Summary
- RFC 8379 addresses a directional blind spot in OSPF maintenance. Raising the metric at one endpoint discourages traffic originated toward that endpoint's advertised edge, but it does not change the neighbour's separately originated reverse path.
- The standard adds a zero-length Graceful-Link-Shutdown marker, rules for identifying the matching edge, and a distributed response from the remote endpoint and routing consumers. The marker communicates intent; only state from both ends, traffic observation, and successful restoration can prove the drain.
Analysis
One circuit, two routing statements
The dangerous sentence in a maintenance plan is often the shortest: “set the metric to maximum and wait.” It sounds complete because the physical object is singular. There is one fibre pair, one logical adjacency, one ticket and one engineer preparing to touch it. OSPF's account is different. Router A originates its cost for reaching Router B; Router B originates its own cost for reaching Router A. Changing the first statement does not rewrite the second.
RFC 8379, published on the Standards Track in May 2018, begins from precisely this asymmetry. Its authors are Shraddha Hegde, Pushpasis Sarkar, Hannes Gredler, Mohan Nanduri and Liliya Jalil. Their mechanism is called OSPF Graceful Link Shutdown. The name matters: the target is one link, not necessarily the whole router, and graceful means diverting traffic in both directions while leaving the link available as a last resort when no alternative exists.
That attribution supports a person-centred account without turning collective standards work into biography. The IETF Datatracker profile for Hannes Gredler documents his participation. It does not make him the sole inventor, owner of an implementation, or authority over any operator's change. The RFC is an IETF consensus document whose consequences depend on co-authors, review, code, configuration and real networks.
The two-sided problem is more than neat protocol theory. A supposedly drained circuit can still carry return traffic. That creates a maintenance window in which the operator's dashboard may show the intended outbound shift while inbound packets continue to cross the equipment about to be disturbed. The link-state view can be internally consistent and still encode a maintenance outcome that is only half complete.
A marker says why the metric changed
RFC 8379 introduces a Graceful-Link-Shutdown sub-TLV. For OSPFv2 it is Type 7 with Length 0, carried in an area-scoped Extended Link Opaque LSA. For OSPFv3 it is Type 8 with Length 0 in an E-Router-LSA. A BGP-LS Graceful-Link-Shutdown TLV, Type 1121 and also Length 0, can expose the same link property to external consumers.
Zero length is a useful discipline. The marker does not carry a maintenance ticket, start time, duration, traffic count or approval. It says that the advertising router intends a graceful shutdown of the identified link. It gives a neighbour or controller a reason for a state transition that would otherwise be ambiguous: high metrics can result from many policies and failures, whereas an explicit marker distinguishes impending maintenance.
The initiating router must advertise the marker and reoriginate the relevant state. It must set the ordinary link metric to MaxLinkMetric, 0xffff, and should set the TE metric to 0xffffffff where applicable. Those values make the link unattractive without deleting it. If no alternate route exists, the path may remain usable. Graceful drain is therefore not equivalent to administrative removal; it preserves a last-resort route by design.
The separation between signal and action protects local authority. The originator states its intent and changes the costs it owns. The far endpoint changes the reverse-direction cost it owns. A controller or TE head end applies its own constraint policy. The common field does not become a remote command merely because several systems understand it.
The far endpoint must find the same edge
On a point-to-point link, a supporting neighbour that receives the marker must identify the corresponding local link, raise its own metric to MaxLinkMetric, and reoriginate its Router-LSA. In a multi-topology deployment, it should change the reverse-direction metric for every topology that contains the link. TE metrics follow their own advertisements. The desired result emerges from coordinated local state, not from one router mutating its neighbour.
Identification is the hard part when two routers share more than one link. For parallel numbered links, the Remote IPv4 Address sub-TLV can identify which remote interface corresponds to the advertised local interface. For parallel unnumbered links, Local and Remote Interface IDs serve that purpose. A signal without a stable edge identity could make the wrong circuit expensive and leave the intended circuit carrying traffic.
Other interface models need different treatment. On broadcast and NBMA networks, simply raising one remote link metric can affect paths involving other neighbours, so RFC 8379 relies on the two-part metric procedures defined elsewhere. Point-to-multipoint and hybrid interfaces require each relevant remote node to locate the matching neighbour and reoriginate its own metric state. The standard supplies a common intention but refuses to pretend that every adjacency has the same topology.
This is where the mechanism earns its operational seriousness. It does not collapse a physical cable, a routing edge and an interface identifier into one convenient noun. It names the evidence required to show that both endpoints are talking about the same thing.
Compatibility can preserve the risk
The extension is backward compatible in a narrow protocol sense. A router that does not implement the marker can ignore the unfamiliar sub-TLV and continue operating. There need not be a loop merely because one endpoint understands the new signal and the other does not.
But continuity is not completion. An older far endpoint may continue advertising and using its ordinary reverse-direction metric. The initiating side can make its own direction unattractive while the neighbour still sends traffic over the circuit. The adjacency survives; the maintenance objective does not.
That distinction should change how support is reported. “RFC 8379 accepted” is not the same as “both directions drained.” Useful evidence includes the marker originated on the intended link, the corresponding marker received by the intended neighbour, the neighbour's reverse metric change, every relevant topology, the view exported through BGP-LS where used, and measured traffic in both directions. Compatibility describes parser behaviour. Safety depends on the running result.
The comparison with RFC 6987 sharpens the scope. RFC 6987 uses MaxLinkMetric to discourage transit through a router while retaining reachability to that router. RFC 8379 addresses a narrower link property, including cases where an overlay cannot see the maintenance state of the underlying node. Whole-router isolation and individual-link drainage can share a metric value without expressing the same intention.
Restoration is another distributed transition
Maintenance does not end when a command reports success. When the originator withdraws the graceful-shutdown marker or purges the LSA, a supporting remote endpoint must restore the original metric values and reoriginate the appropriate state. The initiating endpoint, neighbour, topologies, TE consumers and traffic should converge back to the intended service condition.
This reverse transition deserves the same evidence as the drain. A stale maximum metric can strand traffic on a longer or more expensive route long after the physical work is complete. A stale marker can keep a controller in maintenance policy. Restoring one endpoint while leaving the other expensive produces the mirror image of the original one-sided mistake.
The RFC does not provide a record of successful deployment, convergence time, packet loss or vendor coverage. It specifies behaviour and interoperability expectations. No responsible reading can turn that into a claim that a particular network drained safely. The standard tells an operator what states should be observable; the network must supply the proof.
Minimum agreement, local action, running evidence
Lu Heng's later essay on Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption offers Sofia Ren a useful interpretive lens. RFC 8379 shares a small vocabulary for link identity and maintenance intention. Each endpoint retains control of its originated metrics. Controllers retain policy. Operators decide timing, acceptable fallback and whether a missing alternate path justifies keeping the link as a last resort.
This comparison is an editorial reading from 2026, not a claim about the authors' private philosophy. The normative force remains in the RFC and the collective IETF process.
Running-Code Primacy supplies the harder test. A marker is stronger than an informal note because independent systems can parse and act on it. It is weaker than observed forwarding. The trustworthy sequence is declaration, matching, local response, routing convergence, traffic verification and clean restoration.
Hannes Gredler's place in this record is therefore not a story of central control. It is a lesson in how little common machinery may be enough when every actor's boundary remains visible. The marker coordinates; the endpoints decide; the traffic reveals whether the agreement worked.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
