Expand description
Precise IP and port policy summarisation algorithm
We don’t use macrology for v4/v6, instead writing things twice. We don’t fear copypasta errors because the type system almost always prevents mixing v4 and v6 information.
We’re using iprange::IpRange for our IP address sets.
That is a trie, but it’s a pretty unoptimised one:
every node is fully boxed and there is no layer elision.
But it does have a nice API.
See Summariser for the algorithm.
Macros§
- derive_
deftly_ 🔒template_ Port Policies - Define
PortPolicies::from_summariser. - derive_
deftly_ 🔒template_ Port Summary Thresholds - Define impls on
PortSummaryThresholds - tprintln 🔒
eprintlnbut in tests only, and prefix with"TPRINT "
Structs§
- Port
Policies - A pair of port policy summaries, one for IPv4 and one for IPv6
- Port
Summary Thresholds - Thresholds for deciding whether a port counts as open, for a summary
- Rejects 🔒
- Which V4 and V6 addresses we are rejecting for a particular port
- Summariser 🔒
- State for summarisation algorithm
Constants§
- ALL_
PORTS 🔒 - Range for all real ports (not zero)
Traits§
- Net 🔒
Ipv4NetorIpv6Net- IP-version specific handling
Type Aliases§
- Port 🔒
- Ports are 16-bit. Alias for clarity.