Re: [quicwg/base-drafts] Clarify server CONNECTION_CLOSE with Handshake (#2688)
Martin Thomson <notifications@github.com> Mon, 13 May 2019 00:02 UTC
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B9F21120130 for <quic-issues@ietfa.amsl.com>; Sun, 12 May 2019 17:02:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.01
X-Spam-Level:
X-Spam-Status: No, score=-3.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, SPF_PASS=-0.001, T_DKIMWL_WL_HIGH=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zvLp3cZ-a29y for <quic-issues@ietfa.amsl.com>; Sun, 12 May 2019 17:02:29 -0700 (PDT)
Received: from out-24.smtp.github.com (out-24.smtp.github.com [192.30.252.207]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14AC512021D for <quic-issues@ietf.org>; Sun, 12 May 2019 17:02:29 -0700 (PDT)
Date: Sun, 12 May 2019 17:02:27 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1557705748; bh=QFKrYHtWUSUCdZ+BBUig/GGqexSUcFIwlqg+w4JDGNQ=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=xHtFkI+NX9sdA9k0j9i+aippjcuT7BDXWXSLrRmdep/CsDSjOdtozM/mCUbO0JerG zq7JeiUBoyzOMAWwfNw8zdp/ULkJQfw8UPCrA5Gjz+qxlOxqxNX+Mtc82pXoJAB+8G ZRPLxWbSsonHtHkSRJUL/ocC5dM9qC8I2tGjwU4k=
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+AFTOJK3SEYVSN5OR5YBKO4V24XTJHEVBNHHBUYT4BY@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/2688/review/236443175@github.com>
In-Reply-To: <quicwg/base-drafts/pull/2688@github.com>
References: <quicwg/base-drafts/pull/2688@github.com>
Subject: Re: [quicwg/base-drafts] Clarify server CONNECTION_CLOSE with Handshake (#2688)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5cd8b413f0f2c_79ce3f8d9d4cd960229229"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/udZgApMTVZ8kzrrE2zWKywy6pGw>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 May 2019 00:02:37 -0000
martinthomson commented on this pull request.
> @@ -2307,10 +2307,14 @@ signal closure.
If the connection has been successfully established, endpoints MUST send any
We should also try to kill #2151 with this change:
```suggestion
When sending CONNECTION_CLOSE, the goal is to ensure that a peer will process
the frame. Generally, this means sending the frame in a packet with the highest
level of packet protection to avoid the packet being discarded. However, during
the handshake, it is possible that more advanced packet protection keys are not
available to a peer, so the frame MAY be replicated in a packet that uses a
lower packet protection level.
If the connection has been successfully established, endpoints MUST send any
```
> @@ -2307,10 +2307,14 @@ signal closure.
If the connection has been successfully established, endpoints MUST send any
CONNECTION_CLOSE frames in a 1-RTT packet. Prior to connection establishment a
peer might not have 1-RTT keys, so endpoints SHOULD send CONNECTION_CLOSE frames
-in a Handshake packet. If the endpoint does not have Handshake keys, or it is
-not certain that the peer has Handshake keys, it MAY send CONNECTION_CLOSE
-frames in an Initial packet. If multiple packets are sent, they can be
-coalesced (see {{packet-coalesce}}) to facilitate retransmission.
+in a Handshake packet. If the endpoint does not have Handshake keys, it SHOULD
+send CONNECTION_CLOSE frames in an Initial packet.
+
+The server may not know whether the client has Handshake keys. In order to
That assumes a lot about the shape of the handshake though. If you are going to make that call, cite QUIC-TLS.
> @@ -2307,10 +2307,14 @@ signal closure.
If the connection has been successfully established, endpoints MUST send any
CONNECTION_CLOSE frames in a 1-RTT packet. Prior to connection establishment a
peer might not have 1-RTT keys, so endpoints SHOULD send CONNECTION_CLOSE frames
-in a Handshake packet. If the endpoint does not have Handshake keys, or it is
-not certain that the peer has Handshake keys, it MAY send CONNECTION_CLOSE
-frames in an Initial packet. If multiple packets are sent, they can be
-coalesced (see {{packet-coalesce}}) to facilitate retransmission.
+in a Handshake packet. If the endpoint does not have Handshake keys, it SHOULD
+send CONNECTION_CLOSE frames in an Initial packet.
+
+The server may not know whether the client has Handshake keys. In order to
+guarantee a CONNECTION_CLOSE is processed, it SHOULD send a CONNECTION_CLOSE
+in both Handshake and Initial, because the client discards Initial keys as soon
+as it has Handshake keys. If multiple packets are sent, they can be coalesced
+(see {{packet-coalesce}}).
A bigger point here is that the server also isn't sure when the client gets 1-RTT keys. We should say the same about that transition. I believe that we can rely on handshake confirmation for this transition. Endpoints might choose to send CONNECTION_CLOSE in Handshake packets prior to the handshake being confirmed.
--
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/pull/2688#pullrequestreview-236443175
- [quicwg/base-drafts] Clarify server CONNECTION_CL… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Nick Banks
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Jana Iyengar
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Mike Bishop
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Jana Iyengar
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Jana Iyengar
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… MikkelFJ
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Jana Iyengar
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… ianswett
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson
- Re: [quicwg/base-drafts] Clarify server CONNECTIO… Martin Thomson