Summary

  • RFC 3626 requires an OLSR node to choose symmetric one-hop relays that cover its symmetric strict two-hop neighborhood. The rule creates a control-plane opportunity to disseminate information with fewer retransmissions; it does not observe end-to-end data delivery.
  • An accountable routing claim needs separate receipts for HELLO observations, relay selection, TC propagation, topology freshness, route installation, next-hop resolution, packet behavior and application acceptance. Each stage has a different author and a different failure mode.

A covered map is not a travelled road

Suppose a node can reach every strict two-hop neighbor through at least one selected multipoint relay. The selection algorithm has completed. The coverage condition is true. A topology screen can color the local neighborhood green.

Nothing in that statement says that the selected relay retransmitted the next control message. It does not say that every downstream node accepted the same topology, that the operating system installed the calculated route, that the next hop remained reachable when a packet arrived, or that the destination application replied. Coverage describes the shape of a local option set. Delivery describes an event.

RFC 3626, published in October 2003, defines the Optimized Link State Routing Protocol as an Experimental protocol for mobile ad hoc networks. It is not an Internet Standard. Its engineering purpose is clear: a proactive link-state protocol can create heavy control traffic in a dense radio network, so OLSR selects a subset of neighbors to relay broadcasts and advertises a sufficient subset of links for route calculation.

That optimization is still a useful lesson in authority. The selected set is allowed to carry more of the control burden, but the selection record cannot author the physical medium. Running code can turn a record into a forwarding decision. It cannot turn the decision into evidence that the packet arrived.

HELLO draws a local boundary

OLSR begins with HELLO messages. They are periodically broadcast on a local interface and never forwarded. From them a node maintains link state, detects symmetric neighbors, learns claims about two-hop neighbors and tells neighbors which of them it has selected as relays.

The word symmetric already contains an evidentiary boundary. Under the protocol, a link becomes symmetric because accepted HELLO information satisfies the state machine. The corresponding tuple remains until its validity time expires or later information changes it. That is a disciplined operational record. It is not continuous measurement of the radio path.

A strict two-hop neighbor is also a constructed category. It is reachable through a symmetric one-hop neighbor while not being the node itself or already a direct neighbor. The MPR calculation must select one-hop neighbors whose combined symmetric neighborhoods cover all such nodes. The algorithm may prefer a small set because fewer relays mean less overhead.

This is coverage over reported adjacency, not a reservation of bandwidth. It says nothing by itself about interference, queue depth, loss rate, link metric, energy at the instant of forwarding or whether the relay will handle unicast data. The receipt should retain the HELLO origin, interface, receive time, validity interval and exact neighborhood version from which the calculation was made. Without those fields, even the local coverage claim cannot be reconstructed.

Selection creates a duty, not performance evidence

Each node advertises a willingness value. WILL_NEVER excludes it from MPR selection; WILL_ALWAYS places it in the initial selected set. The RFC offers battery and fixed-power examples and permits willingness to change with conditions.

Willingness is a policy declaration. It may reflect a sensible resource judgment, but it is not a capacity probe and not an attestation that the node will forward correctly. The selection heuristic gives the declaration real consequence: among candidates with reachability, willingness is an early preference before reachability and degree break ties.

That makes willingness an authority-bearing input. Whoever configures or computes it influences which nodes carry control traffic and which links become visible through topology advertisements. An operations system should therefore record who or what set the value, why, for how long, and which selections changed as a result. A label such as WILL_ALWAYS must never be translated into “always available.”

RFC 3626 itself identifies the gap in its security discussion: a node can forward broadcast control messages unchanged while refusing to forward unicast data. That single case defeats any attempt to promote relay participation into service proof. The correct conclusion is narrower. Selection assigns an expected control function. Only subsequent observations show whether the function was performed.

A duplicate record closes one local question

Flooding creates copies. OLSR suppresses unnecessary work by keeping a duplicate set indexed by originator and message sequence information. When matching state already exists, a node can avoid processing or retransmitting the same message again under the forwarding rules.

The duplicate tuple is a receipt for a local fact: this node has already recorded this control-message identity within the relevant lifetime. It is not a global acknowledgement. A message may have reached one relay and stopped before another branch. A node may process it but not retransmit it because selection, interface or duplicate conditions differ. A later receiver may hold an inconsistent topology.

This distinction changes how control-plane health should be measured. A rising duplicate count can show that traffic is circulating through overlapping paths. It cannot establish that the intended coverage frontier was reached. Operators need sampled per-hop receive and forward observations, selector relationships, sequence continuity and topology agreement at representative nodes. The absence of a duplicate is likewise ambiguous: the message may be new, lost or expired from the set.

Optimization removes transmissions that the model predicts are unnecessary. The evidence system should not remove the observations needed to determine whether the prediction was correct.

TC turns selected relationships into shared assertions

Nodes selected as MPRs emit Topology Control messages. A TC advertises at least the links to nodes that selected the sender as a relay. Those messages are themselves flooded through MPRs. Receivers store topology tuples for a stated validity time and calculate routes from the resulting link graph together with local neighbor information.

