[secdir] Re: draft-ietf-nfsv4-uncacheable-files-11 ietf last call Secdir review

Thomas Haynes <loghyr@gmail.com> Thu, 13 August 2026 18:25 UTC

Return-Path: <loghyr@gmail.com>
X-Original-To: secdir@mail2.ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 70FBA129505BA for <secdir@mail2.ietf.org>; Thu, 13 Aug 2026 11:25:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786645528; bh=F2sy0UHSbVDQ/gMZgQ0rZegT/Zp5MHwlrWGsUPZJKd0=; h=From:Date:To:Cc:Subject:References:In-Reply-To; b=jzWAQDfleVIiKveyhduBwl3Ppb3/3hu2c/0XJEKLh/7SaOcZGvjx6SHvLxpOY+5fg MLV1cfIajGnaXxXelcsLphUvmB8mWjvpuAoQ770DbPpTw+T0HdzLgqIYpqByZq5Uh+ KRAyDY1Pph9ag0dCJXlgJbrKzXa78CWC5CtOSw5U=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rqhv2Wejv8JX for <secdir@mail2.ietf.org>; Thu, 13 Aug 2026 11:25:27 -0700 (PDT)
Received: from mail-oo1-xc2d.google.com (mail-oo1-xc2d.google.com [IPv6:2607:f8b0:4864:20::c2d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6ED7B12950577 for <secdir@ietf.org>; Thu, 13 Aug 2026 11:25:27 -0700 (PDT)
Received: by mail-oo1-xc2d.google.com with SMTP id 006d021491bc7-6ae6e407bfdso108648eaf.1 for <secdir@ietf.org>; Thu, 13 Aug 2026 11:25:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786645521; x=1787250321; darn=ietf.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Xv9fZxxvRgCkRwkiccFthiQSwa0R0G69fe4Iqkus198=; b=mwZ94aGrpPaK5pvwA+bGr4S1+H3nhvPy0GEH3Y5A6XYEINhG1syGQ3gxJqwl6/PVQF M9IT26eaK6Rt/hW6t1wHXlztW+opRoi9CTTUZzfTX2k83kX6D1g+WjppgIL2ND2MWSUc 31RTgkc/NgHgHzf1e71/ZkGfEblKwtDudLzC6Qyt13feQyrKmy1wZYnO2m6h2K9jYh6X 5IsZqrKO5x1+C9r1GqCC18Hkqlm2N2liUq8aYE7nUAhS7bkbYuumV5/iQQSU9ErLXiNN /MfOe2LyCldaKeEqkoxNYRJVCwFfekE4nLiPjNPzRyrFFV50DMIfrRgl42+rcLOiQILo FyHw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786645521; x=1787250321; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Xv9fZxxvRgCkRwkiccFthiQSwa0R0G69fe4Iqkus198=; b=AYK+bMIEPLuWyRqnfAXmZw6zOamdmXEPQ4jkA8jVkxWqcFTseEi4BK3iidO9Du6S/C Q5HBbcCRKQkJCvElrN4OtfMaONhlagJy7a8LiDzc/dcTXJig1ozkH/a8MRQtmVCQmyaE qIzECECkl09eQmdKwonRCXdQprRGhcJi313V/d0XOHIMRAjfn6vGOHCEP9Hl8xSbymvs UdPrn6urLpumvWifl2hxJT8dXDAFtC4qNSq5ncful7nDrDIZdbC0hUuZE2pxc3HioZHw 4gpovqar8ULjP6m+Mw+deS52d1fH9IV7s+FOlo0BEs1iH33rcL7o9kRQiYb+HYyF8Acj 9MMQ==
X-Gm-Message-State: AOJu0YzwkLbCtpR2M8F01H9tmDfa5LA55Hl9WW/YC7VrfzOjIYhmAJVl vX6N+XgKh3IwyaPbcZ2eyHoQcDHGxwwdR3KyBzrkBuL6FoYudo1/SZ3W
X-Gm-Gg: AR+sD11Lfk/K0JfsXXnInHbdhaUvzLYsOy/+dvaBYM2RF6k7xS1VYSMINW/152O08k1 Q7EUZD6XZZJtqcLoX5z8yp9phtSwWCSzsg9eNQXPtDZlDz6z7JHxXy4WCX9bpB8LJ09G+mJoJg1 UofR5gnnZHK+eO+n+CWUOf5Iq7Q+nMSojFvhL3NeArp9hUnQRQVnF3xIsqA2f6R4Hqc/b1mVd0S cm/aNbOvlStE3OQUcX1PLmynYUeoouRRB3BvlpnZ7E3CbsggaO0KuVokih1pYrDbKnro4rDuq/0 3+lsKJF9vh9EJ29ft6Z+p7QeV6Sthl62jS/G3XNQeeWN1iFpyT7i2LY+an5eGacaFgdhnbG28b2 rX0//6W9XeZbcvNkiXeeJ/du9PlT91VYs+1y9c9MHa7V0OmfApLgfAlPHm3K9yb852ve/rdrKW2 cfuV0Do+MbltyqGS1h3kBHUcGNupfI7mLU+7IRY8KFSAnWNnwdaC3tH77ZZ9f1dcuOQES+Ri5// R8zlg==
X-Received: by 2002:a05:6820:1623:b0:6ac:b930:f2f4 with SMTP id 006d021491bc7-6b0d69246d4mr303551eaf.36.1786645521230; Thu, 13 Aug 2026 11:25:21 -0700 (PDT)
Received: from localhost ([2601:647:6701:9440:88f1:c2a0:d4be:676a]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b0c47a8978sm2842883eaf.15.2026.08.13.11.25.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Aug 2026 11:25:20 -0700 (PDT)
From: Thomas Haynes <loghyr@gmail.com>
X-Google-Original-From: Thomas Haynes <loghy@gmail.com>
Date: Thu, 13 Aug 2026 11:25:19 -0700
To: Barry Leiba <barryleiba@computer.org>
Message-ID: <an4LvzCcIsIm_5t7@mana>
References: <178663460582.82495.12458802157423865341@dt-datatracker-559c48c7fb-jvzsw>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <178663460582.82495.12458802157423865341@dt-datatracker-559c48c7fb-jvzsw>
Message-ID-Hash: JDNUJTT33GT4EE3FVYZYQ4RIV2FVPBY6
X-Message-ID-Hash: JDNUJTT33GT4EE3FVYZYQ4RIV2FVPBY6
X-MailFrom: loghyr@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir@ietf.org, draft-ietf-nfsv4-uncacheable-files.all@ietf.org, last-call@ietf.org, nfsv4@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [secdir] Re: draft-ietf-nfsv4-uncacheable-files-11 ietf last call Secdir review
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/JGp3ntKpW46rY_h7fqKbbXOgb-A>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>

