[tsvwg] Re: draft-ietf-tsvwg-usr-exp-10 ietf last call Genart review
"touch@strayalpha.com" <touch@strayalpha.com> Mon, 18 August 2025 00:47 UTC
Return-Path: <touch@strayalpha.com>
X-Original-To: tsvwg@mail2.ietf.org
Delivered-To: tsvwg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CB8FF5533ACF; Sun, 17 Aug 2025 17:47:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=strayalpha.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PWEAZQGeqhMu; Sun, 17 Aug 2025 17:47:03 -0700 (PDT)
Received: from server217-3.web-hosting.com (server217-3.web-hosting.com [198.54.115.226]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F2D5D5533AB6; Sun, 17 Aug 2025 17:47:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=strayalpha.com; s=default; h=To:References:Message-Id:Cc:Date:In-Reply-To: From:Subject:Mime-Version:Content-Type:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=yTfz7BB0J3dLrv/rZOc+ss+EGfO6mgoV+lc7vkxWwh8=; b=457GrctX48l34FzAsXcddxDlEj jsCSF8KVXmZVfMHrWpsJtVz1LzrJtWrmKlQiE/5kqsFNAhE6HsxTqHbz+MILd+F2sQBppd4+tv7Y0 r0u43+EfAAzaX7KhYfsGgBkhuelmUmotrCaq7CkUsyrvgSAoz3LfCg4Ml9nH8dKaDSZ8CTXn9iNHQ noz34e94EyuJp3MXiVs5bTwOMSUBE9uu7oPr96PyJDa0m1BfQq08VIMuLi4ctzONcZuig+poVeNL+ WNF/rKqsks97j1XeVnecbjWBV8Bp6QgJUHg94I/vmdBXhMrp5eeqVTAnOSHwEfEcJ+PYRg4opu2zY Cu86kLbA==;
Received: from [172.56.54.165] (port=48729 helo=smtpclient.apple) by server217.web-hosting.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from <touch@strayalpha.com>) id 1uno1d-0000000BxmI-07h4; Sun, 17 Aug 2025 20:47:01 -0400
Content-Type: multipart/alternative; boundary="Apple-Mail=_A4E39014-D080-4F98-8719-2E1F3A853161"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81\))
From: "touch@strayalpha.com" <touch@strayalpha.com>
In-Reply-To: <175453220792.1392379.14423369859353565165@dt-datatracker-5bd446d5fd-c47nq>
Date: Sun, 17 Aug 2025 17:46:48 -0700
Message-Id: <93A001A9-24E7-4244-9624-6ACC57ADE0E6@strayalpha.com>
References: <175453220792.1392379.14423369859353565165@dt-datatracker-5bd446d5fd-c47nq>
To: Tim Evens <tievens@cisco.com>
X-Mailer: Apple Mail (2.3826.700.81)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server217.web-hosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - strayalpha.com
X-Get-Message-Sender-Via: server217.web-hosting.com: authenticated_id: touch@strayalpha.com
X-Authenticated-Sender: server217.web-hosting.com: touch@strayalpha.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-From-Rewrite: unmodified, already matched
X-Rspamd-Queue-Id: 1uno1d-0000000BxmI-07h4
Message-ID-Hash: 2QJ65V476G6GRPVEUZIR5CMKTAQTODET
X-Message-ID-Hash: 2QJ65V476G6GRPVEUZIR5CMKTAQTODET
X-MailFrom: touch@strayalpha.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tsvwg.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: gen-art@ietf.org, draft-ietf-tsvwg-usr-exp.all@ietf.org, last-call@ietf.org, tsvwg@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [tsvwg] Re: draft-ietf-tsvwg-usr-exp-10 ietf last call Genart review
List-Id: Transport Area Working Group <tsvwg.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsvwg/CgsnD04O2ye5YUGUx_1OuKJOoQ8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsvwg>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Owner: <mailto:tsvwg-owner@ietf.org>
List-Post: <mailto:tsvwg@ietf.org>
List-Subscribe: <mailto:tsvwg-join@ietf.org>
List-Unsubscribe: <mailto:tsvwg-leave@ietf.org>
