Weekly update

Week of 2026-09-21

Ze can back up and restore its configuration store, including on a running router. BGP gained AIGP and BGP-LS export, and every RFC Ze implements has now been read end to end.

The release queue closed the week at 191 required work items and 219 nice-to-have, against 157 and 183 at the start. 74 items joined and 4 left. Almost everything that joined is a defect or a missing behavior found by reading the RFCs end to end. Three of the four that left are the backup and restore work below. This is an inventory preview. It reads two endpoints, so an item added and finished inside the same week never appears in it, and the counts measure work items rather than readiness: https://ze-software.net/project/roadmap/

← All weekly updates

💾 Configuration store

The store is now a database/ directory beside the configuration file. Each configuration version is kept once, under its SHA-256, and checked on every read. A store created before this change has to be initialised again. New:

  • ze data backup <file> writes the whole store to one file, taken under the store lock, so a commit is in the backup whole or not at all.
  • ze data restore <file> config adds the backup's configuration as a new version. ze data restore <file> full replaces the whole store and keeps the old one aside.
  • request data backup path <file> and request data restore path <file> config do the same on a running daemon. A restored configuration goes live only if the normal reload accepts it.
  • ze init --from <path or URL> --sha256 <hex> creates a store from a backup, fetched over http or https and checked before anything is written.
  • ze config edit --backup <file> edits a backup with no daemon running.
  • ze data check, ze data repair and ze doctor report missing or corrupted history entries.

🛰️ BGP

New:

  • AIGP best-path selection and re-advertisement (RFC 7311), under session aigp with enabled, originate (default false), link-metric and domain-as.
  • BGP-LS export of BGP, OSPF and IS-IS link state (bgp-ls-export), and Egress Peer Engineering (bgp-epe).
  • RPKI over TLS, under rpki cache-server <name> tls with ca-certificate, certificate and server-name. ASPA follows revision 28 of the draft.
  • The Software Version capability goes out in the draft's own form by default. FRR and ExaBGP expect the older framing, so set software-version encoding legacy for them. ze exabgp migrate writes it for you.

Fixed:

  • A reload now applies a changed router-id and local AS. show bgp and the metrics kept the old values.
  • A configuration change sends a Cease notification before it stops a session (RFC 4486). Adding one iBGP peer no longer restarts every other session.
  • FlowSpec rules are validated against unicast routes (RFC 8955 Section 6), and the firewall installs only the rule BGP selected.

🔀 Other protocols

New:

  • vpn ipsec unmatched discard drops traffic that no IPsec policy covers (RFC 4301 Section 5). The default stays bypass.
  • LDP answers a label mapping above hop-count-max (default 254) with Loop Detected (RFC 5036 Section 3.4.4.1).

Fixed:

  • OSPF sent no grace-LSAs after an unplanned restart when no neighbour was up yet, so helpers never saw the restart (RFC 3623 Section 5).
  • A VRRP address owner answered ARP and ND for the virtual address with its physical MAC.
  • LDP retried a failed session at the Hello rate. It now backs off from 15 seconds to two minutes.
  • A SIGHUP during startup no longer kills ze.

📚 Standards programme

Ze is being checked against every RFC it implements, one MUST at a time. The work continues.

All 174 RFCs on the list have now been read end to end, against 59 last week. Of 6,282 requirements, 4,403 are MUST-level and 4,027 are checked. 248 still owe a test, against 228 last week: reading the documents in full found requirements the earlier lists had missed.

The OSPF and VRRP fixes above both came from this reading, and the same reading turned the LDP checklist from 19 requirements into 86. It also removed requirements a summary had invented, which no RFC sentence supports.

A green run proves everything on the list. The list now comes from reading each document in full, and the work items that joined the queue this week are what that reading found: https://ze-software.net/quality/rfc-compliance/

🔭 Coming up

ExaBGP catch-up. Much of this week went into ExaBGP itself: BGP confederations, route target membership (RFC 4684), ADD-PATH for FlowSpec, prefix-limit, capabilities that can be required, and neighbours that can be disabled and enabled from the API. Its GitHub issue tracker now has no open issues. The only-to-customer support for the compatibility bridge, planned for this week, has not landed yet.