Functional Weave
Code in Rust

net.ipv4@1.0.0

README.md

1,303 bytes · view raw

# net.ipv4

Parse dotted-quad IPv4 text to an unsigned 32-bit number, format a number back
to text, and check text without raising.

## Why so strict

There is more than one way to read "an IPv4 address". The C library's
`inet_aton` (and so `ping`, `curl` and many socket libraries) accepts
`127.1` (meaning 127.0.0.1), `0x7f.0.0.1` (hex) and `010.1.1.1` (octal, so
8.1.1.1). Python's `ipaddress` and most validators refuse them. When the
validator and the thing that connects disagree, an allow-list can be bypassed
(CVE-2021-29921 was exactly this). This capability accepts only the form
RFC 791 writes and everyone reads the same way: exactly four decimal octets
0-255, no leading zeros (a lone `0` is fine), no signs, no whitespace, ASCII
digits only.

## Notes

- `parseIpv4` and `formatIpv4` are inverses over 0 to 4294967295.
- `isIpv4` never raises; it is true exactly when `parseIpv4` would succeed.
- The number is an ordinary integer, so it compares and subtracts correctly
  in every language (no signed 32-bit wrap above 128.0.0.0).
- `ipv4Value` (`ipv4_value`) is exported for sibling capabilities that want
  "number or null"; it is not part of the contract.

Sources: RFC 791 (Internet Protocol), section 2.3 and 3.2; RFC 6943 section
3.1.1 on the ambiguity of non-dotted-decimal forms.