{"sha":"53c089fca9f29b7a02d9144824be06187a07cc8c","node_id":"C_kwDOABA-c9oAKDUzYzA4OWZjYTlmMjliN2EwMmQ5MTQ0ODI0YmUwNjE4N2EwN2NjOGM","commit":{"author":{"name":"Norman Maurer","email":"norman_maurer@apple.com","date":"2026-06-01T14:04:05Z"},"committer":{"name":"GitHub","email":"noreply@github.com","date":"2026-06-01T14:04:05Z"},"message":"IpSubnetFilter: Correctly handle ipv6 (#16860)\n\nMotivation:\n\nWe need to correctly handle subnets for ipv6\n\nModifications:\n\n- Correctly handle subnets\n- Add unit test\n\nResult:\n\nCorrectly filter ipv6 addresses","tree":{"sha":"7651aab75579150fa6ad824e4fcc6d2a406c7a56","url":"https://api.github.com/repos/netty/netty/git/trees/7651aab75579150fa6ad824e4fcc6d2a406c7a56"},"url":"https://api.github.com/repos/netty/netty/git/commits/53c089fca9f29b7a02d9144824be06187a07cc8c","comment_count":0,"verification":{"verified":true,"reason":"valid","signature":"-----BEGIN PGP SIGNATURE-----\n\nwsFcBAABCAAQBQJqHZFVCRC1aQ7uu5UhlAAAvB0QAC+R5IkVqD75XtWWYXT//c1Z\nseJdoqTS0o/29ORKSzKMHuUK21cL328bn4WYvewEBMzef6yl/kNedY2cRfTlRyzi\nYS5YVBR3jV9cgACbGOmo2hZWQrCZysSE8cWMNb2xbB2NiE3JJVUMjqJUaAXjIfyr\ngAnEoY9AQGAD1JfYwko7N9h3WoMeIsLfcd/hwLVBNSZoRrxB91DBWn9yWjJ8OKfY\np3TY/q37439zyDFa5eO1I9HPGKKqJsrw3zcLca/A00G/Bo+SmDI1Xuy3OeIBvl0C\nk5JNdDZojx3/U1xtlAU7O/EAlPrysZFL0VMB2zj+5JVSYWJS/GwqGR6AH2LXgmHs\nAg1nU4b3YQGQvn7NmB9sh8OSvH4C99cRx5MCDI0zIHPoevj+1d1MfZ4lhICId7GO\nW0Meg2iEcEjm9wLLwWyKaU5vtS81dLLF2LiadPQ2shd9sIfTbXeiB+0gnC79dqcm\nhXrsbFq/aZfZJwE4sDl2a5mRJ5uxEUgS7y4MSAFO994RHr9u1Pg7R7TiuRx5zwGa\nAWd4smImUHNxteJ3UMQCYSwVbLjQ9sh3J0OLAXWXn9na23OjgL8DqyWT4q/sY0PE\nk2u0T9ehUlmkV87aTCoUgSAsrwm2jdRs/ZN/BUlTTDBOI9WN5JsMPcQjElQlKY/c\n41mvsz3Bg7XyuT4icwap\n=GjBA\n-----END PGP SIGNATURE-----\n","payload":"tree 7651aab75579150fa6ad824e4fcc6d2a406c7a56\nparent aa0cae5a9126e20fe4793723cb0fe78b7c4a7d8f\nauthor Norman Maurer <norman_maurer@apple.com> 1780322645 +0200\ncommitter GitHub <noreply@github.com> 1780322645 +0200\n\nIpSubnetFilter: Correctly handle ipv6 (#16860)\n\nMotivation:\n\nWe need to correctly handle subnets for ipv6\n\nModifications:\n\n- Correctly handle subnets\n- Add unit test\n\nResult:\n\nCorrectly filter ipv6 addresses","verified_at":"2026-06-01T14:04:12Z"}},"url":"https://api.github.com/repos/netty/netty/commits/53c089fca9f29b7a02d9144824be06187a07cc8c","html_url":"https://github.com/netty/netty/commit/53c089fca9f29b7a02d9144824be06187a07cc8c","comments_url":"https://api.github.com/repos/netty/netty/commits/53c089fca9f29b7a02d9144824be06187a07cc8c/comments","author":{"login":"normanmaurer","id":439362,"node_id":"MDQ6VXNlcjQzOTM2Mg==","avatar_url":"https://avatars.githubusercontent.com/u/439362?v=4","gravatar_id":"","url":"https://api.github.com/users/normanmaurer","html_url":"https://github.com/normanmaurer","followers_url":"https://api.github.com/users/normanmaurer/followers","following_url":"https://api.github.com/users/normanmaurer/following{/other_user}","gists_url":"https://api.github.com/users/normanmaurer/gists{/gist_id}","starred_url":"https://api.github.com/users/normanmaurer/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/normanmaurer/subscriptions","organizations_url":"https://api.github.com/users/normanmaurer/orgs","repos_url":"https://api.github.com/users/normanmaurer/repos","events_url":"https://api.github.com/users/normanmaurer/events{/privacy}","received_events_url":"https://api.github.com/users/normanmaurer/received_events","type":"User","user_view_type":"public","site_admin":false},"committer":{"login":"web-flow","id":19864447,"node_id":"MDQ6VXNlcjE5ODY0NDQ3","avatar_url":"https://avatars.githubusercontent.com/u/19864447?v=4","gravatar_id":"","url":"https://api.github.com/users/web-flow","html_url":"https://github.com/web-flow","followers_url":"https://api.github.com/users/web-flow/followers","following_url":"https://api.github.com/users/web-flow/following{/other_user}","gists_url":"https://api.github.com/users/web-flow/gists{/gist_id}","starred_url":"https://api.github.com/users/web-flow/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/web-flow/subscriptions","organizations_url":"https://api.github.com/users/web-flow/orgs","repos_url":"https://api.github.com/users/web-flow/repos","events_url":"https://api.github.com/users/web-flow/events{/privacy}","received_events_url":"https://api.github.com/users/web-flow/received_events","type":"User","user_view_type":"public","site_