Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"schema_version": 1,
"fetched_at_utc": "2026-08-04T00:01:37Z",
"lifecycle_at_snapshot": "Open",
"lifecycle_evidence": "source state In Progress (state code 2) with no published end at the refresh retrieval; the event remains open",
"snapshot_role": "latest reviewed immutable snapshot (exact source refresh retrieval)",
"cutoff_provenance": "Analysis cutoff is the reviewed snapshot cutoff: the exact source refresh retrieval 2026-08-04T00:01:37Z (state In Progress, no end). It is the reviewed end of the provisional analysis window (manifest analysis_end_utc), not the fetch time of the older tracked offline fixture.",
"provenance": "docs/audits/2026-08-smithville-source-refresh.md (Exact source refresh); manifests/INC0301970.json analyst note 3"
}
11 changes: 10 additions & 1 deletion case-studies/indiana-gigapop-smithville-2026/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,20 @@ labeled provisional.
reported unavailable.
- **Ticket horizon:** work_start 2026-07-28T04:35:26Z; source state In
Progress; no published end (open event).
- **Source snapshot:** fetched at 2026-08-04T00:01:37Z (the exact
source refresh retrieval, reviewed); source lifecycle at that
snapshot: Open (state In Progress, no end). The tracked immutable
snapshot `INC0301970.source.json` is the refreshed snapshot; the
older tracked offline fixture is not the reviewed snapshot.
- **Analysis horizon:** the reviewed event window from
2026-07-28T04:35:00Z (reviewed window start; the source work_start is
04:35:26Z) through the reviewed snapshot cutoff 2026-08-04T00:01:37Z
(the exact source refresh retrieval, reviewed). Result is
Provisional.
Provisional. The analysis cutoff is the reviewed snapshot cutoff —
the reviewed end of the provisional analysis window, not a fixture
fetch time; its provenance is recorded in
`INC0301970.source.json.meta.json` and
`docs/audits/2026-08-smithville-source-refresh.md`.

## Reviewed identities

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
{
"schema_version": 1,
"event_id": "INC0301970",
"reviewed_at": "2026-08-05",
"provenance": "Reviewed observer-coverage summary for the INC0301970 open-event run. Counts are the canonical event-date baseline preflight facts recorded in docs/audits/2026-08-smithville-source-refresh.md (Event-date baseline preflight table) and the reviewed manifest analyst notes (manifests/INC0301970.json, analyst note 4). Collector sites come from the reviewed collector-location metadata (case-studies/manlan-2019/pilot/collector-locations.json; same collectors, stable locations). No new acquisition; no analysis rerun.",
"summary": "Smithville-origin routes were visible at selected public collectors, but none exposed the reviewed Indiana GigaPOP\u2013Smithville AS-path adjacency and no direct AS19782 observer session was available. No qualifying baseline cohort was formed, so UPDATE archives were not acquired.",
"updates_acquired": false,
"updates_explanation": "No qualifying baseline cohort was formed: zero AS11550 routes traversed AS19782 and zero direct AS19782 observer sessions existed at the selected collectors, so no UPDATE acquisition was justified. The zero-baseline stop is by design.",
"rows": [
{
"collector": "route-views2",
"family": "RouteViews",
"target_visible": true,
"target_prefixes": 13,
"relationship_visible": false,
"direct_observer_session": false,
"human_label": "Target routes visible; reviewed relationship not visible",
"blocker_classification": "TargetPresentRelationshipAbsent + RequiredSessionAbsent",
"note": "221 AS11550 routes; 0 of 221 traverse AS19782"
},
{
"collector": "rrc00",
"family": "RIPE RIS",
"target_visible": true,
"target_prefixes": 13,
"relationship_visible": false,
"direct_observer_session": false,
"human_label": "Target routes visible; reviewed relationship not visible",
"blocker_classification": "TargetPresentRelationshipAbsent + RequiredSessionAbsent",
"note": "546 AS11550 routes; 0 of 546 traverse AS19782"
},
{
"collector": "rrc06",
"family": "RIPE RIS",
"target_visible": true,
"target_prefixes": 13,
"relationship_visible": false,
"direct_observer_session": false,
"human_label": "Target routes visible; reviewed relationship not visible",
"blocker_classification": "TargetPresentRelationshipAbsent + RequiredSessionAbsent",
"note": "65 AS11550 routes; 0 of 65 traverse AS19782"
},
{
"collector": "rrc11",
"family": "RIPE RIS",
"target_visible": true,
"target_prefixes": 13,
"relationship_visible": false,
"direct_observer_session": false,
"human_label": "Target routes visible; reviewed relationship not visible",
"blocker_classification": "TargetPresentRelationshipAbsent + RequiredSessionAbsent",
"note": "91 AS11550 routes; 0 of 91 traverse AS19782"
},
{
"collector": "route-views6",
"family": "RouteViews",
"target_visible": false,
"target_prefixes": 0,
"relationship_visible": false,
"direct_observer_session": false,
"human_label": "Target origin not visible",
"blocker_classification": "TargetOriginNotVisible (IPv6-only collector)",
"note": "0 AS11550 announces of 4,854,128 parsed"
}
]
}
15 changes: 12 additions & 3 deletions case-studies/manlan-2019/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,11 +26,20 @@ study:
- MAN LAN does **not** speak BGP, does not originate routes, and does
**not** appear as an AS-path hop;
- MAN LAN facilitates Layer-2 connectivity among attached networks
(reviewed attachments are listed in `case-study.json` →
`interconnection_context`, with ASN labels only where the reviewed
target research establishes them for 2019-08-21);
(reviewed attached networks are listed in `case-study.json` →
`interconnection_context` → `attachments`, with ASN labels only
where the reviewed target research establishes them for 2019-08-21;
all other source-mentioned entities are classified separately as
test equipment, interconnect context, service references, or
unresolved mentions and are **not** fabric attachments — source
mention is not proof of attachment, a reviewed ASN is not proof of
attachment, and a familiar organization name is not proof of entity
class);
- **Layer-2 attachment is not BGP adjacency**: an attached network may
or may not have exchanged routes directly with other attachments;
- **test/measurement equipment (Ixia) is not a peer**: it has no ASN,
no BGP relationship, and no network-participant role; it appears
only as operational/test-equipment context;
- public BGP observes **exported route consequences** at public
collectors, never switch-fabric state.

