bneradt commented on code in PR #13737:
URL: https://github.com/apache/trafficserver/pull/13737#discussion_r4134857924


##########
src/iocore/net/Net.cc:
##########
@@ -43,12 +47,67 @@ int net_throttle_delay = 50; /* milliseconds */
 std::string net_ccp_in;
 std::string net_ccp_out;
 
+namespace
+{
+constexpr char THROTTLE_EXEMPT_LIST_VAR[] = 
"proxy.config.net.connections_throttle_exempt_list";
+
+/** Parse a comma-separated list of IP addresses, networks, and ranges into @a 
list.
+ *
+ * @return The first entry that does not parse, or an empty view if every 
entry parses.
+ */
+swoc::TextView
+parse_throttle_exempt_list(std::string_view text, swoc::IPRangeSet &list)
+{
+  swoc::TextView entries{text};
+
+  while (!entries.empty()) {
+    swoc::TextView entry = entries.take_prefix_at(',').trim_if(&isspace);
+    swoc::IPRange  range;
+
+    if (entry.empty()) {
+      continue;
+    }
+    if (!range.load(entry)) {

Review Comment:
   [P2] Validate CIDR prefix bounds before accepting the exemption list
   
   `IPRange::load()` does not reject out-of-range prefix lengths in the bundled 
libswoc: `IPMask::load()` narrows the parsed integer to its byte-sized storage. 
I reproduced that `127.0.0.1/256` parses successfully and the resulting 
`IPRangeSet` contains `203.0.113.42`; likewise `::1/256` exempts 
`2001:db8::42`. The prefix wraps to zero, so a malformed local-health-check 
entry silently exempts the entire address family from both throttling and 
connection accounting instead of rejecting startup or preserving the previous 
list on reload. Please validate the original prefix against 0–32 for IPv4 / 
0–128 for IPv6 before marking the range (or fix the parser), with coverage for 
invalid prefixes at startup and reload.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to