Partial

RFC 4724 - Graceful Restart Mechanism for BGP

Every requirement this repository extracted from RFC 4724, the tests bound to it, and what a reader has verified about them. This summary is enrolled and gated by ./le rfc check.

Overview

Positive

what Ze has

Tested both ways64.0%16 of 25 binding obligations

a positive test proves Ze does what the requirement demands and a negative one proves it refuses what the requirement forbids

One polarity plus reason4.0%1 of 25 binding obligations

the requirement admits no counter-case, so one polarity plus a recorded reason is the whole proof available for it

One polarity, unexcused0.0%0 of 25 binding obligations

one direction is tested, the other is neither tested nor excused, and nothing states which

Proven by a recorded break0.0%0 of 43 tagged units

a red was observed once under a recorded procedure, and the unit, the claim and the producer it rested on still hash to what was recorded. The break is not re-run. A test pair is not a proof until one has been observed

Neutral

measures that are neither good news nor bad

Gated MUSTs26of 31 this summary declares

MUST-level requirements the gate HOLDS. A population, not a result: the shares beside it are what says how Ze stands

Out of scope1of 26 gated MUSTs

a {not-applicable} annotation says the obligation does not bind Ze. Scope, not coverage: it is in no share below

Negative

what Ze owes

No test at all32.0%8 of 25 binding obligations

no test carries the requirement id, whether or not a gap states why

The 4 shares marked as a part above are the whole of the 25 obligations that bind Ze: they add to 100%. Proven by a recorded break is a share of TAGGED UNITS, a different population, so it is not one of them.

How to read the colors

A color names what the measure MEANS, not how well Ze scores on it. Green is a good outcome at any value, red is a bad one, and neither a population nor a scope count is an outcome, so both take no color. The number under the label is what says how far Ze has got.

CardTone hereWhy that color
Gated MUSTs neutral no color: a population is a scale, and a larger one is neither good news nor bad. It is the accounting total
Out of scope neutral no color: an obligation that never bound Ze is neither an achievement nor a failure, and counting it either way would be a claim
Tested both ways ok green at every value: a test pair is the outcome this gate exists to produce, and the share under the label is what says how far Ze has got
One polarity plus reason ok green at every value: where no counter-case exists, one polarity IS the complete answer, and a recorded reason is what the gate demands beside it
One polarity, unexcused ok green at zero, RED above it: half a proof with no reason for the other half
No test at all bad green at zero, RED above it: a binding obligation nothing exercises is a claim with nothing behind it, whether or not a reason is stated
Proven by a recorded break ok green at every value: an observed break is the outcome the discrimination gate exists to produce. The denominator is TAGGED UNITS, not obligations, so this share is not one of the parts above
Audit verdicts warn RED on the first weak, wrong or unimplemented verdict, amber while a verdict is no longer current or a gated MUST is unjudged, green when every one is judged sound and current

At a glance

FieldValue
Public status Partial
Enrolment Enrolled
Requirements 31
Gated MUST-level 26
Obligations that bind Ze 25
Not applicable, so out of scope 1
Declared gaps 8
Gated with no test 0
Nightly-only evidence 0
Test tags 43
Tagged units 43
Recorded audit verdicts 0
Discrimination records 0
Summary rfc/short/rfc4724.md
Requirement shard rfc/requirements/rfc4724.md
RFC text rfc/full/rfc4724.txt

Enrolment

Enrolled: Graceful Restart Mechanism for BGP (RFC 4724): 16 MET (GR capability advertise + last-instance negotiate, Restart-State/Forwarding-State bit encoding, End-of-RIB send + detect, mark-stale on non-NOTIFICATION drop, stale deletion on consecutive restart / Restart-Time expiry / F-bit-clear / no-GR-cap re-establish, GR-stale level-1 competes normally in best-path) + 1 single-polarity positive + 8 gap (GR-capability collision-detection override and related receiving-speaker obligations) + 1 not-applicable

