Summary
- RFC 3208 replaced per-receiver positive acknowledgements with selective NAKs. Each NAK was confirmed hop by hop, while routers recorded the downstream branches on which the loss had been reported.
- A NAK Confirmation proved that a repair request had been handled at one point in the reverse path. It did not prove that RDATA was emitted, reached the requesting receiver, restored the packet, or completed delivery for an unknown group.
Reliable delivery is easiest to imagine as a growing pile of receipts. One sender, one receiver, one acknowledgement: the sender can keep a packet until the other endpoint says it arrived. Multicast turned that arithmetic against itself. If one transmission had thousands of receivers and every successful packet provoked thousands of positive acknowledgements, the evidence of success could consume the system it was meant to protect.
RFC 3208's Pragmatic General Multicast, or PGM, took the opposite route. It dispensed with positive acknowledgements. Sources sent sequenced Original Data packets, called ODATA. Receivers watched the sequence and spoke when something was missing. Their selective negative acknowledgements, NAKs, asked for repair. Silence meant no observed gap had produced feedback through this machinery; it did not enumerate the receivers or certify their applications.
That decision defined the promise PGM could make. It had no group-membership model. Members could join and leave without the source knowing. It was not intended for applications that required acknowledged delivery to a known set of recipients or total ordering across multiple sources. Within a source's moving transmit window, each receiver either obtained the packets from original transmission and repair or detected unrecoverable loss.
The grammar matters. The guarantee belonged to a receiver, not to a source's universal ledger. A receiver could know that it had all packets or that recovery had become impossible. The source did not thereby possess one authoritative statement about everyone.
When a receiver detected a sequence gap, it did not send its NAK straight to an abstract global source. It unicasted the request to its last-hop PGM network element on the source's distribution tree. The receiver repeated the NAK until that network element multicast a matching NAK Confirmation, an NCF, on the receiving interface.
The network element then forwarded the NAK toward the next upstream PGM element and repeated it until that upstream element returned its own NCF. The procedure continued hop by hop until the source received and confirmed the request. NCFs were multicast where they mattered, but PGM routers did not propagate an NCF as an end-to-end success message.
This created a precise receipt. An NCF said: the negative request has been observed and taken into the next stage at this hop. It did not say: the missing packet has been retransmitted. It did not say: the retransmission followed every required branch. It did not say: the receiver accepted it. Those facts belonged to later actions and later observations.
The distinction was structural. Once a network element had received a NAK, it recorded repair state: the transport session, missing sequence number, and interfaces on which the request arrived. After an upstream NCF, the element did not retain the NAK packet until repair. It discarded the request. The durable bridge to later RDATA was the repair state, not the confirmation and not the original NAK object.
Repair Data, or RDATA, could come from the original source or from a Designated Local Repairer. Routers forwarded that repair only on the interfaces recorded for the loss. This constrained retransmission to branches where someone had asked for it instead of flooding the entire multicast group again.
The default was deliberately strict. Without matching repair state, a PGM network element did not forward RDATA. A repair could exist upstream and still fail to reach a receiver if the reverse request path had not installed the required downstream state. A packet's existence and its authority to traverse one interface were different facts.
How did a router know which direction led back toward the source? PGM sources interleaved Source Path Messages, SPMs, with data. Each PGM element rewrote the path address to identify the upstream neighbour on that source's distribution tree. Receivers used the resulting path state to address NAKs. Routers used it to relay the request along the reverse of the ODATA route.
SPMs also advertised the trailing and leading edges of the source's transmit window. That window bounded what remained available for repair. If a receiver discovered a loss only after the packet fell behind the trailing edge, another NAK could not manufacture bytes the source or DLR no longer held. The failure could become detectable without becoming recoverable.
PGM strengthened negative feedback because negative feedback was its only repair trigger. Sources periodically sent SPMs even when data was quiet, giving receivers new occasions to notice gaps and updated information about the window. Receivers used retry timers. A confirmed request that produced no RDATA could lead to another repair cycle rather than being treated as completion.
At the same time, PGM had to stop negative evidence from imploding. A population of receivers might all miss the same ODATA packet. Each began a random back-off before sending its NAK. If a receiver heard a matching NCF or local NAK during that interval, it suppressed its own request and behaved as if it had sent it. Routers also eliminated duplicate NAKs once they had repair state for that loss.
The usual outcome was one NAK returning toward the source for a packet missed by many receivers. That was the scalability win. It was also an evidentiary compression. One NAK could stand for an unknown number of suppressed observations. An NCF could quiet receivers that had never individually sent a request. Neither packet was a receiver roster.
The repair subtree was likewise a projection. Its interface list said where negative evidence had arrived. It did not count the receivers behind an interface, distinguish one receiver from a hundred, or prove that every host behind the branch still participated when repair came back. It was enough state to route an attempted repair, not a census.
A Designated Local Repairer changed the physical source of RDATA without changing the transport session identity. The DLR used the original source's Transport Session Identifier on the repair. That continuity let receivers place the packet in the right sequence, but it did not mean the original source had emitted the repair. Session identity, repair custody and packet origin had to remain separate in an audit.
PGM even allowed DLR discovery and redirection, adding more receipts that could be mistaken for outcomes. A redirect could tell a receiver or router where to send a repair request. A poll response could announce a repairer's availability. Those messages established possible control paths; they did not prove the repairer retained the packet or that a later RDATA reached its destination.
The transmit window made the source's local policy visible. Under a data-driven strategy, NAKs for data near the trailing edge could postpone advancement. The source favored completeness at the cost of delay. Under a time-driven strategy, the window advanced in real time without waiting for outstanding NAKs, preserving throughput and timeliness at the cost of possible unrecoverable loss.
These were not two spellings of reliability. They encoded different decisions about what the source was willing to retain and for how long. An NCF under either strategy had the same limited meaning, while the probability that a later repair remained possible depended on the window policy.
Forward Error Correction changed the form of repair but not the evidence chain. A repair might be a copy of the missing packet or a parity packet from which a receiver could reconstruct data. A parity NCF could confirm a request for a number of parity packets. The receiver still waited for enough repair packets and still had to decode them. Confirmation of the count requested was not confirmation of successful reconstruction.
PGM's Experimental status was not decorative. Its applicability statement called congestion control, router assistance, local retransmission and a programmatic API prototypical elements. RFC 2357 had already described the criteria reliable multicast proposals should address, especially congestion responsibility. RFC 3208 supplied one large working design space, not proof that every mechanism had become a deployed standard service.
Its security section made the cost of stateful assistance explicit. False SPMs could misdirect NAKs. False NAKs could consume memory with spurious repair state. False NCFs could stop upstream request forwarding too early. False RDATA could tear down legitimate repair state and prevent real repair from traversing the branch.
The attacks followed the protocol's evidence transformations. A control packet did not need to corrupt application content to cause harm; it could corrupt the record of where loss occurred, whether a request remained outstanding, or which interface was entitled to receive repair. Full authentication of neighbouring sources, receivers, routers and DLRs lay beyond the simple message sequence.
This is why NCF must not be rendered as a checkmark beside delivery. It was a bounded acknowledgement inside the mechanism that made NAKs less likely to vanish. Its value came from saying less: this request was heard here. RDATA, receiver state and application state had to say the rest.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
