From f968d22867beb2ea44a6e6716e2fb40e73a68b39 Mon Sep 17 00:00:00 2001 From: Ruben Herold Date: Fri, 7 Aug 2026 22:56:21 +0200 Subject: utils: T9177: fix _are_same_ip() using wrong address family _are_same_ip() computed the address family of both arguments but only ever passed the first one's family to inet_pton() for both, via a computed-but-unused "s_two" local. Comparing addresses of different families (e.g. one IPv4, one IPv6) raised instead of returning False. Found via ruff flagging s_two as an unused local; the function currently has no callers. --- python/vyos/utils/network.py | 6 ++++-- src/tests/test_utils_network.py | 9 +++++++++ 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/python/vyos/utils/network.py b/python/vyos/utils/network.py index 5b75de1cc..ef8205b97 100644 --- a/python/vyos/utils/network.py +++ b/python/vyos/utils/network.py @@ -25,8 +25,10 @@ def _are_same_ip(one, two): from vyos.template import is_ipv4 # compare the binary representation of the IP f_one = AF_INET if is_ipv4(one) else AF_INET6 - s_two = AF_INET if is_ipv4(two) else AF_INET6 - return inet_pton(f_one, one) == inet_pton(f_one, two) + f_two = AF_INET if is_ipv4(two) else AF_INET6 + if f_one != f_two: + return False + return inet_pton(f_one, one) == inet_pton(f_two, two) def get_protocol_by_name(protocol_name): """Get protocol number by protocol name diff --git a/src/tests/test_utils_network.py b/src/tests/test_utils_network.py index 6d9a358c1..2e12aea7f 100644 --- a/src/tests/test_utils_network.py +++ b/src/tests/test_utils_network.py @@ -44,6 +44,15 @@ class TestVyOSUtilsNetwork(TestCase): self.assertFalse(vyos.utils.network.is_loopback_addr('::2')) self.assertFalse(vyos.utils.network.is_loopback_addr('192.0.2.1')) + def test_are_same_ip(self): + self.assertTrue(vyos.utils.network._are_same_ip('192.0.2.1', '192.0.2.1')) + self.assertFalse(vyos.utils.network._are_same_ip('192.0.2.1', '192.0.2.2')) + self.assertTrue(vyos.utils.network._are_same_ip('::1', '::1')) + self.assertFalse(vyos.utils.network._are_same_ip('::1', '::2')) + # mixed address families must never compare equal, and must not raise + self.assertFalse(vyos.utils.network._are_same_ip('192.0.2.1', '::1')) + self.assertFalse(vyos.utils.network._are_same_ip('::1', '192.0.2.1')) + def test_check_port_availability(self): self.assertTrue(vyos.utils.network.check_port_availability('::1', 8080)) self.assertTrue(vyos.utils.network.check_port_availability('127.0.0.1', 8080)) -- cgit v1.2.3