What the public ledger says

Status: Partial

What the ledger says is covered Receiving-Speaker Graceful Restart: GR capability advertise and last-instance negotiate, Restart-State/Forwarding-State bit encoding, End-of-RIB send and detect, mark-stale on a non-NOTIFICATION drop, stale deletion on consecutive restart / Restart-Time expiry / F-bit-clear, and GR-stale routes competing normally in best-path (internal/component/bgp/plugins/gr, internal/component/bgp/plugins/rib). The send covers a session where neither speaker advertised a Multiprotocol capability. RFC 4271 carries that session as IPv4 unicast, so RFC 4724 Section 4 owes it a marker. Negotiate (internal/core/bgp/capability/negotiated.go) reads a side that advertised none as advertising ipv4/unicast. sendInitialRoutes (internal/component/bgp/reactor/peer_initial_sync.go) then sends the marker. FRR 10.3.1 decodes it in test/interop/scenarios/no-family-peer-eor-frr. The marker also waits for the plugins that push routes into the session: setState marks it owed, sendInitialRoutes closes the queueing gate and only then waits for every binding ProcessBinding.MayPushRoutes counts, by the send [ update ] rail or the send [ raw ] one (internal/component/bgp/reactor/peer_initial_sync.go, peer_settings.go). test/plugin/initial-sync-barrier-raw.ci asserts the injected route and the marker byte for byte, in that order, and goes red when the SendRaw arm of that predicate is removed. Requirements bound per line in rfc/short/rfc4724.md.
What the ledger says remains Eight MUST gaps annotated in rfc/short/rfc4724.md: ze implements the Restarting-Speaker path as GR signaling only and does not retain its own Loc-RIB across a restart, so it runs no selection-deferral cycle and exposes no Selection_Deferral_Timer (RFC4724-4.1-1, 4.1-2, 4.1-3, 4.1-5, 4.1-6, 4.1-8); and on a re-established GR-capable session it follows plain RFC 4271 Section 6.8 collision detection (closes the new connection, keeps the existing session) rather than the RFC 4724 Section 4.2 override that treats the new OPEN as terminating the old session (RFC4724-4.2-1, 4.2-2).

Coverage

BucketCountWhat it counts
Positive and negative tests 16 one part of the gated population
Annotated instead of tested 10 one part of the gated population
One polarity only 0 one part of the gated population
No test and no annotation 0 one part of the gated population
Evidence that runs nightly only 0 an overlay: each of these is also counted by the part it falls in
Gated MUST-level requirements26every gated MUST falls in exactly one bucket above

Positive and negative tests (16): RFC4724-3-2, RFC4724-3-3, RFC4724-3-4, RFC4724-4-1, RFC4724-4-2, RFC4724-4.1-4, RFC4724-4.1-7, RFC4724-4.2-3, RFC4724-4.2-4, RFC4724-4.2-5, RFC4724-4.2-6, RFC4724-4.2-7, RFC4724-4.2-8, RFC4724-4.2-9, RFC4724-4.2-10, RFC4724-4.2-11

Annotated instead of tested (10): RFC4724-3-1, RFC4724-3-5, RFC4724-4.1-1, RFC4724-4.1-2, RFC4724-4.1-3, RFC4724-4.1-5, RFC4724-4.1-6, RFC4724-4.1-8, RFC4724-4.2-1, RFC4724-4.2-2

Requirements

RequirementLevelSectionTests
RFC4724-3-1A BGP speaker MUST NOT include more than one instance of the Graceful Restart Capability in the capability advertisement (Section 3)
MUST 3
negativeno testno negative test

{single-polarity}: ze's GR sender emits exactly one code-64 declaration per peer (internal/component/bgp/plugins/gr/gr.go:703 extractGRCapabilities appends one CapabilityDecl per peer) and the encoder writes a single TLV (internal/core/bgp/capability/capability.go:553 WriteTo); there is no code path that emits two instances, so the more-than-one case cannot be constructed to test negatively

