Summary

  • draft-ietf-pim-pfm-forwarding-enhancements-08 lets capable routers carry one (S,G) plus flow-specific Sub-TLVs in GSI, but requires conversion to legacy GSH on mixed-capability interfaces; the conversion preserves group, source and holdtime while ignoring the Sub-TLVs.
  • Its Relaxed-RPF optimization also replaces redundant transmissions over parallel point-to-point links with one implementation-selected copy, so evidence must separate capability, original content, conversion, selected-link state, timely receipt, downstream understanding and actual multicast forwarding.

A healthy row with missing meaning

An operator opens a source-discovery table after a staged upgrade. The group is right. The source is right. The holdtime is fresh. Every familiar field suggests that the announcement crossed the network intact.

It did not.

Upstream, the First-Hop Router originated a Group Source Info TLV carrying three additional attributes as Sub-TLVs. One interface led only to capable neighbors and received that GSI unchanged. Another interface included a legacy neighbor. On that branch the protocol did exactly what revision 08 requires: it created a Group Source Holdtime TLV, copied the group, source and holdtime, ignored the Sub-TLVs and forwarded the smaller form.

The downstream row is neither corrupt nor stale. It is a valid, narrower statement. The danger begins when an auditor treats equality in the surviving fields as equality of the original message.

Revision 08 of PIM Flooding Mechanism and Source Discovery Enhancements was published on 25 August 2026 and expires on 26 February 2027. The Datatracker identifies it as an active PIM Working Group Internet-Draft intended for Experimental status; the working-group document page places it in the RFC Editor queue awaiting editor assignment. It remains work in progress, not an RFC, implementation report, interoperability result or measured deployment.

The draft proposes useful efficiencies. One enriches source announcements without abandoning older PFM peers. The other avoids sending redundant PFM messages over every parallel link between the same two routers. Both are compatible with operational prudence. Neither makes the surviving record self-describing.

GSI adds a semantic envelope

RFC 8364 defined PFM and its Group Source Holdtime TLV. GSH communicates a multicast group, a source and a lifetime. Revision 08 adds the Group Source Info TLV, which applies to one (S,G) entry and can carry zero or more Sub-TLVs with additional flow-specific information.

That changes the evidence shape. The group, source and holdtime are the common core. Sub-TLVs are an extensible semantic envelope. Their types come from a separate registry, and future documents can define meanings that revision 08 itself does not enumerate.

An unrecognized Sub-TLV must be ignored. It must not cause the enclosing GSI or the whole PFM message to be discarded. This is the right rule for extensibility: one new attribute should not destroy source discovery for older code. It also means that protocol acceptance is not proof of semantic comprehension. A router can truthfully say “I processed this GSI” while understanding none of the optional fact that mattered to the operator.

The wire record therefore needs two receipts. One says the enclosing (S,G) announcement was accepted. The other inventories which Sub-TLV types and values the consumer actually understood. Without the second, a green parser status is only a framing receipt.

One old neighbor sets the interface's language

GSI support is advertised in a PIM Hello option. An implementation must also provide a configuration control; when GSI use is disabled, the router must stop advertising the option and must not originate GSI. Capability is thus both observed neighbor state and local operating state.

When every neighbor on an outgoing interface supports GSI, an enabled First-Hop Router must originate GSI. When any neighbor does not, it must use GSH on that interface. A single legacy participant can therefore determine the representation received by every neighbor on the shared interface.

Forwarding routers apply the same boundary per interface. They forward GSI unchanged toward an all-capable neighborhood. Toward a mixed neighborhood, they convert each GSI to GSH, preserve group, source and holdtime, and ignore its Sub-TLVs. At the same time, they continue sending full GSI on capable interfaces.

This is not a network-wide version switch. It is a branching semantic topology. The same origin event can arrive in full on one branch and in reduced form on another. A fleet-wide dashboard that stores only the three common fields erases precisely the evidence needed to explain that divergence.

GSI and GSH may also coexist in one PFM message. For the same (S,G), GSI takes precedence, while GSH provides fallback for peers that cannot use the richer form. Coexistence proves that compatibility material was present. It does not prove which form each neighbor selected, understood or passed onward.

Conversion is a lossy act, not an error

The draft is unusually helpful because it states the conversion rule plainly. The Sub-TLVs are not tunneled through a side channel. They are ignored. No mandatory error marks their disappearance, because the objective is to retain source discovery across a heterogeneous network.

That design creates an important control distinction. Availability of the core announcement and fidelity of the enriched announcement are different service properties. An operator can legitimately choose availability over richer semantics on a legacy branch. What the operator cannot do is claim both without a conversion receipt.

The minimum conversion record includes the incoming GSI bytes, the outgoing interface, the neighbor capability set at that time, the generated GSH fields and a list of removed or unrecognized Sub-TLVs. It should also say whether the conversion occurred at the FHR or at an intermediate router. Otherwise a downstream observer knows that information is missing but not where the semantic boundary moved.

Multiple (S,G) entries for one group should be aggregated into one GSH TLV, but that aggregation is recommended rather than mandatory. Two conforming implementations may therefore produce different message shapes while expressing the same reduced source state. Packet-count equality is not a conformance invariant, just as surviving-field equality is not a fidelity invariant.

Three links become one control path

The second enhancement targets redundant processing. Two PIM routers may be adjacent over several parallel point-to-point links. Under ordinary PFM behavior, a message can be sent over all of them and rejected by RPF on redundant arrivals. Revision 08 lets capable peers exchange only one copy.

