Demultiplexing QUIC

Marten Seemann <martenseemann@gmail.com> Sat, 22 July 2023 22:24 UTC

Return-Path: <martenseemann@gmail.com>
X-Original-To: quic@ietfa.amsl.com
Delivered-To: quic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EE3DC15153F for <quic@ietfa.amsl.com>; Sat, 22 Jul 2023 15:24:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id skCQT3bVjuvU for <quic@ietfa.amsl.com>; Sat, 22 Jul 2023 15:24:00 -0700 (PDT)
Received: from mail-ej1-x631.google.com (mail-ej1-x631.google.com [IPv6:2a00:1450:4864:20::631]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9AA0BC15108D for <quic@ietf.org>; Sat, 22 Jul 2023 15:24:00 -0700 (PDT)
Received: by mail-ej1-x631.google.com with SMTP id a640c23a62f3a-98de21518fbso520355366b.0 for <quic@ietf.org>; Sat, 22 Jul 2023 15:24:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1690064639; x=1690669439; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=XWVZgaIltTtww4/IsXQTXFdFYFo/DIhLtoS/FPIQkqE=; b=o95Jkmqfyh0IxMBewQJM3Bec+aTw9vCobOqNpj9rPbtkwKnjJEUxt3gy6L8Wnmd1/w fYvuDxI6/iw2ef7M5lEg3J6NzluEtks74pe3KyyE9k8WSlPr+w2KC7PM8KqfNPn+22fc tEKX978tr1Z2SFyugxnc4m214FEDzJX/TSdC2ECFdYqdQ8jN/tUAf1rehLgDZ427VYYQ 0iZyg0DKHWx90W8pNO3pDOMGJKpuNXV2cMru3R5vcwdmBFzwtcPkZnvj1u8lTcuHJ+eE eSFsWb5BtxI3QHejTDst23bKMQYstEc4aJoe+43lkMcxUh91m+TWJ/y1KzhMR6VeGqoT UDng==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1690064639; x=1690669439; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=XWVZgaIltTtww4/IsXQTXFdFYFo/DIhLtoS/FPIQkqE=; b=Z/aHI5+6r2XijDLzNMUo7sood97ESucRszPmFwE6HTnCLawJw7gwc/ohblSXS5sakG bVeamg/5TBtyadfSiICPynQbeaWF2U4k1P6qk18tC/HkEFbfXlzsqmJIcls2XfLbhOlh p99vW8Z8xDsSIO5Z26GBDBKrZPRfNXD6xb8Amp/p/8P32KKK+U38kI9XL+GRXpr5urNe 1+FktfnkFfWu/MDY49U+kaRqkejVe9jTUWZ9QdAC+7NkFWg56R9sp1bqWGXUCgp8H04O aMUwqTjXCLnzu4W/9MSp6Icfd0SRTbx7oWiK5cGcLlI45rI9nY+PyzTNE93sUp+0d03V MxSg==
X-Gm-Message-State: ABy/qLaPwTXPUNwEYbzacwOc2V6Cx1gD+6kCVlVGBAnCl+iASP2Eh+PA lzYSCFR0vnxyagh2wVLEyO4MGnNfimFBan6ZBG9hzkAk7I0=
X-Google-Smtp-Source: APBJJlHio3QsIyHyFSdYjGSjasQdW2FMsIR3GziwbJOMYHm4CHYKVDEHKIivrGCo+t0+9SN7VrvRr+SrEnB94u+UoGg=
X-Received: by 2002:a17:907:7622:b0:994:b53:77fc with SMTP id jy2-20020a170907762200b009940b5377fcmr5473285ejc.12.1690064638532; Sat, 22 Jul 2023 15:23:58 -0700 (PDT)
MIME-Version: 1.0
From: Marten Seemann <martenseemann@gmail.com>
Date: Sat, 22 Jul 2023 15:23:47 -0700
Message-ID: <CAOYVs2o+KTz=0vO+a=c_3ORGLHGyKJGQKK=DCqW3bAbh-LvbOA@mail.gmail.com>
Subject: Demultiplexing QUIC
To: QUIC WG <quic@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000006d5ec406011ad686"
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/oR4kxGKY6mjtPC1CZegY1ED4beg>
X-BeenThere: quic@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic>, <mailto:quic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic/>
List-Post: <mailto:quic@ietf.org>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic>, <mailto:quic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 22 Jul 2023 22:24:01 -0000

RFC 9443 defines how to demultiplex QUIC from a whole range of other
protocols. Packets in the range 128..191 (i.e. all packets starting with
0b10xxxxxx) are supposed to be forwarded to RTP/RTCP.

This mostly works, since QUIC v1 packets (both short and long header)
define the "QUIC bit", the second bit (0x40) to be set to 1. On the other
hand, Version Negotiating packets are defined as 0b1xxxxxxx, where the last
7 bits are an arbitrary value. RFC 8999 defines these bits as unused, and
it's up to the server to decide how to set these bits. Specifically, it's a
valid strategy to set them to a fixed value. If that value starts with a 0,
Version Negotiation packets would be consistently mis-classified as RTP
packets.

Section 17.2.1 of RFC 9000 says that servers SHOULD set the first of the
unused bits to 1 "where QUIC might be multiplexed with other protocols".
This advice is fine for some deployments, but in the general case, the
server has no way of knowing what other things the client is demultiplexing
on the same UDP socket.

I see two ways out here:

   1. Change the recommendation in RFC 9000 to always set 0x40 to 1 (e.g.
   by removing the "where QUIC might be multiplexed with other protocols"
   subclause). It might also make sense to add this recommendation to RFC
   8999, too.
   2. Change the classification logic in RFC 9443, such that 128..191 are
   only routed to RTP/RTCP if the next 4 bytes are not equal to 0. I'm not
   sure about the implications for RTP/RTCP though.