RFC4724-3-2Reserved bits in Restart Flags MUST be set to zero by the sender (Section 3)
MUST 3
RFC4724-3-3Reserved bits in Address Family Flags MUST be set to zero by the sender (Section 3)
MUST 3
RFC4724-3-4If more than one instance of the Graceful Restart Capability is received, the receiver MUST ignore all but the last instance (Section 3)
MUST 3
RFC4724-3-5When R bit is set, peer MUST NOT wait for End-of-RIB marker from the speaker before advertising routing information (Section 3)
MUST 3
positiveno testno positive test
negativeno testno negative test

{not-applicable}: ze advertises its Adj-RIB-Out and per-family End-of-RIB immediately on reaching Established (internal/component/bgp/reactor/peer_initial_sync.go:277,334) and has no receive-side mechanism that gates advertisement on a peer's End-of-RIB; the only End-of-RIB timer (internal/component/bgp/reactor/session_health.go:114 startEORTimer) raises a health warning and never defers advertisement, so there is no wait state for the R bit to override

RFC4724-4-1The End-of-RIB marker MUST be sent by a BGP speaker to its peer once it completes the initial routing update for an address family (Section 4)
MUST 4
RFC4724-4-2Normal BGP procedures MUST be followed when the TCP session terminates due to sending or receiving a NOTIFICATION message (Section 4)
MUST 4
RFC4724-4.1-1Restarting Speaker MUST retain, if possible, the forwarding state for BGP routes in Loc-RIB (Section 4.1)
MUST 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: ze's Restarting Speaker path implements only GR signaling -- it writes a restart marker and sets the R bit (internal/component/bgp/grmarker/grmarker.go, internal/component/bgp/reactor/peer.go:574) -- and does not retain its own in-memory Loc-RIB forwarding state across a process restart within the bgp packages; the Loc-RIB is rebuilt from scratch on restart

RFC4724-4.1-2Restarting Speaker MUST mark retained forwarding state as stale (Section 4.1)
MUST 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: because ze does not retain its own Loc-RIB across a restart (see RFC4724-4.1-1), there is no retained own-forwarding state to mark stale; the stale-marking machinery (internal/component/bgp/plugins/rib/rib_commands.go:817 markStaleCommand) applies to routes received from a restarting peer, not to ze's own routes on ze's restart

RFC4724-4.1-3Restarting Speaker MUST NOT differentiate between stale and other information during forwarding (Section 4.1)
MUST NOT 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: this governs forwarding over ze's own retained stale Loc-RIB, which ze does not build on restart (see RFC4724-4.1-1); the generic non-differentiation of level-1 stale in best-path selection (internal/component/bgp/plugins/rib/bestpath.go:308) is the Receiving Speaker path for peer routes, not ze's own routes as a Restarting Speaker

RFC4724-4.1-4Restarting Speaker MUST set the "Restart State" (R) bit in the Graceful Restart Capability of the OPEN message (Section 4.1)
MUST 4.1
positiveunit/verifyTestSetRBitOnCapability
negativeunit/verifyTestSetRBitTimeGatePattern
RFC4724-4.1-5Restarting Speaker MUST defer route selection per address family until End-of-RIB from all peers or Selection_Deferral_Timer expires (Section 4.1)
MUST 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: ze runs best-path selection as updates arrive and has no selection-deferral path keyed on End-of-RIB; the only End-of-RIB timer (internal/component/bgp/reactor/session_health.go:114 startEORTimer) raises a health warning and does not gate route selection

RFC4724-4.1-6After route selection, forwarding state MUST be updated and stale information MUST be removed (Section 4.1)
MUST 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: this is the completion step of the deferred-selection cycle ze does not run (see RFC4724-4.1-5); with no own-Loc-RIB stale state (RFC4724-4.1-1) there is no post-selection stale removal on ze's own restart

