[Tools-discuss] June tools update

Robert Sparks <rjsparks@nostrum.com> Thu, 04 June 2026 21:54 UTC

Return-Path: <rjsparks@nostrum.com>
X-Original-To: tools-discuss@mail2.ietf.org
Delivered-To: tools-discuss@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 59353FB40092; Thu, 4 Jun 2026 14:54:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780610084; bh=7GjkQGnKCOyvrr9O1J9hpzUhRtFVehdqCMUHGIk9cxU=; h=Date:To:Reply-To:From:Subject; b=ea884G6ry7zbLFkVcjtW2ijSxqODGHpilNkRGPiOvQO5V6HqVYXRuZwDP0np+rEkv +1ayJ3XRzi2qGxfEG59EGSU+ppUBXQrxVhkD3P/LpnEqAcKzxXc7f2TX8vvSYGXBRl 2RozBInSCmdyOHiFc/ODCG/dAR00QVNMP+vAr1X0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=nostrum.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fFdN4WW6Lf-D; Thu, 4 Jun 2026 14:54:41 -0700 (PDT)
Received: from magus.nostrum.com (magus.nostrum.com [104.236.102.164]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D17CBFB4008D; Thu, 4 Jun 2026 14:54:41 -0700 (PDT)
Received: by magus.nostrum.com (Postfix) id 247E273211A; Thu, 04 Jun 2026 16:54:41 -0500 (CDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=nostrum.com; s=submissiondev2025; t=1780610081; bh=7GjkQGnKCOyvrr9O1J9hpzUhRtFVehdqCMUHGIk9cxU=; h=Date:To:Reply-To:From:Subject; b=Pho6E2fOycl62tmMAuvNpEbEMXwRcoGnP/oMR2HnGvuLThBLMj902mxpIaRPyVZ+D HSsRaufTSjf8HIowUeNv1ueQscDUjj6yjVp29JziR84W5kn78jXfXggP1mVP7bi96f DrDN6mrlAreuGg/xseh0H6yqcng/ANYEdzMyVlwcvbeXFke+yAw3r11XT3RgUcnVQ1 4LPfzelK2ados4r4NAL2s56dFuh5dYfHmr5yZ5iq1YOtChGSBtfKozFvzjyAPP4xFF xaqKOnBUVfg5dhuxflFbWK3qvOle0oQp8KCfkRU2OcdJtt0tRHSQ3ksUMNI804Heen JaElbyNBqYUYw==
Message-ID: <4bd1e7da-9c0c-4cd4-ac7f-9217494768a0@nostrum.com>
Date: Thu, 04 Jun 2026 16:54:40 -0500
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: Tools Team Discussion <tools-discuss@ietf.org>, "wgchairs@ietf.org" <wgchairs@ietf.org>
From: Robert Sparks <rjsparks@nostrum.com>
Autocrypt: addr=rjsparks@nostrum.com; keydata= xsDNBFx4PQwBDADIIJqFKIeYNmVR3iH8YnNqwApV+ci83VqFaPg0UXZAZ1utH/2O2LOLJKmV Ol11+lOSfH4OJgpARt37PWbqfG2TzzGfEucRBPMAV8TEDmzKL+7/OUMLEoPeexgxz6ADxK2Q ACKKzHhF30y4fx2fn9rYZrCvYHV9HDKcfFotNLna0U6P6wu70L0mT2hcjQgZ7+8HSZCpK2XG PTya1mEiMklH6+UHfcTLoAxd3chQiseRi19/TQZZCD3LuuaGFWyTIeF9ZNWV9yL0HQeb/XMs tmZnObSSHSUbZwn5PR9Uf+3iW7jdG5JuXBvNbDpAHfLyPXRqxErM/nCLrbwGB6AgNSKFCwkL lb3uxsGFWcOt6sedrjixoVUO2k4zQWVnCUCwFHGrgIxUK24dI8oqydGPctXAKj5VqoCVJBv6 4JxSpiR+V8fl3A8gksBUnuIMLNlRjB5RAgZaSUpaOkXsWUBA8Z75wQWoIzkJIeMm29w2l1kB B9kGMdyiXGr2JV8VQZ4lAscAEQEAAc0kUm9iZXJ0IFNwYXJrcyA8cmpzcGFya3NAbm9zdHJ1 bS5jb20+wsEUBBMBCAA+AhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAFiEEGNywdGDCHUYB