Summary
- The current MPLS STAMP draft relies on locally provisioned session state at both endpoints and leaves STAMP-specific VCCV signalling outside its scope.
- A returned test packet proves a bounded exchange, not a durable bilateral record of the path, mode, clock, rate, service and decision purpose the two configurations were meant to share.
The revealing line is not in a packet diagram. It appears in the architecture: the mechanism that terminates a STAMP test packet for an LSP or pseudowire is locally provisioned at both ends. A nearby sentence places signalling extensions for STAMP over the pseudowire VCCV Control Channel outside the document. For an LSP, where that VCCV signalling has not been defined, local provisioning is described as the only presently viable option.
This is not a flaw disguised as standards prose. Local configuration is often the right boundary inside one operator’s network. It keeps business identifiers, customer policy and operational authority out of a measurement packet. But it creates a second object that the wire exchange cannot supply: evidence that the sender and reflector were configured as two halves of the same measurement decision.
A protocol exchange and a configuration agreement are different objects
RFC 8762 defines a STAMP session as a bidirectional packet flow between one sender and one reflector for a period of time. It deliberately leaves configuration and management outside scope. A command line, an OSS/BSS platform, SNMP or a NETCONF/YANG controller might create the state. The reflector then acts according to that state, in stateless or stateful mode and with authenticated or unauthenticated packets.
RFC 8972 adds the STAMP Session Identifier. A supporting reflector must be provisioned before a test with all the elements that identify a session, and it must discard packets that do not match. The means of provisioning remains outside that specification. The MPLS draft tightens the rule for its own environment: the SSID is non-zero and travels in both directions.
The identifying material changes with the encapsulation. Format-1 retains IP and UDP. The sender and reflector use the relevant address, destination port and SSID together with locally provisioned parameters. Format-2 removes the IP/UDP header. There, the SSID must be joined to the forward or reverse LSP or pseudowire context and the local parameters. The packet carries enough information to be associated with state; it does not carry the state itself.
That distinction matters because the same SSID can be surrounded by very different operational claims. One endpoint may associate a session with a customer pseudowire while the other associates it with a maintenance view of the underlying transport. Both may choose the same packet format yet use different alert thresholds. They may agree on the path and disagree on whether the reflector is stateful. Their clocks may be synchronized to sources with different holdover quality. A reply cannot enumerate all of those intentions.
The pseudowire already negotiates something—but not everything
It would be inaccurate to say that pseudowire VCCV has no signalling. RFC 5085 provides capability advertisement for Control Channel and Connectivity Verification types. The two provider edges advertise supported combinations, select a common type and continue to use it until the pseudowire is signalled again. RFC 7708 adds the GAL-based Type 4 option and selection rules when several types are available.
The MPLS STAMP draft reuses these control-channel mechanisms to get a test packet out of the forwarding path and into endpoint control-plane processing. It clarifies that exactly one such exception mechanism is in effect for a session. It also separates exception from identification. A TTL condition or GAL can stop ordinary forwarding; the following G-ACh type says whether the payload includes IP/UDP or carries STAMP directly.
This existing VCCV agreement is valuable evidence. It can show that the endpoints found a compatible control-channel capability. It does not, by itself, negotiate the complete STAMP session: SSID policy, chosen header format, LSP or PW context, addresses and ports, authentication and reflector mode, optional TLVs, packet size, test rate, clock source, service association or permitted downstream use. The draft’s own local-provisioning language preserves that boundary.
The right conclusion is therefore narrower than “nothing was agreed.” The network may contain several agreements at different layers. The governance problem appears when a control-channel capability, a returned packet and a local service record are collapsed into one undocumented claim that “the measurement was configured correctly.”
What a successful reply actually supports
Suppose a sender receives a well-formed reply with the expected non-zero SSID. That is evidence that a packet left the sender, traversed a usable forwarding context, was excepted and identified at a reflector, and came back under enough compatible state to be processed. Depending on mode and validation, it may support delay, variation or loss calculations. That is already useful.
The reply does not reveal who approved the session, which configuration generations were active, whether both ends mapped the session to the same service, or whether the operator intended the measurement to support troubleshooting, capacity engineering or an SLA decision. It cannot show that the clocks met an agreed accuracy envelope. It cannot prove that an alert threshold was shared, that the test rate complied with an operational budget, or that the association survived a later change at one endpoint.
Nor does the new single-administrative-domain statement close the gap. One network domain can contain different teams, controllers, vendors, configuration stores and change windows. “One operator” is an authority boundary, not proof of transactional configuration consistency.
This is an evidence-boundary problem, not an argument against STAMP. A standards document should not be forced to transport every commercial or organizational fact. The packet is most interoperable when it carries the minimum necessary technical state. The richer agreement belongs in a protected local record joined to the packet-level evidence.
A bilateral measurement-configuration receipt
The missing object can be compact. A bilateral measurement-configuration receipt should record the sender and reflector identities, administrative domain, LSP or pseudowire and direction, selected exception mechanism, STAMP header format, G-ACh type and SSID. For Format-1 it also binds the relevant addresses and ports; for Format-2 it binds the forward and reverse path context used to identify the session.
The receipt then records the semantic configuration: stateful or stateless reflector, authenticated or unauthenticated mode, TLV set, clock source and synchronization evidence, packet size and MTU allowance, transmit rate, expected reverse-path capacity, service association, observation objective and the class of decision allowed to rely on the result. Those fields need not travel in every test packet. They need a common identity and time.
Both endpoint configuration generations should be represented by hashes or immutable version references. The record should name the controller or operator that supplied each side, the reviewer who accepted the pair, the tests used to establish compatibility, and the moment the agreement expires. A later change to either endpoint opens a new receipt; it does not silently inherit the old one.
The receipt should also distinguish evidence classes. “VCCV capability selected” is not “STAMP parameters matched.” “Reply received” is not “clocks within policy.” “Metric computed” is not “customer service met its objective.” A downstream system can then rely on the strongest completed class without borrowing authority from the rest.
This proposal is not an IETF extension. It adds no new field, registry or signalling requirement. It is operator-side governance for facts the protocol intentionally leaves local.
Failure can look cleaner than disagreement
An explicit mismatch is often the easier case. A reflector discards a packet it cannot associate with a session; a management alarm points toward missing state. The harder case is partial agreement. The endpoints align on enough identifiers to exchange packets but disagree on a fact that the wire does not expose.
A stateful reflector replaced by a stateless configuration can still answer while changing which loss inference is available. An authentication-mode change can alter the trust afforded to the result. A new path association can preserve the SSID while moving the measurement away from the service a dashboard still names. A clock-source degradation can leave clean-looking timestamps whose uncertainty no longer satisfies the intended decision.
These are scenarios, not claims about deployed systems. The source set contains no incident, vendor defect or interoperability census. Their value is to show why packet success cannot serve as a hash of the complete bilateral configuration.
Sources
- Current MPLS STAMP draft, history and Datatracker API record
- Revision 21 HTML, plain text, XML and revision 20–21 comparison
- IESG ballot record, shepherd write-up and MPLS Working Group
- RFC 8762: STAMP and RFC 8972: STAMP extensions
- RFC 5085: VCCV, RFC 7708: GAL as a VCCV channel and RFC 5586: Generic Associated Channel
- RFC 7799: Internet measurement terminology, Minimum Initial Specification and The Policy Mirror
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
