yuyr 15c8de82ba
Some checks failed
ci / rust (push) Has been cancelled
ci / docker-runtime (push) Has been cancelled
freeze initial panda-rpki staging
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00
2026-09-01 12:13:53 +08:00

panda-rpki

panda-rpki is the staging workspace for the independently distributable RPKI synchronization and validation component. The first component is panda-rpki-validator (Cargo package and CLI); its Rust import path is panda_rpki_validator.

This directory is currently a private staging repository. It has no copied history from the existing private rpki repository. The normal synchronization and validation path has now been extracted, together with its daemon and Docker lifecycle wrapper. The first M5 canonical snapshot/delta baseline and amd64/arm64 staging image checks are complete; remaining profile/performance gates still block any public release. Do not use this staging build as a production validator.

Current milestone

M4/M5 contain the first functional extraction from source commit 74cbebbd3334ac0063761c1a97a88ee000cc2a57: normal RRDP/rsync synchronization, RPKI validation, RocksDB state, CIR/CCR/report/CSV outputs, the run daemon, and the snapshot/delta lifecycle wrapper. The verification-only mode is intentionally deferred. The project license is intentionally TBD; no external contributions or public release are accepted until ownership and licensing are approved.

Build and test the staging component

cargo build --locked -p panda-rpki-validator
cargo test --locked -p panda-rpki-validator
cargo fmt --all --check
cargo clippy --locked -p panda-rpki-validator --all-targets -- -D warnings
./scripts/docker/build_image.sh --arch amd64 --allow-dirty --no-save

The extracted test suite currently passes 735 tests with 1 ignored test in the normal profile. The APNIC offline snapshot/delta profile has also passed the M5 canonical comparator and a five-run pinned release smoke baseline; the full cache/fallback/failure/profile matrix is still pending.

For a deterministic single-RIR run against the checked-in test repository, build the binaries first and invoke the lifecycle wrapper with RPKI_EXTRA_ARGS=--disable-rrdp --rsync-local-dir ...; the wrapper writes the normal run ABI under RUN_ROOT/runs/run_0001/.

Docker smoke

./scripts/docker/build_image.sh --arch amd64 --allow-dirty
./scripts/docker/verify_image.sh \
  --image panda-rpki-validator:0.1.0-dirty-amd64

The runtime image contains both panda-rpki-validator and panda-rpki-validator-daemon, the complete normal-run wrapper, and the redistributable TAL/TA fixtures. It uses one persistent data root mounted at /var/lib/panda-rpki-validator; run, run-validator, and daemon are entrypoint subcommands. The wrapper preserves the output contract documented in docs/output-abi.md.

For native or container A/B output checks, run the ABI verifier and canonical comparator against two retained run directories:

tests/compat/verify_run_abi.sh /path/to/run_0001
tests/compat/compare_runs.py \
  /path/to/original/runs/run_0001 \
  /path/to/panda/runs/run_0001

The comparator has matched the original runtime for the APNIC offline snapshot/delta baseline. Five serial release samples on that small single-RIR profile stay within the current wall-time gate under a pinned CPU. A live APNIC run also produced an identical decoded CCR state (MFT/VRP/VAP/TA/RK); only the time-bearing producedAt byte differed in the raw DER. A concurrent all-RIR (all5) run is retained as network/fallback evidence, but its source was not an atomic snapshot (the original image timed out on the ARIN RRDP notification), so its different CCR state is not a code-parity verdict. See the detailed M5 live RIR comparison report. The follow-up remote-231 serial all5 run (old image first, then this image; one snapshot plus three warm deltas per image with cache/prefetch/parallel flags) also completed 4/4 runs on each side and retained full artifacts. Its live CCR/CIR and timing differences are documented separately and are not a frozen-input parity result: remote-231 all5 cache/prefetch report. The new image also completed a separate remote-231 all5 long sequence of one snapshot plus ten deltas; the timing and cache counters are retained as live health evidence, not as a frozen-input parity gate: one snapshot + ten delta timing report. Cache, RRDP/fallback, constraints, replay and failure-path profiles remain in M5.

Repository status

  • verification-only: deferred to a separate backlog item.
  • License and copyright owner: TBD; do not add a speculative LICENSE file.
  • Staging Git remote: https://git.nasp.fit/yuyr/panda-rpki.git (private staging target selected); public visibility, registry prefix, signing identity, and release tags remain unselected until release governance is complete.
  • Source provenance baseline: provenance/source-baseline.toml.
Description
No description provided
Readme BSD-3-Clause 1.5 MiB
Languages
Rust 97.6%
Shell 2%
Python 0.2%
Dockerfile 0.2%