Summary
- RFC 9961 identifies one MPLS SR P2MP tree instance with Root, Tree-ID and Instance-ID; the probe does not test the candidate path as an abstract whole.
- Active and backup instances, non-adjacent unicast connectors, ingress steering, service context and user delivery require distinct tests and timestamps.
The tempting dashboard sentence is short: “P2MP policy ping passed.” The packet behind it was more particular. It entered one candidate path, selected one P2MP tree instance and followed that instance’s replication state toward a chosen response scope. Other candidate paths remained untouched. A make-before-break replacement may have been present but inactive. A separate unicast tunnel may have connected two non-adjacent replication segments. None of those facts fits inside a single green light.
RFC 9961, published in April 2026 as an IETF Standards Track document, extends MPLS ping and traceroute to SR P2MP Policies with MPLS encapsulation. It does not cover SRv6. Its publication record and errata search bound the document’s status; they do not report a deployment.
The hierarchy comes from RFC 9960. A policy is identified by Root and Tree-ID. It contains one or more candidate paths, each expressing constraints and optimization objectives. A candidate path can have no tree instance when computation fails, one instance in steady state, or more than one during make-before-break. Exactly one PTI is active within a candidate path. Different PTIs can have different topology and replication state.
RFC 9961 therefore adds a Target FEC Stack sub-TLV containing address family, Root, Tree-ID and Instance-ID. The text is unusually useful for audit design: that sub-TLV tests a specific PTI within a specific CP; it is not testing the CP. The IANA registry records the assigned subtype in the MPLS LSP Ping parameters. A parser accepting that identifier proves only that both ends agree on the object under test.
The test can deliberately target inactive state. Implementations should let operators test each candidate path and each associated PTI, and a capable downstream node must process the request even if that CP and PTI are not currently active. This is operationally helpful: a backup can be checked before selection. It also destroys a common inference. A successful backup probe cannot prove which candidate path was active when user traffic arrived.
The responder set is another boundary. RFC 6425 supplies the P2MP LSP Ping procedures reused here, while RFC 8029 supplies the MPLS data-plane failure framework. In an SR P2MP domain, the Root knows the Leaves, but transit routers often do not. Egress-address responder sub-TLVs should therefore not be used for this FEC: a transit node may be unable to decide whether it lies on the requested Leaf’s path and may not answer. Node-address scoping can intentionally suppress other replies. Silence is meaningful only beside the exact responder request.
Non-adjacent replication segments introduce a second instrument. RFC 9961 uses P2MP Policy OAM for the replication tree and unicast OAM for the path connecting the separated replication segments. Failure detection for that unicast path is explicitly outside its scope. For traceroute, the start of the unicast section must use Pipe Mode so the hidden connector does not consume the P2MP TTL; RFC 3270 supplies the MPLS TTL model. One tool cannot truthfully absorb the other’s evidence.
RFC 9524 defines the Replication segment substrate, while RFC 9256 supplies the broader SR Policy candidate-path selection model. Together they expose the missing receipts: the controller’s computed object, the installed replication state, the Root’s active CP and PTI, the local steering decision, the probe’s addressed instance, each scoped response, the unicast connector result and the service outcome are different records.
An illustrative failure makes the distinction concrete. A scheduled probe reaches every requested Leaf on an inactive replacement PTI. Minutes later, ingress policy continues steering user traffic into the old active PTI. One non-adjacent connector drops multicast data while its replication endpoints remain individually responsive. The probe was not false; the label attached to it was too broad.
Heng Lu’s running-code primacy requires the return path from stated mechanism to observed operation. His minimum initial specification supports precise shared identities while leaving accountable deployment choices local. His essay on reality layers explains why a policy name must not swallow the instance, observation and result beneath it.
The right status is longer than “green” but more useful: this Root tested this Tree-ID and Instance-ID, with this response scope and TTL mode, at this time. Everything beyond that sentence needs its own receipt.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
