Search RPD Archives
[rpd] [Last Call] AFPUB-2026-ASN-001-DRAFT02 — six open questions to those opposing
Tshepo Masuku
TshepoMasuku26 at hotmail.com
Thu Jul 23 11:44:58 UTC 2026
Dear Hendrik and colleagues,
Thank you for collecting the questions. I will answer them directly.
1. The two-object case
Where two independent IRR sources publish the same flat AS-SET name, tooling should not silently merge them or guess which one the operator intended. The query should be bound to an explicitly selected source, or the tool should stop and report the ambiguity.
That safeguard is required whether this proposal passes or not. The proposal leaves existing objects untouched, so the AS-GOOGLE example will remain ambiguous after implementation. It therefore cannot be presented as the remedy to that live case. It is a prospective naming restriction, not a complete solution to cross-IRR resolution.
2. Squatting remedy
This proposal creates no mechanism for removing a squatted object from a database AFRINIC does not control. Where the remote database’s rules have been breached, the affected party must use that database operator’s dispute or abuse process.
Where no removal right exists, consumers must treat the IRR source and object name together as the object’s identity, rather than assuming that an unqualified name is globally unique. The absence of a universal takedown mechanism is an architectural problem. An AFRINIC creation rule cannot manufacture authority over every other IRR.
3. Does the proposal provide an improvement?
Yes, narrowly. It would reduce future flat-name collisions in the AFRINIC database and improve attribution for newly created objects.
That does not settle the policy question. A change can be useful while binding policy remains the wrong instrument. The issue is whether the same improvement can be implemented operationally, as it largely is elsewhere, without enlarging the permanent policy layer.
4. The evidence bar
The threshold is not a magic number of incidents. One serious incident may be sufficient if the causal chain is demonstrated.
For an incident to justify this proposal, proponents should show that:
* the harm resulted from creation of a flat AS-SET in the AFRINIC database;
* the proposal, as written, would have prevented it;
* an operational implementation or source-aware, fail-closed tooling would not provide the same protection;
* and the expected benefit, remaining risks, and success criteria are defined.
The AS-GOOGLE case does not satisfy the second point because the proposal leaves that existing object untouched. The AS-AMAZON incident should likewise be mapped to the actual text and scope of this proposal, not merely cited by name. Adoption by four RIRs demonstrates feasibility and institutional preference. It does not, by itself, prove that binding policy is the necessary instrument for AFRINIC.
5. The Impact Assessment
I do not dispute the findings that implementation may have minimal direct member impact and no identified legal or financial issue.
My concern is what the assessment does not answer. It does not establish why policy is required rather than a transparent operational change. It does not resolve existing collisions, define safe multi-source consumer behaviour, measure the expected reduction in harm, or provide review criteria if the claimed benefit does not materialise.
An implementation may be easy and still be unnecessary as binding policy. Ease of enforcement is not the same as justification for enforcement.
6. Capacity
I participate in my individual capacity. I do not claim to represent an organisation or resource member.
That disclosure provides context. It does not turn the policy process into a headcount or make organisational affiliation a condition for having a technical or policy concern considered.
These answers narrow the disagreement. I accept that hierarchical naming offers a limited operational benefit. I do not accept the leap from limited benefit to mandatory policy, particularly when the cited live collision remains unresolved by the proposal and the same technical outcome may be achieved through an accountable operational implementation.
The proper test is not simply whether the working group can create a rule. It is whether the rule is necessary in the mandatory common layer and whether it is the minimum instrument required by running networks.
On that basis, I remain opposed to AFPUB-2026-ASN-001-DRAFT02.
Regards,
Tshepo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.afrinic.net/pipermail/rpd/attachments/20260723/16fb7705/attachment.html>
More information about the RPD
mailing list