Skip to content

docs(bgp): record Securebit AS-SBAG membership and /48 reach - #568

Open
Svaag wants to merge 1 commit into
mainfrom
docs/securebit-as-set-resolved
Open

Svaag wants to merge 1 commit into
mainfrom
docs/securebit-as-set-resolved

Conversation

@Svaag

@Svaag Svaag commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Verified the claim: Securebit added AS215932 to their transit as-set, and the
/48 more-specifics now propagate through their cone instead of dying at their
border. That is what lets return traffic leave the degraded Servperso links.

Closes #517. Supersedes #518 (same diagnosis, never merged, now also stale
against the 2026-09-10 membership).

What was verified (2026-09-14)

RIPE object AS-SBAG:AS-CH-ZUR, last-modified: 2026-09-10T00:48:56Z, now
lists AS215932. Nesting is AS-SBAG → AS-SECUREBIT → AS-SBAG:AS-CH-ZUR.

RIS real-time looking-glass, 23 collectors:

prefix via ch1 (58057/56755) via nl1/de1 (34872) total
2a0c:b641:b50::/48 360 — 360
2a0c:b641:b51::/48 360 — 360
2a0c:b641:b50::/44 293 77 (prepended) 368

AS6939 sits immediately upstream of 58057 on 245 /48 peer-paths, AS174 on 34.
That is the #517 success criterion (6 → ~350, with HE and Cogent appearing).

The /44 still has Servperso paths because it is announced from all three cores;
that is the failover, not a leak of the more-specifics.

What this PR changes

Docs only. No FRR, no route-map.

  • docs/bgp-policy.md — current reach table, membership recipe, corrected
    verification control (single-homed unfiltered prefix, not our own aggregate),
    historical 6-peer-path diagnosis kept so it is not re-derived.
  • docs/blog/asymmetric-return-path-as215932.md — addendum so the published
    1.6% reach ending is not left as current truth.

Not claimed

Looking-glass shows the routes are in the DFZ via Securebit. Whether return
bytes have actually moved off Servperso still needs a capture on rtr
(src net 2a04:4e42::/32 and inbound) and a native-IPv6 download against the
52.7 KB/s baseline — still #351.

Aut-num import/export lines still omit AS58057. Hygiene, not a blocker.

Securebit added AS215932 to AS-SBAG:AS-CH-ZUR on 2026-09-10. RIS
looking-glass on 2026-09-14 shows both /48s at 360 peer-paths via
cr1-ch1, with AS6939 and AS174 upstream of 58057 — the #517 success
criterion. The /48 more-specific strategy can now steer return
traffic off the degraded Servperso links.

Also corrects the 1.6% reach misdiagnosis still on main, and the
verification recipe that compared a more-specific against our
equally-filtered aggregate.

Closes #517

Assisted-by: pi-coding-agent:grok-4.6
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T14:06:53.856449Z d4557bf PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d4557bf31d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/bgp-policy.md
Comment on lines +161 to +162
# Count rrcs[].peers[] and read the as_paths. Read the ASN immediately BEFORE
# ours in each path — that is the upstream actually carrying us, and its absence

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Skip origin prepends when identifying the upstream

When checking the aggregate paths exported through nl1/de1, the AS path ends with several consecutive 215932 entries because those routers prepend the origin ASN three times. Reading the ASN immediately before an occurrence of “ours” can therefore report 215932 itself rather than the actual adjacent upstream (34872), causing the verification recipe to misclassify paths; instruct readers to skip the complete trailing origin-AS run and select the first distinct ASN before it.

Useful? React with 👍 / 👎.

Comment thread docs/bgp-policy.md
| `2a0c:b641:b50::/48` | 6 | — | 6 |
| `2a0c:b641:b51::/48` | 6 | — | 6 |
| `2a0c:b641:b50::/44` | 6 | 365 (prepended) | 372 |
| `2a0c:b641:b50::/44` | 6 | 368 (prepended) | 374 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Separate the July and August propagation measurements

This row rewrites the documented 2026-07-25 result from 365 / 372 to 368 / 374 while line 222 says the July and August measurements were identical with no drift. The same commit retains the original July values in docs/blog/asymmetric-return-path-as215932.md:140-150, so the repository now gives two different results for that measurement; record the August result separately or explain why the original July count was corrected.

Useful? React with 👍 / 👎.

Comment thread docs/bgp-policy.md
|---|---|---|---|
| `2a0c:b641:b50::/48` | 360 | — | 360 |
| `2a0c:b641:b51::/48` | 360 | — | 360 |
| `2a0c:b641:b50::/44` | 293 | 77 (prepended) | 368 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reconcile the current /44 peer-path totals

Under the adjacent-upstream classification described above, the cr1-ch1 and AS34872 buckets are mutually exclusive, but this row reports 293 and 77 paths while giving a total of 368 rather than 370. This makes at least one of the headline reach numbers or its classification incorrect and prevents the table from serving as a reproducible verification record; correct the counts or explicitly define and explain overlapping buckets.

