Summary
- The RTGWG's 25 September QoS-model revision 16 remains an Internet-Draft, not an approved RFC. Its proposed YANG model describes hierarchical traffic policies.
- A
child-policythat previously accepted an arbitrary string now uses aleafrefto the configured policy-name list. A separatemustrule rejects a policy naming itself. - The draft also says implementations must reject cyclic chains. That last requirement is not automatically satisfied by finding a valid immediate target: A→B→A has two existing targets and still loops.
A reference is not a path
The earlier revision 15 made child-policy a string. The August Security Area review marked that draft “Not ready” and noted that a name could designate no policy at all, or participate in a cycle. Those were model-level questions, not evidence of a network failure or a vulnerable product.
In revision 16, the child leaf instead refers to /traffic-policy:policies/traffic-policy:policy/traffic-policy:name. Under ordinary YANG 1.1 semantics, that constrains the named target's existence. A new local condition prevents the containing policy from citing its own name. The draft's description then separately directs implementations to reject configurations that create cyclic policy chains. The three protections have different scopes: target existence, direct self-reference, and the graph formed by multiple policies.
That separation is the news. A validator that checks every reference independently could accept both A→B and B→A; neither name is missing and neither policy points directly to itself. A system must inspect the chain as a whole to discharge the draft's cycle requirement. Hierarchical policies influence classification, queuing, marking and dropping of traffic, so whether a management system accepts a finite hierarchy is operationally more consequential than whether a label merely resolves.
Security language also changed, but asks a different question
Revision 16 marks the statistics clear action nacm:default-deny-all and substantially expands Security Considerations. NACM concerns authorization of management operations; it does not prove the policy graph is acyclic. Nor does a fuller risk inventory prove deployed controls. The Datatracker reports zero YANG validation errors and six warnings for this draft. That is useful syntax feedback, not an IESG approval or a verdict on every implementation.
Sources
- https://datatracker.ietf.org/doc/draft-ietf-rtgwg-qos-model/16/
- https://www.ietf.org/archive/id/draft-ietf-rtgwg-qos-model-16.txt
- https://www.ietf.org/archive/id/draft-ietf-rtgwg-qos-model-15.txt
- https://datatracker.ietf.org/doc/review-ietf-rtgwg-qos-model-15-secdir-lc-jain-2026-08-02/
- https://www.rfc-editor.org/rfc/rfc7950.html
- https://www.rfc-editor.org/rfc/rfc8341.html
- https://www.rfc-editor.org/rfc/rfc2475.html
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