RFC4724-4.1-7Once initial update is complete, the End-of-RIB marker MUST be sent (Section 4.1)
MUST 4.1
positiveunit/verifyTestBuildEOR_IPv4Unicast
negativeunit/verifyTestIsEndOfRIBAnyFamily
RFC4724-4.1-8An implementation MUST support a configurable Selection_Deferral_Timer (Section 4.1)
MUST 4.1
positiveno testno positive test
negativeno testno negative test

{gap}: ze exposes no Selection_Deferral_Timer configuration -- the GR YANG model (internal/component/bgp/plugins/gr/yang/ze-graceful-restart.yang) carries restart-time and long-lived-stale-time only, and no code defers selection (see RFC4724-4.1-5)

RFC4724-4.2-1Receiving Speaker MUST treat subsequent open connection from peer as termination of old TCP session when GR Capability was received (Section 4.2)
MUST 4.2
positiveno testno positive test
negativeno testno negative test

{gap}: ze follows plain RFC 4271 Section 6.8 collision detection -- a new inbound connection while the session is Established is rejected with Cease/Connection Collision (internal/component/bgp/reactor/reactor_connection.go:134-136), with no GR-capability branch that treats the new OPEN as terminating the old session

RFC4724-4.2-2Previous TCP session MUST be closed, and the new one retained (Section 4.2)
MUST 4.2
positiveno testno positive test
negativeno testno negative test

{gap}: the same RFC 4271 collision path closes the NEW connection and keeps the existing Established session (internal/component/bgp/reactor/reactor_connection.go:134-136 rejectConnectionCollisionWithSettings), the opposite of the RFC 4724 Section 4.2 override that closes the previous session and retains the new one

RFC4724-4.2-3Receiving Speaker MUST retain routes from peer for all address families previously in Graceful Restart Capability and MUST mark them as stale (Section 4.2)
MUST 4.2
RFC4724-4.2-4On consecutive restarts, previously stale routes from the peer MUST be deleted (Section 4.2)
MUST 4.2
RFC4724-4.2-5Receiving Speaker MUST NOT differentiate between stale and other routing information during forwarding (Section 4.2)
MUST NOT 4.2
RFC4724-4.2-6The "Restart State" bit in the Receiving Speaker's OPEN MUST NOT be set unless the Receiving Speaker has itself restarted (Section 4.2)
MUST NOT 4.2
positiveunit/verifyTestSetRBitTimeGatePattern
negativeunit/verifyTestSetRBitOnCapability
RFC4724-4.2-7If session not re-established within Restart Time, Receiving Speaker MUST delete all stale routes from the peer (Section 4.2)
MUST 4.2
RFC4724-4.2-8If F bit not set, or AFI/SAFI missing, or no GR capability on re-establishment, Receiving Speaker MUST immediately remove all stale routes for that address family (Section 4.2)
MUST 4.2
RFC4724-4.2-9Receiving Speaker MUST send End-of-RIB marker once it completes the initial update (Section 4.2)
MUST 4.2
positiveunit/verifyTestBuildEOR_IPv4Unicast
negativeunit/verifyTestIsEndOfRIBAnyFamily
RFC4724-4.2-10Receiving Speaker MUST replace stale routes by routing updates received from the peer (Section 4.2)
MUST 4.2
RFC4724-4.2-11Once End-of-RIB is received from peer, Receiving Speaker MUST immediately remove any routes still marked as stale for that address family (Section 4.2)
MUST 4.2
positiveunit/verifyTestGRStateManagerEORPurge
RFC4724-2-1Sending End-of-RIB upon completion of initial update is recommended even without GR (Section 2)
RECOMMENDED 2
positiveno testno positive test
negativeno testno negative test
RFC4724-4-3Advertising Graceful Restart Capability even without forwarding preservation ability is recommended (Section 4)
RECOMMENDED 4
positiveno testno positive test
negativeno testno negative test
RFC4724-4-4A BGP speaker MAY advertise the Graceful Restart Capability for an address family if it can preserve forwarding state (Section 4)
MAY 4
positiveno testno positive test
negativeno testno negative test
RFC4724-4.2-12Receiving Speaker MAY delete all stale routes if peer's forwarding state is determined non-viable (e.g., via BFD) (Section 4.2)
MAY 4.2
positiveno testno positive test
negativeno testno negative test
RFC4724-4.2-13An implementation MAY support a configurable stale route retention timer (Section 4.2)
MAY 4.2
positiveno testno positive test
negativeno testno negative test

