moonchen commented on code in PR #13737:
URL: https://github.com/apache/trafficserver/pull/13737#discussion_r4146644736


##########
src/iocore/net/Net.cc:
##########
@@ -43,12 +47,67 @@ int net_throttle_delay = 50; /* milliseconds */
 std::string net_ccp_in;
 std::string net_ccp_out;
 
+namespace
+{
+constexpr char THROTTLE_EXEMPT_LIST_VAR[] = 
"proxy.config.net.connections_throttle_exempt_list";
+
+/** Parse a comma-separated list of IP addresses, networks, and ranges into @a 
list.
+ *
+ * @return The first entry that does not parse, or an empty view if every 
entry parses.
+ */
+swoc::TextView
+parse_throttle_exempt_list(std::string_view text, swoc::IPRangeSet &list)
+{
+  swoc::TextView entries{text};
+
+  while (!entries.empty()) {
+    swoc::TextView entry = entries.take_prefix_at(',').trim_if(&isspace);
+    swoc::IPRange  range;
+
+    if (entry.empty()) {
+      continue;
+    }
+    if (!range.load(entry)) {

Review Comment:
   Thanks, this still applies after the rework. The exempt list is now 
`proxy.config.http.per_client.connection.exempt_list`, and both its records 
parser and `TSConnectionLimitExemptListAdd()` parse entries with 
`swoc::IPRange::load()`. With the list set to only `192.0.2.1/256`, ATS still 
accepted a connection from 127.0.0.1 at `connections_throttle` and counted it 
as exempt.
   
   The wrap is in libswoc, and every other parser that takes address ranges has 
it too, so I fixed it there in #13756, which makes libswoc reject a prefix 
wider than the address family. With #13756 applied, the same list is rejected 
at startup with a warning that names the entry, and 127.0.0.1 is refused at the 
limit. Once #13756 is merged, we can also add an autest here for invalid 
prefixes at startup and on reload.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to