a positive test proves Ze does what the requirement demands and a negative one proves it refuses what the requirement forbids
RFC 9117 - Revised Validation Procedure for BGP Flow Specifications
Every requirement this repository extracted from RFC 9117, the tests bound to it, and what a reader has verified about them. This summary is enrolled and gated by ./le rfc check.
Overview
Positive
what Ze has
the requirement admits no counter-case, so one polarity plus a recorded reason is the whole proof available for it
one direction is tested, the other is neither tested nor excused, and nothing states which
scoped tests exist; the remaining obligation is unmet or unproven, with zero whole-requirement credit
no test carries the requirement id, whether or not a gap states why
a red was observed once under a recorded procedure, and the unit, the claim and the producer it rested on still hash to what was recorded. The break is not re-run. A test pair is not a proof until one has been observed
0 weak, wrong or unimplemented, 0 no longer current. Each is named below under its own requirement id
Neutral
measures that are neither good news nor bad
MUST-level requirements the gate HOLDS. A population, not a result: the shares beside it are what says how Ze stands
an obligation that does not bind Ze. A {not-applicable} annotation says it never bound; a {feature-declined} annotation says its condition is an optional feature Ze does not offer, and quotes the RFC sentence that makes it optional. Scope, not coverage: it stays in the denominator every share on this page is taken over
a {not-applicable} annotation says the obligation does not bind Ze, so no test is owed for it. It stays in the denominator every share here is taken over
a {lower-layer} annotation says a layer under Ze performs the behavior, on state Ze installs into that layer, and names the producer that installs it. The obligation binds Ze and is met; Ze proves none of it, because its own boundary carries no value the behavior reads
a {feature-declined} annotation says the obligation is conditional on a feature the RFC makes optional and Ze does not offer, and it quotes the sentence that makes it optional. The condition is false, so nothing is owed and nothing is missing. It stays in the denominator every share here is taken over
The 8 shares marked as a part above are the whole of the 2 gated MUSTs: they add to 100%. Proven by a recorded break is a share of TAGGED UNITS, a different population, so it is not one of them.
How to read the colors
A color names what the measure MEANS, not how well Ze scores on it. Green is a good outcome at any value, red is a bad one, and neither a population nor a scope count is an outcome, so both take no color. The number under the label is what says how far Ze has got.
| Card | Tone here | Why that color |
|---|---|---|
| Gated MUSTs | neutral | no color: a population is a scale, and a larger one is neither good news nor bad. It is the accounting total |
| Out of scope | neutral | no color: an obligation that never bound Ze is neither an achievement nor a failure, and counting it either way would be a claim |
| Tested both ways | ok | green at every value: a test pair is the outcome this gate exists to produce, and the share under the label is what says how far Ze has got |
| One polarity plus reason | ok | green at every value: where no counter-case exists, one polarity IS the complete answer, and a recorded reason is what the gate demands beside it |
| One polarity, unexcused | ok | green at zero, RED above it: half a proof with no reason for the other half |
| Partial proof; remaining gap | ok | green at zero, RED above it: a tested clause cannot prove the whole requirement |
| No test at all | ok | green at zero, RED above it: a binding obligation nothing exercises is a claim with nothing behind it, whether or not a reason is stated |
| Not applicable | neutral | no color: an obligation that never bound Ze is neither an achievement nor a failure, and counting it either way would be a claim |
| Met below Ze | neutral | no color: an obligation met below Ze is neither a test Ze wrote nor work Ze owes, and the two green shares above are what says how much Ze proves itself |
| Optional feature declined | neutral | no color: an obligation whose condition Ze never meets is neither an achievement nor a failure. The absent FEATURE is disclosed on the RFC's own status row, as an implementation gap a later scope decision can revisit |
| Proven by a recorded break | ok | green at every value: an observed break is the outcome the discrimination gate exists to produce. The denominator is TAGGED UNITS, not obligations, so this share is not one of the parts above |
| Audit verdicts | ok | RED on the first weak, wrong or unimplemented verdict, amber while a verdict is no longer current or a gated MUST is unjudged, green when every one is judged sound and current |
At a glance
| Field | Value |
|---|---|
| Public status | Partial |
| Enrolment | Enrolled |
| Requirements | 5 |
| Gated MUST-level | 2 |
| Not applicable, so out of scope | 0 |
| Declared gaps | 0 |
| Declared gaps a test demonstrates | 0 |
| Gated with no test | 0 |
| Nightly-only evidence | 0 |
| Test tags | 8 |
| Tagged units | 8 |
| Recorded audit verdicts | 2 |
| Discrimination records | 8 |
| Summary | rfc/short/rfc9117.md |
| Requirement shard | rfc/requirements/rfc9117.md |
| RFC text | rfc/full/rfc9117.txt |
Enrolment
Enrolled: Revised FlowSpec validation: two MUST-level requirements, both met by flowSpecAuthorized (internal/component/bgp/plugins/rib/rib_flowspec_validation.go) on the received-UPDATE rail. RFC9117-4.1-1 redefines step (b) of RFC 8955 Section 6 (the originator match, or an empty or confederation-only AS_PATH); RFC9117-4.2-1 replaces the RFC 8955 neighboring-AS rule with a comparison against the left-most AS of the best-match unicast route. Both are proven in both polarities by TestFlowSpecAuthorizationFromReceivedUpdates. Enrolled 2026-10-02 so the redefined rule has its own row: RFC8955-6-2, which quoted the replaced sentence, is retired under D-10 (rfc/corrections/rfc8955.md).