wWN3bipqV3X5ExgFAmf+YFcFCREpvcsACgkQbipqV3X5EximYwv+LojObKPKfx66R9ZmfI3D uB7Sx7X8iYNgNpird/OqHQZcXhQjsv7C26k5y9VMgmU2bibUlm8o/q+kzkpHI9RZ5s27twiR ON1aN8vfzi5iXxY3oKI0sNrZX+gSaAwfNTckDIIdyCKXt/K0i02qHXxe/nke1+JV4uUSDR/e ea3M+cM0MEb25cclmz2Ac9vH/gXCzn9NaEoVOXh6xIztfZYGWtJ8YNVryv2noWumI4dDGPIp +UBgE7gaP/1lXwOurdTvRkDP1+VuVq9qJOGORQZgU6gow/K6ujs0LYPmWzvPbRWxfTd43cQ9 4EbkXUbOiefHdZBWhYxXRc9qahgi4MY10ws9oxn7LKXbWBgx8UltkTmdmbQ6AVV/XxGfaqFC FQPvPGv7qPEowkfwyCl0PV0lqz15A3rE6lhCKFaJM9oYrAWk5S/6qjVs0sgchFhwwGAbYAO0 38AZW+4A96RavAUg2EDxEMycB5Fd6dHuHBnoUC+iQGzRTufheY52gLBgTVOEzsDNBFx4PQwB DAC03e1kk41e9Z9FuVW8UKWIkVUBeH3gfJMsb94d/c0cqBMRw5rulSY7+U76rw4AXo792LZn ydjDfoL0GQxGqkrZh397Sn9P/sLCb5I+wC14251nkmh5tmU2sQqCk+g9nykcE/NJft/zFkeb HHCKAosK6glO+W0YPHc/k7nXt/fLz7dMRpFpmqFXWjeN2VtwKr9znMg9+iX6XfgAJPMdDNH8 fn30Cp5TIsn5WCI70+JztgvfjFhD15Eb3rtDdOfOydjGCV2ZVxfM8ECmc8Z3DrThyiC2M3uo 2Y50rs6MH+TmVCtpHkISnH7B+80Vy2SC60K9l2xgCaezN1SlkQy3ZpprzcDrNTI8FcJa/UUM ayMGvSDGEGuHZRaNUyXP3jQ8oss+067axmNr5vgjpf01kmE1RJtiGEDWmCr8u1SbVQjdax6C pDqq3RKoX2ZVGLtkdDYZbsqSq4TgmFukoijWRbLxsFBdeEgruTViWRw4PKZav0piLxrhHUGI m6F6JFngapUAEQEAAcLA/AQYAQgAJgIbDBYhBBjcsHRgwh1GAcFjd24qald1+RMYBQJn/mEh BQkRKb6VAAoJEG4qald1+RMYaOgL/j06duNc5/OTAzOY3MawOwSPskXHLHiZUYG3TfN9eWYg TNCxTaP7wglLhHOsZF7rIzfPw3IAj9k8lnuLK1Z7C3VaJHQuayzLJ8jAF5gVryrqA/ia552u ejdg3k3OnExZB5Rvm/9joD5TpEa8f8XkLnfl/ez2H1rYR4gCjSIO6Kpi6B7Jxgt5is+HKP1x f/havxpBa/0c8f/9XEIgzQ6G190j4pBym1tzZCOx/NB3kp9oYVXejUwVA+WryJgpHvlzCxUW P7svyD4Mal4cgJCNptQ0Q2y8S4Yf/G+vF8+DVHd9x+xeNRX7USvqlxkpabAjLc3bp/egxFul i7Vb9qhlfcMwzOHrG1u3sYNFuL+hou9nNR5kdWVAVxKw0du9YptGtXlMK9PKlangBbeeNc6f h/wJMnCeITDBWb/Pm3nIstAVnftJSFaMaQwLLlcxCgUS7gD1axzeIGY3XPLnJX6ZjjdHZ5Z7 I8lfj4rMCctcE0pudHYWrhznMBoUaEADjiOpdw==
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: XKBVTSBWEFXJXC5IWRHVOL7IDDWLDG3D
X-Message-ID-Hash: XKBVTSBWEFXJXC5IWRHVOL7IDDWLDG3D
X-MailFrom: rjsparks@nostrum.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tools-discuss.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: Tools Team Discussion <tools-discuss@ietf.org>
Subject: [Tools-discuss] June tools update
List-Id: IETF Tools Discussion <tools-discuss.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tools-discuss/UimM7PT4i2K7BQMLLcrqzF7R88U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tools-discuss>
List-Help: <mailto:tools-discuss-request@ietf.org?subject=help>
List-Owner: <mailto:tools-discuss-owner@ietf.org>
List-Post: <mailto:tools-discuss@ietf.org>
List-Subscribe: <mailto:tools-discuss-join@ietf.org>
List-Unsubscribe: <mailto:tools-discuss-leave@ietf.org>

