Summary
- RFC 9917 adds exclude, include-any and include-all reverse Administrative Group constraints to IGP Flex-Algorithm definitions for both IS-IS and OSPF.
- A receiving node can classify a condition observed on the reverse directed edge, and that label can cause the corresponding forward edge to be pruned; the label does not by itself prove physical failure, threshold validity or a change in carried traffic.
- The RFC also establishes an ordered IANA registry for path-computation rules: new rules can be inserted, but the relative order of existing rules cannot be changed and established rules cannot be deleted, merged or repeated.
One cable, two directed records
The operational problem starts with direction. On a point-to-point connection between A and B, the IGP treats A-to-B and B-to-A as separate directed edges. A fault visible in packets arriving at B is observed at B, even when the path decision that needs protection is A-to-B. Before RFC 9917, ordinary forward Administrative Group constraints did not provide a standard way for that far-end observation to govern the opposite directed edge.
RFC 9917 supplies the join. Its use case describes input errors, including CRC errors, counted at the receiving node over an observation period. Local policy can associate an Extended Administrative Group with the reverse direction. A Flex-Algorithm Definition can then consult that reverse group while deciding whether the forward edge is eligible.
That is an important control-plane mechanism, but it is also an evidentiary trap. The RFC does not choose one universal counter, observation window, error threshold or hysteresis policy. A reverse colour is the output of an operator's classification decision. It must therefore be recorded with the raw measurement, measurement location, window, set and clear thresholds, policy version and time. Without those fields, the colour is attributable intent but not reproducible fault evidence.
Three constraints, each with a precise pruning test
The new constraints mirror the familiar affinity forms. An Exclude Reverse Administrative Group constraint removes a link when any specified group appears on the reverse directed edge. Include-Any Reverse removes it when none of the specified groups appears. Include-All Reverse removes it unless every specified group appears. RFC 9917 defines the corresponding sub-TLVs in the IS-IS and OSPF Flex-Algorithm Definition encodings.
Parsing details are part of the control boundary. A reverse-group sub-TLV whose length is invalid is ignored in its entirety. Duplicate appearances are handled by defined first-occurrence or FAD-rejection rules, depending on where they occur. Those behaviours stop malformed or ambiguous inputs from becoming an implementation-specific policy language.
The calculation result is still local. A router first has to receive a link-state version, select the winning FAD under RFC 9350, support the constraints it contains and apply the ordered rules. Only then does it produce a constrained topology and calculate a path. The standardised chain does not prove that every router held the same database at the same instant, selected the same definition, installed the same route or forwarded the same packets.
Thresholds can create their own instability
The mechanism can react to measurements, so the measurement-to-label boundary deserves as much attention as the label-to-route boundary. A counter oscillating around a single threshold can repeatedly add and remove a reverse group. Each change can trigger link-state flooding and path recalculation. RFC 9917 calls out this risk, illustrates using different thresholds for setting and clearing the attribute, and notes that ordinary LSP or LSA throttling can constrain the rate of updates.
Hysteresis and throttling reduce churn; they do not establish truth. A slow clear threshold may keep a link excluded after the underlying condition has improved. A high set threshold may leave degraded traffic eligible. Throttling can make routers observe different versions during a transition. These are legitimate local trade-offs, provided reports preserve them instead of translating the final colour into “link bad” or “link healthy”.
An incident timeline should therefore retain at least four clocks: when the far-end measurement crossed policy, when the reverse group changed locally, when each link-state version was originated and received, and when each calculation and forwarding change occurred. Service measurements form a fifth clock. Collapsing them into one event removes the very delays that operators need to diagnose.
Rule order is now a compatibility contract
RFC 9350 established the base Flex-Algorithm calculation sequence, and RFC 9843 added bandwidth and delay constraints. RFC 9917 adds the reverse-group rules and creates the IANA “IGP Flex-Algorithm Path Computation Rules” registry to preserve the complete order.
The registry is more than a list of feature names. Expert guidance permits a future rule to be inserted at any position, but the relative order of existing rules must not change. An established rule cannot be deleted, merged with another rule or repeated. Two implementations that support the same definition but execute its pruning tests in different orders could construct different eligible topologies. Stable ordering is therefore a minimum shared specification for future extension.
The live registry proves what the coordination contract says. It does not prove that a particular router implements a listed rule, participated in the algorithm or executed the rule on a specific database. Capability, configuration, received state, calculation trace and forwarding state remain separate records.
The audit chain ends with packets, not colours
A defensible explanation follows the full join: receive-side counters; threshold and window decision; reverse-edge EAG version; originated and received LSP or LSA; winning FAD; ordered prune result; local constrained topology; calculated route; installed FIB entry; observed packet path; service outcome. Each arrow has its own owner and failure mode.
This distinction prevents two opposite errors. One team may dismiss a reverse label as “just metadata” even though it legitimately removed a forward edge under agreed policy. Another may announce a physical forward-link failure or a recovered service solely because the colour changed. RFC 9917 supports neither shortcut. It gives the metadata deterministic computational force while leaving the underlying observation and resulting operation open to verification.
Sources
- https://www.rfc-editor.org/rfc/rfc9917.html
- https://www.rfc-editor.org/rfc/rfc9350.html
- https://www.rfc-editor.org/rfc/rfc9843.html
- https://www.rfc-editor.org/rfc/rfc7308.html
- https://www.rfc-editor.org/rfc/rfc8126.html
- https://www.rfc-editor.org/rfc/rfc5305.html
- https://www.rfc-editor.org/rfc/rfc3630.html
- https://www.rfc-editor.org/rfc/rfc8919.html
- https://www.rfc-editor.org/rfc/rfc8920.html
- https://www.iana.org/assignments/igp-parameters/
- https://heng.lu/minimum-initial-specification-localized-future-decision-voluntary-adoption-internet-coordination-system/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
- https://heng.lu/on-reality-layers-symbolic-power-and-why-clarity-feels-so-hostile/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