What the public ledger says
Status: Partial
What the ledger says is covered
- Received IPv4 and IPv6 FlowSpec (SAFI 133/134) rules are feasible through the revised step (b): an originator match with the covering unicast route, or an empty or confederation-only AS_PATH
- an eBGP rule's left-most AS must equal the covering unicast route's left-most AS, so FlowSpec crosses a route server that does not prepend its AS. Condition (b.2) is always enabled.
What the ledger says remains:
No configuration disables condition (b.2) and no policy permits a non-empty AS_PATH (the two Section 4.1 MAYs). No discriminating test yet proves that the covering unicast route compared is the longest-prefix (best-match) one.Coverage
| Bucket | Count | What it counts |
|---|---|---|
| Positive and negative tests | 2 | one part of the gated population |
| Annotated (including scoped evidence) | 0 | one part of the gated population |
| One polarity only | 0 | one part of the gated population |
| No test and no annotation | 0 | one part of the gated population |
| Partial proof; remaining gap (subset of annotated; zero whole-requirement credit) | 0 | an overlay: each of these is also counted by the part it falls in |
| Evidence that runs nightly only | 0 | an overlay: each of these is also counted by the part it falls in |
| Derived from other rows | 0 | outside the gated population: each asserts nothing and derives its state from the rows it names, which the parts above already count |
| Gated MUST-level requirements | 2 | every gated MUST falls in exactly one bucket above |
Positive and negative tests (2): RFC9117-4.1-1, RFC9117-4.2-1
Requirements
| Requirement | Level | Section | Tests |
|---|---|---|---|
RFC9117-4.1-1 | b) One of the following conditions MUST hold true: | | 1. The originator of the Flow Specification matches the | originator of the best-match unicast route for the | destination prefix embedded in the Flow Specification (this | is the unicast route with the longest possible prefix | length covering the destination prefix embedded in the Flow | Specification). | | 2. The AS_PATH attribute of the Flow Specification is empty or | contains only an AS_CONFED_SEQUENCE segment [RFC5065]. (§4.1) | ||
| MUST | 4.1 - Revision of Route Feasibility | ||
RFC9117-4.2-1 | BGP Flow Specification implementations MUST enforce that the AS | in the left-most position of the AS_PATH attribute of a Flow | Specification route received via the External Border Gateway | Protocol (eBGP) matches the AS in the left-most position of the | AS_PATH attribute of the best-match unicast route for the | destination prefix embedded in the Flow Specification NLRI. (§4.2) | ||
| MUST | 4.2 - Revision of AS_PATH Validation | ||
RFC9117-4.1-2 | This condition SHOULD be enabled by default. (§4.1) | ||
| SHOULD | 4.1 - Revision of Route Feasibility | positive
no testno positive testnegative
no testno negative test |
|
RFC9117-4.1-3 | This condition MAY be disabled by explicit | configuration on a BGP speaker. (§4.1) | ||
| MAY | 4.1 - Revision of Route Feasibility | positive
no testno positive testnegative
no testno negative test |
|
RFC9117-4.1-4 | As an extension to this rule, a given non-empty AS_PATH | (besides AS_CONFED_SEQUENCE segments) MAY be permitted | by policy. (§4.1) | ||
| MAY | 4.1 - Revision of Route Feasibility | positive
no testno positive testnegative
no testno negative test |
|
Gaps and untested MUSTs
RFC 9117 declares no gap, and every gated MUST it carries has a test bound to it.
Proof state
A tagged unit reads unproven where no discrimination record exists for it: nothing in this tree has been observed to break it, so the claim its tag makes is unproven.
