Summary

  • RFC 9506 describes endpoint-generated Spin, Delay, T, Q, L, R and E signals that let an on-path observer estimate delay, loss or ECN-reported congestion without decrypting the transport.
  • Every value depends on a measurement contract: signal binding, endpoint cooperation, flow epoch, timing or block parameters, observer direction, stable path and exclusion rules. A missing or noisy signal is not a zero.
  • The signal is neither authenticated truth nor service proof. GREASE, tampering, path changes, Connection-ID resets and preferential treatment of marked traffic can change what the observer is actually measuring.

A benchmark flow crossed the new network path with one attractive result: round-trip delay had fallen. The payload remained encrypted. No endpoint exported a full trace. The observer needed only a small rhythm in the visible packet header, and that rhythm looked cleaner after the change.

Then the comparison began to loosen. Some flows had randomized the measurement bit to resist ossification. One client had changed its QUIC Connection ID and destination during migration. The marked experiment was classified into a priority queue. The dashboard's number was not invented; it was a valid calculation over packets that passed one observer. What had not been established was whether those packets still represented the same population, path, treatment and service.

RFC 9506 offers a practical answer to transport encryption's observability problem. Cooperative endpoints can expose a few explicit markings so network operators estimate loss and delay without recovering encrypted sequence or acknowledgment state. The discipline required is equally explicit: a signal is an observation interface, not a certificate of cause or outcome.

A toolkit, not one universal bit

The RFC is Informational and transport-independent. It does not reserve one universal set of header positions. A concrete transport binding must decide which bits carry which meaning, how an observer distinguishes those meanings from other uses, and what security and privacy rules apply.

The Spin bit is the familiar latency signal. Client and server maintain a per-connection value that produces a square-wave-like transition about once per RTT. An observer watching one direction can measure time between edges. The simplicity is valuable, but the edge is not immune to the traffic around it. Reordering can create false transitions, a lost edge can stretch a period, and an application-limited sender can make application pacing appear inside the delay.

The Delay bit uses a rarer sample that bounces between endpoints. A client creates the sample; the receiver reflects it on the first suitable packet in the other direction. This can be more resilient than reading every Spin edge, but it brings a different contract. Reflection must occur within a threshold. A sample gap must remain below T_Max. Endpoint and observer must use compatible timing assumptions. A delayed application send can invalidate a sample even though the network itself behaved correctly.

Calling both values “RTT” erases their provenance. A useful record names the bit method, endpoint roles, flow epoch, observation direction, threshold, sample exclusions and confidence. Without those fields, two numerically equal results may describe different realities.

Loss has several geometries

RFC 9506 does not offer a single loss flag. It describes multiple ways to expose different parts of the loss picture.

The T bit samples round-trip loss and depends on a working Spin signal. The Q, or square, bit divides sent packets into blocks of a known size N; an observer estimates upstream loss by counting what arrives in each block. The L bit conveys loss events inferred by an endpoint's own loss-detection machinery. Q says something about a counted block on the path to the observer. L says something about the transport's internal view of a missing delivery. Those are related claims, not interchangeable claims.

The R bit reflects completed Q blocks. Combined with Q, it can support estimates for the unobserved direction, three quarters of a round trip, a half-round-trip segment or downstream loss. Which result is available depends on whether the observer sees one direction or both, knows which side is client and server, and can correlate the same block and epoch.

The E bit exposes ECN-Echo events reported by the receiver. An observer may also count CE-marked packets directly before that point. One is downstream feedback surfaced by an endpoint; the other is a local wire observation. A divergence can be diagnostic, but only if the two counters are not falsely treated as the same instrument.

This is why “loss was 0.7 per cent” is incomplete. Was it upstream to one observer, end to end, opposite-direction, half-round-trip or a transport loss event? Which block size and packets-per-ACK applied? Was reordering included? What did the observer not see? The arithmetic begins after those questions, not before them.

The path and the observer are part of the value

An explicit mark travels in production traffic, but that does not free the measurement from topology. The RFC's application discussion assumes monitored flows follow stable paths and cross the same measurement points. If routing changes, a local observer can continue producing immaculate values for a different segment. If forward and reverse traffic are asymmetric, a device that sees only one direction cannot infer every component advertised by a bidirectional design.

Intra-domain RTT makes the dependency concrete. Two observation locations derive components and subtract them. The result inherits each clock, interface, direction, flow classification and correlation decision. A missing packet at the second point might be path loss, a path change, an observation failure or a packet that never belonged to the same epoch.

QUIC migration adds another boundary. RFC 9506 says counters should reset when the destination address, UDP port or outgoing Connection ID changes, and loss from the earlier context must not leak into the new one. A dashboard that aggregates across that reset can produce continuity where the protocol intentionally started a new measurement identity.

Record route evidence, observer interfaces, direction, Connection ID, address tuple and reset reason alongside the metric. “Same customer session” is not enough if the measurement's wire identity changed.

Noise can be deliberate

Measurement bits are not required for the transport to work. That allows protocol designers to protect extensibility by GREASE: a fraction of flows can carry arbitrary values so the network does not become dependent on a fixed interpretation. For those flows, the apparent signal is noise by design, and observers must ignore it.

This turns silence and incoherence into ambiguous states. They may mean the endpoint disabled measurement, the binding is unsupported, the flow was GREASE-selected, the observer missed events, a path or identity reset occurred, or an attacker changed markings. None means zero delay or zero loss.

The markings are also not universally authenticated. An on-path attacker can flip bits or inject packets and damage the estimate. A concrete application may protect them, but RFC 9506 does not supply one authentication rule for every transport. Even an honest endpoint exposes only its implemented state. The L bit, for example, reflects loss detection inside the transport; it does not name the device, queue or policy that caused the event.

An operational record should therefore preserve four verdicts: signal recognized, sample valid, metric computed, causal claim supported. Collapsing them into one green tile converts malformed, missing and adversarial evidence into confidence.

The instrument can change the experiment

The most important warning is almost sociological. Visible experimental bits can be recognized by a network operator. If marked traffic is placed in a priority queue, it may receive better service than ordinary traffic. The benchmark then measures the treatment awarded to the instrumented population.

This is not necessarily malicious. A test range, troubleshooting policy or traffic-engineering rule may intentionally protect marked flows. But if the result is presented as ordinary user experience, the observer has crossed from measurement into intervention without preserving the change in subject.

Fingerprinting creates a related selection effect. When few implementations expose the bits, the presence of a pattern can identify a software family or configuration. Privacy-preserving Connection-ID rotation can be undermined if measurement state is carried across identities. A covert channel can also use the visible field. The operator who gains observability acquires duties over retention, population selection and access to the signal.

RFC 9506 does not say a visible bit is bad evidence. It says, by design, what kind of evidence it can become. The right conclusion is bounded: this observer, for this signal-valid flow epoch, saw enough marked packets under these assumptions to estimate this delay, loss or congestion component. Cause, remediation, application completion and customer effect need their own receipts.

Sources