Summary

  • draft-ietf-pce-entropy-label-position-07 proposes PCEP flags for negotiating, requesting and specifying where ELI/EL pairs belong in an SR-MPLS label stack. It is an active Working Group Internet-Draft in Last Call, not an RFC or deployment result.
  • Revision 07 says a PCUpd carries the complete replacement for the previous ELP set. Valid new state replaces old state, an E-free set removes old pairs, and invalid or partial input must leave existing state untouched.
  • That atomic control-plane rule does not prove that forwarding hardware applied the stack, that current path nodes can read the selected depth, that local hashes use the entropy value, or that traffic distribution improved.

The easiest way to overstate an orchestration system is to point at a successful update and call the network changed. PCEP can carry a precise path. A controller can compute two exact positions. A client can accept a complete replacement set. Every message can be valid while the operational claim remains unfinished.

An entropy label exists for a practical reason. Deep in an MPLS stack, transit equipment may be unable or unwilling to inspect the original IP and transport fields needed for per-flow load balancing. The ingress computes a value from packet fields and places it in an EL. An Entropy Label Indicator immediately precedes it. A transit LSR can then use the EL as one of its hash inputs without looking beyond the stack.

The words “can” and “use” carry the whole boundary. RFC 8662 defines Entropy Readable Label Depth as the number of labels a router can both read and use for load balancing. A device that can parse a label but cannot use an EL at that depth must advertise ERLD zero. The resulting number is not just parser reach. It is a bounded claim about a forwarding function.

Revision 07 addresses the controller side of that problem. It gives a stateful PCE a way to tell a PCC where ELI/EL pairs should be inserted after selected SR-ERO subobjects. Its new error text and replacement semantics are substantially stronger than revision 06. They make the intended transaction less ambiguous. They do not observe the transaction’s consequence.

Three E flags describe three different decisions

The proposal uses related E bits at three layers. In the OPEN exchange, a PCE advertises that it can compute SR-MPLS entropy-label positions from MSD and ERLD information. A PCC advertises that it can insert one or more pairs at PCE-indicated positions. This is capability negotiation.

The E bit in the LSP-EXTENDED-FLAG TLV asks for ELP computation on one LSP operation. This is request scope. An SR-ERO subobject’s E bit then identifies a specific insertion boundary: put the pair after this segment. This is placement instruction.

Treating those three receipts as one produces false confidence. OPEN capability does not say that sufficient inputs exist for this path. A request does not prove that a complete answer was possible. A returned SR-ERO does not prove that the PCC applied it. Application does not prove that the selected label fell inside every relevant node’s current ERLD.

Revision 07 closes several control-plane gaps. A PCE must not send positions that an incapable PCC cannot apply. A PCC that requests ELP from an incapable PCE is supposed to receive an error. Unexpected positions must not be applied. Missing, inconsistent or insufficient ERLD or MSD information must produce no usable SR-ERO subobjects and a bounded error instead of a partial best effort.

This is good protocol discipline. Partial authority is especially dangerous here because one readable pair can make a path look protected while another part of the stack remains beyond a downstream component’s reach. The proposal rejects the appearance of a complete plan when the inputs cannot support one.

Complete replacement is a state rule, not an effect receipt

The most important change from revision 06 is the explicit update rule. For PCUpd, the received ELP information is the complete replacement for the previous position set. A valid set with E flags atomically replaces the old set. A valid SR-ERO with no E flags removes all old ELI/EL pairs. Invalid or partially valid information must not modify existing path or ELP state and should return an error correlated with the SRP ID.

That definition prevents an implementation from quietly merging new positions with stale positions. It also gives operators a testable negative obligation: after a successful removal, an old pair must not remain active.

But “atomically replaces” names the protocol state transition, not a universal hardware transaction. A PCC can accept and record a PCUpd before every forwarding component has converged. A chassis can have different line cards. Fast and slow paths can have different abilities. A readback system can observe intended state while packet processing still uses the previous programming epoch.

The correct completion record therefore needs both sides. It should identify the SRP ID, old and new position-set fingerprints, controller computation epoch, PCC acceptance, forwarding-hardware readback and proof that superseded pairs are absent. If the platform cannot produce the last two, it can honestly report accepted intent, not completed replacement.

This distinction is not an argument against central computation. It is the condition under which central computation remains accountable. The controller owns the calculation. The PCC owns local admission and application. Forwarding hardware owns the packet behavior. Measurement owns the claim about distribution.