admin":false},"parents":[{"sha":"aa0cae5a9126e20fe4793723cb0fe78b7c4a7d8f","url":"https://api.github.com/repos/netty/netty/commits/aa0cae5a9126e20fe4793723cb0fe78b7c4a7d8f","html_url":"https://github.com/netty/netty/commit/aa0cae5a9126e20fe4793723cb0fe78b7c4a7d8f"}],"stats":{"total":24,"additions":21,"deletions":3},"files":[{"sha":"428dec64149d8b1c84ddf44c4f82a8d9b1638e40","filename":"handler/src/main/java/io/netty/handler/ipfilter/IpSubnetFilterRule.java","status":"modified","additions":2,"deletions":2,"changes":4,"blob_url":"https://github.com/netty/netty/blob/53c089fca9f29b7a02d9144824be06187a07cc8c/handler%2Fsrc%2Fmain%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterRule.java","raw_url":"https://github.com/netty/netty/raw/53c089fca9f29b7a02d9144824be06187a07cc8c/handler%2Fsrc%2Fmain%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterRule.java","contents_url":"https://api.github.com/repos/netty/netty/contents/handler%2Fsrc%2Fmain%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterRule.java?ref=53c089fca9f29b7a02d9144824be06187a07cc8c","patch":"@@ -149,7 +149,7 @@ int compareTo(InetSocketAddress inetSocketAddress) {\n             Ip6SubnetFilterRule ip6SubnetFilterRule = (Ip6SubnetFilterRule) filterRule;\n             return ip6SubnetFilterRule.networkAddress\n                     .compareTo(Ip6SubnetFilterRule.ipToInt((Inet6Address) inetSocketAddress.getAddress())\n-                            .and(ip6SubnetFilterRule.networkAddress));\n+                            .and(ip6SubnetFilterRule.subnetMask));\n         }\n     }\n \n@@ -245,7 +245,7 @@ private static BigInteger ipToInt(Inet6Address ipAddress) {\n             byte[] octets = ipAddress.getAddress();\n             assert octets.length == 16;\n \n-            return new BigInteger(octets);\n+            return new BigInteger(1, octets);\n         }\n \n         private static BigInteger prefixToSubnetMask(int cidrPrefix) {"},{"sha":"22cdbefe78ec384f4e78c817ff2d2c2f7f866273","filename":"handler/src/test/java/io/netty/handler/ipfilter/IpSubnetFilterTest.java","status":"modified","additions":19,"deletions":1,"changes":20,"blob_url":"https://github.com/netty/netty/blob/53c089fca9f29b7a02d9144824be06187a07cc8c/handler%2Fsrc%2Ftest%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterTest.java","raw_url":"https://github.com/netty/netty/raw/53c089fca9f29b7a02d9144824be06187a07cc8c/handler%2Fsrc%2Ftest%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterTest.java","contents_url":"https://api.github.com/repos/netty/netty/contents/handler%2Fsrc%2Ftest%2Fjava%2Fio%2Fnetty%2Fhandler%2Fipfilter%2FIpSubnetFilterTest.java?ref=53c089fca9f29b7a02d9144824be06187a07cc8c","patch":"@@ -29,6 +29,7 @@\n import java.net.InetSocketAddress;\n import java.net.SocketAddress;\n import java.util.ArrayList;\n+import java.util.Collections;\n import java.util.List;\n \n import static org.junit.jupiter.api.Assertions.assertEquals;\n@@ -213,12 +214,29 @@ public void testBinarySearch() {\n         assertTrue(ch6.close().isSuccess());\n \n         //2001:db8:abcd:0000::/52\n-        EmbeddedChannel ch7 = newEmbeddedInetChannel(\"2001:db8:abcd:1000::\",\n+        EmbeddedChannel ch7 = newEmbeddedInetChannel(\"2001:db8:abcd:0000::1\",\n                 new IpSubnetFilter(ipSubnetFilterRuleList));\n         assertFalse(ch7.isActive());\n         assertTrue(ch7.close().isSuccess());\n     }\n \n+    @Test\n+    public void testIpv6MaskCorrectlyApplied() {\n+        IpSubnetFilterRule rule = new IpSubnetFilterRule(\"2001:db8:abcd:0000::\", 52, IpFilterRuleType.ACCEPT);\n+\n+        EmbeddedChannel ch = newEmbeddedInetChannel(\"2001:db8:ffff:0000::\",\n+                new IpSubnetFilter(false, Collections.singletonList(rule)));\n+        assertFalse(ch.isActive());\n+        assertTrue(ch.close().isSuccess());\n+    }\n+\n+    @Test\n+    public void testIpv6MatchesNoFalsePositiveForAllOnesNetworkBits() {\n+        // FFFF:FFFF::1 is NOT in 2001:db8::/32, which will be the case if the comparison is made unsigned.\n+        IpSubnetFilterRule rule = new IpSubnetFilterRule(\"2001:db8::\", 32, IpFilterRuleType.ACCEPT);\n+        assertFalse(rule.matches(newSockAddress(\"FFFF:FFFF::1\")));\n+     }\n+\n     private static IpSubnetFilterRule buildRejectIP(String ipAddress, int mask) {\n         return new IpSubnetFilterRule(ipAddress, mask, IpFilterRuleType.REJECT);\n     }"}]}