moonchen commented on code in PR #13737:
URL: https://github.com/apache/trafficserver/pull/13737#discussion_r4146644736
##########
src/iocore/net/Net.cc:
##########
@@ -43,12 +47,67 @@ int net_throttle_delay = 50; /* milliseconds */
std::string net_ccp_in;
std::string net_ccp_out;
+namespace
+{
+constexpr char THROTTLE_EXEMPT_LIST_VAR[] =
"proxy.config.net.connections_throttle_exempt_list";
+
+/** Parse a comma-separated list of IP addresses, networks, and ranges into @a
list.
+ *
+ * @return The first entry that does not parse, or an empty view if every
entry parses.
+ */
+swoc::TextView
+parse_throttle_exempt_list(std::string_view text, swoc::IPRangeSet &list)
+{
+ swoc::TextView entries{text};
+
+ while (!entries.empty()) {
+ swoc::TextView entry = entries.take_prefix_at(',').trim_if(&isspace);
+ swoc::IPRange range;
+
+ if (entry.empty()) {
+ continue;
+ }
+ if (!range.load(entry)) {
Review Comment:
Thanks, this still applies after the rework. The exempt list is now
`proxy.config.http.per_client.connection.exempt_list`, and both its records
parser and `TSConnectionLimitExemptListAdd()` parse entries with
`swoc::IPRange::load()`. With the list set to only `192.0.2.1/256`, ATS still
accepted a connection from 127.0.0.1 at `connections_throttle` and counted it
as exempt.
The wrap is in libswoc, and every other parser that takes address ranges has
it too, so I fixed it there in #13756, which makes libswoc reject a prefix
wider than the address family. With #13756 applied, the same list is rejected
at startup with a warning that names the entry, and 127.0.0.1 is refused at the
limit. Once #13756 is merged, we can also add an autest here for invalid
prefixes at startup and on reload.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]