Skip to content

Add ip_classify custom function - #238

Merged
gdollasigns merged 2 commits into
8.6from
feature/ip_classify_cf
Jun 25, 2026
Merged

gdollasigns merged 2 commits into
8.6from
feature/ip_classify_cf

Conversation

@gdollasigns

Copy link
Copy Markdown
Collaborator

Summary

Adds a new ip_classify custom function that supersedes the approach in #185.

Key improvements over #185

  • Uses Python's ipaddress module — stdlib, battle-tested, no manual string parsing
  • Covers 15 RFC-defined ranges vs 3 in added: function to sort public and private IPv4 #185 — adds loopback, link-local, CGNAT (RFC6598), documentation (RFC5737), multicast, reserved, broadcast, and more
  • Correct loopback handling — 127.x.x.x correctly classified as private (was a bug in added: function to sort public and private IPv4 #185)
  • Invalid IPs surfaced — returned as classification: 'invalid' with a reason, rather than silently dropped
  • List output — one entry per IP with ip, classification, and reason fields, making it easy to filter in playbooks (e.g. classification == 'public')
  • snake_case naming — consistent with repo convention
  • Targets 8.6, Python 3.13 — up to date with current platform

Outputs

Each IP in the input list produces one output record:

Field Description
ip (CEF type: ip) The IPv4 address
classification public, private, or invalid
reason e.g. Private (RFC1918), Loopback (RFC1122), Public, Not a valid IPv4 address

Test coverage

Validated against:

  • RFC1918 private ranges (10.x, 172.16-31.x, 192.168.x)
  • Loopback (127.0.0.1)
  • Link-local (169.254.x.x)
  • CGNAT (100.64.x.x)
  • Documentation ranges (192.0.2.x, 198.51.100.x, 203.0.113.x)
  • Public IPs (8.8.8.8, 1.1.1.1, 208.67.222.222)
  • Invalid inputs (256.0.0.1, not-an-ip)

Closes #185

@gdollasigns
gdollasigns merged commit 4774043 into 8.6 Jun 25, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant