Skip to content

Commit

Permalink
detect/iponly: break out range insert code
Browse files Browse the repository at this point in the history
So we can reuse it.
  • Loading branch information
victorjulien committed Mar 2, 2022
1 parent a67b97e commit 4020e2f
Showing 1 changed file with 46 additions and 34 deletions.
80 changes: 46 additions & 34 deletions src/detect-engine-iponly.c
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,50 @@ static uint8_t IPOnlyCIDRItemCompare(IPOnlyCIDRItem *head,
static IPOnlyCIDRItem *IPOnlyCIDRItemInsert(IPOnlyCIDRItem *head,
IPOnlyCIDRItem *item);

static int InsertRange(
IPOnlyCIDRItem **pdd, IPOnlyCIDRItem *dd, const uint32_t first_in, const uint32_t last_in)
{
DEBUG_VALIDATE_BUG_ON(dd == NULL);
DEBUG_VALIDATE_BUG_ON(pdd == NULL);

uint32_t first = first_in;
uint32_t last = last_in;

dd->netmask = 32;
/* Find the maximum netmask starting from current address first
* and not crossing last.
* To extend the mask, we need to start from a power of 2.
* And we need to pay attention to unsigned overflow back to 0.0.0.0
*/
while (dd->netmask > 0 && (first & (1UL << (32 - dd->netmask))) == 0 &&
first + (1UL << (32 - (dd->netmask - 1))) - 1 <= last) {
dd->netmask--;
}
dd->ip[0] = htonl(first);
first += 1UL << (32 - dd->netmask);
// case whatever-255.255.255.255 looping to 0.0.0.0/0
while (first <= last && first != 0) {
IPOnlyCIDRItem *new = IPOnlyCIDRItemNew();
if (new == NULL)
goto error;
new->negated = dd->negated;
new->family = dd->family;
new->netmask = 32;
while (new->netmask > 0 && (first & (1UL << (32 - new->netmask))) == 0 &&
first + (1UL << (32 - (new->netmask - 1))) - 1 <= last) {
new->netmask--;
}
new->ip[0] = htonl(first);
first += 1UL << (32 - new->netmask);
dd = IPOnlyCIDRItemInsert(dd, new);
}
// update head of list
*pdd = dd;
return 0;
error:
return -1;
}

/**
* \internal
* \brief Parses an ipv4/ipv6 address string and updates the result into the
Expand Down Expand Up @@ -202,7 +246,7 @@ static int IPOnlyCIDRItemParseSingle(IPOnlyCIDRItem **pdd, const char *str)

dd->ip[0] = in.s_addr & netmask;

} else if ((ip2 = strchr(ip, '-')) != NULL) {
} else if ((ip2 = strchr(ip, '-')) != NULL) {
/* 1.2.3.4-1.2.3.6 range format */
ip[ip2 - ip] = '\0';
ip2++;
Expand All @@ -224,39 +268,7 @@ static int IPOnlyCIDRItemParseSingle(IPOnlyCIDRItem **pdd, const char *str)
goto error;

SCLogDebug("Creating CIDR range for [%s - %s]", ip, ip2);
dd->netmask = 32;
/* Find the maximum netmask starting from current address first
* and not crossing last.
* To extend the mask, we need to start from a power of 2.
* And we need to pay attention to unsigned overflow back to 0.0.0.0
*/
while (dd->netmask > 0 &&
(first & (1UL << (32-dd->netmask))) == 0 &&
first + (1UL << (32-(dd->netmask-1))) - 1 <= last) {
dd->netmask--;
}
dd->ip[0] = htonl(first);
first += 1UL << (32-dd->netmask);
//case whatever-255.255.255.255 looping to 0.0.0.0/0
while ( first <= last && first != 0 ) {
IPOnlyCIDRItem *new = IPOnlyCIDRItemNew();
if (new == NULL)
goto error;
new->negated = dd->negated;
new->family= dd->family;
new->netmask = 32;
while (new->netmask > 0 &&
(first & (1UL << (32-new->netmask))) == 0 &&
first + (1UL << (32-(new->netmask-1))) - 1 <= last) {
new->netmask--;
}
new->ip[0] = htonl(first);
first += 1UL << (32-new->netmask);
dd = IPOnlyCIDRItemInsert(dd, new);
}
//update head of list
*pdd = dd;

return InsertRange(pdd, dd, first, last);
} else {
/* 1.2.3.4 format */
r = inet_pton(AF_INET, ip, &in);
Expand Down

0 comments on commit 4020e2f

Please sign in to comment.