Expand Down
67 changes: 41 additions & 26 deletions case-studies/manlan-2019/case-study.json
Original file line number Diff line number Diff line change
Expand Up @@ -395,70 +395,85 @@
"interconnection_context": {
"kind": "Layer2Fabric",
"label": "MAN LAN",
"provenance": "Reviewed 2026-08-04 (session-54 semantic correction): MAN LAN is a Layer-2 exchange/fabric operated by Internet2 for research-and-education interconnection (per the operator after-action report and the reviewed target research, case-studies/manlan-2019/target-research.json). Attachments and their reviewed ASN labels where established come only from the reviewed target research (historical_asns, validity date 2019-08-21); no ASN is guessed. Attachment describes reviewed physical/Layer-2 participation context; it does not prove BGP adjacency, exported route visibility, a commercial relationship, traffic flow, or active state during the event.",
"provenance": "Reviewed 2026-08-04 (session-54 semantic correction) and 2026-08-05 (session-55 entity taxonomy correction): MAN LAN is a Layer-2 exchange/fabric operated by Internet2 for research-and-education interconnection (per the operator after-action report and the reviewed target research, case-studies/manlan-2019/target-research.json). Reviewed attached networks and their ASN labels where established come only from the reviewed target research (historical_asns, validity date 2019-08-21) and the reviewed pilot selection; no ASN is guessed. Entities whose attachment is not established are classified separately (test equipment, interconnect context, service references, unresolved mentions) and are not fabric attachments. Attachment describes reviewed physical/Layer-2 participation context; it does not prove BGP adjacency, exported route visibility, a commercial relationship, traffic flow, or active state during the event.",
"limitations": [
"MAN LAN is a Layer-2 fabric: it has no ASN for the purposes of this case study, does not speak BGP, does not originate routes, and does not appear as an AS-path hop.",
"Layer-2 attachment is not BGP adjacency: an attached network may or may not have exchanged routes directly with other attachments.",
"A source mention (AAR) is not proof of attachment; a reviewed ASN is not by itself proof of MAN LAN attachment; a familiar organization name is not proof of entity class.",
"Test equipment (Ixia) is not a peer, an AS node, or a network participant; it appears only as operational/test-equipment context.",
"The reviewed ASN labels are 2019-08-21 historical identities; current registry metadata must not be used as 2019 truth.",
"The NORDUnet pilot observes one attached network (AS2603) at selected public collectors; it is not a complete analysis of the fabric or of all connectors."
],
"attachments": [
{
"label": "NORDUnet",
"note": "research/education network operator; analyzed target of the completed historical pilot",
"note": "research/education network operator; analyzed target of the completed historical pilot (AAR-documented MAN LAN interface actions; reviewed pilot selection)",
"asn": 2603,
"asn_validity_date": "2019-08-21"
},
{
"label": "ESnet",
"note": "research/education network operator",
"note": "research/education network operator; AAR-documented MAN LAN interface actions (interface shut ~16:39, disabled 17:30, re-enabled 20:44)",
"asn": 293,
"asn_validity_date": "2019-08-21"
},
{
"label": "GÉANT",
"note": "research/education network operator",
"note": "research/education network operator; AAR-documented MAN LAN interface state (still not up 13:13). Attachment identity AS21320 (2019 PeeringDB capture) is distinct from AS20965 observed in actual NORDUnet route paths (current-identity-only review); the differing ASNs are not treated as contradictory",
"asn": 21320,
"asn_validity_date": "2019-08-21"
},
{
"label": "CANARIE",
"note": "research/education network operator",
"note": "research/education network operator; MAN LAN presence explicitly documented (2019 Wikipedia: external segments extend to Manhattan Landing; AAR-documented optic swap/dropped interface 12:03-12:34)",
