OsSF01l0MMxwOPiB57pz+XuUoWvLEjLgnb83eY0/YpBJdYESL3zZ3zMBo zA65cUozqSGHwQnlE1ACRDKhsReSYmiPJR5o3pWvNf5z+1M3tyn4qpuPxFFA1X8tEstpoC9t QoX8oextRj9BXlJCcCOwSVbCN8buO7aJMN3PIwSewjYvNLMxLrMph/8jNAHIaZnIt3CRHAq6 RsEAv8VQBWruIyNyyX0N8upnOpvriqx1eI2yS/B/Z2D8fQoFewARAQABzSlCcmlhbiBIYWJl cm1hbiA8YnJpYW5AaW5ub3ZhdGlvbnNsYWIubmV0PsLBlAQTAQgAPhYhBKm74/fFK6tXux1c k5E020tPLWqqBQJhQlrSAhsDBQkHhh8tBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEJE0 20tPLWqq9fAP/1BO1H3SxphcXPbIsuJ+LoBCoKhrIftwGrLZzyiHYyLSFJ/HWLH2Kv79XJP4 6GkpTCk3VfJp6LEjw9FItwXUn0BEf0LyEy1L7w81YXPq+e4kwTPaQI8CgnbpSS9HBkcUj2r9 bwCjf+QZMqfgbz4d2MkVdVrIM2XPLYQND+Xtu1tyTTnrvFndLQFkDdqHAM9HqoikoNqWqz5j JPaxpJfxqmWr86vNThI7sD0rgMX5TWj7Flngzv2G9/uGEz4rHOIwK6KKiXNKk79kTqjUCQ9j tXl8BC2LQj8xsnWeGISTMR3xbiBPeTX94686O6KcLl7QIVKVS+nqs2l2j2gaXo1AjhBXO7gP GFN+rZzPOUZnPQUek3FeQoZCkfC/ljWBPooCpBe2euv5uZ4NbfKHAr9nmmhg4Uh1IceMxMQ/ /kB2wXTbuoprWLkK02r/y9LyGI5zLqLNl0NG17erJ0NCke76xYJkKBYezgBj1pZmYQDC1Sox fKlsaFCWkBrcKuGWc49qbEtWVM8h/mw+0w5pFyKX733xa6A+S8TOPYng/qFYgauotV9unjjt b7Npn7XyYzypk7QqKo4zipBqpHKeQ96Y/FKXSHPuTVj7dGK3Dn4b0q9Dgti7ogCc8F3tJcZI E0R8Q+4TRcQ192dLvyyTrv4h9BY6q5aB56Z6dsn11TAx7YCAzsFNBGFCWtIBEACqN6OFHSNq jiPy8s05QTC2fCqi0G5CcbRFXcqmHDEKdwqHk5VuOEL8CcWKNzOEMCt6EJvNL4ivfeHs1e7f rfm08+0Da0xAFiab92B9lOTLfv/NkKZ3jakQs06rtSzX7tYDbnmDeX206Uqff1mDjsiXHoAJ fdW7CjNLdWp42B3fkSjUR8mUgeNPqO4Jhgd7d3tTN2ov7M0rS7kUoE6Gd01LmNoPUQ024g8G ecMXVBldgg78aKmehs5pSWLmoBfczymGmNT/++9B6btmy7ruU+febVXRaQJY7aqpkTL7oy4H 3LMRSy/0BXHm1WgO7201Aj7PuaXM424hAhzmAJhO5AvlT9PuS9eSaIP0sqgP7ZTX7UezVj1H Tv5VJtgHI1fiNfhd/KFqDQDGaKdlM0iysyPanSCscjsWqAG0Od2TPdSuURqvgt8suBZrAAfK d55Ovguy+8uCi047sQxShUonw7TxGl3FMAe04PBIOgMCB/uys4yDUjYrawrlNigvx60Nec+T ExE+qszoO57If3/rG78J2ntGjog+yTDNffkbzljcy3YDe3k/r+T2FKOcWxJTlwSWAs1aVLZ7 DWx73lpYrSNJxiU7PrPihfS/Doy3VfmfF/RbH/xmkuPvsyrVfd16pEEtHGi5hBk2KQyjVqi1 IWwXV9ZVOQFBE9nJ7i6A7Aw3EwARAQABwsF8BBgBCAAmFiEEqbvj98Urq1e7HVyTkTTbS08t aqoFAmFCWtICGwwFCQeGHy0ACgkQkTTbS08taqrpIBAAjc6GdUjCyVsZLYwV8bMM4loltFrx z/mroCIFW4PZ0u4zENaloQbHuhDx7Ii6mR9jRiVNbXP4XvuyhjlUO+pt6hGrPbzsmV9vGvN0 2nkGYmSpxQNEzHQf/CJyLhPWY5qTJlDEr4zHbloG2KRPQ6dv9mdRIyAwDxNDSq2tVlrJC+b4 hG9vYp9msCZspqVDRTzvRTZQoWAvGJUaUgZd/FLPTfFePAmX+enXkUKl332i82xNU/nTix73 WajK7WhWC2GugrEbi42fJgUKRtYWhY36QyxucB1VWUacn7iKt/eLfPrCVVsHP2j4vqjlL/HJ 38TvbqfI4WbXyXF630U7IOlMT8//vpo3Y8hjWw0p5dm22fyPcjfnqxDdDefKCJpN215JgvDi Ww42J+VDTsd+5FJYCSUqg3jXmJl1z6FewF5hjuUGf/VdKCrhFocfh1b8VFgne2M1vyNcPoS8 23lJOMpcVAmzFhmVl5y/az/kgPJzbQggSByv3pZZUlJttLKf9BSGwmKcoGEgNo8p/DUyMkQV kVCJdmnamJzYEa/s3XRasTZhoWzNSjIEfeJaLd8dVXTzByMzgYuj/raFP1UF33GQ8W+zr23b VLVc8pEjMQlWeRGfJRyvG4ZOYpFk0c7jw8LpERCd/1SGHL3RQ3CwOqouQgKV+0BjMbY6A6Vj CuWio7k=
In-Reply-To: <CAHANBtLPuGUAqKeJF_H86_N6RnzYitugHNBV0tgVb6cTMTq_xw@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------y9fTLB64GhZVypZZN81d2yTU"
Archived-At: <https://mailarchive.ietf.org/arch/msg/pim/k0WGqwls3bpxhjEcte5caz6diWo>
Subject: Re: [pim] [MBONED] IGMPv3 backward compatibility issue killing SSM
X-BeenThere: pim@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Protocol Independent Multicast <pim.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pim>, <mailto:pim-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pim/>
List-Post: <mailto:pim@ietf.org>
List-Help: <mailto:pim-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pim>, <mailto:pim-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Apr 2024 12:31:37 -0000

