Summary

  • RFC 9084 adds an originating Router ID and a reachable Router Address to an OSPF prefix advertisement. The fields preserve who first advertised a prefix when an ABR becomes the visible advertiser, but they do not alter SPF or authorise the prefix.
  • Ketan Talaulikar is the document's editor within a five-person author group. The design is strongest where it refuses to guess: an ABR may carry only originators that contribute to its calculated ECMP result, and must omit the attributes when it cannot determine them.

A route survived; its provenance did not

Inside one OSPF area, the Advertising Router field of the link-state advertisement can identify the router originating an intra-area prefix. The relationship changes when an Area Border Router generates an inter-area advertisement. The ABR writes its own identity into the new LSA. Other areas can learn the prefix, calculate a route and forward traffic, while the ordinary record no longer says which earlier router originated the advertisement.

This is not a corruption bug. It follows the abstraction that allows an ABR to summarise and propagate information between areas. Yet the abstraction removes an answer that topology analysis, troubleshooting and traffic-engineering software may need. If several prefixes came from one node, an analyst can no longer group them reliably. If several nodes originate the same prefix, the loss is sharper: the remote area can see reachability without seeing the set of contributors behind it.

RFC 9084, published in August 2021, defines two optional sub-TLVs to carry that missing record with the prefix. Its author list is A. Wang, Acee Lindem, J. Dong, Peter Psenak and Ketan Talaulikar, with Talaulikar named as editor. The IETF Datatracker profile supplies the person-level connection to a larger routing-standards record.

The attribution must stay collective. An editor's name supports a focused article about documented participation; it does not make Talaulikar the sole inventor of the fields, the owner of IETF consensus or the controller of any implementation. The protocol's behavior belongs to the complete standard, and its result exists only when implementations and operators use it correctly.

The current advertiser and the first originator are different facts

The core distinction is temporal as well as topological. The Advertising Router field tells a receiver which router originated the LSA it is reading. The new Prefix Source fields describe the router that originated the prefix advertisement earlier in the propagation chain. Both can be correct at the same time because they answer different questions.

Conflating them makes a relay look like the original source. That mistake matters in diagnosis. An engineer may investigate the ABR because its identifier appears on the remote LSA, even though the prefix entered the area hierarchy at another router. A controller may group prefixes by the current LSA producer and infer a topology relationship that the ABR never meant to assert.

RFC 9084 repairs the missing association rather than rewriting the established field. This preserves compatibility and keeps the semantics legible: one identity belongs to the current advertisement; the optional attributes record earlier provenance. The extension does not assign blame or ownership. It gives an observer enough information to ask the next question at the correct node.

Router ID and Router Address must not be collapsed

The first new attribute is the Prefix Source OSPF Router-ID. It carries the 32-bit OSPF Router ID of the router that originated the prefix advertisement within the OSPF domain. A Router ID must be unique in that domain, but it is not necessarily an address that can be reached. Even when an IPv4 loopback address is commonly used, the standard does not let an observer assume that identity and reachability are the same property.

The second attribute is the Prefix Source Router Address. It carries a reachable IPv4 or IPv6 address of the source router and has a length of four or sixteen octets according to the prefix address family. If the originator already advertises an OSPF Router Address through the applicable mechanism, the same address must be used. Otherwise the implementation may select a unique reachable local address, for example one marked as a node address.

The split prevents a convenient number from acquiring two kinds of authority. Router ID supports protocol identity. Router Address supports reaching or associating the node for analysis. A correct ID with an unreachable address is incomplete operating evidence. A reachable address without the right originator identity can point analysis at the wrong device. Accountable tooling retains both fields and the distinction between them.

The containers on which the extension depends are themselves bounded. RFC 7684 defines the extended-prefix attribute surface for OSPFv2, while RFC 8362 supplies the extensible LSA forms for OSPFv3. They provide places for the metadata to travel. They do not authenticate the person or organisation said to control the resulting prefix.

ECMP turns one origin into a set

A prefix may be originated by more than one equal-cost node. RFC 9084 therefore allows more than one Prefix Source Router-ID and more than one Prefix Source Router Address in the parent prefix TLV. Each represents an ECMP originator.

This is a small but important refusal to force distributed reality into a single-owner field. The standard does not choose a ceremonial primary router simply to make the record easier to display. It preserves the set that contributes to the reachable result.

Multiple values also raise an operational obligation. A monitoring system must not treat the first value it parses as the complete answer. It must associate IDs and addresses carefully, preserve the advertisement context and notice when the contributing set changes. A dashboard that compresses several originators into one label can recreate the very information loss the protocol extension was designed to avoid.

The record still has a ceiling. ECMP originators explain which nodes contributed to the route calculation represented by the advertisement. They do not prove how traffic was hashed, whether every next hop forwarded successfully or which path an individual packet took. Those answers require forwarding-plane observation.

An ABR may transmit evidence only from its calculated set

The strongest rule in RFC 9084 is not the new field; it is the condition for repeating it. When an ABR propagates an inter-area prefix from the backbone into another non-backbone area, it calculates the nodes contributing to the ECMP paths for that prefix. It must use originator information only from that set.