RFC9117-4.1-1
b) One of the following conditions MUST hold true: | | 1. The originator of the Flow Specification matches the | originator of the best-match unicast route for the | destination prefix embedded in the Flow Specification (this | is the unicast route with the longest possible prefix | length covering the destination prefix embedded in the Flow | Specification). | | 2. The AS_PATH attribute of the Flow Specification is empty or | contains only an AS_CONFED_SEQUENCE segment [RFC5065]. (§4.1)
Audit verdict: enforced (the tests do what the requirement demands), fresh. RFC 9117 Section 4.1: 'b) One of the following conditions MUST hold true: 1. The originator of the Flow Specification matches the originator of the best-match unicast route for the destination prefix embedded in the Flow Specification (this is the unicast route with the longest possible prefix length covering the destination prefix embedded in the Flow Specification). 2. The AS_PATH attribute of the Flow Specification is empty or contains only an AS_CONFED_SEQUENCE segment [RFC5065].' Section 1 adds: 'If AS_CONFED_SET segments are also present in the AS_PATH, the same considerations apply to them.' Both tagged functions were read: internal/component/bgp/plugins/rib/rib_flowspec_validation_test.go::TestFlowSpecAuthorizationFromReceivedUpdates and internal/component/bgp/plugins/rib/rfc9117_best_match_test.go::TestRFC9117AuthorizationUsesLongestCoveringRoute. The former installs matching ORIGINATOR_ID, empty-path and each confederation-segment control, and refuses nonlocal paths whose transport or ORIGINATOR_ID differs. Shared BGP identifiers cannot substitute for the transport address. The latter now supplies /8 and /16 routes covering a /24, with distinct originators: internal cases change only the rule originator and require exactly the /16 match to authorize. The nonempty internal AS_SEQUENCE prevents condition b.2 masking b.1, and internal peering isolates originator selection from the external-AS check. Both functions assert current-generation eligibility, received-route retention, candidate availability through the real gatherCandidatesLocked producer, and exact selected-event NLRI/actions or no event. Producers read: handleReceivedStructured, reconcileFlowSpecs, flowSpecDestination, flowSpecASPath, flowSpecOriginator and flowSpecAuthorized in the RIB. The /16 comparison cases close the prior weak verdict's missing longest-prefix clause; selecting /8 instead reverses their exact expectations. Stored revert records establish reach only; this is a source judgment, with no new execution claim. Optional configuration to disable b.2 or permit nonempty paths is outside this MUST and remains absent, not implementation authorization.
| Polarity | Test | Kind and tier | Proof state |
|---|---|---|---|
| negative | TestRFC9117AuthorizationUsesLongestCoveringRoute |
unit/verify | revert, verified |
| negative | TestFlowSpecAuthorizationFromReceivedUpdates |
unit/verify | revert, verified |
| positive | TestRFC9117AuthorizationUsesLongestCoveringRoute |
unit/verify | revert, verified |
| positive | TestFlowSpecAuthorizationFromReceivedUpdates |
unit/verify | revert, verified |
RFC9117-4.2-1
BGP Flow Specification implementations MUST enforce that the AS | in the left-most position of the AS_PATH attribute of a Flow | Specification route received via the External Border Gateway | Protocol (eBGP) matches the AS in the left-most position of the | AS_PATH attribute of the best-match unicast route for the | destination prefix embedded in the Flow Specification NLRI. (§4.2)
Audit verdict: enforced (the tests do what the requirement demands), fresh. RFC 9117 Section 4.2: 'BGP Flow Specification implementations MUST enforce that the AS in the left-most position of the AS_PATH attribute of a Flow Specification route received via the External Border Gateway Protocol (eBGP) matches the AS in the left-most position of the AS_PATH attribute of the best-match unicast route for the destination prefix embedded in the Flow Specification NLRI.' The explanation defines that AS as the last added to an AS_SEQUENCE; Section 7 makes comparison to the session neighbor ASN optional, not this row's requirement. All tags map to internal/component/bgp/plugins/rib/rib_flowspec_validation_test.go::TestFlowSpecAuthorizationFromReceivedUpdates and internal/component/bgp/plugins/rib/rfc9117_best_match_test.go::TestRFC9117AuthorizationUsesLongestCoveringRoute, both read in full. The former accepts a route-server peer ASN 65100 carrying first AS 65001 matching unicast, and rejects first AS 65002 and an AS_SET-only path while keeping the originator match. The latter places /8 AS65001 and /16 AS65002 over the /24 rule, holds its originator at /16's, and varies only its first AS; /16 succeeds and /8 fails. Thus originator failure cannot explain the external negative. Both assert eligibility, retained state, real candidate enumeration and exact install/no-install events. Producers read: flowSpecASPath and flowSpecAuthorized through handleReceivedStructured/reconcileFlowSpecs; candidate checks reach gatherCandidatesLocked/gatherKeyCandidatesLocked. Reinstating peer-AS comparison rejects the conforming route-server case; bypassing AS equality accepts isolated negatives; choosing the shorter prefix fails the new /16 pair. The previous weak verdict's best-match test gap is closed by this added function. Existing revert records prove producer reach, not semantic mutation coverage; no commands were run for this judgment.