The Advertised Neighbor Sequence Number orders changes to the advertised set. Removal must increment it; addition should. Modular comparison handles wraparound. This tells a receiver which accepted advertisement is newer relative to another. It does not prove that the newer statement still matches the medium at the instant a route is used.

Nor is one TC necessarily a complete inventory. Message-size limits permit the advertised set to be split, provided the full set is sent within a refresh interval. A monitoring system that snapshots one packet can mistake a fragment for the whole topology. A stronger receipt binds all fragments, originator, sequence, receive interfaces, validity time and accepted topology version before explaining the route that followed.

The important authority transfer is easy to miss. A local HELLO exchange establishes a neighborhood record. MPR selection determines which relationships must be advertised. TC propagation turns a subset of those relationships into shared routing inputs. Each step narrows or transforms evidence. None should be described as if the topology database were the terrain itself.

The routing table is an instruction, not a packet trace

RFC 3626 is unusually explicit here: OLSR does not forward data packets. It maintains the routing table in the underlying operating system, which is assumed to perform forwarding. That sentence protects the boundary between protocol calculation and data-plane action.

A route can be correctly calculated from the available tuples and still fail as a service path. The next-hop neighbor may have changed since the last HELLO. Address resolution can fail. An interface can queue or drop. A relay can handle control broadcasts but reject unicast traffic. A downstream route can differ. The destination host can be available while the application is not.

For this reason, “route installed” deserves its own receipt but never the final one. Record the topology version, calculation result, kernel transaction, actual forwarding entry, next-hop resolution and interface counters. Then observe packets at meaningful ingress and egress points, including loss, duplication, order and latency. Finish with an application acknowledgement that is independent of the routing process.

The chain is longer because the system is distributed, not because OLSR is defective. The defect would be compressing several distinct claims into one green icon.

Time makes stale truth operationally useful

OLSR records are deliberately time-bounded. Holding time must exceed refresh interval so that ordinary loss does not cause constant disappearance and reappearance. This is sensible for a mobile radio protocol, but it means a tuple can remain valid after physical conditions have changed.

“Valid” therefore means valid under the protocol's temporal contract, not freshly re-observed at this instant. Sequence numbers solve a related but different problem. They allow old and out-of-order information to be rejected, including across wraparound. A correctly ordered record can still be wrong about current reality if the last observation has aged inside its permitted lifetime.

Leadership metrics should expose that age. A topology view needs observation time, remaining validity, expected refresh, missed intervals and the consequence of expiry. Otherwise a team may tune longer hold times to create visual stability while increasing the interval during which routing acts on obsolete adjacency.

The second-order risk is incentive distortion. If success is measured as a stable topology database, instability can be hidden by retaining records longer. If success is measured only as packet delivery, teams lose the protocol evidence that explains why a path changed. Both layers must remain visible and neither should impersonate the other.

External reachability requires a different principal

HNA messages extend the problem beyond the ad hoc domain. A node can advertise a network and netmask reachable through a non-OLSR interface. Receivers keep association tuples and can add routes through the advertising gateway. Unlike TC state, HNA information disappears by expiry rather than by an advertised-neighbor sequence cancellation.

Receiving and propagating the message proves neither ownership of the prefix nor present reachability through the external domain. The originator may be authentic while the claim is unauthorized. The network may be authorized while the external path is down. Import and export across the boundary require an explicit principal, validation policy, scope and rollback.

This is Heng Lu's record-and-reality distinction at a routing edge. The MANET record can truthfully say which gateway asserted a prefix and when the assertion expires. It cannot create the external route's legitimacy. A route domain should accept only the authority it can name and verify.

Authentication does not validate every link

RFC 3626 specifies no special security mechanism and warns that proactive messages reveal topology on an unprotected wireless network. It recommends authentication because malicious or malfunctioning nodes can invent neighbors, impersonate originators, alter messages, suppress forwarding, select relays incorrectly or replay old traffic.

The RFC distinguishes authenticating an entire control message from validating individual announced links. That distinction is essential. A valid signature can show which credential produced the message and that the protected bytes were not altered. It does not show that each adjacency exists, that the credential holder was authorized to announce an external prefix, or that the state is fresh enough for the current decision.

Later MANET work added standardized message formats, neighborhood discovery, integrity mechanisms and detailed threat analysis. OLSRv2 also separated flooding MPRs from routing MPRs. These developments sharpen the evidence model: dissemination and route construction are different functions, and message integrity is only one part of topology integrity. They do not retroactively prove conformance by any RFC 3626 implementation.

The durable design rule is modest. Preserve the signer, message identity, claimed links, temporal evidence, acceptance decision and observed behavior separately. An authenticated assertion remains an assertion.

The service owns the final receipt

OLSR demonstrates how a compact control plane can turn many local observations into useful routes. It also demonstrates why a distributed record must not be promoted into authorship of reality. MPR coverage proves that a selection algorithm found a local relay set over its accepted neighborhood. TC reception proves that one advertisement arrived. Route installation proves that an operating system accepted an instruction.

None of those facts is disposable. None is the whole result.

The operational chain should end only after the chosen next hop was resolved, the packet crossed the expected boundaries, the destination received it and the application accepted it. If a stage is missing, say which stage remains unproven. Precision is not pessimism. It is how optimized control stays subordinate to the service it exists to support.

Sources