fix: handle non-canonical CIDR notation where host bits are set - #899
Merged
Merged
Conversation
master already accepts CIDRs with host bits set: since 3bdac9c parse_address uses IpInet::from_str, which keeps the host bits, and then expands net_addr.network(). normalize_cidr could therefore never be reached, so take master's parse_address and keep this PR's regression tests. Drop the DNS-dependent resolver tests, which master removed in bee-san#942.
Closed
bee-san
approved these changes
Oct 1, 2026
bee-san
left a comment
Owner
There was a problem hiding this comment.
Thanks @Nicceboy, and thanks for the clear bit-by-bit explanation! While merging master in I found the bug itself was already fixed on master by 3bdac9c. parse_address now uses IpInet::from_str, which accepts host bits, and expands network(), so 192.168.1.13/29 already resolves to .8–.15 and normalize_cidr could never be reached. I dropped the helper and kept your four tests as regression coverage, which is valuable on its own. They pass on all four CI platforms. I'm merging it as a test-only change.
Contributor
Author
|
Thank you for letting me know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
RustScan fails silently when a CIDR is given where the input IP has host bits set (i.e. the IP is not the network address for that prefix).
This is valid and common input. Users naturally provide their known host IP with a subnet mask to mean "scan this subnet". Tools like
nmapaccept it without complaint.What currently happens:
IpInet::from_str("192.168.1.13/29")rejects it — host bits101in.13are non-zeroFix
Adds a
normalize_cidrhelper that masks off the host bits to derive the true network address before parsing.192.168.1.13/29becomes192.168.1.8/29(.13=0000 1101→ mask last 3 bits →.8=0000 1000), which is then expanded to the expected 8 addresses.The change is one helper function and one additional
else ifbranch inparse_address.