On Thu, Aug 13, 2026 at 08:23:25AM -0800, Barry Leiba via Datatracker wrote:
> Document: draft-ietf-nfsv4-uncacheable-files
> Title: Adding an Uncacheable File Data Attribute to NFSv4.2
> Reviewer: Barry Leiba
> Review result: Ready
> 
> Thanks for this well-written and clear document.  I have only one question:
> 
> -- Section 4.1 --
> 
>    When honoring the uncacheable file data attribute, clients SHOULD NOT
>    delay transmission of WRITE data for the purpose of combining
>    multiple WRITE operations or improving efficiency.
> 
> I wonder about the SHOULD NOT here.  For write caching, there's a real issue of
> corrupting the file, so why is this not "MUST NOT"?
> 
> 

Barry,

Thanks for the review and catching this!

MUST NOT is safe here because Section 4.2 has already carved out
the legitimate case:

> The transient retention of WRITE data needed to complete an
> in-flight UNSTABLE4 and COMMIT exchange is not considered "caching"
> for the purposes of this attribute.

With that exclusion in place, nothing legitimate remains under
"delay transmission for the purpose of combining WRITEs or improving
efficiency" -- that's the exact behaviour the attribute exists to
forbid.

MUST NOT is also consistent, because Section 4.2 already uses it
in the identical conditional context — "Clients MUST NOT defer
COMMIT past the point at which the application's write call returns"
— for what is arguably the lesser hazard. This is a real asymmetry:
the stronger corruption risk currently carries the weaker keyword.

So I'll make the change.

Tom


-- 
Tom Haynes <loghyr@gmail.com>