Summary
draft-dikshit-netconf-yang-push-causal-ordering-00proposes Hybrid Logical Clock fields for comparing YANG-Push notifications across publishers. It addresses a real gap: publisher-local counters can expose local loss or reordering, but their numbers have no cross-publisher meaning.- The original HLC result is one-way. If event e happened before event f, its HLC is smaller. A smaller HLC does not prove happened-before: concurrent events can be ordered by clock values, and equal pairs from independent publishers still need a tie-breaker.
- Operational decisions therefore need more than a sorted stream: publisher epoch, gap and replay treatment, clock condition, explicit dependency, common observation window, datastore evidence, authorization, applied state and independent service verification.
The missing comparison is real
A counter scoped to one publisher answers a narrow and valuable question. If a receiver has accepted sequence 104 and then sees 106 from that same publisher and epoch, it has a reason to investigate the missing value. If 103 arrives after 106, it has a reason to classify reordering or replay. The counter does not say whether publisher A’s 104 precedes publisher B’s 39. The numbers were allocated by different processes, from different histories, and may advance at different rates.
Revision 00 of the individual Internet-Draft names that gap directly. It also notes a second ambiguity: a finite counter can eventually repeat. A receiver that sees the same numeric value after wraparound needs an epoch or another rule to distinguish a new record from an old duplicate. These are not cosmetic concerns. Distributed telemetry becomes decision input precisely when several publishers describe different parts of one system. If their records cannot be compared, an aggregator may invent order from arrival time, collector scheduling or storage insertion order without saying so.
The proposal evaluates three families. Publisher-local counters are cheap but local. Vector clocks can distinguish causal precedence from concurrency, but their state grows with the participant set. Hybrid Logical Clocks keep constant-sized physical and logical components and preserve a logical-clock ordering property while remaining near physical time. That makes HLC attractive for a high-rate telemetry header. It does not make every comparison a causal finding.
One implication must not be read backwards
The original HLC paper states the property with an arrow in one direction: when e happened before f, hlc(e) < hlc(f). “Happened before” is not ordinary English chronology. It is built from information-bearing relations: local program order, a send followed by its corresponding receive, and the transitive closure of those edges. The clock is designed not to reverse such a path.
The converse is different. Suppose publisher A observes a fan-speed change at 10:00:00.010 and publisher B observes a route withdrawal at 10:00:00.014. They have exchanged no relevant message and share no causal dependency. Their physical components can still differ, so a lexicographic sort puts A first. That is a convenient presentation order. It does not show that the fan event caused the route event, that both came from one transaction, or that a repair should follow the first record toward the second.
This distinction is not an attack on HLC. Logical clocks have always been useful because they respect causal order without claiming that every clock inequality reveals causality. Vector clocks carry more information: componentwise comparison can support the stronger equivalence, while incomparability exposes concurrency. HLC chooses a smaller operational footprint and one-way causal preservation. Leadership should demand that the loss of the converse remain visible in the consuming system.
A two-field pair can still tie
The draft proposes hlc-physical and hlc-logical and tells a receiver to compare the pair lexicographically. Within one correctly maintained process, the logical component prevents local events that share a physical value from collapsing. Across two independent publishers, the same pair remains possible. Both can read the same millisecond and both can emit their first event at logical zero. Without a publisher identity or another stable discriminator, neither pair is smaller.
A deployment can solve deterministic sorting by appending a publisher identifier, process epoch and perhaps a per-event nonce. It should. But the added field changes the administrative ordering rule, not the causal graph. If publisher A sorts before publisher B because its identifier is lexicographically smaller, the receiver has gained repeatability, not evidence that A influenced B. A tie-break receipt should therefore record the rule used and keep it out of causal labels, root-cause scoring and rollback selection.
Equal-pair handling also intersects with restarts. A hostname that remains familiar does not prove a process epoch remained continuous. A restored virtual machine, cloned image or replaced line card can reuse an identity while losing the prior HLC state. A receiver needs an authenticated publisher identity, a boot or process epoch, and explicit state-recovery semantics before treating the next pair as part of the old series.
Epsilon is a quarantine rule, not a truth certificate
The proposal recognizes a clock-trust problem. A publisher whose physical clock is far ahead can make its records sort after normal records for an extended period. It recommends treating a physical component more than a configured epsilon ahead of the receiver’s clock as suspect. That is a useful anomaly boundary. It does not establish that values inside the boundary are accurate or that the receiver clock is authoritative.