Hi Stig,
      Thanks for the clarification...

I am curious if the following two additions would address this issue 
without delaying the advancement of the documents to Internet Standard.

1. In Section 7.2.1 - Add this to the last paragraph : "It is 
recommended that implementers provide a configuration option to disable 
use of Host Compatibility Mode to allow networks to operate only in SSM 
mode. This configuration option should be disabled by default."

2. In Section 7.3.1 - Add an additional bullet : "It is recommended that 
implementers provide a configuration option to disable use of 
compatibility mode to allow networks to operate only in SSM mode. This 
configuration option should be disabled by default."

Regards,
Brian

On 4/8/24 5:26 PM, Stig Venaas wrote:
> Hi Brian
> 
> I don't think changing defaults would be sufficient. My concern (and I
> think that is what others are concerned about as well) is that hosts
> and routers fall back to older versions when there is an older version
> querier, as specified in 7.2.1 and 7.3.1. Regardless of the default,
> it says that they must change mode or fall back.
> 
> I think we need some text where we RECOMMEND that hosts and routers
> have a knob that disables compatibility mode and makes the host/router
> always operate in IGMPv3 mode. This should of course be off by default
> (fall back as usual). I'm happy if there is a more lightweight
> approach that I'm not seeing.
> 
> Regards,
> Stig
> 
> On Tue, Apr 2, 2024 at 12:10 PM Brian Haberman <brian@innovationslab.net> wrote:
>>
>> Hi Hitoshi,
>>
>> On 3/20/24 10:01 PM, Hitoshi Asaeda wrote:
>>>
>>> I thought what we need to clarify in DS IGMPv3/MLDv2 RFCs is that, as Brian mentioned, we can simply add recommended default settings for the compatibility mode variables. That’s all, I thought.
>>>
>>> But you remind me of the following four situations.
>>>
>>> 1. querier = SSM capable, forwarder = SSM capable -> no fallback
>>> 2. querier = SSM capable, forwarder = non-SSM capable -> fallback
>>> 3. querier = non-SSM capable, forwarder = SSM capable -> no fallback (and SSM capable router must become (replace) querier?)
>>> 4. querier = non-SSM capable, forwarder = non-SSM capable -> fallback
>>>
>>> I wonder how above 2 and 3 are clearly considered in some RFCs?
>>
>> Which RFCs are you worried about? I think 3376 and 3376bis cover this in
>> section 7.3 with discussion of the compatibility mode and group
>> compatibility mode variables. We would augment that discussion with a
>> recommendation that those compatibility mode variables default to IGMPv3
>> mode.
>>
>> Table 9 in section 7.2.1 already indicates that hosts default to IGMPv3
>> mode. We need to indicate a similar default in section 7.3.1.
>>
>> Regards,
>> Brian
>>
>> _______________________________________________
>> pim mailing list
>> pim@ietf.org
>> https://www.ietf.org/mailman/listinfo/pim