suricata
util-cidr.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * CIDR utility functions
24  */
25 
26 #include "suricata-common.h"
27 #include "util-cidr.h"
28 #include "util-unittest.h"
29 
30 /** \brief turn 32 bit mask into CIDR
31  * \retval cidr cidr value or -1 if the netmask can't be expressed as cidr
32  */
33 int CIDRFromMask(uint32_t netmask)
34 {
35  netmask = ntohl(netmask);
36  if (netmask == 0) {
37  return 0;
38  }
39  int p = 0;
40  bool seen_1 = false;
41  while (netmask > 0) {
42  if (netmask & 1) {
43  seen_1 = true;
44  p++;
45  } else {
46  if (seen_1) {
47  return -1;
48  }
49  }
50  netmask >>= 1;
51  }
52  return p;
53 }
54 
55 uint32_t CIDRGet(int cidr)
56 {
57  if (cidr <= 0 || cidr > 32)
58  return 0;
59  uint32_t netmask = htonl(0xFFFFFFFF << (32UL - (uint32_t)cidr));
60  SCLogDebug("CIDR %d -> netmask %08X", cidr, netmask);
61  return netmask;
62 }
63 
64 /**
65  * \brief Creates a cidr ipv6 netblock, based on the cidr netblock value.
66  *
67  * For example if we send a cidr of 7 as argument, an ipv6 address
68  * mask of the value FE:00:00:00:00:00:00:00 is created and updated
69  * in the argument struct in6_addr *in6.
70  *
71  * \todo I think for the final section: while (cidr > 0), we can simply
72  * replace it with a
73  * if (cidr > 0) {
74  * in6->s6_addr[i] = -1 << (8 - cidr);
75  *
76  * \param cidr The value of the cidr.
77  * \param in6 Pointer to an ipv6 address structure(struct in6_addr) which will
78  * hold the cidr netblock result.
79  */
80 void CIDRGetIPv6(int cidr, struct in6_addr *in6)
81 {
82  int i = 0;
83 
84  memset(in6, 0, sizeof(struct in6_addr));
85 
86  while (cidr > 8) {
87  in6->s6_addr[i] = 0xff;
88  cidr -= 8;
89  i++;
90  }
91 
92  while (cidr > 0) {
93  in6->s6_addr[i] |= 0x80;
94  if (--cidr > 0)
95  in6->s6_addr[i] = in6->s6_addr[i] >> 1;
96  }
97 }
98 
99 #ifdef UNITTESTS
100 
101 static int CIDRFromMaskTest01(void)
102 {
103  struct in_addr in;
104  int v = inet_pton(AF_INET, "255.255.255.0", &in);
105 
106  FAIL_IF(v <= 0);
107  FAIL_IF_NOT(24 == CIDRFromMask(in.s_addr));
108 
109  PASS;
110 }
111 
112 static int CIDRFromMaskTest02(void)
113 {
114  struct in_addr in;
115  int v = inet_pton(AF_INET, "255.255.0.42", &in);
116 
117  FAIL_IF(v <= 0);
118  FAIL_IF_NOT(-1 == CIDRFromMask(in.s_addr));
119 
120  PASS;
121 }
122 
123 static int CIDRFromMaskTest03(void)
124 {
125  struct in_addr in;
126  int v = inet_pton(AF_INET, "0.0.0.0", &in);
127 
128  FAIL_IF(v <= 0);
129  FAIL_IF_NOT(0 == CIDRFromMask(in.s_addr));
130 
131  PASS;
132 }
133 
134 static int CIDRFromMaskTest04(void)
135 {
136  struct in_addr in;
137  int v = inet_pton(AF_INET, "255.255.255.255", &in);
138 
139  FAIL_IF(v <= 0);
140  FAIL_IF_NOT(32 == CIDRFromMask(in.s_addr));
141 
142  PASS;
143 }
144 
145 #endif /* UNITTESTS */
146 
147 void UtilCIDRTests(void)
148 {
149 #ifdef UNITTESTS
150  UtRegisterTest("CIDRFromMaskTest01", CIDRFromMaskTest01);
151  UtRegisterTest("CIDRFromMaskTest02", CIDRFromMaskTest02);
152  UtRegisterTest("CIDRFromMaskTest03", CIDRFromMaskTest03);
153  UtRegisterTest("CIDRFromMaskTest04", CIDRFromMaskTest04);
154 #endif /* UNITTESTS */
155 }
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:103
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:296
CIDRGet
uint32_t CIDRGet(int cidr)
Definition: util-cidr.c:55
util-unittest.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
util-cidr.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
CIDRFromMask
int CIDRFromMask(uint32_t netmask)
turn 32 bit mask into CIDR
Definition: util-cidr.c:33
UtilCIDRTests
void UtilCIDRTests(void)
Definition: util-cidr.c:147
CIDRGetIPv6
void CIDRGetIPv6(int cidr, struct in6_addr *in6)
Creates a cidr ipv6 netblock, based on the cidr netblock value.
Definition: util-cidr.c:80
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
suricata-common.h