资料核查日期:2026-09-24 1. RFC 6480, RPKI Architecture, IETF, 2012-02 https://www.rfc-editor.org/rfc/rfc6480.html 用途:资源证书与路由起源授权基础。 2. RFC 6811, BGP Prefix Origin Validation, IETF, 2013-01 https://www.rfc-editor.org/rfc/rfc6811.html 用途:Valid、Invalid、NotFound 的输入与含义;结合覆盖、长度和起源条件。 3. RFC 7908, BGP Route Leaks, IETF, 2016-06 https://www.rfc-editor.org/rfc/rfc7908.html 用途:路由泄漏问题定义;来源合法不等于传播符合预期。 4. RFC 9234, BGP Roles and OTC, IETF, 2022-05 https://www.rfc-editor.org/rfc/rfc9234.html 用途:基于角色的泄漏预防与检测条件。 运行:python3 rpki_model.py 预期:退出码 0;覆盖 Valid、两类 Invalid、NotFound,以及来源 Valid 但被本地策略拒绝的泄漏案例。 NOT_RUN:真实 RPKI 仓库/验证器、RTR、BGP 邻居、BGPsec 与数据面路径。