ERLD and MSD constrain opposite sides of the same stack

Maximum SID Depth answers how many labels a node can impose. ERLD answers how deeply a node can read and use an entropy label. More ELI/EL pairs may improve the chance that downstream nodes see one, but each pair consumes two more stack entries. A plan can satisfy downstream readability while exceeding ingress imposition headroom.

The standards expose further nuance. A distributed chassis may advertise the minimum ERLD across interfaces or components. That is conservative and interoperable, but it can cause a controller to insert more pairs than a more granular model would require. Those extra pairs deepen the stack and consume MSD. A single system value is therefore a safe coordination floor, not a perfect picture of every forwarding path.

Absence has bounded meaning too. RFC 9088 and RFC 9089 say absence of ERLD-MSD advertising means only that the node does not support advertising that capability. It does not prove that the hardware cannot use an entropy label. The controller must not convert missing evidence into either optimism or a universal incapability verdict.

The proposal’s fail-closed error is the right response for automated placement: without sufficient input, do not fabricate a usable SR-ERO. Operations may still choose another path, a locally computed position, a stack without ELP, or a policy exception. That localized future decision should be explicit rather than hidden inside the common protocol.

The topology epoch can expire before the label does

For an adjacency segment, the relevant ERLD belongs to the node processing that adjacency. For a Node SID, the path can include several transit nodes. RFC 8662 allows an implementation to calculate the minimum ERLD along that path; if it cannot, it may fall back to the tail-end’s ERLD. The fallback is specified behavior, not proof about every intermediate device.

Node-SID paths can change. A shortest path recalculation, maintenance event or inter-domain change can move traffic through hardware with a different readable depth while the SR policy and its ELP instruction remain unchanged. RFC 8662 accordingly says minimum ERLD needs recomputation after topology change.

That gives every ELP plan an evidence epoch. The controller needs to retain which topology, Node-SID resolution, Binding SID state, ELC, ERLD and BMI-MSD observations supported the positions. A later path can invalidate the evidence without invalidating the syntax of the stored SR-ERO.

Binding SIDs make the boundary sharper. Their entropy-label capability must be inherited from the associated LSP. If the advertiser does not know the target FEC’s capability, it must not set ELC, and the ingress must not push the corresponding pair. A label name is not a capability certificate. The actual stitching point and hidden LSP remain part of the proof.

Being readable does not determine the hash

Even perfect placement stops short of the business result. RFC 6790 and RFC 8662 leave hash inputs to local configuration. A node may use the EL alone or combine it with other fields. Two devices with the same ERLD and the same visible EL can distribute flows differently.

The entropy value is designed to preserve per-flow ordering while giving multipath equipment useful variation. It does not promise equal utilization. Flow sizes are unequal. A few large flows can dominate one member. ECMP and LAG membership can change. A valid EL can be read and included in a hash while observed utilization remains skewed.

The measurement contract must therefore name its denominator and window. Operators need member-link counters, flow distribution, loss, reordering, path membership and before/after comparison tied to the same policy epoch. A fan-out diagram or a nonzero counter is not enough.

The draft itself says its extensions add no new liveness or operation-verification mechanism beyond the underlying PCEP specifications. That is a useful limit. It keeps the wire mechanism narrow. It also means an operator cannot cite the E flag as an implicit probe.

The operational chain has twelve separate receipts

Receipt Minimum evidence What it does not prove
Capability PCE/PCC OPEN flags and session identity Inputs exist for this LSP
Topology epoch Resolved segments, links and observation time Forwarding remained unchanged
Depth input Scoped ELC, ERLD and BMI-MSD records Advertisements are current in hardware
Computation Complete position set and algorithm/policy version PCC acceptance
Request LSP identity, SRP ID and requested ELP flag Successful answer
Response Complete SR-ERO or bounded PCErr Installation
Acceptance PCC transaction result Forwarding-hardware convergence
Replacement New-set fingerprint and absence of old pairs Every packet used the new epoch
Readability Per-component proof that relevant EL is in depth EL became a hash input
Hash use Local hash-policy version and counters Balanced distribution
Distribution Named window, paths, counters, loss and reordering End-to-end delivery
Outcome Independent destination or service observation Authority for another change

A single “ELP success” event erases the place where repair belongs. Missing topology is a computation problem. Rejected SR-ERO is a protocol problem. Stale old pairs are a replacement problem. An unread EL is a depth problem. Readable but skewed traffic is a hash or workload problem. Delivered traffic with the wrong application effect is outside ELP altogether.

Revision 07’s value is that it improves the middle of this chain. The controller and client can agree more precisely about complete state. Leadership should resist using that precision to claim the later links by implication.