(This is also available at https://notes.ietf.org/tools-update-202606)

# IETF tools update 2026-06

[Previous report](https://notes.ietf.org/tools-update-202605) | [Next 
report](#)

## The Big Picture

### RFC Production Center Modernization Project

The first versions of the new RPC related applications were deployed May 
20. The deployment went as planned, with minimal disruption to users of 
rfc-editor.org. The feedback from the deployment has been predominantly 
positive with good suggestions for improvement being captured on the 
tools-discuss list and in github issues. In particular, in response to 
feedback we diverted some resources to providing basic fallback 
functionality for better access to the rfc-editor content for users that 
do not use javascript.

This set of deployments brought several years of effort into production, 
which now provides

* A new queue management workflow tool for the RPC fully integrated with 
the datatracker. This is the core RPC database and it has replaced the 
existing database and software that could not handle five-digit RFC numbers.
* A complete reimplementation of www.rfc-editor.org.  The backend takes 
data from the new queue management system and the datatracker, and the 
frontend uses a new design from our UI/UX specialist contractors that 
aims to significantly improve the experience for consumers of RFCs. The 
frontend is also built around the concept of pre-computation, and is 
served almost entirely from the edge.
* A new public site, queue.rfc-editor.org, for authors and others 
tracking the editing of an RFC, with detailed information about 
documents in the queue.
* Editing software for the RPC that now provides all the current 
functionality that the editors rely on in an integrated GUI, replacing 
the multiple command line scripts they previously worked with. This also 
integrates with GitHub and Datatracker, automating previously manual 
processes.
* A new, more streamlined publication process for RFCs that leverages 
GitHub.
* A reimplementation of the existing errata system into a new site, 
errata.rfc-editor.org that is integrated with the new www.rfc-editor.org 
and datatracker.
* As part of this work, extensive work has gone into identifying and 
resolving differences in data between the RPC database and datatracker, 
leading to significantly improved data on authors and RFCs in the 
datatracker.

More functionality remains to be developed building on this initial set 
of releases:
* The next set of improvements for www.rfc-editor.org have been 
professionally designed and implementation is beginning.
* A final review process that streamlines and integrates auth48 into the 
new system including the datatracker is being constructed.
* Further integration into the datatracker.

With the initial release, development is returning to a wider focus, 
addressing work that has been deferred by this project. The above 
additional functionality will be scheduled along with that work.

If you discover issues with the new Rfc Editor website, please either 
report them at https://github.com/ietf-tools/red/ or at 
tools-discuss@ietf.org.

### IETF Tools roadmap

The roadmap has not been updated since the last report. We will be 
discussing our planning and how to engage with the community going 
forward at the tools retreat the week of 15 June.