Gaps and untested MUSTs

RequirementStateReason
RFC4724-3-5 When R bit is set, peer MUST NOT wait for End-of-RIB marker from the speaker before advertising routing information (Section 3) no test no test carries this requirement id; annotated {not-applicable}: ze advertises its Adj-RIB-Out and per-family End-of-RIB immediately on reaching Established (internal/component/bgp/reactor/peer_initial_sync.go:277,334) and has no receive-side mechanism that gates advertisement on a peer's End-of-RIB; the only End-of-RIB timer (internal/component/bgp/reactor/session_health.go:114 startEORTimer) raises a health warning and never defers advertisement, so there is no wait state for the R bit to override
RFC4724-4.1-1 Restarting Speaker MUST retain, if possible, the forwarding state for BGP routes in Loc-RIB (Section 4.1) {gap}, no test ze's Restarting Speaker path implements only GR signaling -- it writes a restart marker and sets the R bit (internal/component/bgp/grmarker/grmarker.go, internal/component/bgp/reactor/peer.go:574) -- and does not retain its own in-memory Loc-RIB forwarding state across a process restart within the bgp packages; the Loc-RIB is rebuilt from scratch on restart
RFC4724-4.1-2 Restarting Speaker MUST mark retained forwarding state as stale (Section 4.1) {gap}, no test because ze does not retain its own Loc-RIB across a restart (see RFC4724-4.1-1), there is no retained own-forwarding state to mark stale; the stale-marking machinery (internal/component/bgp/plugins/rib/rib_commands.go:817 markStaleCommand) applies to routes received from a restarting peer, not to ze's own routes on ze's restart
RFC4724-4.1-3 Restarting Speaker MUST NOT differentiate between stale and other information during forwarding (Section 4.1) {gap}, no test this governs forwarding over ze's own retained stale Loc-RIB, which ze does not build on restart (see RFC4724-4.1-1); the generic non-differentiation of level-1 stale in best-path selection (internal/component/bgp/plugins/rib/bestpath.go:308) is the Receiving Speaker path for peer routes, not ze's own routes as a Restarting Speaker
RFC4724-4.1-5 Restarting Speaker MUST defer route selection per address family until End-of-RIB from all peers or Selection_Deferral_Timer expires (Section 4.1) {gap}, no test ze runs best-path selection as updates arrive and has no selection-deferral path keyed on End-of-RIB; the only End-of-RIB timer (internal/component/bgp/reactor/session_health.go:114 startEORTimer) raises a health warning and does not gate route selection
RFC4724-4.1-6 After route selection, forwarding state MUST be updated and stale information MUST be removed (Section 4.1) {gap}, no test this is the completion step of the deferred-selection cycle ze does not run (see RFC4724-4.1-5); with no own-Loc-RIB stale state (RFC4724-4.1-1) there is no post-selection stale removal on ze's own restart
RFC4724-4.1-8 An implementation MUST support a configurable Selection_Deferral_Timer (Section 4.1) {gap}, no test ze exposes no Selection_Deferral_Timer configuration -- the GR YANG model (internal/component/bgp/plugins/gr/yang/ze-graceful-restart.yang) carries restart-time and long-lived-stale-time only, and no code defers selection (see RFC4724-4.1-5)
RFC4724-4.2-1 Receiving Speaker MUST treat subsequent open connection from peer as termination of old TCP session when GR Capability was received (Section 4.2) {gap}, no test ze follows plain RFC 4271 Section 6.8 collision detection -- a new inbound connection while the session is Established is rejected with Cease/Connection Collision (internal/component/bgp/reactor/reactor_connection.go:134-136), with no GR-capability branch that treats the new OPEN as terminating the old session
RFC4724-4.2-2 Previous TCP session MUST be closed, and the new one retained (Section 4.2) {gap}, no test the same RFC 4271 collision path closes the NEW connection and keeps the existing Established session (internal/component/bgp/reactor/reactor_connection.go:134-136 rejectConnectionCollisionWithSettings), the opposite of the RFC 4724 Section 4.2 override that closes the previous session and retains the new one