Hi, Tim, Thank you for the review. Some comments below. Joe — Dr. Joe Touch, temporal epistemologist www.strayalpha.com > On Aug 6, 2025, at 7:03 PM, Tim Evens via Datatracker <noreply@ietf.org> wrote: > > Document: draft-ietf-tsvwg-usr-exp > Title: User Ports for Experiments > Reviewer: Tim Evens > Review result: Ready with Issues > > I am the assigned Gen-ART reviewer for this draft. The General Area > Review Team (Gen-ART) reviews all IETF documents being processed > by the IESG for the IETF Chair. Please treat these comments just > like any other last call comments. > > For more information, please see the FAQ at > > <https://wiki.ietf.org/en/group/gen/GenArtFAQ>. > > Document: draft-ietf-tsvwg-usr-exp-?? > Reviewer: Tim Evens > Review Date: 2025-08-06 > IETF LC End Date: 2025-08-04 > IESG Telechat date: Not scheduled for a telechat > > Summary: > Overall the draft is well written and addresses an issue with developer use of > layer 4 ports (UDP, TCP, ...) that may have otherwise been privileged or > disallowed by security control points. The draft aims to standardize a range of > user ports for experimental (aka developer) use, starting with two ports, that > supports multiplexing to scale the usage of the user ports. I like the > simplistic multiplexing approach using a single 4-byte PExID, but I am > concerned that the simplistic method may not scale to future requirements that > may need some flags or additional TLVs. FWIW, the approach is an extension of the IANA ports numbers. Although additional flags or TLVs may be useful to differentiate uses of a port, they are not currently part of how transport protocols use ports, and appear to be premature to consider in this document. > Major issues: > None > > Minor issues: > > There are developer use-cases, especially within labs, that need help from the > network infrastructure to ensure traffic does not leak out of contained > labs/etc. Security inspection points, such as a firewall, are used to catch a > leak and filter it. I see this basic requirement missing for containment of > developer/experiment user ports and PExIDs from being leaked out. There is no > indication to the FW that it should drop or allow the packet based on PExID. PExIDs extend the IANA port space. There is no similar indication in the port space itself. Even the distinction between System and non-System assignments has become ineffective and inaccurate, as noted in RFC 7605. Sec 7.9. > Suggest to define a PExID range for IANA to be used where no registration will > exist. If there is no registration, I would tend to expect that packets would > not be allowed outside of containment (aka LAB, local, ...). In other words, no > public internet or corporate network access allowed within this PExID range. > If there is a registration, maybe that should indicate scope of where these > packets should be forwarded... Might make sense to define a range for some > basic scopes, such as allowed within LAB only, allowed within > local/enterprise/campus, allowed everywhere including internet. I don't > believe this needs to go into the weeds of authorization... There is a > pre-established trust with the experimental user-ports and PExIDs. These > scopes are more of a safe guard to prevent accidental leakage of traffic that > should have not been allowed out of an experiment/lab. This assignment is primarily intended to reduce squatting. Current ports - both assigned and ’squatted - have no such capability, nor do the self-assigned ranges. This document is not intended to address that issue, nor might it even be possible to address, given the “genie is already out of the bottle” for all other cases. > Nits/editorial comments: > >
- [tsvwg] draft-ietf-tsvwg-usr-exp-10 ietf last cal… Tim Evens via Datatracker
- [tsvwg] Re: draft-ietf-tsvwg-usr-exp-10 ietf last… C. M. Heard
- [tsvwg] Re: [Gen-art] draft-ietf-tsvwg-usr-exp-10… worley
- [tsvwg] Re: [Gen-art] Re: draft-ietf-tsvwg-usr-ex… worley
- [tsvwg] Re: [Gen-art] Re: draft-ietf-tsvwg-usr-ex… Gorry Fairhurst
- [tsvwg] Re: [Gen-art] Re: draft-ietf-tsvwg-usr-ex… touch@strayalpha.com
- [tsvwg] Re: [Last-Call] [Gen-art] Re: draft-ietf-… touch@strayalpha.com
- [tsvwg] Re: [Last-Call] [Gen-art] draft-ietf-tsvw… touch@strayalpha.com
- [tsvwg] Re: draft-ietf-tsvwg-usr-exp-10 ietf last… touch@strayalpha.com