"asn": 6509,
"asn_validity_date": "2019-08-21"
},
{
"label": "TWAREN",
"note": "research/education network operator",
"asn": 7539,
"asn_validity_date": "2019-08-21"
},
{
"label": "SINET",
"note": "research/education network operator",
"note": "research/education network operator; AAR-documented MAN LAN interface action (swapped with NORDUnet 15:48; BGP not re-establishing)",
"asn": 2907,
"asn_validity_date": "2019-08-21"
},
}
],
"test_equipment": [
{
"label": "Ixia",
"note": "connector/test context; no reviewed ASN label",
"label": "Ixia test equipment",
"note": "network test/measurement hardware (traffic generation and analysis); not an autonomous system, not a BGP peer, not a participant network, and not a reviewed fabric attachment. AAR documents an outage at 16:54. No reviewed ASN; no PeeringDB network entry.",
"asn": null
},
}
],
"interconnect_context": [
{
"label": "WIX interconnect",
"note": "exchange fabric (Washington International Exchange; Internet2 + MAX partnership), not an origin network and not established as an attached network on MAN LAN. AAR documents a brief outage 13:26-13:27, resolved 14:40."
}
],
"operational_services": [
{
"label": "NEAAR",
"note": "ambiguous service identity; no reviewed ASN label",
"asn": null
},
"note": "research/education connectivity consortium and circuit/connectivity service (NEA3R: Networks for European, American, African and Arctic Research); listed as a MAN LAN peer in Internet2's international peers table, but not established as an attached autonomous network. AAR documents VLAN no packets 13:04, up 13:32. No origin ASN."
}
],
"unresolved_mentions": [
{
"label": "OMAN",
"note": "unresolved identity; no reviewed ASN label",
"asn": null
"label": "TWAREN",
"note": "identity historically reviewed (AS7539, 2019-08-21) and AAR documents an interface not receiving light at 13:45, but the reviewed pilot selection flags MAN LAN attachment as less certain (2019 US presence primarily via PacificWave, West Coast). Not rendered as an attached network; the reviewed ASN is retained here as identity detail only.",
"asn": 7539,
"asn_validity_date": "2019-08-21"
},
{
"label": "WIX interconnect",
"note": "interconnect context; no reviewed ASN label",
"label": "OMAN",
"note": "unresolved source mention: no reviewed source connects OMAN/OMREN to MAN LAN or CANARIE; MAN LAN peer lists contain no Oman entry. AAR notes it rides the CANARIE interface. No reviewed ASN, no organization or country-network assumption.",
"asn": null
}
]
],
"entity_review": {
"date": "2026-08-05",
"reason": "Internal walkthrough correction: test equipment and entities without established attachment were rendered as reviewed Layer-2 fabric attachments. Reviewed classification now follows the reviewed target research and pilot selection: only entities whose reviewed evidence supports fabric attachment are AttachedNetwork; all others are classified TestEquipment / InterconnectContext / OperationalService / UnresolvedMention.",
"prior_classification": "10 reviewed attachments (NORDUnet, ESnet, GÉANT, CANARIE, TWAREN, SINET, Ixia, NEAAR, OMAN, WIX interconnect), all rendered as Layer-2 attachments.",
"corrected_classification": "5 reviewed attached networks (NORDUnet, ESnet, GÉANT, CANARIE, SINET); Ixia = test equipment; WIX interconnect = interconnect context; NEAAR = operational/service reference; TWAREN and OMAN = unresolved source mentions (TWAREN AS7539 retained as identity detail).",
"evidence": "case-studies/manlan-2019/target-research.json; case-studies/manlan-2019/pilot/PILOT-SELECTION.md; AAR-derived target roles in case-study.json"
}
}
}
}
13 changes: 13 additions & 0 deletions docs/DOMAIN.md
Original file line number Diff line number Diff line change
Expand Up @@ -427,6 +427,19 @@ the reviewed records establish them, their ASN labels with a validity
date. It is stored as reviewed interpretation in the case-study layer
(`interconnection_context`) and rendered as presentation.

