you are viewing a single comment's thread
view the rest of the comments
[–] 314 points 2 years ago (9 children)

Ok. This covers every ipv6 and ipv4 address.

"^\s*((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])(.(25[0-5]|2[0-4][0-9]|1[0-9][0-9]|[1-9]?[0-9])){3}))|:)))(%.+)?\s*$"

  • source
  • hideshow 18 child comments
  • [–] 83 points 2 years ago* (1 child)

    Please don't. Use regex to find something that looks like an IP then build a real parser. This is madness, its's extremely hard to read and a mistake is almost impossible to spot. Not to mention that it's slow.

    Just parse [0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3} using regex (for v4) and then have some code check that all the octets are valid (and store the IP as a u32).

  • source
  • parent
  • hideshow 2 child comments
  • [–] 11 points 2 years ago (2 children)

    And dupe check. 0.0.0.0 and 000.000.000.000 may both be valid, but they resolve the same

  • source
  • parent
  • hideshow 4 child comments
  • [–] 6 points 2 years ago (1 child)

    Fuck that, if for whatever reason I'm writing an IP validator by hand I'm disallowing leading zeros. Parsers are very inconsistent, some will parse 010 as 10, others as 0o10 == 8 (you can try that right now with a POSIX ping). Talk about a footgun.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago* (3 children)

    Definitely, tho if you store it as a u32 that is fixed magically. Because 1.2.3.4 and 1.02.003.04 both map to the same number.

    What I mean by storing it as a u32 is to convert it to a number, similar to how the IP gets sent over the wire, so for v4:

    octet[3] | octet[2] << 8 | octet[1] << 16 | octet[0] << 24

    or in more human terms:

    (fourth octet) + (third octet * 256) + (second octet * 256^2) + (first octet * 256^3)
    
  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 2 years ago (1 child)

    Because 1.2.3.4 and 1.02.003.04 both map to the same number.

    But 10.20.30.40 and 010.020.030.040 map to different numbers. It's often best to reject IPv4 addresses with leading zeroes to avoid the decimal vs. octal ambiguity.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 51 points 2 years ago (5 children)

    IPv6 was a mistake. We should have just added an addition octet

  • source
  • parent
  • hideshow 10 child comments
  • [–] 75 points 2 years ago (4 children)

    That would allow for like, 2 trillion devices? Feels like a bandaid, my dude. Next you’re gonna suggest a giant ice cube in the ocean once a year to stop global warming.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 13 points 2 years ago (1 child)

    So add two more octets:

    Moat companies will still just use something like 10.0.13.37.0.1

  • source
  • parent
  • hideshow 2 child comments
  • [–] 11 points 2 years ago (2 children)

    IPv6 is not made with internal networks in mind lol

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 2 years ago

    You can use a ULA if you want to. That's essentially the IPv6 equivalent of a private IP.

    Why though? Having the same IP for both internal and external solves a bunch of issues. For example, you don't need to use split horizon DNS any more (which is where a host name has a different IP on your internal network vs on the internet). You just need to ensure your firewalls are set up properly, which you should do anyways.

  • source
  • parent
  • [–] -2 points 2 years ago (1 child)

    Never claimed it was, please quote me where I said as much

  • source
  • parent
  • hideshow 2 child comments
  • [–] 17 points 2 years ago (1 child)

    My dude, you used the 10.xx private IP as an example. Why wouldn’t they assume you were referring to internal networks?

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 2 years ago (1 child)

    I thought it was pretty clear with me adding 13.37 that I was making a joke, the earlier post spoke about how just adding one octet would still be too few addresses, so I joked about adding one more octet.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 2 years ago (1 child)
  • [–] 4 points 2 years ago*

    You could follow this logic and add 2 alphanumeric digits before 4 numeric octets. E.g. xf.192.168.1.1

    This would at least keep it looking like an IP and not a Mac address. Another advantage would be graceful ipv4 handling with a reserved range starting with "ip" like ip.10.10.10.1

  • source
  • parent
  • [–] 17 points 2 years ago (2 children)

    Oh yeah, great, let's change the fundamental protocol on which all the networks in the world are based. Now two third of the devices in the world crashed because you tried to ping 192.168.0.0.1

  • source
  • parent
  • hideshow 4 child comments
  • [–] 37 points 2 years ago (1 child)
  • [–] 19 points 2 years ago* (last edited 2 years ago) (1 child)

    Made that joke in an interview once.

    They didn't think it was funny. They truly thought Regex was the solution to, but never the cause of, all problems.

    They wanted to make a Regex to verify every single address in the world. Dodged a bullet

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 2 years ago* (2 children)

    Holy hell yeah you did. How would you go about doing that in a single expression? A bunch of back references to figure out the country? What if that's not included? Oy.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 15 points 2 years ago* (1 child)

    You wouldn't. It's not possible. Which is what I told them.

    And why would you want to? Legally if you change the given address, and it fails to get delivered - that is on you. Not them.

    Some countries have addresses that are literally 'Last house on the left by the Big Tree. Bumban(Neighborhood). NN (Country)'. Any US Centric validation would fail this but I assure you - mail gets delivered just fine.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    The only valid regex is (.+). Maybe add a separate country field (especially because some Americans wholeheartedly believe that the entire world should understand that "foobar, TX" means "foobar, Texas, United States") (don't get me started on states whose abbreviations are also ISO country codes).

    Unfortunately I guess business people only care about getting fewer support calls for missing shipping details, not correctness or a couple of calls from customers who live in the boonies. Then the proper answer is a form with a bunch of fields... which Americans will inevitably fuck up by making the "State" field mandatory despite most countries not having an equivalent.

    What I'd really do is use one of those services that automatically fill on the address using google maps or whatever. Not perfect, probably not free, but a whole lot less work for presumably way fewer PEBCAKs from customers.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago

    If you're using one of those services then PLEASE allow manual entry / override because I've had forms like that which I were blocked from filing in because it didn't acknowledge that my address existed.

  • source
  • parent