Reject the network and broadcast hosts in the endpoint range check

This commit is contained in:
Viktor Liu
2026-09-29 22:46:35 +02:00
parent 2732f511e6
commit e71927db29
2 changed files with 3 additions and 1 deletions
+1 -1
View File
@@ -66,5 +66,5 @@ func inRange(addr netip.Addr) bool {
}
b := addr.As4()
v := uint32(b[0])<<24 | uint32(b[1])<<16 | uint32(b[2])<<8 | uint32(b[3])
return v >= addrRangeBase && v < addrRangeBase+addrRangeSize
return v >= addrRangeBase && v < addrRangeBase+addrRangeSize && b[3] != 0 && b[3] != 0xff
}
@@ -89,6 +89,8 @@ func TestInRange(t *testing.T) {
}{
{"127.128.0.1", true},
{"127.255.255.254", true},
{"127.128.0.0", false}, // network host, never handed out
{"127.128.5.255", false}, // broadcast host, never handed out
{"127.127.255.255", false}, // below the range, where 127.0.0.53 and friends live
{"127.0.0.1", false},
{"127.0.0.53", false},