The optimization depends on Router-IDs advertised under RFC 6395. Within a PIM VRF, a router must use the same four-octet Router-ID on every interface and cache the Router-IDs learned from neighbors. Router-IDs are assumed to be unique in the PIM domain. If that assumption fails, the optimization cannot be applied safely.

Support for the optimization has its own Hello option. For each learned Router-ID, the router constructs PFM_OPT_IF: the set of interfaces on which that Router-ID belongs to the sole PIM neighbor and that neighbor advertises the option. The sole-neighbor condition excludes shared LANs, where messages continue to be sent normally.

With Relaxed-RPF enabled, the sender selects one interface from the set. The selection method is implementation-specific. The receiving peer first determines the standard RPF interface, then may accept the message on any interface in the eligible set when both sides support the optimization.

The result is deliberate asymmetry. Router identity makes several physical adjacencies look like one control relationship, and implementation policy chooses the current carrier. Seeing one accepted copy does not prove which alternatives were eligible, why that interface was chosen or how quickly the choice will move after failure.

Fewer copies make state accuracy more valuable

Redundant transmission spends bandwidth and processing to gain multiple chances of arrival. The optimization removes that duplication. It does not remove dependence; it concentrates dependence in PFM_OPT_IF, link detection and the selection implementation.

The draft recognizes a transient. A sender can choose an interface just before it fails, while its local optimization state still says the interface is eligible. The message can be lost or delayed until later state catches up. This is not unique to Relaxed-RPF—ordinary RPF operation can also lose a message during path change—but the optimized system should not be described as if selecting one link preserved the receipt supplied by several attempts.

Periodic PFM announcements refresh the soft state. That gives the system a repair path. A later refresh, however, proves later convergence. It cannot prove that the first triggered announcement reached the peer, or that a receiver joined in time for initial packets. When timing matters, “eventually fresh” and “initially delivered” are separate service claims.

Routers must update the eligible set on neighbor addition and removal, capability changes, configuration changes, topology changes, and software upgrades or downgrades. Those are not housekeeping details. They are the events that can change both the chosen path and the representation carried over it.

Return suppression has a different threshold

Revision 08 also prevents a PFM message from being sent back toward its originator on a single-neighbor link when that neighbor's Router-ID matches the originator. Here the neighbor need advertise only the Router-ID; it does not need the optimization option.

This saves another unnecessary transmission, but its evidence should not be confused with full Relaxed-RPF eligibility. One rule relies on originator identity and the sole-neighbor shape. The other relies on mutual optimization capability and an eligible parallel-link set. A single “PFM optimization active” flag cannot explain which suppression decision occurred.

It also raises the value of Router-ID discipline. The identifier is not a cryptographic identity. Its uniqueness is an operating assumption within the domain. A duplicate or stale association can make topology reasoning wrong even when the Hello message is syntactically valid.

Authentication stops at the neighbor boundary

The draft inherits the security considerations of PIM and RFC 8364 and says the optimization relies on correct Router-ID and capability advertisements plus PIM Hello integrity. RFC 8364 explains the deeper limit: link-local PFM messages can be authenticated hop by hop, but trusting the originator information requires trusting every router in the path to have authenticated what it received.

That is a custody chain, not end-to-end authorship. A verified neighboring sender proves the message arrived from that neighbor under the configured association. It does not prove the originator chose the same bytes, that an intermediate router retained every Sub-TLV, or that the selected Router-ID maps to the physical and administrative principal the operator assumes.

The GSI-to-GSH conversion is authorised behavior, not tampering. Cryptographic integrity on each hop can coexist with intentional semantic loss between hops. An audit that checks only authentication can therefore certify every transmission while missing the compatibility decision that changed the meaning.

Nine receipts for a source-with-attributes claim

A defensible operational record links nine stages:

  1. The exact revision and standards status bound the rule set being evaluated.
  2. The PIM VRF, originator, Router-ID, interface and epoch bind the identities.
  3. The GSI and optimization Hello options plus the local configuration knobs establish effective capability.
  4. The original GSI bytes preserve (S,G), holdtime and each ordered Sub-TLV.
  5. A per-interface conversion record says whether GSI passed unchanged or became GSH and which meaning was removed.
  6. PFM_OPT_IF, the sole-neighbor tests, standard RPF result and selected interface explain transmission.
  7. A receipt or bounded timeout distinguishes the triggered message from a later periodic refresh.
  8. The consumer records which TLV and Sub-TLV semantics it understood and which source-discovery state it installed.
  9. SPT join, forwarding/replication state, packet observation and application result close the outcome chain.

The absence of one receipt does not invalidate every other fact. It narrows the conclusion. A fresh GSH can prove a living source announcement while remaining silent about the attributes that disappeared. An authenticated PFM packet can prove neighbor custody while remaining silent about end-to-end fidelity. A later refresh can prove recovery while remaining silent about initial loss.

What the sources do not prove

The frozen record supports an analysis of revision 08, its compatibility conversion, capability controls, Router-ID assumptions, selected-link behavior and transient-repair language. It does not prove adoption, a named implementation, a performance improvement in a real network, an interoperability result, a failure, an attack, packet delivery or user-visible service.

RFC 8364 contains earlier prototype and limited-field-test discussion. That historical text does not test revision 08's new GSI/Sub-TLV and Relaxed-RPF procedures, and it should not be promoted into evidence that this extension works in production.

Read through Heng Lu's distinction between records and authority, the important event is not that the smaller record survived. It is that the system must keep the authority to say what survived with the component that performed the conversion, and keep the authority to say what worked with the running network that observed the result.

Sources