RFC conformance: review against the code, the verify budget, newer RFCs
Security model: the key-holder gap is closed
Security model: a compromised neighbour that holds the key
Deployment: under a flood
Limitations: the capability exchange
Deployment: the loop runs on a SCHED_DEADLINE reservation
Deployment: what sets the reply latency
Scheduling and the dead-man bound, from the bare-metal runs The unit now runs the engine SCHED_FIFO 60 (#26) and the dead-man bound defaults to 3 s (#25). Why, with the bare-metal numbers, and which sessions need the engine scheduled at all.
Authentication: works with FRR master since #23331
Echo: the engine returns an FRR peer's v6 echo; not-self narrowed
Deployment: --pin and systemctl reload under the packaged unit
Limitations: --max-sessions, measured to 8192, and the neighbour table
Restarting the engine without the peers noticing (--pin)
Finals within a budget, packets no faster than the peer may send RFC conformance names the Poll budget as deviation 4 and the spacing as a note; Monitoring lists too-fast and changes-lost; the security model adds the churning-timer flood; Limitations has the engine at 2% for 1024.
Security model: floods at 1024 sessions, and the two new budgets The eight flood arms against the 1024-session mesh, and the moved-address and echo budgets they led to; Monitoring lists the two new counters.
1024 sessions, and the registration burst a released bfdd loses The engine holds 1024 sessions. A released bfdd offloads only about 58 of them per connect; #22645 on master fixes it, and the measured numbers are from master.
RFC conformance: the fast path demuxes on Your Discriminator and keeps one source port Deviation 4 is gone: a packet naming one of our discriminators reaches userspace when the address pair misses. The fallback socket is bound within 49152-65535, and both planes send from the port the session bound.
RFC conformance: name the remaining deviations; fix the deployment example The fast path now keeps to our transmit rate, which the page explains. Echo sourcing and the fast path's address-pair demux are listed as deviations. The engine.conf example drops --dp-peer, which a TCP port ignores, and --stats-dump, now the default.
Add FRR compatibility page with measured per-version results Records the 10.1.2 floor, the unixc EINVAL range and the ten merged bfdd fixes that are not in any release yet. Corrects the Installation claims, which said 8.4 onwards and named 10.5.1 as the unixc boundary.
Separate the instructions from the measurements The instruction pages had this testbed in them. A sample attach showed an interface the page had not told anyone to use, the scheduling note appealed to the testbed as though a reader knew what that was, and the troubleshooting page talked about a full mesh, which is this project word for its own fabric and not something anyone else has. The measurement pages keep their numbers, which is the point of them, but now say what travels to another machine. Per-frame costs do; packets per second belong to one NIC and one CPU. Session counts are given out of 64 because that is the fabric they were taken on, and what matters is whether any session was lost rather than the denominator. Also says what native and generic attach mean, since the sample output prints one of them and nothing explained it.
Rewrite the wiki as pages a reader can use The first pass moved the old README sections across as they were, which gave a Deployment page that was six caveats in a bullet list and nothing telling anyone how to deploy anything. Written properly this time, for someone arriving without the project in their head: install it, wire it to FRR in an order that works, then check the fast path is really carrying the traffic rather than trusting show bfd peer, which looks identical either way. Two new pages carry most of the value. Troubleshooting is symptom first and covers what actually goes wrong: a peer configured on one side only, the 64 session ceiling, sessions stranded by an engine restart, the three separate reasons an authenticated session never comes up, a snapshot file left behind by a previous engine, and the observer quietly stealing the XDP attach. Monitoring explains the snapshot and all eighteen counters, since a number nobody can interpret is not monitoring. Limitations is prose with the reasoning and the upstream links rather than a list of bullets.
Seed the wiki: deployment, limitations, conformance, kernels, security, testing The README was cut back to what a reader needs first. This is the rest of it: the deployment notes and the reserved-port trap, the deviations from stock bfdd and from the RFC, the kernels the object is known to load on, the threat model and the flood measurements, and what each test suite covers and needs.
Initial Home page