Re: [v6ops] IPv6 EHs Packet Drops (Fwd: New Version Notification for draft-gont-v6ops-ipv6-ehs-packet-drops-02.txt)

Warren Kumari <warren@kumari.net> Wed, 17 February 2016 14:23 UTC

Return-Path: <warren@kumari.net>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 50B081B31E0 for <v6ops@ietfa.amsl.com>; Wed, 17 Feb 2016 06:23:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level:
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lQ6dSrvjZ6Ts for <v6ops@ietfa.amsl.com>; Wed, 17 Feb 2016 06:23:51 -0800 (PST)
Received: from mail-yw0-x232.google.com (mail-yw0-x232.google.com [IPv6:2607:f8b0:4002:c05::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A7AE21B351E for <v6ops@ietf.org>; Wed, 17 Feb 2016 06:23:51 -0800 (PST)
Received: by mail-yw0-x232.google.com with SMTP id u200so13961549ywf.0 for <v6ops@ietf.org>; Wed, 17 Feb 2016 06:23:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kumari-net.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-type; bh=MLkJWCjEdrKbOtBC01aBiILGDXvXXHrsdn3zs5eU2pc=; b=nYuT8A+dHhpFFQys1sKMf4ABCZg8vbL6f3zv8V34b07qrEHax45fXp9oIffyWynupu zCt3rjguBiTLTb4dti5oYUX0CjPYDps6+wlfNcTGMvTVs7P8WEIXH+KwgCpStmRCKd1D bDE7EFFkr1+enTMkuQnJMDTEz46qA+lceyHy/gCX/3CO1xmR2m5yDkwjA4tN8ektlRW9 GgQPm6OejmLn0t0vADNvt6SzgXMNgCKDemUMinXdHAWCf3nSdQQKeNxm9S8Hx/vcgxGj 9qa2I3xQH2edYZaBc6sTjKpRyS1LcIgWpDjyfcELTg+Dc935tR1fb5xflVBMoDjqraW0 w8jQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-type; bh=MLkJWCjEdrKbOtBC01aBiILGDXvXXHrsdn3zs5eU2pc=; b=LFUu11OXJP2y+Qy2/8okF4V5SmvEbFp/xms8Uxzpf3TyupWHP7pUNQdoQGBOMpf3io qzvdKgS3HANjWRDrpgdGTIEQ8/TWD5Ut3/xO59jAi6RdWr7hkpNmx6x1WkbhqH8Xn2VA I8OARazEdGB6aV1ujIZsd+YJRDiy9ciRbfBfJ5cXWAGiNme5VH6wkmLSEmn2eE3CEwSI we7Od678L+96XV/n2FRKQYNDq0bvF2vf8Ki+frGEkqsti3EZ+kkLhjdMYzV6/P9gyMMR mZPZMtkWqBa5sLqLTzh/CeYTfnJPuB0BGbHTeDKjV72RsPniwgL/PuQKmc37UEIeSbpr kLxw==
X-Gm-Message-State: AG10YORN2hhq1vwIf99TJMLuXdFtji5rw84Q2UVjfmDrOMY930Q8WfvKv8t8d6FmkDeSI7f+ommzxdOqiU5ghCSC
X-Received: by 10.129.70.8 with SMTP id t8mr942865ywa.105.1455719030898; Wed, 17 Feb 2016 06:23:50 -0800 (PST)
MIME-Version: 1.0
References: <20160204214639.14168.48254.idtracker@ietfa.amsl.com> <CAO42Z2yG_85ASJKbgMwXBzAAT41_DTsgYTpHm4ZtiPyjL0ZeVQ@mail.gmail.com> <56B668C3.8090009@foobar.org> <CAO42Z2zfXymKK_jPUXnV+e-6-BxJBvui2EOi7XAdo-5o5vj2ag@mail.gmail.com> <56B67671.3010409@foobar.org> <CAO42Z2zXd17fNsArj-JFGNo+s7PtiwLKLaWPkkcHiEHybO49Fw@mail.gmail.com> <56B742AC.7010307@foobar.org> <CAO42Z2wQHftEMQUPPfjvz3d+j_5ag0hV0cP1FcufGDk27WbqNg@mail.gmail.com> <56B7B919.8090001@foobar.org> <56B83BB9.7040704@isi.edu> <56B8BA32.3010505@foobar.org> <56B8F12F.30307@isi.edu> <56B90B6C.9060105@si6networks.com> <56B90E16.1090402@gmail.com> <56B933A4.6060405@si6networks.com> <B9EACBEF-0C11-4BC9-BDC4-FC720EA38985@employees.org> <74B4E9A1-E6FE-40C0-9EC9-0C2C5172A246@employees.org> <6E0AE4AB-330D-4670-9EF0-21F8E43AC6CB@employees.org> <m1aTSxz-0000CUC@stereo.hq.phicoh.net> <56C2DF32.3010901@si6networks.com> <m1aVfep-0000CuC@stereo.hq.phicoh.net> <CAHw9_i+ymjmj0Lz+hM5Y3YOh7GYQd2K_4LToG5c4RgATAZn5Qw@mail.gmail.com> <56C34009.1070508@si6networks.com> <m1aW0D2-0000F2C@stereo.hq.phicoh.net>
In-Reply-To: <m1aW0D2-0000F2C@stereo.hq.phicoh.net>
From: Warren Kumari <warren@kumari.net>
Date: Wed, 17 Feb 2016 14:23:41 +0000
Message-ID: <CAHw9_iKgT7b4JjwkSST9vz-8-QkSPn6XVUMuKq22ZKbPWtwRuw@mail.gmail.com>
To: Philip Homburg <pch-v6ops-4@u-1.phicoh.com>, v6ops@ietf.org
Content-Type: multipart/alternative; boundary="001a114d71a8bb2045052bf7ff34"
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/5lON__15gn_GTXfOTVXxIme-E0g>
Cc: Fernando Gont <fgont@si6networks.com>
Subject: Re: [v6ops] IPv6 EHs Packet Drops (Fwd: New Version Notification for draft-gont-v6ops-ipv6-ehs-packet-drops-02.txt)
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Feb 2016 14:23:53 -0000

