Skip to main content

is_globally_reachable_unicast

Function is_globally_reachable_unicast 

Source
pub(crate) fn is_globally_reachable_unicast(addr: IpAddr) -> bool
Expand description

Return true if addr is a globally reachable unicast address.

Returns false if addr is any of the following:

  • the loopback address (127.0.0.1/8, ::1). See RFC1122, RFC4291
  • a private address, as defined in RFC1918
  • unspecified (0.0.0.0, ::)
  • part of the Shared Address Space defined in RFC6598 (100.64.0.0/10)
  • a unique local address (fc00::/7). See RFC4193
  • a unicast address with link-local scope, as defined in RFC4291

Used for deciding whether an address is a valid BEGIN target. Additionally, we use this to determine whether to allow a reverse DNS lookup (ordinarily, reverse lookups for non-globally reachable addresses are rejected), and to filter out any non-globally reachable addresses from the exit-provided RESOLVED responses.

False negatives are allowed, but false positives are not (to avoid unintentionally opening connections to local services, either on the exit, or on the client itself).

Semantically, this function is roughly equivalent to checking (IpAddr::is_global() && !IpAddr::is_broadcast() && !IpAddr::is_multicast()), with the only difference being that our implementation of the is_global() check does not cover

  • addresses reserved for benchmarking (RFC2544, RFC5180)
  • addresses reserved for documentation (RFC5737, RFC3849, RFC9637)
  • v4 addresses reserved by IANA for future use (RFC1112)
  • v6 discard-only address block (100::/64)
  • v6 IETF special assignments of 2001::/23
  • 6to4 (2002::/16) – it’s not explicitly documented as globally reachable, IANA says N/A.
  • segment routing (SRv6) SIDs (5f00::/16)