04 Mechanisms
Routers and managed switches
Where shaping affects a whole household or office, and where the queue disciplines actually live.

Where the queue actually lives when it matters for everyone
A home router or managed switch is the one place on a local network where every packet must pass. Shape traffic there and you catch phones, laptops, smart televisions, and game consoles in a single policy, without installing anything on any of them. Shape it anywhere else and you are always chasing exceptions.
The queue disciplines that make this possible are not exotic. They are the same mechanisms described in the congestion-control literature, transplanted into firmware. A router running Linux — which most consumer and prosumer devices do, under whatever branded interface sits on top — has access to the kernel's traffic-control subsystem, usually exposed as tc and the family of queueing disciplines it manages. The question is whether the manufacturer bothered to expose or enable them.
Most did not, and for a long time that omission had serious consequences. Memory became cheap in the early 2000s, and router vendors responded by giving their devices enormous buffers. A packet that should have been dropped to signal congestion was instead held in a queue for hundreds of milliseconds, then eventually delivered — late enough to ruin interactive traffic while appearing, by throughput metrics alone, to be perfectly fine. Jim Gettys named and documented this pathology as bufferbloat, and the Bufferbloat.net project, with contributors including Dave Taht and Kathleen Nichols, pushed the problem into public view and drove the development of remedies.

The primary remedy is active queue management. Rather than letting a buffer fill to capacity before dropping anything, an AQM algorithm drops or marks packets early and deliberately, giving senders a signal to slow down before the queue has grown long enough to inflate latency. CoDel — Controlled Delay — was designed by Kathleen Nichols and Van Jacobson, published in 2012, and became the reference algorithm for this class of problem. The CoDel specification is documented in RFC 8289. It measures the sojourn time of packets inside the queue, not the queue length, which makes it robust across different link speeds.
CoDel is often paired with a flow-fair queueing discipline. fq_codel, the combination that emerged from the Bufferbloat.net work, keeps separate queues for separate flows and serves them in a way that prevents any single bulk transfer from monopolising the link. CAKE — Common Applications Kept Enhanced — extends the idea further, adding bandwidth shaping and traffic classification in a single queueing discipline rather than a chain of separate tools. Both are now standard on OpenWrt, the open Linux distribution that runs on a wide range of consumer routers and that has become the practical proving ground for these algorithms.
Managed switches add a different layer. A switch operating at Layer 2 can apply Quality of Service markings and per-port rate limits, but it sees Ethernet frames, not IP packets, so it cannot inspect transport-layer flows or apply per-flow queuing the way a router can. What a managed switch offers is prioritisation across physical ports and the ability to honour DSCP or 802.1p markings already set by the router upstream. In a larger office network, the router sets policy and marks packets; the switches downstream honour those marks and deliver traffic in the right order.
The boundary between router and switch matters when you are reasoning about where delay is introduced. A switch with deep buffers and no AQM will add latency even if the router upstream is perfectly tuned. OpenWrt's documentation on traffic shaping reflects this layered reality: getting the router right is necessary, but a badly configured managed switch between the router and the endpoints can reintroduce the same queue bloat the router was designed to prevent.
The lesson from the bufferbloat decade is that the right place to manage a queue is the point of congestion, which on a typical network is the uplink leaving the router. Everything downstream of that — the managed switches, the access points, the devices themselves — benefits, but none of them is a substitute.