If it cannot determine the originators contributing to the calculated paths, it must not include either source attribute. The absence can be less satisfying than a guessed name, but it is more honest. A blank provenance record says that reachability is known under the current calculation while earlier attribution is not safely derivable. A fabricated continuity of identity would turn uncertainty into false evidence.

This rule also makes propagation state-dependent. Source information learned earlier cannot be copied indefinitely without regard to the current route calculation. A node that no longer contributes to ECMP should not remain named simply because its attribute is still available in another record. The ABR has to relate provenance to the current set before advertising it onward.

For intra-area advertisements, the receiver can perform a direct check: a Prefix Source Router ID that differs from the containing LSA's Advertising Router is invalid and ignored. That check cannot be performed reliably for inter-area and external prefixes, where the identities are expected to differ. The evidence becomes more useful across the boundary precisely as direct validation becomes weaker.

Invalid values are contained, not promoted into route decisions

A source Router ID of zero is invalid and must be ignored. A source Router Address whose length does not match the prefix address family is also invalid and ignored. Both cases should be logged as errors, subject to rate limiting.

These are structural tests. They keep obviously malformed metadata out of analysis and prevent an error stream from becoming its own resource attack. They do not establish that a well-formed nonzero Router ID is truthful or that a correctly sized address belongs to the claimed originator.

That boundary is explicit in the security section. A rogue node able to inject prefix advertisements can also inject bogus source information. Because the fields are optional and do not affect the OSPF route calculation, their compromise need not change SPF directly. It can still poison a controller, troubleshooting record or operational attribution system that grants provenance more trust than the routing security context supports.

The safe consumer therefore carries confidence with the value. Intra-area agreement with the Advertising Router is stronger evidence than an inter-area field that cannot be checked the same way. Authentication of the OSPF adjacency or LSA protects a different boundary from proof of original source. A validly received record can still contain a false statement from an authorised but compromised originator.

External redistribution leaves a policy choice visible

For a prefix redistributed from another routing domain, the visible OSPF originator may be the ASBR. The actual node associated with the prefix may lie outside the OSPF domain. RFC 9084 permits implementations to control whether the Router Address represents the ASBR or the external node that owns the prefix, and leaves the detailed redistribution mechanism outside its scope.

That is not a defect to fill with an undocumented default. The two choices answer different operational questions. The ASBR address identifies the local handoff into OSPF and is often the node an OSPF operator can act on. The external owner address preserves a longer provenance chain but may disclose information outside the domain and may be harder to validate or reach.

NSSA translation has the same accounting problem. When an NSSA ABR converts a prefix advertisement to an AS-external form, it follows the inter-area propagation procedure. The translation should not erase the source silently, but neither may the translator carry a source that no longer belongs to the contributing calculation.

Operators must therefore document what the field means at each redistribution boundary. A controller cannot infer from the type alone whether the address names the OSPF handoff or a remote owner. Meaning depends on the explicit local policy that produced the attribute.

Provenance has a storage and disclosure price

Adding source attributes increases the size of the OSPF link-state database. A design that attaches two identities to every prefix, including multiple ECMP contributors, can expand both storage and flooding work. RFC 9084 advises considering that operational impact and allows deployments to choose a subset of prefixes for which origin information is needed.

Selection is therefore a governance decision. Critical infrastructure prefixes, redistributed service anchors or prefixes consumed by a traffic-engineering controller may justify the cost. Carrying the same detail for every low-value or transient record may not. The standard offers the field; the operator decides where the information gain exceeds the state and churn it creates.

Disclosure is the other side of the decision. OSPF area and domain boundaries normally abstract some internal topology. Propagating a source node beyond those boundaries can reveal which router originates a service or how responsibility is distributed. That knowledge can help repair a failure and can also expose an operational map to a wider audience than intended.

The useful question is not whether more metadata is always transparent or always dangerous. It is who receives it, for which prefixes, under which trust relationship, for how long and with what ability to revoke it. Provenance without a distribution policy can turn an accountability feature into an unbounded inventory.

A name in the LSA is evidence, not authority

RFC 9084 says explicitly that its extensions do not change core OSPF route computation. That sentence protects the architecture from a common category error. The source record can explain where a prefix came from. It does not make the prefix preferable, install it in the forwarding plane or grant the source a right to originate it.

A controller can use the metadata for topology analysis or traffic engineering, but the controller remains responsible for its decision. It must reconcile the source fields with the LSDB, the calculated route, current reachability, policy and data-plane observation. Treating the optional source attribute as an authenticated command would give descriptive metadata a power the standard never assigned.

Lu Heng's later essay on Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption gives Sofia Ren a useful lens for this design. The common layer standardises two small pieces of provenance and strict omission or rejection rules. Which prefixes receive them, which address is exposed across redistribution and how a controller acts remain local decisions.

Running-Code Primacy supplies the complementary test. A source attribute is meaningful only when it can be reconciled with the running LSDB, the ABR's selected contributor set, the reachable router, the consuming controller and the forwarding result. These Heng texts are a 2026 editorial framework, not evidence of Talaulikar's or his co-authors' private intention.

The extension matters because it restores a fact that hierarchy had hidden without claiming that the fact governs the route. The first router's name can survive the boundary. Responsibility still belongs to the people and systems that decide whether to believe it, distribute it and act.

Sources