Summary

  • draft-geng-grow-bmp-rr-sync-00 proposes a targeted BoRR–Route Monitoring–EoRR sequence for repairing one BMP RIB view while the session remains up.
  • EoRR proves that the sender declared the replay finished. Without an epoch, expected population or digest, it does not independently prove that every route survived generation, transport, ingestion and commit.

The collector receives an Ending of Route Refresh marker. It removes every route still marked stale and turns its dashboard green. That can be exactly the right result: the absent prefixes may truly have disappeared from the router. It can also be the wrong result produced with perfect protocol syntax: a route was omitted before the marker, a buffer dropped a batch, or a live withdrawal crossed the replay at the wrong moment. The same EoRR closes both stories.

That ambiguity is the useful news in BMP Extension for Non-Disruptive RIB View Synchronization, uploaded on 30 September 2026. Revision 00 is an active individual Internet-Draft with Datatracker state I-D Exists. Its header says Standards Track, while Datatracker records no intended RFC status. It is not a GROW Working Group document, an RFC, an allocated BMP message type or a deployment report.

A narrow repair instead of a wide reset

BMP streams routing state from routers to collectors. Transient downtime, socket pressure and process resets can leave the sender's RIB and the stored monitoring view apart. The blunt remedies are expensive: reset the BMP session, re-export every peer, or disturb a BGP relationship merely to correct one monitoring scope.

The proposal creates a BMP Route-Refresh message. For a chosen <Peer, AFI, SAFI>, the sender emits Beginning of Route Refresh, streams the complete set of current active routes in ordinary Route Monitoring messages, then emits Ending of Route Refresh. The collector marks the old scoped entries stale at BoRR, clears that status as matching routes arrive, and purges whatever remains stale at EoRR.

This borrows a tested pattern from RFC 7313. Enhanced BGP Route Refresh marks an Adj-RIB-Out population stale, re-advertises the population that existed at refresh start and removes leftovers when EoRR arrives. Applying that pattern inside BMP is operationally attractive because one damaged view can be repaired without collapsing unrelated monitoring sessions.

The envelope has no inventory slip

BoRR and EoRR are strong delimiters. They answer when a sender says a refresh began and ended. Revision 00 does not add a refresh identifier, expected route count, per-prefix acknowledgement, final digest or independent readback. The example permits zero or more Route Monitoring messages between the markers. Zero is legitimate when the current RIB is empty; it is also what the wire looks like if every replay message disappears and an EoRR survives.

RFC 7854 adds another complication. Route Monitoring carries both an initial snapshot and ongoing changes. Peer dumps need not arrive in an order, and BMP may compress state: if a prefix changes while an update is waiting, the router may report only the final state. Those properties are sensible for scalable monitoring. They also mean the collector needs an explicit rule for deciding whether an intervening announcement or withdrawal belongs to the refresh population, a later live epoch, or both.

Revision 00 does not put a replay-versus-live label or sequence number on each Route Monitoring message. A compliant sender can know what it meant. A different collector must reconstruct that meaning from the ordered TCP stream and local implementation behavior. The envelope is portable; the completeness proof remains local.

Scope is more than three names

The draft repeatedly describes one <Peer, AFI, SAFI> view. In modern BMP that shorthand is not the complete identity. RFC 8671 distinguishes Adj-RIB-In from Adj-RIB-Out and pre-policy from post-policy using per-peer flags. RFC 9069 adds Loc-RIB Instance Peers, instance identity and a flag showing that the exported Loc-RIB is filtered.

A defensible refresh record must therefore bind the operation to the full view: router and BMP session; peer type and distinguisher; BGP ID; address family; Adj-RIB direction; policy stage; Loc-RIB instance; filter state; and the configuration version that selected the export. Otherwise a collector can successfully refresh one stream while an operator later reads the receipt as proof about another.

This distinction matters economically. Security analytics, route-leak detection and topology systems often treat the collector as their factual substrate. A cleanly synchronized pre-policy Adj-RIB-In is not a Loc-RIB. A complete Loc-RIB is not a FIB. None of them proves that packets followed a route or that a mitigation worked.

Protected transport cannot count missing routes

The draft correctly warns that a forged EoRR could force premature deletion and says BMP sessions must use IPsec, TLS or strict ACL filtering as recommended by RFC 7854. Authentication and integrity protect the message from an outsider. They do not prove that an authorized sender assembled the right population, that its internal queue did not lose data or that the collector committed every received message before processing EoRR.

The necessary evidence chain is longer: authorized trigger and cause; exact RIB-view identity; refresh operation ID and start epoch; BoRR receipt and stale-mark commit; sender-side population count or digest; transport loss and backpressure state; replay batches; ordering of concurrent changes; EoRR emission and receipt; collector purge and rejection counts; then a post-refresh comparison or targeted prefix readback.

Heng Lu's minimum-specification doctrine puts the boundary in the right place. A common protocol should standardize enough meaning for independent systems to interoperate. It should not let a shared marker impersonate the local proof that only routers and collectors can produce. Running-code primacy asks what the deployed system actually observed, committed and compared.

The proposal makes recovery smaller and safer. Leadership should adopt that operational gain without over-selling its evidence. EoRR can close the replay. Only a separate receipt can show that the refreshed view was whole.

Sources