Primary Domain
Internet Infrastructure
Within the Primary Domain facet, Internet Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.
CASE FILE
The Client Reported the File Attributes. The Metadata Server Could Still Verify Them: RFC 9766
RFC 9766 gives an NFS client a cheaper way to carry data-file observations back to the metadata server. The design is valuable because it refuses to make that report final: weak evidence can save work without becoming metadata sovereignty.

History
The Permission That Survived Deletion: How IMAP Separated ACL Entries from Effective Rights
The administrator removed Fred from the mailbox list. Fred could still write to it. Nothing supernatural had happened, and the server did not need to be broken: Fred might also belong to a group, or receive the same authority through `anyone`. In the access-control language that…
CASE FILE
The Second Approval Could Be Prepared Before the First Was Signed
Revision 04 of EP-QUORUM fixes an unusually revealing defect: its earlier “strong” approval chain linked contexts that could all exist before any human signed. The replacement makes each successor depend on the completed predecessor proof. That repairs cryptographic causality…
CASE FILE
One Durable Name, a Fresh Route at Every Hop: RFC 9758
RFC 9758 gives a resource a compact name that can survive movement. That durability comes from what the name refuses to contain: no location, no reachability promise and no route. Each relay must still decide what the identifier means here and now.

History
The Address That Had to Be Empty: How SMTP Stopped Errors from Mailing Errors
The most important address in SMTP is sometimes no address at all. A delivery failure has to travel back to the system responsible for the original message, yet a failure to deliver that failure must not produce another failure notice, and another after that. `MAIL FROM:<>`…
CASE FILE
The Hashes Matched. That Did Not Prove the Network Was Right
Revision 01 of the proposed IS-IS Aggregated SNP Hash exchange can make a million-fragment database cheaper to compare. Its restraint matters more than its speed: a matching summary ends a search for differences, but does not authenticate the state, validate the topology or prove…
CASE FILE
The Grandmaster Won the Election. That Did Not Prove the Time Was Right: RFC 9760
The Best timeTransmitter can be selected exactly as the profile requires while the winning clock, its external reference or the path to it remains wrong. RFC 9760 gives enterprise PTP a disciplined way to interoperate at scale. It does not turn an election result into proof of…

History
The Number That Stopped Naming Every Packet: How IPv4 Narrowed the Identification Field
IPv4 put a 16-bit Identification value in every header so a receiver could reunite fragments of one datagram. Over time, the value was treated as a more general packet identity—even when fragmentation was impossible. Link speeds then outran the number space, implementations…
CASE FILE
RDAP Can Name the Assessor. It Cannot Authenticate the Result
Revision 02 turns a lone score into a time-bounded, contestable set of claims from multiple issuers. Yet its most important field, `scoreIssuer`, supplies attribution rather than in-band proof that the named assessor actually made the assertion.

History
The Address That Recruited a Subnet: Why Routers Stopped Forwarding Directed Broadcasts
One IPv4 datagram could cross the Internet as an ordinary routed packet, reach the router responsible for a remote network and become a local broadcast there. With a victim's address forged as the source, that last-hop conversion could turn willing hosts on someone else's subnet…
CASE FILE
The Firewall Did Not Recognize the TLS Parameter. Blocking It Would Have Broken Extensibility: RFC 9761
A new ClientHello value can mean malware, a legitimate update, deliberate GREASE or simply that the firewall is older than the endpoint. RFC 9761 makes that uncertainty operational: compare the device's declared profile with what the firewall actually understands, then keep…

History
The Link That Borrowed Its Address: How Relative URLs Made Documents Movable
A short hyperlink is not a small absolute address. It is an instruction to borrow missing components from a base. That dependency let authors omit repeated schemes, hosts and path prefixes, and it let a collection of pages move while preserving its internal edges. The economy…
CASE FILE
The Chain Passed. The Header That Said So Was Unsigned
A new DKIM2 draft gives mail systems a compact way to report a verified custody chain. Its sharper contribution is the warning attached to that convenience: the report is a local, unprotected memo, not evidence that can be inherited by the next hop.
CASE FILE
The Router Set the P Flag. No Prefix Had Been Delegated Yet: RFC 9762
An IPv6 Router Advertisement can now tell a capable host to prefer a delegated prefix over another address from the shared link. That one bit arrives early enough to prevent a disruptive double start. It still cannot stand in for the DHCP exchange, the relay route or a packet…
CASE FILE
The Large BFD Packet Stayed Up. The Whole Path Was Not Proven: RFC 9764
A green BFD session can now say something useful about packet size, but only if the claim stays as narrow as the packets that earned it. RFC 9764 turns padded control traffic into a recurring lower-bound test. It does not turn one forwarding treatment into a certificate for every…
CASE FILE
The Packet Carried a Resource ID. The Path Did Not Promise to Obey
An IPv6 packet may name the resource partition it wants at every hop and still emerge without proof that every router recognized the request, used the intended queue or preserved the promised isolation.
CASE FILE
The Certificates Were Related. The Verifier Still Owned the Decision: RFC 9763
A certificate authority can attest that two credentials belong to the same end entity. It cannot make two private keys act in a live exchange, choose a peer’s trust anchors or decide whether one successful authentication is enough. RFC 9763 is valuable because it draws that line…
CASE FILE
The Cache Could Stay. The Old Answer Could Not
An NFS client may re-read a busy directory, see the same names and still tell an application that a growing file has its old size. Revision 11 of a working-group draft answers that failure without pretending to abolish caching: it limits which answer the client may expose after…
CASE FILE
The Authorization Server Said Active. The Resource Server Still Had to Decide
One green boolean can look like permission. RFC 9767 is more disciplined: `active: true` is an authorization server’s answer to a resource server’s specific question about a token, a proof method and, sometimes, minimum access. The resource server still owns the application…
CASE FILE
One Subscription, Many Publishers: The Parent Owns the Split
A collector can ask one network node for one stream of updates and receive data from several publishing processes hidden behind the same address and subscription identifier. Revision 21 of the NETCONF distributed-notification draft corrects the authority that makes this possible…
