Summary

  • RFC 3479 gave protected LDP operations per-session sequence numbers and cumulative ACK frontiers so two peers could identify what had become durable before their TCP connection failed.
  • Reconnection replayed the uncertain suffix, checkpoints flushed the durable prefix, and a three-message Cork exchange was needed to stop both directions at one controlled boundary.

A reliable TCP stream had been doing more work for LDP than merely carrying bytes. Its continuity let each peer assume that label operations arrived in order. When that stream failed during a control-plane switchover, the new connection could not reveal which old messages had crossed the fault, which had been processed, or which had reached durable storage. RFC 3479 approached that uncertainty as a ledger problem.

The document first negotiated the scope of that ledger. The FT Session TLV's S bit enabled sequence-numbered protection for selected label operations. The A bit could require it for every label. The C bit selected checkpointing and could operate without S. These choices were not cosmetic capabilities. They decided which messages entered the recoverable history and therefore which conclusions a later ACK could support.

For a Sequence Numbered FT Label, a sender placed an FT Protection TLV on each relevant LDP message and advanced a sequence number local to that session. The receiver had to secure either the message or the state derived from processing it before returning an FT ACK. The standard deliberately left the representation open. One implementation might retain the message; another might store the resulting label state. Durability was required, but identical storage architecture was not.

ACKs were cumulative. A peer that had secured operations one through four could acknowledge four once, rather than emit four separate replies. That made the number a frontier: everything at or below it was within the secured prefix. Nothing above it was covered. ACKs could be delayed and accumulated, duplicates were acceptable, and out-of-order ACKs were forbidden because they would destroy the meaning of the prefix.

The unresolved suffix mattered only when the connection broke. On the replacement session, each peer advertised the last FT sequence it had secured. Messages sent beyond that point were re-issued and processed as though received for the first time. Recovery did not recreate the vanished TCP transcript. It compared the two durable frontiers and reconstructed the operations whose fate remained uncertain.

RFC 3479 allowed a narrow compression. A Label Request followed by its Label Abort, or a Label Mapping followed by its Label Withdraw, could form a net-zero pair that did not need to be replayed. But the optimization had an evidence boundary. Operations already sent before failure could not be folded merely because the local queue contained their opposite. The sender first needed the peer's ACK to know which half, if any, had crossed the broken session.

Address state joined the protected history for the same reason. Without secure Address and Address Withdraw operations, a reconnect could leave each side with a different belief about which addresses still applied. A newly invalid address had to be explicitly withdrawn after recovery. If both peers did not claim preserved state, the old addresses were treated as withdrawn and rebuilt.

Checkpointing changed the granularity. A Keepalive carrying an FT Protection TLV asked the receiver to secure all earlier check-pointable messages and flush an acknowledgement. With C set but S clear, ordinary messages did not each carry active sequence numbers; the checkpoint synchronized their collective history. With S enabled, the checkpoint applied to the sequence-protected set and addresses. The same word therefore covered different populations depending on negotiated flags.

One checkpoint still ran in one direction. Controlled shutdown required something stronger because the node asking to stop also needed proof that it had secured everything the peer had sent. The FT Cork TLV initiated a three-way exchange. One peer requested quiescence, the other finished and secured prior work while stopping new label or address messages, and a final response closed the opposite direction. Only then did both ledgers share a stopping boundary.

The protocol was honest about failure. A peer unable to preserve state or pend operations had to clear its FT Reconnect Flag. If either side did so, both released the old session's FT state rather than invent continuity. Changed session parameters, such as label-space bounds, also blocked a simple restoration because an old operation might no longer have the same legal meaning.

The IESG Note is essential history, not editorial debris. It warned that retry and timer guidance was inadequate, that premature failover was a real concern, and that the design should not become a general model for future TCP fault tolerance. The RFC defined a reconciliation grammar; it did not supply a universally safe operating point.

This is distinct from the neighboring questions already covered elsewhere. RFC 3478's graceful restart retained stale forwarding while control meaning returned. RFC 3612 examined why preserved state and peer acknowledgements did not prove forwarding truth. RFC 3479's special contribution was narrower: it made the uncertain part of an interrupted control transcript enumerable, replayable and, in specified pairs, safely collapsible.

Heng Lu's reality-layer method turns that contribution into an audit sequence. Preserve both session identities, the negotiated S, A, C and R flags, and unchanged parameters. For each peer, reconstruct sent sequence numbers, locally secured operations and ACKs actually transmitted. Freeze the moment of failure. At reconnect, compare the advertised durable frontiers, then account for every replay, every pended operation and every net-zero omission.

The same discipline prevents an attractive but false shortcut. An ACK is not a claim that all later work survived. A checkpoint is not a complete snapshot unless its negotiated population is known. A Cork request is not quiescence until all three messages complete. And none of these control receipts says whether packets reached an application. They answer a prior question: which operations can the two peers prove they share?

That question explains RFC 3479's place in Internet history. The document treated failure recovery not as amnesia followed by optimism, but as a dispute between two partial memories. Sequence numbers bounded the dispute, ACKs located the common past, replay rebuilt the uncertain suffix, and the Cork handshake created a shared full stop. The TCP session died; the operation ledger had to reconcile.

Sources