Summary
- RFC 9912 defines a RAW recovery graph as a finite set of feasible DetNet paths. The graph is a possibility envelope, not a receipt for the path experienced by a particular packet.
- Distributed Packet Loss Recovery decisions may leave no single node able to report the current end-to-end path. Accountability therefore requires separate, time-aligned records of observation, decision, action, traversal and egress outcome.
The control room had a complete diagram. Every permitted hop between the wireless ingress and the wired egress was visible. The current graph revision was installed, redundant branches were available, and the service dashboard showed a healthy recovery domain. One packet still missed its deadline.
When the review asked which route that packet had taken, the first answer was a copy of the graph. It was accurate and insufficient. The graph showed all routes the packet could have experienced. It did not say which local recovery functions had forwarded, replicated, suppressed or eliminated that packet at that moment.
This opening is an illustrative investigation, not a report of a named deployment or incident. Its distinction comes directly from RFC 9912, the April 2026 Informational architecture for Reliable and Available Wireless. RAW extends the Deterministic Networking model into environments where wired or wireless delivery can vary, loss can arrive in bursts, and waiting for an ordinary routing convergence may be too slow for the application.
The recovery graph is the architecture’s bounded answer to uncertainty. It coalesces a finite collection of feasible DetNet paths between an ingress and an egress. That finite boundary matters. A controller cannot promise useful predictability from an undefined universe of detours. It needs an admissible set of nodes, links and recovery behaviours whose latency and resource consequences can be reasoned about.
But RFC 9912 refuses the tempting next inference. A recovery graph represents potential paths. A DetNet path is the experience of a packet. One describes the available space; the other describes an executed history. An installed graph may be necessary for recovery without being evidence that any one branch carried a given packet.
That distinction becomes sharper when Packet Loss Recovery, or PLR, is distributed. A node can observe a deteriorating link, choose a different next segment for future packets, replicate traffic across two branches, or invoke a lower-layer action. A downstream node can make another choice from a different observation window. There may be no central selection event that reconstructs the whole path, and the RFC explicitly allows the result that no single node can report the current DetNet path.
This is not a defect in the architecture. Local decision can be the reason the system reacts quickly enough. It is, however, a defect in an evidence model that asks a controller for “the path” and assumes the answer must exist as one row. Distributed authority creates distributed knowledge. If management promises a single omniscient path record without adding a suitable observation mechanism, the promise exceeds the design.
The graph itself can be strict or loose. A strict recovery graph spells out all possible hops. A loose graph can cross a segment that RAW does not control in the same way. The loose segment may be perfectly useful transport, but it cannot inherit a RAW latency guarantee merely because the surrounding graph has one. The diagram’s line does not transfer a property that the segment does not expose or enforce.
RFC 8655 supplies the larger DetNet architecture: explicit flows, resource awareness, protection and bounded delivery objectives. RFC 9450 describes the industrial, transport and other settings that motivate RAW. RFC 9913 surveys relevant radio and forwarding technologies. None of those documents turns an architectural option into proof that a named network deployed it or met an objective. The standard coordinates concepts; the operator must supply running evidence.
Time is the next boundary. Routing generally changes the graph on a relatively slow cadence. Packet forwarding acts at line or radio timescales. RAW’s adaptive recovery loop sits between them: faster than a routing recomputation, slower and more deliberate than the treatment of an individual bit. RFC 9912 notes that routing statistics may aggregate minutes or hours even when a transient fade or interference burst demands a quicker reaction.
A metric can therefore be authentic and still be unfit for the decision. Loss observed forty seconds ago may describe a link that has recovered. A radio-quality sample taken before a moving obstruction may bless a branch that is now weak. Freshness is not decorative metadata attached to a number; it determines which reality the number is allowed to describe.
RFC 9473 makes the broader point for path properties: some properties change with time, visibility can be partial, and a consumer needs to understand how current a dynamic value is. RFC 9551 gives DetNet OAM a structured vocabulary for per-flow, per-path and per-device performance. Those records improve orientation, but they remain observations made through a method and over a population.
