Skip to content

docs(bgp): correct the cr1-ch1 propagation diagnosis — AS-SBAG, not reach - #518

Closed
Svaag wants to merge 1 commit into
mainfrom
docs/securebit-as-set-propagation
Closed

Svaag wants to merge 1 commit into
mainfrom
docs/securebit-as-set-propagation

Conversation

@Svaag

@Svaag Svaag commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Corrects a wrong conclusion in docs/bgp-policy.md that has been steering
planning since 2026-07-25.

What was wrong

The doc recorded that cr1-ch1's inbound reach was capped because "Securebit
AS58057 accounts for only ~1.6% of RIS peer-paths to AS215932"
, and that IX
peering (#138) was therefore the only fix. The 6/372 measurement was accurate,
but it measured our own filtered footprint and attributed it to Securebit's
DFZ presence.

What is actually true

AS215932 is absent from AS-SBAG, the as-set Securebit announces to all
thirteen of its transit/peer ASNs. Their upstreams build IRR prefix-filters from
it and drop us. We are registered only in AS-SBIX-RS (SBIX route servers).

Re-measured 2026-08-06, RIS real-time looking-glass, 23 collectors:

  • Securebit's own prefixes: 360–362 peer-paths, via AS6939 / AS20473
  • Their single-homed customers in AS-SBAG: 322–365 through the same session
  • AS215932: 6, with no path behind AS6939, AS174 or AS1836

Absence from the tree verified two ways — recursive expansion (8 nested sets,
626 member ASNs, no 215932) and irrexplorer member-of.

Also fixed: the verification recipe

The doc's propagation-check snippet taught exactly the reasoning that produced
the wrong answer — "compare the more-specific against the covering aggregate; if
the counts match via that upstream, it is not filtered." Both prefixes were
equally filtered, so the counts matched, and the match was read as proof of
absence.

Replaced with: the control must be a prefix known to be unfiltered through
that upstream, and it must be single-homed. RIS returns each peer's best path
only, so a multi-homed customer's masked Securebit path looks identical to a
filtered one — which is why most AS-SBAG members also show ~6.

Not changed

No config, no route-map, no FRR behaviour. tests/iac/test_frr_static.py passes
(15 passed, 34 subtests).

Related

🤖 Generated with Claude Code

…each

The policy doc recorded that cr1-ch1's inbound reach was capped because
"Securebit AS58057 accounts for only ~1.6% of RIS peer-paths to AS215932."
The measurement was real; the causal reading was not. It measured our own
filtered footprint and attributed it to Securebit's DFZ presence.

Re-measured 2026-08-06 via RIS real-time looking-glass: Securebit's own
prefixes reach 360-362 peer-paths, and their single-homed customers registered
in AS-SBAG reach 322-365 through the same session. AS215932 is absent from the
AS-SBAG tree (8 nested sets, 626 member ASNs), so their upstreams' IRR-built
filters drop us. We are in AS-SBIX-RS only, which feeds the SBIX route servers.

Also fixes the verification recipe, which taught the reasoning that produced
the wrong answer: comparing a more-specific against our own covering aggregate
is not a control when both are equally filtered. The control has to be a prefix
known to be unfiltered through that upstream, and it has to be single-homed —
RIS returns best paths only, so a multi-homed customer's masked path is
indistinguishable from a filtered one.

Refs #517, #480, #138

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Svaag
Svaag requested a review from a team as a code owner August 6, 2026 22:02
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@Svaag

Svaag commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #568.

The diagnosis here was right — we were missing from AS-SBAG, not short on Securebit reach — but it never merged, and Securebit has since added AS215932 to AS-SBAG:AS-CH-ZUR (2026-09-10). #568 records both the correction and the 2026-09-14 looking-glass confirmation (360 peer-paths via ch1, AS6939/AS174 upstream of 58057).

Closing this PR; the branch can be deleted after #568 lands.

@Svaag

Svaag commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #568.

@Svaag Svaag closed this Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant