Summary
draft-ietf-spring-resource-aware-segments-20lets an existing SR-MPLS or SRv6 instruction also select a named subset of bandwidth, buffer and queue resources. The SID remains a forwarding selector; it is not evidence that the resource subset exists at every participating node.- Revision 20 says an NRP must not carry service traffic until every node is provisioned, an update is not finished until all changes succeed, inconsistent bindings should fail closed, and best-effort fallback should be logged and reported.
- The draft also admits the hard limit: a compromised node can overstate capacity, omit the claimed allocation or selectively degrade a partition. Intent, admission, allocation, binding, packet treatment and measured outcome therefore need separate receipts.
The label arrives before the guarantee
Segment Routing is attractive because an ingress can place an ordered instruction set into the packet and avoid installing per-path state at every hop. A SID can mean reach this node, use this adjacency or execute this behavior. The SR architecture, SR-MPLS and SRv6 network programming provide that forwarding vocabulary.
Revision 20 of the resource-aware segments draft adds a second meaning without inventing a new SID type. The same instruction can also identify the bandwidth, buffers and queues available for the action. A local resource-aware SID points to a resource subset on a particular node or link. A global one can associate a destination and algorithm with a Network Resource Partition across many nodes.
That is useful compression. One label can carry a forwarding instruction and a resource choice. It is also where dashboards can become dangerously confident. The packet proves only that it carried the selector. A successful lookup proves only that a node found a mapping. Neither fact proves that admission was valid, the promised capacity was installed, the mapping was current, excess traffic stayed inside the allocation, or the customer received the stated latency and loss behavior.
The distinction matters because RFC 9543 defines an NRP as a subset of underlay resources used to realize network-slice objectives, while RFC 9732 supplies architecture and identifiers. Naming a partition is necessary. It is not the same act as furnishing it.
A distributed commit disguised as a route
Revision 20 makes the commit boundary unusually clear. Support for the NRP and its SIDs or SRv6 locators must align across participating nodes. A controller or management system is responsible for confirming completion and should be able to roll back partial failure. A failed SID-to-resource association must be reported. The NRP must not be used for service until it is fully provisioned, and an update is not finished until every involved node has made its change.
Those sentences convert “configuration succeeded” from a local event into a distributed claim. One router accepting a queue profile is not completion. A controller finishing its request loop is not completion. Even a unanimous set of acknowledgements may describe configured state rather than the scheduler, buffer and policing behavior actually active in silicon.
The draft therefore calls for consistency checks between configured allocation and intended state. If a node detects inconsistent binding, the affected resource-aware SIDs must not be used for forwarding by default, with an error logged and reported. That is a sensible fail-closed rule. It still depends on what the node can observe and whether the node tells the truth.
The Datatracker record shows why the status must remain modest. Revision 20, posted 30 September 2026, is an active SPRING working-group Internet-Draft in IESG Evaluation with AD follow-up and an unresolved DISCUSS. Its history and machine record establish version and process state, not approval or deployment.
The fallback that preserves reachability and spends the promise
The forwarding rules contain two different escape hatches. If a transit node cannot find local resources for the selected partition, the default is to discard, but an operator can enable best-effort forwarding. Separately, when traffic exceeds the allocated resources, policy may drop it or lower its priority. Revision 20 says best-effort fallback should be logged and reported.
Fallback can be operationally correct. During maintenance, it may be better to preserve reachability than to drop every packet. But it changes the service. A packet that arrives after leaving the reserved lane has not proved the reserved lane worked. A green reachability counter can coexist with a broken latency guarantee.
This is the central accounting rule: delivery and entitlement are different receipts. The flow may arrive. The NRP may have failed. If the fallback event is not joined to the affected flow, interval and customer promise, an operator can report availability while silently spending the SLA.
The same applies to scale. The draft says using topology/algorithm tuples may suit fewer than roughly ten NRPs; larger deployments need more SIDs or additional distribution mechanisms. Avoiding per-path state does not mean avoiding state. It moves state into SID inventories, locator plans, resource bindings, thresholds, rollback records and control-plane extensions.
A truthful controller cannot redeem a dishonest node
The security section is more candid than the label. Allocation and association channels must provide mutual authentication, authorization, integrity and replay protection, with confidentiality recommended for topology or capacity data. Flexible Algorithm hijack can compromise both route choice and resource isolation. Admission thresholds must stop a controller or locally authorized node from starving the base SR forwarding plane.
Yet secure control transport does not turn local resource claims into physical truth. The draft says a compromised node may decline to allocate what it claims, overstate availability or selectively degrade an NRP. Authentication can establish which node sent the statement. Integrity can preserve the statement. Replay protection can reject stale statements. None of them proves that the queue was really reserved or that the scheduler honored it for this flow.
That is why performance measurements or packet traces using the same resource-aware segment belong beside configuration checks. They are not decorative monitoring. They test a later reality layer. Even then, a good probe interval proves only that interval. It cannot guarantee the next failure transition or expose selective treatment it did not sample.
Running code is evidence, not a certification badge
The draft records a Huawei implementation report covering named router families and says the implementations are in production and follow the current requirements. The surrounding language, derived from RFC 7942, is equally important: the IETF did not verify contributor-supplied information, listing is not endorsement, and the section is not a catalog of available implementations or features.
The distinction protects both the vendor and the reader. The report is relevant evidence that the mechanism has been implemented. It is not an interoperability test, an independent capacity audit, a market-adoption measure or proof of any customer's SLA.
The June Security Directorate review shows how running review improved the text: it pressed for conjunctive channel security, a mandatory explanation in companion protocols, observable fallback, correct update atomicity and fail-closed inconsistency. The earlier Operations Directorate review is part of that review trail. Comparing revision 19 with revision 20 HTML and XML shows the resulting normative tightening. It does not show that installed networks changed with the document.
This is where Heng Lu's essays are useful as disclosed editorial lenses. Running-Code Primacy says operational reality should discipline symbolic authority. Minimum Initial Specification argues for a thin common core and local deployment choice. Reality Layers warns against promoting a record or declaration into the reality it merely describes. Applied here, the SID may name the lane; only independent receipts can show that the lane existed and performed.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