Entities mentioned by sources are classified with a **bounded entity
taxonomy**: `AttachedNetwork` (reviewed evidence supports a Layer-2
attachment), `TestEquipment` (measurement/test hardware — never a
peer, an AS node, or an attached network), `InterconnectContext`
(interconnection or external-fabric reference), `OperationalService`
(service/facility context), and `UnresolvedMention` (role not
sufficiently established). Only reviewed attached networks are fabric
diagram participants; every other class is listed separately as
context. Source mention is not proof of attachment; a reviewed ASN is
not by itself proof of attachment; a Layer-2 attachment is not proof
of BGP adjacency; a familiar organization name is not proof of entity
class.

The context is deliberately **not protocol evidence**: production
analysis never uses fabric attachment metadata in route predicates,
cohort selection, or findings. Layer-2 attachment is not BGP
Expand Down
17 changes: 17 additions & 0 deletions docs/GLOSSARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -228,6 +228,23 @@ provisional run is never mutated.
adjacency, exported route visibility, a commercial relationship,
traffic flow, or active state during the event. Attachment is never
rendered as a directional BGP edge.
- **Source-mentioned entity** — an entity that appears in reviewed
source material (for example an after-action report) without its
role being established. A source mention is **not** proof of fabric
attachment; a reviewed ASN is not by itself proof of attachment; a
familiar organization name is not proof of entity class. Entities
whose role is not established are classified separately (for
example as unresolved mentions) and are not rendered as fabric
attachments.
- **Test equipment** — network test/measurement hardware (for example
a traffic generator or analyzer) mentioned by sources. Test
equipment is not an autonomous system, not a BGP peer, not an AS
node, and not an attached network; it may be described in prose as
operational/test-equipment context only.
- **Interconnect context** — an interconnection or external-fabric
reference (for example another exchange) that is not established as
a participant AS on the reviewed fabric. It is listed as context,
never as an attached network.
- **Observed AS-path diagram** — a presentation of an observed AS path
at one public observer, rendered from canonical route evidence. A
solid arrow is observed AS-path order; arrow direction never labels
Expand Down
18 changes: 18 additions & 0 deletions docs/OBSERVABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,24 @@ NotDirectlyVisible condition stays NotDirectlyObservable even when a pilot
run exists; a narrow pilot's absence of observations never refutes
non-BGP-visible conditions, and never extends beyond its own window.

## Observer-coverage summaries (2026-08)

Event pages may render a reviewed **observation-coverage summary**
(collector-by-collector: collector, collector site, source family,
target-origin visibility, reviewed-relationship visibility, and the
qualification reason). Coverage summaries are derived from canonical
preflight/run evidence (reviewed per-collector counts, the reviewed
archive manifest, and the reviewed manifest analyst notes) and are
reviewed interpretation, not new evidence. Target-origin visibility and
reviewed-relationship visibility are distinct facts and are always
presented separately: target routes may be visible at a collector while
the reviewed relationship is not exposed by its baselines. Collector
site describes where the collector's route reflector is hosted; it is
not the observer peer's location. A coverage summary never claims a
relationship did not exist, that routing was stable, or that no outage
occurred — it states what the selected public observers could and could
not see.

## Pilot timing interpretation

Temporal relations preserve event order: for point action anchors the
Expand Down
8 changes: 8 additions & 0 deletions docs/UX.md
Original file line number Diff line number Diff line change
Expand Up @@ -208,6 +208,14 @@ Evidence semantics are encoded visually and repeated in text:
- **grey undirected line** — reviewed Layer-2 attachment context (never
a BGP adjacency claim).

Case-study pages separate **reviewed attached networks** (the only
entities drawn in the fabric diagram) from **other incident context**
(test equipment, interconnect/service references, unresolved source
mentions), which are listed in tables with their reviewed notes and
never given attachment edges. The fabric attachment count counts only
reviewed attached networks; other source-mentioned entities are
counted separately.

Rules: arrow direction is never described as provider/customer/peer
without separate reviewed evidence; a Layer-2 fabric is never drawn as
an ASN node; a withdrawn route is an absence block, never an arrow to
Expand Down
Loading