Re: Potential data corruption in DDP with MSN protocol violation
Caitlin Bestler <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
On Apr 27, 2004, at 1:06 AM, [email protected] wrote: > Tom, > > I think at a minimum there should also be something added to say that > if such a case occurs the receiver MUST not deliver whatever junk is > lying around as message 2. > > I don't mind the case where the connection grinds to a halt because it > has message 3 complete and no message 2. Something somewhere will time > out eventually and while it may not be as graceful as detecting the > error it is not disastrous. > > The case that worries me is a designer who did not think about > protecting against this error in the received stream. An > implementation may be built that assumes when the stream receives the > completion of MSN 3 and the stream has no gaps up to that point that > the prior messages are also complete. If we don't want to allow that, > then we need to says something explicit about it. > > Once we do that, we might as well add the error and at least allow an > implementation the choice of reporting it instead of silently > freezing. > > Pat > Do you agree that such text would be merely informative? My reading is that the existing rules already forbid delivery of message 3 when message 2 has not been delivered, and message 2 can only be delivered when its L segment is deliverable -- which it can never be if it does not exist. -- Caitlin Bestler http://asomi.com/