Week of 2026-09-14
Ze measures the path MTU to a peer now, and sizes every IPsec tunnel from what it measured. Two of the week's fixes are worth a maintenance window: Graceful Restart told every peer that Ze preserved nothing, and RPKI reported origin validation as active with no cache server reachable.
The release queue closed the week at 157 required work items and 183 nice-to-have, against 141 and 181 at the start. Four items left it when the path MTU work finished, and most of what joined is checking work. This is an inventory preview. It reads two endpoints, so an item added and finished inside the same week never appears in it, and the counts measure work items rather than readiness: https://ze-software.net/project/roadmap/
📏 Path MTU
New:
show mtuprobes every IPsec peer and a reference address, then reports the ceiling, the value to set, and the TCP MSS that follows from it. Each tunnel is classified (down, oversized, tight, under-utilized, ok) and carries theset interface xfrm <name> mtu <n>that corrects it.show mtu host <address>measures one target,detailshows every probe,exhaustivewalks the full ladder, andenvironment mtu reference-addresspicks the off-net target, default 1.1.1.1.- A tunnel whose IKE security association is up is measured a second time over the association itself, with a padded probe the far end has to authenticate. Every row names the prober that produced it, so a figure confirmed that way reads
ike-confirmed. That settles the paths where a firewall eats ICMP errors. do-not-fragment honor-cacheandbypass-cacheonshow pingandshow traceroute, and on theirresolveforms, set the bit and read the router's reported next-hop MTU back off the error queue. A probe no longer needs privilege: where the raw socket is refused, Ze opens Linux's unprivileged ICMP socket instead.
🔒 Security
Fixed:
- A typo in a key-chain name left OSPF and IS-IS running unauthenticated, and IS-IS
showthen reported the session as authenticated while it sent unsigned packets. A reference naming no key chain is refused when the configuration is validated, and the error names the chain. - A session with GTSM enabled accepted a spoofed ICMP error from off the link. Ze's own ICMP errors to a GTSM peer left with a TTL of 64 as well (RFC 5082 Sections 3 and 6.1).
ze doctornow reports a GTSM peer whose kernel state did not install. - A password typed on a command line was written to the CLI transcript on disk. A fetch URL carrying a username and password reached the log whole, including on the console of a machine being installed.
New:
- AES CCM for the IKEv2 encrypted payload, checked against strongSwan.
encryption aes128ccm8and its 12 and 16 octet forms sit undervpn ipsec ike-group <name> proposal <n>. They are for the IKE security association only, and anesp-groupthat names one is refused at commit.
🛰️ BGP
Fixed:
- Graceful Restart was doing nothing, quietly. The capability named
ipv4/unicastwhatever families were configured. It also told every peer that forwarding state survived for none of them, and RFC 4724 Section 4.2 makes that an instruction to drop Ze's routes the moment the session comes back. The families Ze preserves are nowcapability graceful-restart familyunder the peer, and absent means every family the session carries. validation-enabledinshow bgp rpki statuswas hardcoded true, so an operator whose cache server was unreachable was told origin validation was protecting them while every route resolved Not-Found.preferenceon a cache server now orders connection and failover, which it never did.- Ze advertised the capability that offers an IPv6 link-local forwarding address and had no code able to send one. In the other direction it read the 32-octet next hop of RFC 8950 Section 3 as malformed and reset the session. A conformant peer carrying IPv4 routes over an IPv6 next hop was dropped.
🔌 Sessions and interfaces
Fixed:
- A neighbor taking BFD down for maintenance dropped the BGP session at this end. An administrative down is not a path failure (RFC 5882 Section 3.2).
- A disabled interface still ran a DHCP client, installed the lease it got, and sent IPv6 Router Advertisements.
disablestops every service on the unit now, not only its addresses. - An IRR prefix list too large for one set was truncated and programmed as a partial filter with nothing said. The apply is refused now, the working filter stays in place, and
show firewall irrreports the reference as oversized.
🧩 ExaBGP compatibility
An attached ExaBGP process reads ExaBGP's own JSON, and a batch of fixes closed the places where Ze spelled it differently. An IPv4 route with an IPv6 next hop carried the wrong address. An AS path could not be read as a set or a sequence, attribute 9 printed as a hex blob rather than originator-id, and no event named the local end of the session.
📚 Standards programme
Ze is being checked against every RFC it implements, one MUST at a time. The work continues.
Of 5,472 requirements, 3,599 are MUST-level and 3,322 are checked. 228 still owe a test, against 237 last week. 59 of the 184 documents have been read end to end, the same as last week: the week went on closing what earlier reading had already found.
The find worth naming is a requirement recorded as met against an encoder with no caller outside its own tests. Nothing it produced ever reached the wire, so nothing was proving the code that really carries the rule. That code was conformant, which is the good news, and the proof now sits on it.
A green run proves everything on the list. It does not yet prove the list is complete, which is what reading each document end to end is for: https://ze-software.net/quality/rfc-compliance/
🔭 Coming up
The configuration store becomes ordinary files on disk, and the single-file form stays for backups and seeding. ExaBGP's own handling of the only-to-customer attribute (RFC 9234) goes into the compatibility bridge. Bug fixes and standards closure work carry on.