Re: WG chair on buffer exhaustion
Caitlin Bestler <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
On Wednesday, July 30, 2003, at 02:37 PM, Mallikarjun C. wrote: > I recall several on this WG have agreed that the > current DDP text that I pointed out is severe. > Let's just fix that text to address the WG concerns. > > You had earlier argued that DDP text is fine the way > it is, now you're proposing a _lot of_ text that > does not fix the text the WG had a problem with. > > No amount of wordsmithing that does not fix the original > text will resolve the issue I had brought up. Besides, I do > not agree with all the text you suggest. > > Needless to say, I prefer the text I recommended. The text you proposed fails to distinguish between ULP authorized messages and ULP unauthorized messages. As has been discussed on the WG, this creates a severe security vulnerability. The wording I propose makes it clear that the receiving side has flexibility in handling a problem caused by lack of buffering *without* creating a responsibility to try to recover from unauthorized untagged messages. Can you be specific as to which portion you disagree with? And are those disagreements consistent with keeping iWARP a *reliable* protocol with ULP flow control? The bottom line is that when the Data Source sends an untagged message it is either authorized by the ULP or it is not. If it is authorized, the Data Sink is expected to receive it. Pretending not to receive it, or dropping the connections are strategies for fault-containment. That does not mean they are acceptable protocol behaviors. The wording you propose endorses such strategies. If it is not authorized, the Data Sink SHOULD reject it. It definitely MUST NOT place another session at risk by accepting an unauthorized message. The consensus on the WG is *solely* to allow a local implementation to have some flexibility in how to recover from fault conditions. Your proposed wording changes far exceed that.