Proof state

A tagged unit reads unproven where no discrimination record exists for it: nothing in this tree has been observed to break it, so the claim its tag makes is unproven.

RFC4724-3-1

A BGP speaker MUST NOT include more than one instance of the Graceful Restart Capability in the capability advertisement (Section 3)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
positive TestExtractGRCapabilities_CapabilityDecl unit/verify unproven

RFC4724-3-2

Reserved bits in Restart Flags MUST be set to zero by the sender (Section 3)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGracefulRestartEncodeReservedBits unit/verify unproven
positive TestGracefulRestartEncodeReservedBits unit/verify unproven

RFC4724-3-3

Reserved bits in Address Family Flags MUST be set to zero by the sender (Section 3)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGracefulRestartEncodeReservedBits unit/verify unproven
positive TestGracefulRestartEncodeReservedBits unit/verify unproven

RFC4724-3-4

If more than one instance of the Graceful Restart Capability is received, the receiver MUST ignore all but the last instance (Section 3)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestNegotiateGracefulRestartLastInstance unit/verify unproven
positive TestNegotiateGracefulRestartLastInstance unit/verify unproven

RFC4724-3-5

When R bit is set, peer MUST NOT wait for End-of-RIB marker from the speaker before advertising routing information (Section 3)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-3-5, so no unit is bound to it.

RFC4724-4-1

The End-of-RIB marker MUST be sent by a BGP speaker to its peer once it completes the initial routing update for an address family (Section 4)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestIsEndOfRIBAnyFamily unit/verify unproven
positive TestBuildEOR_IPv4Unicast unit/verify unproven
positive TestInitialSyncBarrierCreditsOnlyTheProcessesItNames unit/verify unproven
positive TestInitialSyncClosesTheQueueGateBeforeItWaitsForRoutePushingPlugins unit/verify unproven
positive TestInitialSyncEORReachesTheSilentFamilyToo unit/verify unproven
positive TestInitialSyncEORSentWhenNeitherSideDeclaredAFamily unit/verify unproven
positive TestRoutePushingBindingsCountBothRails unit/verify unproven
positive checkNoFamilyEndOfRIB interop/nightly unproven

RFC4724-4-2

Normal BGP procedures MUST be followed when the TCP session terminates due to sending or receiving a NOTIFICATION message (Section 4)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRStateManagerRouteRetention unit/verify unproven
positive TestGRStateManagerNotificationBypass unit/verify unproven

RFC4724-4.1-1

Restarting Speaker MUST retain, if possible, the forwarding state for BGP routes in Loc-RIB (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-1, so no unit is bound to it.

RFC4724-4.1-2

Restarting Speaker MUST mark retained forwarding state as stale (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-2, so no unit is bound to it.

RFC4724-4.1-3

Restarting Speaker MUST NOT differentiate between stale and other information during forwarding (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-3, so no unit is bound to it.

RFC4724-4.1-4

Restarting Speaker MUST set the "Restart State" (R) bit in the Graceful Restart Capability of the OPEN message (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestSetRBitTimeGatePattern unit/verify unproven
positive TestSetRBitOnCapability unit/verify unproven

RFC4724-4.1-5

Restarting Speaker MUST defer route selection per address family until End-of-RIB from all peers or Selection_Deferral_Timer expires (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-5, so no unit is bound to it.