RFC 7799 separates active, passive and hybrid measurement. An active probe can test a chosen path but add traffic and differ from the protected flow. Passive observation sees production packets but only where instrumentation exists. Hybrid methods combine elements of both. A dashboard that drops the method, sample population and timestamp turns unlike evidence into a false common score.
RFC 9912 organizes adaptation as an Observe–Orient–Decide–Act loop. Observe draws from OAM and lower-layer information. Orient relates those signals to the graph and service-level objective. Decide chooses PLR treatment for future packets. Act changes forwarding through Packet Replication, Elimination, and Ordering Functions, commonly PREOF, or through a lower-layer interface. RFC 8175, for example, defines DLEP as one mechanism for communicating link characteristics. A link report is still an input, not an end-to-end delivery receipt.
Each verb needs its own timestamp and identity. Which measurement was observed? Which graph revision and SLO shaped the orientation? Which node decided, for which flow or sequence range, and for how long? Which forwarding or replication action was applied? Which copies arrived and which were eliminated? What did the egress receive, and did that result meet the latency and loss objective?
Without those separations, automation rewrites its own past. The controller keeps the latest graph and latest metric; the forwarding plane replaces the old entry; elimination discards duplicates by design. After a miss, the remaining state may be internally consistent and historically useless. A useful receipt does not have to record every nanosecond of every packet, but it must state what was sampled, what was inferred and what cannot be reconstructed.
Replication illustrates why more evidence is needed, not less. Sending copies across diverse branches can raise the probability that at least one arrives within the objective. It also spends spectrum, battery, backhaul and queue capacity. Eliminating duplicates downstream prevents the application from seeing all copies, but it does not refund the resources used to carry them. The rational policy seeks the least costly combination that still meets the SLO; it does not maximize redundancy as if redundancy were free.
The control loop can oscillate. A node sees one branch worsen and moves traffic. The relieved branch improves while the chosen branch becomes loaded. A later sample reverses the choice. Without hysteresis, minimum dwell time, confidence and a measurement horizon matched to the disturbance, local intelligence can create global instability. Two individually reasonable PLR decisions can interact badly when neither sees the other’s queue or radio state.
The security consequences follow the same mechanism. A forged, replayed or selectively delayed observation can steer traffic toward a paid access, deplete a battery, congest a remote segment or induce repeated switching. Authentication answers who produced a message and whether it changed in transit. It does not by itself answer whether the sample is fresh, representative, authorized for this decision or sufficient to justify an end-to-end claim.
This is where Heng Lu’s Reality Layers becomes operational rather than philosophical. The graph is a declared possibility layer. Installed entries are a configuration layer. Local selection is a decision layer. Packet traversal is an execution layer. Egress receipt and SLO evaluation are outcome layers. A green status in one layer cannot be promoted into the next without evidence.
Running-Code Primacy places executed behaviour above the symbolic comfort of the controller. The graph matters because running nodes can use it, not because its existence governs packets by declaration. Minimum Initial Specification supplies the constructive limit: standardize the minimum common semantics needed for graph, metric, action and receipt interoperability, while leaving future local choices with the operators who bear their costs.
The practical evidence chain should begin with the flow and SLO, then name the recovery-graph version, ingress, egress and strict or loose segments. It should bind observations to source, method, timestamp and age; bind orientation to the graph and policy revision; record local decisions with actor, scope and lifetime; record PREOF or lower-layer actions; preserve packet sequence or representative sample identifiers; and finish with egress receipt and SLO calculation. Gaps should be explicit rather than filled with the latest control-plane state.
That receipt does not abolish uncertainty. Sampling may miss an event, clocks may differ, lower layers may expose incomplete state, and distributed choices may prevent perfect reconstruction. The honest result can be a set of supported path fragments rather than one authoritative line. That is better evidence than a beautiful graph mislabeled as history.
RFC 9912’s strongest management lesson is therefore not “wireless needs redundancy.” It is that adaptive reliability creates a governance obligation proportional to the autonomy it grants. The graph defines what may happen. Local recovery decides what should happen next. Packets reveal what did happen. Leadership should insist that those three sentences never share one database field.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

