panda-rpki
panda-rpki is the staging workspace for the independently distributable RPKI
synchronization and validation component. The first component is
panda-rpki-validator (Cargo package and CLI); its Rust import path is
panda_rpki_validator.
This directory is currently a private staging repository. It has no copied
history from the existing private rpki repository. The normal synchronization
and validation path has now been extracted, together with its daemon and
Docker lifecycle wrapper. The first M5 canonical snapshot/delta baseline and
amd64/arm64 staging image checks are complete; remaining profile/performance
gates still block any public release. Do not use this staging build as a
production validator.
Current milestone
M4/M5 contain the first functional extraction from source commit
74cbebbd3334ac0063761c1a97a88ee000cc2a57: normal RRDP/rsync synchronization,
RPKI validation, RocksDB state, CIR/CCR/report/CSV outputs, the run daemon, and
the snapshot/delta lifecycle wrapper. The verification-only mode is
intentionally deferred. The project license is intentionally TBD; no
external contributions or public release are accepted until ownership and
licensing are approved.
Build and test the staging component
cargo build --locked -p panda-rpki-validator
cargo test --locked -p panda-rpki-validator
cargo fmt --all --check
cargo clippy --locked -p panda-rpki-validator --all-targets -- -D warnings
./scripts/docker/build_image.sh --arch amd64 --allow-dirty --no-save
The extracted test suite currently passes 735 tests with 1 ignored test in
the normal profile. The APNIC offline snapshot/delta profile has also passed
the M5 canonical comparator and a five-run pinned release smoke baseline; the
full cache/fallback/failure/profile matrix is still pending.
For a deterministic single-RIR run against the checked-in test repository,
build the binaries first and invoke the lifecycle wrapper with
RPKI_EXTRA_ARGS=--disable-rrdp --rsync-local-dir ...; the wrapper writes the
normal run ABI under RUN_ROOT/runs/run_0001/.
Docker smoke
./scripts/docker/build_image.sh --arch amd64 --allow-dirty
./scripts/docker/verify_image.sh \
--image panda-rpki-validator:0.1.0-dirty-amd64
The runtime image contains both panda-rpki-validator and
panda-rpki-validator-daemon, the complete normal-run wrapper, and the
redistributable TAL/TA fixtures. It uses one persistent data root mounted at
/var/lib/panda-rpki-validator; run, run-validator, and daemon are
entrypoint subcommands. The wrapper preserves the output contract documented
in
docs/output-abi.md.
For native or container A/B output checks, run the ABI verifier and canonical comparator against two retained run directories:
tests/compat/verify_run_abi.sh /path/to/run_0001
tests/compat/compare_runs.py \
/path/to/original/runs/run_0001 \
/path/to/panda/runs/run_0001
The comparator has matched the original runtime for the APNIC offline
snapshot/delta baseline. Five serial release samples on that small single-RIR
profile stay within the current wall-time gate under a pinned CPU. A live APNIC
run also produced an identical decoded CCR state (MFT/VRP/VAP/TA/RK); only the
time-bearing producedAt byte differed in the raw DER. A concurrent all-RIR
(all5) run is retained as network/fallback evidence, but its source was not an
atomic snapshot (the original image timed out on the ARIN RRDP notification),
so its different CCR state is not a code-parity verdict. See the detailed
M5 live RIR comparison report.
The follow-up remote-231 serial all5 run (old image first, then this image;
one snapshot plus three warm deltas per image with cache/prefetch/parallel
flags) also completed 4/4 runs on each side and retained full artifacts. Its
live CCR/CIR and timing differences are documented separately and are not a
frozen-input parity result: remote-231 all5 cache/prefetch report.
The new image also completed a separate remote-231 all5 long sequence of one
snapshot plus ten deltas; the timing and cache counters are retained as live
health evidence, not as a frozen-input parity gate: one snapshot + ten delta timing report.
Cache, RRDP/fallback, constraints, replay and failure-path profiles remain in
M5.
Repository status
verification-only: deferred to a separate backlog item.- License and copyright owner: TBD; do not add a speculative
LICENSEfile. - Staging Git remote:
https://git.nasp.fit/yuyr/panda-rpki.git(private staging target selected); public visibility, registry prefix, signing identity, and release tags remain unselected until release governance is complete. - Source provenance baseline:
provenance/source-baseline.toml.