Summary
- RFC 9779 measures each Segment List in an SR Policy candidate path through a separate session; a policy name or a returned percentage is not enough to identify the sampled object.
- A one-way result can return out of band over IP/UDP, while a two-way query can prescribe a separate MPLS return stack. The route that carries the evidence home is not automatically the route whose performance the evidence describes.
- Counters, timestamps and block numbers become defensible SLA evidence only when they remain linked to path identity, ECMP selection, responder provenance, threshold appraisal and the action that followed.
A successful response can be the start of the audit
Imagine an assurance system reporting that an SR-MPLS service met its delay target. The query was accepted, the response came back, the timestamps were well formed and the dashboard drew a green line. Yet the response travelled over IP/UDP outside the measured MPLS direction. The Segment List had several equal-cost realizations, and the stored record omitted the entropy label that influenced which one the probe used. The percentage may be arithmetically correct while the claim attached to it is not yet proved.
RFC 9779, published as a Proposed Standard in May 2025, applies the loss- and delay-measurement messages of RFC 6374 to the SR-MPLS data plane. Its wire mechanisms are precise. For an SR Policy candidate path, queries must be sent for every Segment List by creating a separate session for each one. A query carries the SR-MPLS label stack, then the Generic Associated Channel Label and header; every label-stack entry uses a TTL of 255.
That identifies a measurement procedure, not a commercial service by itself. The evidence record still needs the intended policy, candidate path, Segment List and session. If the system retains only “policy A, 7.3 milliseconds”, it has discarded the level at which RFC 9779 actually separates the work.
The outbound sample and the returning evidence are different objects
The distinction becomes explicit in the response modes. In one-way measurement, the querier can put the UDP Return Object from RFC 7876 in the query. The responder then sends the result out of band in IP/UDP to the address and port supplied by the querier. This is useful precisely because response delivery is decoupled from the MPLS direction under test.
In two-way mode, the responder should use the same incoming link or the same path in reverse when possible. But a querier can demand a specific response route with the new Return Path TLV, Type 5. Its MPLS Label Stack sub-TLV can carry a full return stack or a Binding SID. A supporting responder must process the first such TLV and send the response on the path it specifies.
None of this makes the return path suspect. It makes its role explicit. The forward path is the measured object; the response path transports the observation. An auditor who sees only that the message returned cannot infer which forward member of an ECMP set was sampled, whether the intended responder handled it, or whether the reverse transport remained representative of anything beyond its delivery task.
The Destination Address TLV helps bind the query to the intended responder. A local match can produce success; a mismatch can produce an invalid-destination result. The security section also recognises that a forged return instruction can redirect evidence. It permits rejection when the response destination is not local to the querier and points to source validation and access control. Responder identity and response reachability therefore belong in the evidence chain, not in an implementation footnote.
The numbers need names, intervals and directions
Delay measurement uses Associated Channel Type 0x000C and the RFC 6374 timestamp exchange. Loss has two modes: direct (0x000A) can provide exact accounting but may require hardware support; inferred (0x000B) is approximate. Combined loss and delay use 0x000D or 0x000E, depending on the loss mode. These codes distinguish the calculation being performed. They do not tell a customer which product, exception rule or remedy applies.
Direct loss also depends on associating received traffic with the intended session. RFC 9779 uses a Path Segment Identifier, with scope that can correspond to an SR Policy, candidate path or Segment List. The PSID design itself is specified in RFC 9545, while RFC 9714 supplies an encapsulation for alternate-marking measurement. They provide adjoining machinery; they do not collapse the identities into one.
Block Number makes the loss record more auditable. The querier divides traffic into consecutive blocks, keeps transmit counters, and exchanges counters for the prior marking after those counters have stopped changing. The responder keeps the corresponding receive counts. RFC 9779's Type 6 TLV carries an eight-bit block number, and its R flag distinguishes the query-side forward counters from the response-side reverse counters. The responder's block can be synchronized from LM queries, so the procedure need not depend on synchronized clocks.
But the standard deliberately leaves block-number assignment as a local decision. A block can correlate two counter sets; it cannot decide whether a maintenance interval is excluded, whether the flow represents the contracted service, or who is entitled to declare a breach. Those are appraisal and authority questions layered on top of measurement.
ECMP turns provenance into a first-class field
An SR-MPLS Segment List can resolve across equal-cost paths. RFC 9779 says different entropy-label values can influence the forwarding hash so that delay queries and responses traverse different ECMP paths. It also states that loss measurement for different ECMP paths is outside its scope.
That boundary matters. A system may honestly measure one delay realization and still overstate the result as evidence for the entire Segment List. It may also collect a loss figure whose ECMP representativeness the RFC never promised. The defensible record carries the entropy value or equivalent selection context, topology and policy version, and the precise scope of the conclusion. “No packet loss observed” is weaker than “no packet loss observed for this identified session, block and path selection during this interval”, but the second sentence can survive an audit.
RFC 9779 allows measured link delay and loss to be turned into extended traffic-engineering metrics advertised through OSPF, IS-IS or BGP-LS. That is a path from observation to a control input, not an instruction to reroute. Freshness, confidence, thresholds, oscillation controls, rollback and the owner of the decision remain local responsibilities.
The Datatracker record establishes the standards document and its history. Neither it nor the RFC establishes named deployments, vendor support or an operational outcome. Those unknowns should remain unknown rather than being filled with the authority of a standards number.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
