Skip to main content

Module summary

Module summary 

Source
Expand description

Precise IP and port policy summarisation algorithm

We don’t use macrology for v4/v6, instead writing things twice. We don’t fear copypasta errors because the type system almost always prevents mixing v4 and v6 information.

We’re using iprange::IpRange for our IP address sets. That is a trie, but it’s a pretty unoptimised one: every node is fully boxed and there is no layer elision. But it does have a nice API.

See Summariser for the algorithm.

Macros§

derive_deftly_template_PortPolicies 🔒
Define PortPolicies::from_summariser.
derive_deftly_template_PortSummaryThresholds 🔒
Define impls on PortSummaryThresholds
tprintln 🔒
eprintln but in tests only, and prefix with "TPRINT "

Structs§

PortPolicies
A pair of port policy summaries, one for IPv4 and one for IPv6
PortSummaryThresholds
Thresholds for deciding whether a port counts as open, for a summary
Rejects 🔒
Which V4 and V6 addresses we are rejecting for a particular port
Summariser 🔒
State for summarisation algorithm

Constants§

ALL_PORTS 🔒
Range for all real ports (not zero)

Traits§

Net 🔒
Ipv4Net or Ipv6Net - IP-version specific handling

Type Aliases§

Port 🔒
Ports are 16-bit. Alias for clarity.