detect/iponly: rule parsing does not always apply netmask correctly
Needs backport to 5.0, Needs backport to 6.0
If the ipaddress is not the address range start, it's not masked to turn it into that. So
188.8.131.52/24 is not stored as address
184.108.40.206 with netmask 24, but as
220.127.116.11 with netmask 24. This is then propagated into the radix tree, where it is used as an exact key in exact lookups, giving unexpected results.