This repository has been archived by the owner on Apr 7, 2020. It is now read-only.
forked from istio/istio
/
ipList.go
96 lines (78 loc) · 2.09 KB
/
ipList.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
// Copyright 2017 Istio Authors
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package list
import (
"fmt"
"net"
"strings"
"github.com/ghodss/yaml"
)
type (
ipList struct {
entries []*net.IPNet
}
// represents the format of the data in a list
listPayload struct {
WhiteList []string `yaml:"whitelist" required:"true"`
}
)
func parseIPList(buf []byte, overrides []string) (list, error) {
var lp listPayload
if err := yaml.Unmarshal(buf, &lp); err != nil {
return nil, fmt.Errorf("could not unmarshal data from list %s", err)
}
ls := &ipList{make([]*net.IPNet, 0, len(lp.WhiteList)+len(overrides))}
var err error
// copy to the internal format
for _, ip := range lp.WhiteList {
if err = ls.addEntry(ip); err != nil {
return nil, err
}
}
// apply overrides
for _, ip := range overrides {
// guaranteed correctly formatted, since config was validated
_ = ls.addEntry(ip)
}
return ls, nil
}
func (ls *ipList) addEntry(ip string) error {
orig := ip
if !strings.Contains(ip, "/") {
ip += "/32"
}
_, ipnet, err := net.ParseCIDR(ip)
if err != nil {
return fmt.Errorf("could not parse list entry %s: %v", orig, err)
}
ls.entries = append(ls.entries, ipnet)
return nil
}
func (ls *ipList) checkList(symbol string) (bool, error) {
ipa := net.ParseIP(symbol)
if ipa == nil {
// invalid symbol format
return false, fmt.Errorf("%s is not a valid IP address", symbol)
}
for _, ipnet := range ls.entries {
if ipnet.Contains(ipa) {
return true, nil
}
}
// not found in the list
return false, nil
}
func (ls *ipList) numEntries() int {
return len(ls.entries)
}