Useful? React with 👍 / 👎.

Comment thread docs/bgp-policy.md
Re-measured 2026-09-14 via RIS real-time looking-glass (23 collectors):

| prefix | peer-paths via cr1-ch1 (`58057`/`56755`) | via nl1/de1 | total |
| prefix | peer-paths via cr1-ch1 (`58057`/`56755`) | via nl1/de1 (`34872`) | total |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include the second de1 transit in path classification

When the aggregate propagates through cr1-de1's configured AS210233 session, its adjacent external ASN is 210233, not 34872, but both new measurement tables label the entire nl1/de1 bucket as AS34872. Those paths therefore cannot be classified using the documented columns and may be omitted or folded into the wrong total; include AS210233 in the de1 classification or narrow the column label to what was actually counted.

Useful? React with 👍 / 👎.

Comment thread docs/bgp-policy.md
the /48s in the DFZ via Securebit; whether return *bytes* actually moved off
Servperso still needs a capture on rtr (`src net 2a04:4e42::/32 and inbound`)
and a native-IPv6 download against the 52.7 KB/s baseline. Tracked in #351.
- **Single preferred upstream.** #517 landing means Securebit now carries most

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid claiming the unmeasured traffic shift

This says Securebit now carries most inbound traffic even though the immediately preceding bullet explicitly states that only route visibility was verified and that return-byte movement still requires a packet capture and throughput test. A 360-peer RIS footprint does not establish traffic volume, since peer paths are not weighted by bytes, so this turns the unverified outcome into a documented fact; describe Securebit as the preferred path or defer the traffic claim until the planned measurement is completed.

Useful? React with 👍 / 👎.

@github-actions

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🎫 Ticket compliance analysis 🔶

517 - Partially compliant

Compliant requirements:

  • Verified the RIPE object AS-SBAG:AS-CH-ZUR now lists AS215932.
  • Re-measured via RIS real-time looking-glass: both /48s reach 360 peer-paths via ch1, with AS6939 and AS174 upstream of 58057, meeting the ticket's success criterion.

Non-compliant requirements:

  • The native-IPv6 throughput re-test and wg2 return-traffic tcpdump verification are not performed; the PR itself notes they are still outstanding.
  • AS58057 is still not added to AS215932's aut-num import/export lines.

Requires further human verification:

  • The throughput/tcpdump re-test requires an operator on a customer VM and on rtr, so it cannot be verified from this docs-only PR.

518 - Partially compliant

Compliant requirements:

  • Wrong diagnosis is corrected in docs/bgp-policy.md and in the blog addendum.
  • AS-SBAG membership and the prior AS-SBIX-RS-only state are documented.
  • Verification recipe is replaced with the single-homed unfiltered control and RIS best-path caveat.
  • Historical 6-peer-path diagnosis is retained and the change is docs-only.

Non-compliant requirements:

  • (empty)

Requires further human verification:

  • (empty)

351 - Partially compliant

Compliant requirements:

  • (empty)

Non-compliant requirements:

  • No CDN ASN inventory or probe targets are added.
  • No CDN local-pref override policy documentation is added.
  • No smoke test or runbook for CDN BGP best path and customer traceroute is added.
  • No monitoring or periodic probes for package/download endpoints are added.
  • No rollback criteria for CDN local-pref overrides are defined.

Requires further human verification:

  • (empty)
⏱️ Estimated effort to review: 2 🔵🔵⚪⚪⚪
🏅 Score: 80
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Inconsistent totals

The new reach table reports 293 /44 peer-paths via cr1-ch1 and 77 via nl1/de1, but lists the total as 368; 293+77 is 370. The two missing peer-paths are unexplained, and since this table is the authoritative #517 success-criterion record, an inconsistent total will confuse future comparisons.

| `2a0c:b641:b50::/44` | 293 | 77 (prepended) | 368 |
Premature Closure

The PR closes #517 and states the /48 more-specifics can now steer return traffic off Servperso, but the ticket's DoD also includes re-testing native-IPv6 throughput against the 52.7 KB/s baseline and confirming return traffic lands on wg2 via tcpdump. This PR explicitly records that capture as still outstanding and #351 remains open. Closing #517 on BGP propagation alone can leave the actual CDN-download symptom unverified while the docs read as resolved.

appearing). The /48 more-specific strategy from #477 is therefore live —
longest-prefix-match can now steer infra and customer return traffic onto
cr1-ch1 instead of the degraded Servperso links.

@github-actions

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

No code suggestions found for the PR.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AS215932 is missing from Securebit's AS-SBAG — cr1-ch1 inbound reach capped at 6 peer-paths

1 participant