RFC4724-4.1-6

After route selection, forwarding state MUST be updated and stale information MUST be removed (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-6, so no unit is bound to it.

RFC4724-4.1-7

Once initial update is complete, the End-of-RIB marker MUST be sent (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestIsEndOfRIBAnyFamily unit/verify unproven
positive TestBuildEOR_IPv4Unicast unit/verify unproven

RFC4724-4.1-8

An implementation MUST support a configurable Selection_Deferral_Timer (Section 4.1)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.1-8, so no unit is bound to it.

RFC4724-4.2-1

Receiving Speaker MUST treat subsequent open connection from peer as termination of old TCP session when GR Capability was received (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.2-1, so no unit is bound to it.

RFC4724-4.2-2

Previous TCP session MUST be closed, and the new one retained (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

No test carries RFC4724-4.2-2, so no unit is bound to it.

RFC4724-4.2-3

Receiving Speaker MUST retain routes from peer for all address families previously in Graceful Restart Capability and MUST mark them as stale (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRStateManagerNoGRCapability unit/verify unproven
negative TestRFC4724SessionDownWithoutCapabilityRetainsNothing unit/verify unproven
positive TestGRStateManagerRouteRetention unit/verify unproven
positive TestRFC4724RetentionCoversEveryAdvertisedFamily unit/verify unproven
positive TestRFC4724SessionDownRetainsAndMarksRoutesStale unit/verify unproven

RFC4724-4.2-4

On consecutive restarts, previously stale routes from the peer MUST be deleted (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRConsecutiveRestartClearsPriorStale unit/verify unproven
positive TestGRConsecutiveRestartClearsPriorStale unit/verify unproven

RFC4724-4.2-5

Receiving Speaker MUST NOT differentiate between stale and other routing information during forwarding (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestComparePair_LLGRStale unit/verify unproven
positive TestComparePair_GRStaleCompetesNormally unit/verify unproven

RFC4724-4.2-6

The "Restart State" bit in the Receiving Speaker's OPEN MUST NOT be set unless the Receiving Speaker has itself restarted (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestSetRBitOnCapability unit/verify unproven
positive TestSetRBitTimeGatePattern unit/verify unproven

RFC4724-4.2-7

If session not re-established within Restart Time, Receiving Speaker MUST delete all stale routes from the peer (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRStateManagerReconnectWithFBit unit/verify unproven
positive TestGRStateManagerTimerExpiry unit/verify unproven

RFC4724-4.2-8

If F bit not set, or AFI/SAFI missing, or no GR capability on re-establishment, Receiving Speaker MUST immediately remove all stale routes for that address family (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRStateManagerReconnectWithFBit unit/verify unproven
positive TestGRStateManagerReconnectFBitZero unit/verify unproven

RFC4724-4.2-9

Receiving Speaker MUST send End-of-RIB marker once it completes the initial update (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestIsEndOfRIBAnyFamily unit/verify unproven
positive TestBuildEOR_IPv4Unicast unit/verify unproven
positive TestInitialSyncEORReachesTheSilentFamilyToo unit/verify unproven

RFC4724-4.2-10

Receiving Speaker MUST replace stale routes by routing updates received from the peer (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestFamilyRIB_InsertNewDuringStale unit/verify unproven
positive TestFamilyRIB_InsertClearsStale unit/verify unproven

RFC4724-4.2-11

Once End-of-RIB is received from peer, Receiving Speaker MUST immediately remove any routes still marked as stale for that address family (Section 4.2)

Audit verdict: not audited: no reader has judged these tests

PolarityTestKind and tierProof state
negative TestGRStateManagerEORForNonGRPeer unit/verify unproven
positive TestGRStateManagerEORPurge unit/verify unproven

Extraction sign-off

No extraction sign-off exists for RFC 4724, so no reviewer has walked its text sentence by sentence.

Superseded

No document obsoletes RFC 4724, so its obligations are stated where they were written.