On Wed, Feb 17, 2016 at 6:23 AM Philip Homburg <pch-v6ops-4@u-1.phicoh.com>
wrote:

> >On 02/16/2016 12:13 PM, Warren Kumari wrote:
> >>     The operator adds the number when it is determined to be perfectly
> >>     safe (that I find unlikely for new extension headers) and enough
> people
> >>     are speaking up that the operator is a aware of the problem.
> >>
> >>
> >> This also requires that the application developer makes a judgment call
> >> as to when it is safe to be able to enable this unknown EH.
> >> So, after all middle boxes support "safe-unknown-extension-headers" we
> need:
> >> A: the new unknown EH written
> >> B: someone to be brave enough to try using it (and have it fail in many
> >> / most cases)
> >> C: a large upswell of people going around an poking operators (including
> >> Billybob, who runs the edge middlebox "protecting" Henrys Tire and Wheel
> >> Balancing, Middleburg, VA) to get them to log onto all their devices and
> >> add this new EH to the list of safe things
> >> D: More applications to try using this and have it fail elegantly in
> >> some set of conditions
> >> E: outreach to once again poke Billybob, who replaced his middlebox with
> >> the backup one which lives in the spares closet and wasn't turned on in
> >> step C.
> >> F: application developers to have enough faith that this will work 100%
> >> of the time (keeping in mind that they got bitten in B and D) to turn
> it on.
> >>
> >> This EH would need to provide some *really* compelling benefit to make
> >> this process worthwhile.
> >
> >I think I learned a long-version of the English word "never" (?). :-)
>
> I don't see anything that we do about this at the protocol level.


I fully agree -- and yet we seem to keep trying to...


> Do you want
> to allocate a not-evil bit that can be set on extension headers? "This
> unknown extension header is IETF certified to be not evil, please pass it
> along unchecked".
>
>
That sounds like a grand idea! Let's do that!

More seriously, I think that new EH (and "long" chains") simply won't fly,
that we should admit this and get on with fixing the other issues.
Yes, v6 was supposed to be the grand panacea, curing all ills and being
infinitely extensible - but it turns out that (just like for the
alchemists) the real world gets in the way. Shaking your fists at the gods
and demanding that the world change simply makes your feet sore and your
arm tired :-)

W