Summary

  • draft-many-lsr-power-group-04 proposes IS-IS advertisements for Power Groups, Power Savings Potential, sleeping adjacencies and sleeping LAG bandwidth. They populate a traffic-engineering view; they do not operate the hardware.
  • The companion power-transition draft requires a resource-specific transaction, agreement by both endpoints, separate local power-manager actions, retained TE state and a wake path that does not depend on the sleeping resource. A request or acknowledgement is not physical completion.
  • Before traffic is admitted to a formerly sleeping link, an operator needs fresh receipts for both endpoints, restored adjacency or liveness, current reservations and usable capacity, path installation, packet forwarding and the service result.

At 02:00, a controller sees a LAG with 80 Gbit/s of “sleeping bandwidth”. Its path engine has also retained the dormant adjacency and a large Power Savings Potential. Demand jumps. The controller asks for a member to wake, receives a protocol acknowledgement and admits a 60 Gbit/s flow.

The facts on the screen are individually plausible. Together they still do not establish a usable path. One endpoint may remain in Pending. The remote member may have reset, making part of its mapping unresolvable. The 80 Gbit/s figure may describe maximum component bandwidth that was put to sleep, less RSVP-TE allocations, rather than capacity freshly proved ready for this flow. The retained adjacency may be precisely the record of a resource that cannot yet carry a packet.

This is an analytical scenario, not a documented outage. It exposes the boundary in revision 04 of the IS-IS Power Group draft: a control plane can remember a sleeping resource without possessing a completion receipt for its physical state or its return.

A vocabulary for keeping unavailable resources visible

The draft proposes two top-level TLVs. A Power Group TLV advertises a node-local group identifier, a Power Savings Potential in milliwatts and a node-local parent identifier. A Sleeping Adjacencies TLV embeds complete IS-IS reachability TLVs so an adjacency can remain in the link-state database while it is unavailable for ordinary forwarding.

It also proposes four interface facts: membership in one or more Power Groups, an interface PSP, unidirectional sleeping bandwidth for a non-sleeping LAG, and a Power-Sleep Capable bit in the Link Attributes sub-TLV defined by RFC 5029.

Those fields answer useful but bounded questions:

Record What it can say What it cannot say alone
Power-Sleep Capable bit This link may be eligible for low-power operation The operator authorized a transition or hardware changed state
Interface or group PSP An asserted difference between awake and asleep consumption Watts actually saved in this interval
Sleeping adjacency The originator reports an adjacency as sleeping and retains its identity Both endpoints completed the same transaction or can now wake
Sleeping LAG bandwidth A defined aggregate of dormant component capacity Fresh forwarding-ready capacity after wake
Authenticated LSP The advertisement came through an authenticated IS-IS relationship An authorized originator measured or configured every value correctly
Recomputed path The calculator found a candidate under one policy version The data plane installed it or packets reached the service

The table is the article's central discipline. A standard field can preserve a claim without enlarging its authority.

The current LSP set is a versioned evidence surface

Power Group identifiers do not name global assets. They have meaning only inside the originating Intermediate System. Parent zero means a root. A nonzero parent that cannot be resolved is processed as a root. A cycle invalidates every group in that cycle for path computation.

Duplicates also require stateful judgment. Identical entries for one originator and IS-IS level collapse to one. Entries with the same identifier but different PSP or parent values are all ignored. The receiver must apply that rule across every LSP fragment and every occurrence in the complete current LSP set.

Revision 04 says the originator should update affected fragments as an atomic flooding operation where possible. “Where possible” matters. During convergence, a receiver can see mutually inconsistent fragments. The prescribed response is not to pick the newest arrival or a convenient order; it is to invalidate the affected group until the current set becomes coherent.

The same conservatism appears in sleeping adjacency handling. If the current set advertises an adjacency both sleeping and non-sleeping, sleeping wins. If an embedded reachability TLV is truncated, the whole containing Sleeping Adjacencies TLV is ignored. If the remote endpoint resets, the advertisement may be retained, but fields that can no longer be resolved must not participate in path computation until the remote node advertises again.

These are not parsing footnotes. They define when the database is allowed to become decision evidence. Store the originator, IS-IS level, LSP identifiers and sequence numbers, fragment set, effective interval, validation branch and invalidation reason. A flat export saying sleeping=true throws away the custody needed to reproduce the decision.

A LAG aggregate is not a member-level wake certificate

The draft's LAG treatment contains a particularly important loss of granularity. One L3 LAG can belong to several Power Groups, yet the Power Group Member sub-TLV does not identify which physical member connects the LAG to each group. The unidirectional sleeping-bandwidth field is an aggregate: it sums the maximum bandwidth of sleeping component links and excludes bandwidth already allocated to RSVP-TE LSPs.

That number is neither a live interface counter nor a promise that any particular member can return on demand. It says how much defined component capacity is currently represented as asleep under one originator's view. A 100 Gbit/s member that has awakened electrically but has not re-established adjacency, reconciled reservation state or entered the usable LAG set is not 100 Gbit/s of newly available service.