---

## ⌨️ Development Projects

### Datatracker

Since the last IETF tools update (May 2026) there were four datatracker 
releases (two minor releases and two patch releases). See [the release 
page](https://github.com/ietf-tools/datatracker/releases) for releases 
12.64.0 through 12.65.2. The full set of changes is 
[here](https://github.com/ietf-tools/datatracker/compare/12.63.1...12.65.2).

These releases included:
* Fix for daily YANG model checks task failures
* Backporting a Django security patch for 
[CVE-2026-35192](https://github.com/advisories/GHSA-7h2m-m8vj-598h)
* More accurate author lists for RFCs
* Final preparations and integration with the new RPC tools

Current activities:
* Operational adjustments to reduce downtime during upcoming k8s upgrades
* Preparation for migration to Django 5.2 LTS

### Author Tools

See release notes for 
[1.10.16](https://github.com/ietf-tools/author-tools/releases/tag/1.10.16), 
[1.10.17](https://github.com/ietf-tools/author-tools/releases/tag/1.10.17) 
and 
[1.10.18](https://github.com/ietf-tools/author-tools/releases/tag/1.10.18).

These updates include `kramdown-rfc` and `xml2rfc` updates; also added 
github automation to create PRs for new `kramdown-rfc` releases.

### XML2RFC

See release notes for 
[3.34.0](https://github.com/ietf-tools/xml2rfc/releases/tag/v3.34.0).

This update improves reference sorting and fixes non 5-digit RFC and 
subseries reference sorting issue. See 
[#1318](https://github.com/ietf-tools/xml2rfc/issues/1318).
3.34.0 also bumps up Weasyprint requirement to 
[69.0](https://github.com/Kozea/WeasyPrint/releases/tag/v69.0) which 
contains a security update.

### BibXML Service

We have been working on moving BibXML geernation for RFCs, RFC subseries 
and I-Ds to datatracker.
These will be servered from a blob store.
These chagnes are current on a [feature 
branch](https://github.com/ietf-tools/datatracker/tree/feat/bibgen).

See [#10830](https://github.com/ietf-tools/datatracker/issues/10830), 
[#10914](https://github.com/ietf-tools/datatracker/issues/10914) and 
[#10973](https://github.com/ietf-tools/datatracker/issues/10973) for 
more information.

### Wagtail websites (www.ietf.org, www.iab.org)

_No updates since the last report._

### idnits

_No updates since the last report._

### Mailarchive
There were five releases since the last report. See [the release 
page](https://github.com/ietf-tools/mailarchive/releases) for releases 
2.44.0 through 2.46.2. Work focused on:
  * dependency updates
  * new API to import mbox archives
  * tooling to filter duplicate messages from the archive
  * continued work on blob storage support (message detail pages are now 
being served from the edge)


### Registration
There were three releases since the last report. Work consisted of:
  * improvements to Registration admin view
  * support adding ancillary registrations (hackathon, ANRW) from the 
participant dashboard without submitting another full registration
### Retooling the RPC workflow ("Purple")

#### General overview:
- purple was launched on May 20th
- the leadup to the release involved a large number of adjustments and 
corrections

#### Progress since last report:
- continuous work on non-blocking bugs reported before launch and issues 
reported since
- adjustments on email templates (enqueing, final review, publication 
announcement)
- improvements of label management
- fix of DT notification logic for approvel message updates
- improve UI for handling IANA status

