Topic
Software Lifecycle and Lock-in
Within the Topic facet, Software Lifecycle and Lock-in topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

History
The Requirement Was Firm. The Host Was Still Not Configured: RFC 1127
A capitalized MUST can settle an argument about software. It cannot reach into a machine room and choose a live value. In 1989, the Host Requirements effort made Internet interoperability more explicit by separating firm duties, reasoned recommendations and genuine options. RFC…
CASE FILE
The UDP Payload Was Protected. The Option Was Not: RFC 9868
RFC 9868 gives UDP a place for transport options. It does not place that option area inside the UDP user data that DTLS protects, turn an option checksum into a security decision, or prove that an endpoint, path or application acted on an option.
CASE FILE
The Client Sent the Bytes. The New Protocol Had Not Accepted Them: RFC 9931’s Optimistic-Transition Boundary
An HTTP/1.1 client can make a transition look nearly complete before the party that must interpret it has accepted anything. RFC 9931 is valuable because it refuses that compression: a request may be finished, a client may offer early bytes, and the server may still reject the…

History
The Line Was Complete. The Command Had Not Run: RFC 1116 and Telnet Linemode
In character-at-a-time Telnet, a typist could wait for the network to see each key return. Linemode made the nearby terminal feel immediate: editing and echo could happen before the line crossed the path. That improvement also created a durable evidentiary trap. The completed…
CASE FILE
The Cursor Continued the List. It Did Not Continue the Right: RFC 9865
RFC 9865 gives SCIM a cleaner way to traverse a long result set. It does not convert a continuation value into a portable permission, a complete inventory, or a decision already made.
CASE FILE
The Inventory Found the Algorithm. It Did Not Migrate the System: RFC 9958 and Cryptographic Agility
An organisation can catalogue every algorithm name it knows and still be unable to say which cryptographic path protects a consequential transaction. RFC 9958 makes the inventory indispensable. It does not allow the inventory to pronounce a migration complete.

History
It Worked at NASA. That Did Not Make It Safe for the Internet: RFC 1106 and RFC 1110
June 1989 produced an unusually honest sentence in protocol history: two experimental TCP extensions had been implemented and shown to work using NASA resources. Two months later, another RFC explained why one of them still could not be adopted for the general Internet. The test…
CASE FILE
The Color Reached PCEP. It Did Not Reach the Service: RFC 9863
RFC 9863 lets PCEP carry a color for a TE path. That is useful coordination data. It is not a guarantee that a service was mapped, a latency objective was met, or a customer received a result.
CASE FILE
The UUID Sorted. The Event Was Not Proven: RFC 9562 and the Boundary Between Identifier Order and Evidence Time
At 14:03, a review screen puts two rows in an immaculate order. The smaller UUIDv7 belongs to `reversal-requested`; the larger one belongs to `reversal-completed`. It looks like a ready-made account of what happened. But the first identifier may have been allocated before a…
CASE FILE
DNS Received the Hint. The Parent Still Had to Decide: RFC 9859’s Delegation Boundary
RFC 9859 can make delegation maintenance faster. It cannot make a notification into a parent-side decision, or turn a received response into proof that DNSSEC or delegation state has changed.
CASE FILE
The Router Repaired the Path. It Did Not Restore the Service: RFC 9855 and TI-LFA’s Local Boundary
A router can react to a directly attached failure in milliseconds and still know nothing about whether a customer service has recovered. RFC 9855 gives Segment Routing deployments a disciplined way to precompute and activate a loop-free repair path at the Point of Local Repair.…
CASE FILE
The Collector Received a Delay. It Did Not Receive a Verdict: RFC 9951
At 09:17, a collector receives a Flow Record with a mean delay, a maximum delay and an identifier for the transit point that exported them. By 09:20, someone wants the record to settle three larger questions: whether a customer suffered, whether a path changed, and which team…
CASE FILE
The Resource Named Its Authorization Server. It Did Not Grant a Right: RFC 9728’s Discovery Boundary
A resource can accurately publish where a client should look next and still have made no decision to let that client do anything. RFC 9728 gives protected resources a disciplined way to publish OAuth metadata. Its value is coordination: it narrows a discovery problem. It is not…
CASE FILE
The Authorization Conversation Was Still Pending. It Was Not an API Right: GNAP’s Continuation Boundary
A client can be entitled to continue an authorization conversation without being entitled to call the API it asked about. RFC 9635 makes the distinction unusually explicit: a continuation credential advances one grant request at the authorization server; a resource right appears…

IETF
Adrian Farrel and the Implementation Receipt That Disappeared Before Publication
One of the most useful sections in an Internet-Draft is written with an expiry condition. It can name the code, version, coverage, licence, test contact and interoperability evidence that made a proposal real. Then, if the proposal becomes an RFC, the section is supposed to…
CASE FILE
After a Reboot, “Secure” Must Not Mean “Resume”: RFC 10021 and Group OSCORE Recovery
A controller can regain a safe cryptographic footing after a power loss without regaining permission to continue the process it interrupted. RFC 10021 makes that distinction operational: restore the security context first; decide separately whether anything should resume.

Story
RIPE Rebuilt LatencyMON. A Chart Still Needs Its Own Interpretation Receipt.
RIPE NCC has rebuilt LatencyMON, the RIPE Atlas view used to compare latency trends across probes. The update makes a great deal more of the measurement surface visible: more test types, a choice of grouping logic, an option to reach beyond the aggregated time range and a…
CASE FILE
The Benchmark Found a Limit. It Did Not Grant a Capacity Claim: RFC 9971
A network benchmark often arrives in a meeting as a single number. That number then begins doing work it was never designed to do. It is used to imply that a cloud function has production headroom, that a supplier has met an obligation, that a release is safe, or that a customer…
CASE FILE
The Hybrid Signature Arrived. The Verification Rule Still Had to Be Chosen: RFC 9955
Two signature components can travel together without forcing every receiver to treat them as one indivisible verification event. RFC 9955 makes the distinction useful: a hybrid artifact records a design choice; the receiver's verification rule still decides what was actually…

IETF
Qin Wu and the Registry Rule That Had to Catch Up With Practice
The same YANG module name appears three times in IANA’s register, attached to three dates and one XML namespace. That is not a uniqueness failure. It is the evidence needed to distinguish a stable identity from the revisions that change inside it.