The field is directional, encoded as an IEEE 754 binary32 value in bytes per second, and invalid for a non-LAG interface. NaN, infinities and negative values are rejected. Conflicting copies for the same interface are all ignored. Those safeguards protect the syntax and consistency of the advertised quantity. They do not measure hardware readiness.

RFC 5305 provides the traffic-engineering bandwidth context on which the draft builds. RFC 5120 supplies multi-topology context. Neither turns an aggregate stored in the Traffic Engineering Database into a member-level postcondition.

Path placement and physical transition have different principals

The PCPPS companion draft describes a path strategy that concentrates traffic during low demand. Ordinary computation excludes sleeping adjacencies. If no path exists, the calculator may consider a path containing one, ask a separate sleep-management component to wake it, then retry computation with the newly awakened adjacency.

The sleep manager is explicitly outside that document's scope. That separation is healthy: the path calculator owns selection, not power electronics. It also means wake_requested cannot be stored as link_available.

The newer power-transition framework makes the boundary concrete. A transition is resource-specific and distributed. The endpoint roles apply to one transaction. Preparation moves through Requisition and Ready. The final sleep instruction moves the sender to Pending. Sleeping means the coordinated transition completed; the text says success must not be reported merely because a sleep request was sent.

Physical power control remains implementation-specific. Each endpoint has its own local power manager. Wakeup independently restores local state at both ends. Its request must travel over a path that does not depend on the sleeping resource. Link identity, addressing, TE attributes, parallel-link disambiguation, reservations, labels, protection state and a control-plane wake route must survive the sleep interval.

There are therefore at least nine records, not one green indicator:

  1. provenance for capability, PSP, group parentage and sleeping bandwidth;
  2. authenticated current-LSP-set receipt and validation;
  3. the time-bounded TED projection;
  4. the exact path-computation policy and decision;
  5. the resource-specific two-endpoint transaction;
  6. each endpoint's local physical completion;
  7. preserved identity, TE state and independent wake reachability;
  8. wake, both-end readiness, adjacency/liveness and refreshed capacity;
  9. installation, packet forwarding, measured energy and service outcome.

No earlier record may impersonate a later one.

Authentication protects authorship, not physical truth

RFC 5310 provides cryptographic authentication for IS-IS. Revision 04 recommends using appropriate authentication because false or replayed power data can concentrate traffic on insufficient capacity, select sleeping resources or provoke repeated transitions.

The draft also states the limit: authentication does not stop an authorized but misconfigured router from advertising incorrect information. The distinction is decisive. An HMAC can show that a recognized control-plane participant originated the LSP. It cannot show which sensor, configuration row or hardware API produced the PSP; whether the value is current; whether both endpoints agree; or whether the physical relay changed state.

This is why access to power-management parameters must be restricted and why accepted advertisements still need provenance. A safe record includes source class—hardware observation, administrative setting or derived value—plus calibration or configuration version, collection time, originator, signing context and later readback.

RFC 5880 supplies one possible liveness signal after wake. Even a healthy BFD session proves a bounded bidirectional forwarding condition, not restored reservation capacity, intended LAG membership, energy savings or application success. The receipt chain still must continue.

Publication is not deployment

The Datatracker record shows revision 04 as an active individual Internet-Draft, candidate for the LSR Working Group, with a call for adoption issued. Its formal Datatracker status fields do not make it an adopted working-group document or RFC. The document history records revision activity, not implementation or interoperability.

The draft requests several TBD IANA values. Those numbers and the text can change. Its companion PCPPS and power-transition documents are also active drafts. This article therefore makes no claim about shipping products, operational prevalence, real power savings or a recorded incident.

RFC 1195, RFC 5029, RFC 5120, RFC 5305, RFC 5310, RFC 5880 and RFC 8570 provide established IS-IS, TE, authentication, liveness and policy-metadata context. They do not pre-approve the proposed power-control semantics.

Make the wake postcondition explicit

Before ordinary traffic enters a formerly sleeping resource, require a joined postcondition: the requested resource identifier still names the same parallel link or LAG member; both endpoints report local Operating/readiness state; the physical managers report completion; the adjacency and, where used, liveness return; the current LSP set is coherent; group mappings resolve; reservations and protection state reconcile; a fresh usable-capacity view supports the proposed flow; the forwarding entry is installed; and packet or service evidence confirms the intended effect.

If any element is missing, the correct state is wake_unverified, not available. Keep the prior safe path until the join completes. If no independent control path remains, do not let the resource sleep in the first place.

Running-Code Primacy puts execution before institutional or symbolic labels. Power detached from liability supplies the governance question: who can command the transition, and who bears the loss if the capacity does not return? The Stability Fallacy keeps the continuity of the running service above the continuity of a control-plane story.

An LSDB can remember a sleeping link. It cannot wake one.

Sources