Skip to content

fix(unikernels): reject non-contiguous subnet masks in subnetMaskToCIDR - #950

Open
KHARSHAVARDHAN-eng wants to merge 1 commit into
urunc-dev:mainfrom
KHARSHAVARDHAN-eng:fix/issue-909-subnet-mask-contiguity
Open

KHARSHAVARDHAN-eng wants to merge 1 commit into
urunc-dev:mainfrom
KHARSHAVARDHAN-eng:fix/issue-909-subnet-mask-contiguity

Conversation

@KHARSHAVARDHAN-eng

Copy link
Copy Markdown

Fixes #909

Summary

subnetMaskToCIDR() in pkg/unikontainers/unikernels/utils.go previously computed the prefix length by counting set bits without verifying contiguity. As a result, structurally invalid non-contiguous subnet masks (such as 255.0.255.0 or 0.255.255.255) were silently accepted and mapped to incorrect CIDR prefix lengths instead of being rejected.

Solution

  • Refactored subnetMaskToCIDR() to parse the subnet mask using net.ParseIP() and validate contiguity via net.IPMask.Size(). Non-contiguous masks cause mask.Size() to return (0, 0), which is now detected and returned as a validation error (invalid (non-contiguous) subnet mask).
  • Added comprehensive unit tests in utils_test.go covering canonical masks (/0 to /32), non-contiguous masks, and malformed string inputs.

subnetMaskToCIDR() computed the prefix length by counting set bits without
checking for contiguity. As a result, non-contiguous masks like 255.0.255.0
were accepted as /16.

Refactor subnetMaskToCIDR() using net.ParseIP and net.IPMask.Size() to validate
both mask format and contiguity. Add comprehensive unit tests covering canonical,
non-contiguous, and malformed masks.

Fixes urunc-dev#909

Signed-off-by: Harsha Vardhan <harshahvk2005@gmail.com>
@netlify

netlify Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for urunc canceled.

Name Link
🔨 Latest commit 7624525
🔍 Latest deploy log https://app.netlify.com/projects/urunc/deploys/6a7aca6f0aec240008915b09

@cmainas cmainas added invalid This doesn't seem right do-not-merge labels Aug 11, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge invalid This doesn't seem right

Projects

None yet

Development

Successfully merging this pull request may close these issues.

subnetMaskToCIDR() accepts non-contiguous netmasks, silently producing a wrong CIDR

2 participants