Re: [quicwg/base-drafts] Revise text on ACK frames prior to handshake completion (#719)
ianswett <notifications@github.com> Thu, 10 August 2017 02:34 UTC
Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4388E132529 for <quic-issues@ietfa.amsl.com>; Wed, 9 Aug 2017 19:34:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.799
X-Spam-Level:
X-Spam-Status: No, score=-4.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q-YJKSYoD0xw for <quic-issues@ietfa.amsl.com>; Wed, 9 Aug 2017 19:34:45 -0700 (PDT)
Received: from o5.sgmail.github.com (o5.sgmail.github.com [192.254.113.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 861B313252B for <quic-issues@ietf.org>; Wed, 9 Aug 2017 19:34:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=W4oaJ9zgUfa/Yxcky5dvm2YMMiY=; b=ERNKf1URIqIFF9cI mKrrxyD3PFHNbwQBoV21/yIzWBo4gn0VuQfYv4+ic7R0bBAv9Jln/4cTz5JRzmht KSszr11i7A0xl6VUCw2Mh0tkV61ypSPgilzYWb9D4myVgiYZfOCi+lGV2A8E8Q72 toZhs4riHvKsTwy1QDydWdebxJE=
Received: by filter0546p1mdw1.sendgrid.net with SMTP id filter0546p1mdw1-12925-598BC62B-16 2017-08-10 02:34:19.077816352 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0001p1iad1.sendgrid.net (SG) with ESMTP id sDufp6eAQx66x8Nz8LYRWQ for <quic-issues@ietf.org>; Thu, 10 Aug 2017 02:34:19.036 +0000 (UTC)
Date: Thu, 10 Aug 2017 02:34:19 +0000
From: ianswett <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4abf23da7d1e4fb6cb62e79edccff70cd4f9b66eee892cf0000000115a3882a92a169ce0eda9bff@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/719/review/55420770@github.com>
In-Reply-To: <quicwg/base-drafts/pull/719@github.com>
References: <quicwg/base-drafts/pull/719@github.com>
Subject: Re: [quicwg/base-drafts] Revise text on ACK frames prior to handshake completion (#719)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_598bc62ae731e_2bd1a3ff4989a5c3c5096e"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: ianswett
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak20fjmJ3HMD8We8kAdvf2Hd/SuVA602ku/S+m wM5LAMI41+ry+vrEF0R3VWaMgpgs1FCCxivpKR9iZTpShn9htsn0/DT0tA/kg7WH6pcUltAfxn1mB8 DPKHeC+lhTLNdqnl/yDwAqe7JINidegeD3Y0NliMVuJpfCdTJ4+Bz3G9V5s5UmcD3+jLaJ04oy922Q 4=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/TuonpYTSJgTdnhk559oGe8KkmFo>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Aug 2017 02:34:47 -0000
ianswett commented on this pull request. A few suggestions to make the wording stronger. > -ISSUE: - -: What about 0-RTT data? Should we allow acknowledgment of 0-RTT with - unprotected frames? If we don't, then 0-RTT data will be unacknowledged until - the handshake completes. This isn't a problem if the handshake completes - without loss, but it could mean that 0-RTT stalls when a handshake packet - disappears for any reason. - -An endpoint SHOULD use data from unprotected or 0-RTT-protected `ACK` frames -only during the initial handshake and while they have insufficient information -from 1-RTT-protected `ACK` frames. Once sufficient information has been -obtained from protected messages, information obtained from less reliable -sources can be discarded. +Endpoints MUST NOT use an `ACK` frame in an unprotected packet to acknowledge +packets that were protected by 0-RTT or 1-RTT keys. An endpoint MUST ignore an +`ACK` frame in an unprotected packet if it claims to acknowledge data that was So the endpoint needs to ignore the entire ack frame if any packets acknowledged were protected? > +packets that were protected by 0-RTT or 1-RTT keys. An endpoint MUST ignore an +`ACK` frame in an unprotected packet if it claims to acknowledge data that was +sent in a protected packet. Such an acknowledgement can only serve as a denial +of service, since an endpoint that can read protected data is always able to +send protected data. + +Note: + +: 0-RTT data can be acknowledged by the server as it receives it, but any + packets containing acknowledgments of 0-RTT data cannot have packet protection + removed by the client until the entire server handshake is received by the + client. + +An endpoint SHOULD use data from `ACK` frames carried in unprotected or +0-RTT-protected packets only during the initial handshake and while they have +insufficient information from `ACK` frames in 1-RTT-protected packets. Once I'd like to make this stronger if possible. How about "only before they have received an 'ACK' frame in a 1-RTT protected packet. Once they have received an ack frame in a 1-RTT protected packet, all ack frames with less protection MUST be ignored." > - -An endpoint SHOULD use data from unprotected or 0-RTT-protected `ACK` frames -only during the initial handshake and while they have insufficient information -from 1-RTT-protected `ACK` frames. Once sufficient information has been -obtained from protected messages, information obtained from less reliable -sources can be discarded. +Endpoints MUST NOT use an `ACK` frame in an unprotected packet to acknowledge +packets that were protected by 0-RTT or 1-RTT keys. An endpoint MUST ignore an +`ACK` frame in an unprotected packet if it claims to acknowledge data that was +sent in a protected packet. Such an acknowledgement can only serve as a denial +of service, since an endpoint that can read protected data is always able to +send protected data. + +Note: + +: 0-RTT data can be acknowledged by the server as it receives it, but any I'm not sure how this note is helpful. The server has to send all acks either unprotected or in 1RTT packets, correct? If so, it seems simpler to say "0-RTT data can be acknowledged by the server as it is received, but it must be send with 1-RTT protection."? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/pull/719#pullrequestreview-55420770
- [quicwg/base-drafts] Revise text on ACK frames pr… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… ianswett
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… ianswett
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson
- Re: [quicwg/base-drafts] Revise text on ACK frame… ianswett
- Re: [quicwg/base-drafts] Revise text on ACK frame… Martin Thomson