From: nobu@... Date: 2017-04-04T13:32:50+00:00 Subject: [ruby-core:80560] [Ruby trunk Bug#13399][Assigned] IPAddr accepts invalid address mask Issue #13399 has been updated by nobu (Nobuyoshi Nakada). Description updated Status changed from Open to Assigned Assignee set to knu (Akinori MUSHA) After fixing it, I found that `drb/acl` depends on this behavior. ```diff diff --git a/lib/ipaddr.rb b/lib/ipaddr.rb index 6f70ebf773..4f87738be1 100644 --- a/lib/ipaddr.rb +++ b/lib/ipaddr.rb @@ -422,6 +422,10 @@ raise InvalidPrefixError, "address family is not same" end @mask_addr = m.to_i + n = @mask_addr ^ m.instance_variable_get(:@mask_addr) + unless ((n + 1) & n).zero? + raise InvalidPrefixError, "invalid mask #{mask}" + end @addr &= @mask_addr return self end diff --git a/test/test_ipaddr.rb b/test/test_ipaddr.rb index 86482a08bd..c49e1ab240 100644 --- a/test/test_ipaddr.rb +++ b/test/test_ipaddr.rb @@ -79,6 +79,7 @@ assert_raise(IPAddr::InvalidPrefixError) { IPAddr.new("::1/255.255.255.0") } assert_raise(IPAddr::InvalidPrefixError) { IPAddr.new("::1/129") } assert_raise(IPAddr::InvalidPrefixError) { IPAddr.new("192.168.0.1/33") } + assert_raise(IPAddr::InvalidPrefixError) { IPAddr.new("192.168.0.1/255.255.255.1") } assert_raise(IPAddr::AddressFamilyError) { IPAddr.new(1) } assert_raise(IPAddr::AddressFamilyError) { IPAddr.new("::ffff:192.168.1.2/120", Socket::AF_INET) } end @@ -234,7 +235,14 @@ def test_mask a = @a.mask(32) assert_equal("3ffe:505::", a.to_s) + assert_equal("3ffe:505::", @a.mask("ffff:ffff::").to_s) assert_equal("3ffe:505:2::", @a.to_s) + a = IPAddr.new("192.168.2.0/24") + assert_equal("192.168.0.0", a.mask(16).to_s) + assert_equal("192.168.0.0", a.mask("255.255.0.0").to_s) + assert_equal("192.168.2.0", a.to_s) + assert_raise(IPAddr::InvalidPrefixError) {a.mask("255.255.0.255")} + assert_raise(IPAddr::InvalidPrefixError) {@a.mask("ffff:1::")} end def test_include? ``` ---------------------------------------- Bug #13399: IPAddr accepts invalid address mask https://bugs.ruby-lang.org/issues/13399#change-64060 * Author: rtib (Tibor Repasi) * Status: Assigned * Priority: Normal * Assignee: knu (Akinori MUSHA) * Target version: * ruby -v: ruby 2.4.1p111 (2017-03-22 revision 58053) [x86_64-darwin15] * Backport: 2.2: UNKNOWN, 2.3: UNKNOWN, 2.4: UNKNOWN ---------------------------------------- API Class `IPAddr` can be initialised with e.g. '1.2.3.4/255.255.255.1', which is an invalid mask for an IPv4 address, however, `IPAddr.new` won't throw `ArgumentError`, nor `ip.ipv4?` will return `false`. ```ruby $ cat iptest.rb require 'ipaddr' begin ip = IPAddr.new('1.2.3.4/255.255.255.1') rescue ArgumentError puts 'ArgumentError was thrown' end puts 'IP address is valid' if ip.ipv4? ``` ``` $ ruby iptest.rb IP address is valid ``` ``` $ ipcalc 1.2.3.4/255.255.255.1 INVALID NETMASK INVALID MASK1: 255.255.255.1 Address: 1.2.3.4 00000001.00000010.00000011. 00000100 Netmask: 255.255.255.0 = 24 11111111.11111111.11111111. 00000000 Wildcard: 0.0.0.255 00000000.00000000.00000000. 11111111 => Network: 1.2.3.0/24 00000001.00000010.00000011. 00000000 HostMin: 1.2.3.1 00000001.00000010.00000011. 00000001 HostMax: 1.2.3.254 00000001.00000010.00000011. 11111110 Broadcast: 1.2.3.255 00000001.00000010.00000011. 11111111 Hosts/Net: 254 Class A -- https://bugs.ruby-lang.org/ Unsubscribe: