Weekly update

Week of 2026-09-14

Ze measures the path MTU to a peer now, and sizes every IPsec tunnel from what it measured. Two of the week's fixes are worth a maintenance window: Graceful Restart told every peer that Ze preserved nothing, and RPKI reported origin validation as active with no cache server reachable.

The release queue closed the week at 157 required work items and 183 nice-to-have, against 141 and 181 at the start. Four items left it when the path MTU work finished, and most of what joined is checking work. This is an inventory preview. It reads two endpoints, so an item added and finished inside the same week never appears in it, and the counts measure work items rather than readiness: https://ze-software.net/project/roadmap/

← All weekly updates

📏 Path MTU

New:

  • show mtu probes every IPsec peer and a reference address, then reports the ceiling, the value to set, and the TCP MSS that follows from it. Each tunnel is classified (down, oversized, tight, under-utilized, ok) and carries the set interface xfrm <name> mtu <n> that corrects it. show mtu host <address> measures one target, detail shows every probe, exhaustive walks the full ladder, and environment mtu reference-address picks the off-net target, default 1.1.1.1.
  • A tunnel whose IKE security association is up is measured a second time over the association itself, with a padded probe the far end has to authenticate. Every row names the prober that produced it, so a figure confirmed that way reads ike-confirmed. That settles the paths where a firewall eats ICMP errors.
  • do-not-fragment honor-cache and bypass-cache on show ping and show traceroute, and on their resolve forms, set the bit and read the router's reported next-hop MTU back off the error queue. A probe no longer needs privilege: where the raw socket is refused, Ze opens Linux's unprivileged ICMP socket instead.

🔒 Security

Fixed:

  • A typo in a key-chain name left OSPF and IS-IS running unauthenticated, and IS-IS show then reported the session as authenticated while it sent unsigned packets. A reference naming no key chain is refused when the configuration is validated, and the error names the chain.
  • A session with GTSM enabled accepted a spoofed ICMP error from off the link. Ze's own ICMP errors to a GTSM peer left with a TTL of 64 as well (RFC 5082 Sections 3 and 6.1). ze doctor now reports a GTSM peer whose kernel state did not install.
  • A password typed on a command line was written to the CLI transcript on disk. A fetch URL carrying a username and password reached the log whole, including on the console of a machine being installed.

New:

  • AES CCM for the IKEv2 encrypted payload, checked against strongSwan. encryption aes128ccm8 and its 12 and 16 octet forms sit under vpn ipsec ike-group <name> proposal <n>. They are for the IKE security association only, and an esp-group that names one is refused at commit.

🛰️ BGP

Fixed:

  • Graceful Restart was doing nothing, quietly. The capability named ipv4/unicast whatever families were configured. It also told every peer that forwarding state survived for none of them, and RFC 4724 Section 4.2 makes that an instruction to drop Ze's routes the moment the session comes back. The families Ze preserves are now capability graceful-restart family under the peer, and absent means every family the session carries.
  • validation-enabled in show bgp rpki status was hardcoded true, so an operator whose cache server was unreachable was told origin validation was protecting them while every route resolved Not-Found. preference on a cache server now orders connection and failover, which it never did.
  • Ze advertised the capability that offers an IPv6 link-local forwarding address and had no code able to send one. In the other direction it read the 32-octet next hop of RFC 8950 Section 3 as malformed and reset the session. A conformant peer carrying IPv4 routes over an IPv6 next hop was dropped.

🔌 Sessions and interfaces

Fixed:

  • A neighbor taking BFD down for maintenance dropped the BGP session at this end. An administrative down is not a path failure (RFC 5882 Section 3.2).
  • A disabled interface still ran a DHCP client, installed the lease it got, and sent IPv6 Router Advertisements. disable stops every service on the unit now, not only its addresses.
  • An IRR prefix list too large for one set was truncated and programmed as a partial filter with nothing said. The apply is refused now, the working filter stays in place, and show firewall irr reports the reference as oversized.

🧩 ExaBGP compatibility

An attached ExaBGP process reads ExaBGP's own JSON, and a batch of fixes closed the places where Ze spelled it differently. An IPv4 route with an IPv6 next hop carried the wrong address. An AS path could not be read as a set or a sequence, attribute 9 printed as a hex blob rather than originator-id, and no event named the local end of the session.

📚 Standards programme

Ze is being checked against every RFC it implements, one MUST at a time. The work continues.

Of 5,472 requirements, 3,599 are MUST-level and 3,322 are checked. 228 still owe a test, against 237 last week. 59 of the 184 documents have been read end to end, the same as last week: the week went on closing what earlier reading had already found.

The find worth naming is a requirement recorded as met against an encoder with no caller outside its own tests. Nothing it produced ever reached the wire, so nothing was proving the code that really carries the rule. That code was conformant, which is the good news, and the proof now sits on it.

A green run proves everything on the list. It does not yet prove the list is complete, which is what reading each document end to end is for: https://ze-software.net/quality/rfc-compliance/

🔭 Coming up

The configuration store becomes ordinary files on disk, and the single-file form stays for backups and seeding. ExaBGP's own handling of the only-to-customer attribute (RFC 9234) goes into the compatibility bridge. Bug fixes and standards closure work carry on.