| Polarity | Test | Kind and tier | Proof state |
|---|---|---|---|
| negative | TestRFC9117AuthorizationUsesLongestCoveringRoute |
unit/verify | revert, verified |
| negative | TestFlowSpecAuthorizationFromReceivedUpdates |
unit/verify | revert, verified |
| positive | TestRFC9117AuthorizationUsesLongestCoveringRoute |
unit/verify | revert, verified |
| positive | TestFlowSpecAuthorizationFromReceivedUpdates |
unit/verify | revert, verified |
Extraction sign-off
| Field | Value |
|---|---|
| Reviewer | claude (BGP verdict-fix author c35) |
| Signed off | 2026-10-02 |
| Register | rfc2119 |
| Source | rfc/full/rfc9117.txt |
| Source fingerprint | 76653fb7d70944f4 |
| Record | rfc/extraction/rfc9117.json |
| Mapped sentences | 2 |
| Declined as scope | 1 |
| Relocated to a spec, which Ze OWES | 0 |
| Unclassified | 0 |
Sections
| Section | Name | Sites | Disposition | Reason |
|---|---|---|---|---|
front |
not stated | 0 | skipped (front-matter) | Title block, Abstract, Status of This Memo, Copyright Notice and Table of Contents. The Abstract restates Sections 4.1 and 4.2: originator matching is relaxed for rules originated inside the same AS, and AS_PATH validation is revised so eBGP rules can be validated through a route server. No sentence directs a speaker beyond those sections. |
1 |
Introduction | 0 | walked | Introduction. Indicative: what RFC 8955 FlowSpec is for, that its validation procedure requires the originator of the rule to match the originator of the best-match unicast route, the centralized route controller inside the Local Domain that this check defeats (Figure 1), and the route server case. No capitalised keyword; the obligations it motivates are stated in Section 4. |
2 |
not stated | 0 | walked | Definitions of Terms Used in This Memo: Local Domain, eBGP and iBGP (an eBGP session inside one confederation counts as iBGP). Definitional only. The paragraph also holds the RFC 2119 and RFC 8174 key-words boilerplate, which binds no speaker and is excluded from the site inventory. |
3 |
Motivation | 0 | walked | Motivation. Indicative: why step (b) of RFC 8955 Section 6 assumes the rule follows the path of the longest-match unicast route (Figure 2), and where that assumption fails. No keyword. |
4 |
Revised Validation Procedure | 0 | walked | Revised Validation Procedure. A heading with no body text; its two subsections carry the sites. |
4.1 |
Revision of Route Feasibility | 1 | walked | Revision of Route Feasibility. One MUST-level site, 4.1:1, the redefined step (b), mapped to RFC9117-4.1-1. The SHOULD (condition b.2 enabled by default) and the two MAYs (disable b.2 by configuration; permit a non-empty AS_PATH by policy) are rows RFC9117-4.1-2, 4.1-3 and 4.1-4, not gated. The Explanation paragraphs are indicative. |
4.2 |
Revision of AS_PATH Validation | 2 | walked | Revision of AS_PATH Validation. Site 4.2:1 quotes the RFC 8955 Section 6 sentence this section replaces; site 4.2:2 is the replacement rule, mapped to RFC9117-4.2-1. The Explanation paragraphs are indicative, including the remark that the original rule's enforcement remains optional per RFC 4271 Section 6.3. |
5 |
Topology Considerations | 0 | walked | Topology Considerations. Indicative: congruent topology between unicast and FlowSpec routes, and how condition (b.2) supports non-congruent topologies inside the Local Domain. The lowercase 'should be designed' is advice to network designers, not to a speaker. |
6 |
IANA Considerations: no IANA actions | 0 | walked | IANA Considerations: no IANA actions. |
7 |
Security Considerations | 0 | walked | Security Considerations. The capitalised OPTIONAL describes what Section 4.2 did to the RFC 4271 Section 6.3 rule. The SHOULD and SHOULD NOT advise enforcing that optional rule only when configuration indicates the peer is not a route server; both are recommendations about an optional rule, below the MUST-level the inventory counts. No MUST-level keyword. |
8 |
References heading | 0 | skipped (references) | References heading. |
8.1 |
Normative References | 0 | skipped (references) | Normative References. |
8.2 |
Informative References | 0 | skipped (references) | Informative References. |
Excluded sentences
| Site | Excluded kind | Reason | Quote |
|---|---|---|---|
4.2:1 |
not-a-requirementnever bound Ze the sentence states a fact or describes another document, and directs no implementation |
A quotation: the section opens 'Section 6 of [RFC8955] states:' and cites this sentence in order to replace it. This document does not impose it; the replacement is site 4.2:2. | | BGP implementations MUST also enforce that the AS_PATH | attribute of a route received via the External Border Gateway | Protocol (eBGP) contains the neighboring AS in the left-most | position of the AS_PATH attribute. |
Superseded
No document obsoletes RFC 9117, so its obligations are stated where they were written.