Clock discipline has its own evidence: source selection, offset estimate, dispersion, leap handling, holdover, last successful update and local oscillator behavior. RFC 5905 gives NTP machinery for synchronizing time; it does not turn a timestamp into proof of event origin or causal dependence. RFC 9581 can carry structured time and stated uncertainty; it likewise cannot attest the clock, the measurement or the event by itself.
The decision for a suspect value matters. Dropping it creates a completeness gap. Quarantining it delays correlation. Clamping it changes the publisher’s asserted time. Accepting it can distort windows, retention and last-write decisions. Each action needs an explicit disposition record so later analysis can tell observed publisher data from collector repair.
Ordered notifications are not a common snapshot
Even a perfect causal clock operates on events that publishers actually emit. It cannot reveal an omitted publisher, an access-controlled subtree, a failed transport, a suppressed unchanged value, a coalesced update or a schema path the collector cannot decode. A gap-free series within one visible epoch is not proof that the receiver saw every operational fact relevant to a decision.
Nor do two ordered updates necessarily describe a state that existed at one instant. Publisher A may read interface state from one subsystem while publisher B reads routing state from another. Their local observations can be internally valid and still straddle a transition. Sorting the records produces a line; it does not manufacture an atomic datastore snapshot. The notification-envelope fields, YANG-Push subscription identity, YANG Library context and access-control view remain part of the evidence.
The safe chain therefore distinguishes event time, observation time, emission time, receipt time and decision time. It records the publisher and epoch, local sequence, HLC pair, clock condition, schema identity, subscription scope, gap state and transformation history. If causality is asserted, it adds an explicit message, transaction or dependency edge. If a configuration action follows, it adds a responsible principal, authorization, exact target and parameters, protocol result, readback and observed forwarding or service effect.
What revision 00 does and does not establish
The document is an active individual Internet-Draft dated 30 August 2026, intended as Informational and expiring 1 March 2027. The Datatracker says it is not endorsed by the IETF and has no formal standing in the IETF standards process. Its proposed fields and comparison rule can change. The source record establishes neither NETCONF Working Group consensus nor an implementation, interoperability result, deployment or incident.
The narrow contribution is still worth examining. It turns an implicit collector problem into an explicit protocol question and compares familiar distributed-systems tools. The disciplined conclusion is not that HLC is useless, nor that every use of the word causal is wrong. It is that the proposed receipt has a precise scope. An HLC can prevent a real causal edge from being reversed when the algorithm’s assumptions hold. A numerical order alone cannot create the edge, certify completeness or close the loop from telemetry to outcome.
Sources
- https://datatracker.ietf.org/doc/draft-dikshit-netconf-yang-push-causal-ordering/
- https://datatracker.ietf.org/doc/draft-dikshit-netconf-yang-push-causal-ordering/history/
- https://datatracker.ietf.org/doc/draft-dikshit-netconf-yang-push-causal-ordering/references/
- https://datatracker.ietf.org/doc/draft-dikshit-netconf-yang-push-causal-ordering/referencedby/
- https://datatracker.ietf.org/doc/html/draft-dikshit-netconf-yang-push-causal-ordering-00
- https://www.ietf.org/archive/id/draft-dikshit-netconf-yang-push-causal-ordering-00.txt
- https://datatracker.ietf.org/doc/draft-dikshit-netconf-yang-push-causal-ordering/00/
- https://datatracker.ietf.org/doc/draft-ietf-netconf-yang-push-2/
- https://datatracker.ietf.org/doc/draft-ietf-netconf-distributed-notif/
- https://datatracker.ietf.org/doc/draft-ietf-netconf-notif-envelope/
- https://www.rfc-editor.org/rfc/rfc8641.html
- https://www.rfc-editor.org/rfc/rfc8639.html
- https://cse.buffalo.edu/tech-reports/2014-04.pdf
- https://www.rfc-editor.org/rfc/rfc5905.html
- https://www.rfc-editor.org/rfc/rfc9581.html
- https://heng.lu/on-reality-layers-symbolic-power-and-why-clarity-feels-so-hostile/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