### RFC Editor website ("Red")


Since the launch of the site there have been a flurry of fixes and 
features deployed:
- A new `/rfc-index/` route added, like the previous site's 
`/rfc-index.html` that has a simple list of all RFCs.
- The homepage and search results use Cards to display large block links 
to RFCs and other website content. They now have a hover/focus tint to 
better indicate the clickable area.
- New markdown pages contributed by Eliot Lear: 
[`/authors/ise/ise-checklist/`](https://rfc-editor.org/authors/ise/ise-checklist/), 
[`/authors/ise/iseb/`](https://rfc-editor.org/authors/ise/iseb/), 
[`/authors/ise/ise-reviewer-guidelines/`](https://rfc-editor.org/authors/ise/ise-reviewer-guidelines/).
- Improved No-JS handling (when browsers have JavaScript disabled or 
unavailable): menus, RFC tabs, and a simple search.
- Various redirects, read the [worker router definition for 
details](https://github.com/ietf-tools/red/blob/main/worker/src/index.ts#L56).
- Accessibility contrast color fixes.
- fix: Dark mode search
- fix: `/info/rfcN/` browser line-break hints `<wbr>` handling.
- fix: Safari-specific JS improvements.
- chore: Website JS bundle size optimisations (improved JS bundle 
chunking, removing `@nuxt/content` in favour of a bespoke solution as we 
don't need the WASM SQLite db query features).
- `CHANGELOG.md` moved to 
[`/docs/MAJOR_CHANGES.md`](https://github.com/ietf-tools/red/blob/main/docs/MAJOR_CHANGES.md)

### Queue

- fix: pending activities
- accessibility improvements: reduced motion support for graph.
- table improvements
   - all columns that can be sortable are sortable
   - all tables have 'sticky' headers (follow page scroll)

### Errata system

The re-implemented errata system deployment went smoothly. The system now

* Holds reports for spam screening by the secretariat.
* Uses datatracker credentials for RPC member and stream validator login.
* Makes the set of reported errata a logged in validator can validate 
easier to work with.
* Better integrates with datatracker for information about groups.

The re-impementation otherwise did not change the errata reporting, 
searching, or validation process. We still await community consensus 
around what the errata system should become before making major changes.

Upcoming work:
* A complete test framework, and small improvements to the ci/cd paths.
* Incremental improvements to views and emitted email.


### RPC Editor (DraftForge)

DraftForge has transitioned from alpha/beta to stable release 1.x.

- **feature**: Add export from markdown format
- **fix**: Ignore XML comments in "inconsistent capitalization" tool
- **fix**: Ignore email, target and title elements in "inconsistent 
capitalization" tool
- **fix**: Use output filename as input when generating HTML export
- **fix**: Warn when no format is selected in "Export as" tool

### Side Meetings

The "Request a Side Meeting" button is now disabled until the active 
period starts.

### Email systems

  * Updated Content-Security-Policy on existing mailman web interface to 
make avatars visible, h/t Kesara
  * Unified logging configuration for DMARC rewriting daemon, 
postconfirm, and postfix
  * Migration of UAT environment from Digital Ocean -> Azure
  * Development of global mail system dashboard, based on unified logs 
from all containers, relays and existing mail systems
  * Fixed IMAP failed login logging and dashboard for better awareness 
of operational issues

### YANG Catalog

_No updates since the last report._

### Meetecho Player

Now you can share a link at a certain timestamp with [Meetecho 
player](https://meetecho-player.ietf.org/).

---

## Maintenance

### Django
(Unchanged since previous report) As mentioned in previous IETF tools 
updates, several systems, including Datatracker, still run on Django 4.2 
LTS. This reached the end of long-term support with release 4.2.30 on 7 
April 2026. We are preparing to upgrade to Django 5.2 LTS as soon as 
other priorities allow. In the meantime, we are monitoring for CVEs that 
affect Django 4.2 and will take appropriate action if necessary. So far, 
one possibly relevant vulnerability has been identified 
([CVE-2026-35192](https://www.cve.org/CVERecord?id=CVE-2026-35192)) and 
we have backported the fix from Django 5.2.

### Debian image bases
(Unchanged since previous report) Most of our containerized applications 
rely on Debian, and require updates following the Debian lifecycles. The 
datatracker’s base image is currently built on bookworm (12), but needs 
to move to trixie (13) to support changes to libyang/libyang3-tools that 
are not available on bookworm. We attempted to make this move at the end 
of 2025 but encountered a dependency issue that will need to be resolved 
before we proceed.

### Kubernetes

The June 4 upgrades did not go as planned and will be rescheduled at a 
future date. We have not yet begun upgrading the Kubernetes versions for 
our primary production clusters.