Copilot commented on code in PR #13756:
URL: https://github.com/apache/trafficserver/pull/13756#discussion_r4149435823
##########
lib/swoc/src/swoc_ip.cc:
##########
@@ -850,7 +851,7 @@ bool
IP4Net::load(TextView text) {
if (auto mask_text = text.split_suffix_at('/'); !mask_text.empty()) {
IPMask mask;
- bool mask_p = mask.load(mask_text);
+ bool mask_p = mask.load(mask_text) && mask.width() <= IP4Addr::WIDTH;
Review Comment:
An over-wide decimal prefix can still be accepted here through the
address-mask fallback. For example, `IP4Net().load("127.0.0.1/4294967040")`
fails this CIDR check, but `IP4Addr::load` accepts `4294967040` as
`255.255.255.0`, so the network is silently loaded as `/24`. Distinguish a
decimal CIDR token from address notation before attempting the fallback, and
add this case to the bounds tests.
This issue also appears on line 914 of the same file.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]