Doc #71935 [Opn->Nab]: FILTER_FLAG_NO_RES_RANGE is missing 100.64.0.0/10
| From: | cmb@php.net | Date: | Thu, 05 Aug 2021 16:28:26 +0000 |
| Subject: | Doc #71935 [Opn->Nab]: FILTER_FLAG_NO_RES_RANGE is missing 100.64.0.0/10 | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-19042@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71935&edit=1
ID: 71935
Updated by: cmb@php.net
Reported by: bbcan177 at gmail dot com
Summary: FILTER_FLAG_NO_RES_RANGE is missing 100.64.0.0/10
-Status: Open
+Status: Not a bug
Type: Documentation Problem
Package: Filter related
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> FILTER_FLAG_NO_RES_RANGE is missing 100.64.0.0/10 in the
> documentation.
No, it doesn't. FILTER_FLAG_NO_RES_RANGE only considers addresses
as reserved which are reserved-by-protocol according to RFC 6890.
> Compare this with the code for 5.6.25
That code has long been fixed.
Previous Comments:
------------------------------------------------------------------------
[2016-08-22 12:12:53] jame2 at ceh dot ac dot uk
I think the documentation is missing a lot more IP addresses than given in the original bug report.
127.0.0.1 is the one that caught me out.
The documentation says "Fails validation for the following reserved IPv4 ranges: 0.0.0.0/8,
169.254.0.0/16, 192.0.2.0/24 and 224.0.0.0/4." Compare this with the code for 5.6.25
if (flags & FILTER_FLAG_NO_RES_RANGE) {
if (
(ip[0] == 0) ||
(ip[0] == 10) ||
(ip[0] == 100 && (ip[1] >= 64 && ip[1] <= 127)) ||
(ip[0] == 127) ||
(ip[0] == 169 && ip[1] == 254) ||
(ip[0] == 172 && (ip[1] >= 16 && ip[1] <= 31)) ||
(ip[0] == 192 && ip[1] == 0 && ip[2] == 0) ||
(ip[0] == 192 && ip[1] == 0 && ip[2] == 2) ||
(ip[0] == 192 && ip[1] == 88 && ip[2] == 99) ||
(ip[0] == 192 && ip[1] == 168) ||
(ip[0] == 198 && (ip[1] == 18 || ip[1] == 19)) ||
(ip[0] == 198 && ip[1] == 51 && ip[2] == 100) ||
(ip[0] == 203 && ip[1] == 0 && ip[2] == 113) ||
(ip[0] >= 224 && ip[0] <= 255)
) {
RETURN_VALIDATION_FAILED
}
}
------------------------------------------------------------------------
[2016-03-31 23:45:05] bbcan177 at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/filter.filters.flags
---
FILTER_FLAG_NO_RES_RANGE is missing 100.64.0.0/10 in the documentation.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71935&edit=1