Conversation
…each The policy doc recorded that cr1-ch1's inbound reach was capped because "Securebit AS58057 accounts for only ~1.6% of RIS peer-paths to AS215932." The measurement was real; the causal reading was not. It measured our own filtered footprint and attributed it to Securebit's DFZ presence. Re-measured 2026-08-06 via RIS real-time looking-glass: Securebit's own prefixes reach 360-362 peer-paths, and their single-homed customers registered in AS-SBAG reach 322-365 through the same session. AS215932 is absent from the AS-SBAG tree (8 nested sets, 626 member ASNs), so their upstreams' IRR-built filters drop us. We are in AS-SBIX-RS only, which feeds the SBIX route servers. Also fixes the verification recipe, which taught the reasoning that produced the wrong answer: comparing a more-specific against our own covering aggregate is not a control when both are equally filtered. The control has to be a prefix known to be unfiltered through that upstream, and it has to be single-homed — RIS returns best paths only, so a multi-homed customer's masked path is indistinguishable from a filtered one. Refs #517, #480, #138 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Contributor
Author
|
Superseded by #568. The diagnosis here was right — we were missing from Closing this PR; the branch can be deleted after #568 lands. |
Contributor
Author
|
Superseded by #568. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Corrects a wrong conclusion in
docs/bgp-policy.mdthat has been steeringplanning since 2026-07-25.
What was wrong
The doc recorded that cr1-ch1's inbound reach was capped because "Securebit
AS58057 accounts for only ~1.6% of RIS peer-paths to AS215932", and that IX
peering (#138) was therefore the only fix. The 6/372 measurement was accurate,
but it measured our own filtered footprint and attributed it to Securebit's
DFZ presence.
What is actually true
AS215932 is absent from
AS-SBAG, the as-set Securebit announces to allthirteen of its transit/peer ASNs. Their upstreams build IRR prefix-filters from
it and drop us. We are registered only in
AS-SBIX-RS(SBIX route servers).Re-measured 2026-08-06, RIS real-time looking-glass, 23 collectors:
AS-SBAG: 322–365 through the same sessionAbsence from the tree verified two ways — recursive expansion (8 nested sets,
626 member ASNs, no 215932) and irrexplorer
member-of.Also fixed: the verification recipe
The doc's propagation-check snippet taught exactly the reasoning that produced
the wrong answer — "compare the more-specific against the covering aggregate; if
the counts match via that upstream, it is not filtered." Both prefixes were
equally filtered, so the counts matched, and the match was read as proof of
absence.
Replaced with: the control must be a prefix known to be unfiltered through
that upstream, and it must be single-homed. RIS returns each peer's best path
only, so a multi-homed customer's masked Securebit path looks identical to a
filtered one — which is why most AS-SBAG members also show ~6.
Not changed
No config, no route-map, no FRR behaviour.
tests/iac/test_frr_static.pypasses(15 passed, 34 subtests).
Related
route6registration, completed 2026-08-03, closed; changed nothing🤖 Generated with Claude Code