Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

next/sv/661/70x/20241207/v1 #2169

Merged
merged 4 commits into from
Dec 9, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion tests/bug-7414-decoder-event-01/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7

checks:
- filter:
Expand Down
2 changes: 1 addition & 1 deletion tests/bug-7414-decoder-event-02-ips/test.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
pcap: ../bug-7414-decoder-event-01/ip_secopt.pcap

requires:
min-version: 8
min-version: 7

checks:
- filter:
Expand Down
2 changes: 1 addition & 1 deletion tests/flowint-isnotset/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.8

pcap: ../tls/tls-subjectaltname/input.pcap

Expand Down
3 changes: 3 additions & 0 deletions tests/requires-7-unknown/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
Test that the new behavior in 8 for treating unknown requirements as
unsatisfied can be disable in 7.0.8 and newer, but that this setting is not
respected in 8.
1 change: 1 addition & 0 deletions tests/requires-7-unknown/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert http any any -> any any (content:"uid=0"; requires: foo bar; sid:9; rev:1;)
27 changes: 27 additions & 0 deletions tests/requires-7-unknown/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
args:
# Suricata 8 doesn't respect this setting.
- --set ignore-unknown-requirements=true

pcap: ../eve-metadata/testmyids.pcap

checks:

- filter:
requires:
lt-version: 8
count: 1
match:
event_type: stats
stats.detect.engines[0].rules_skipped: 0
stats.detect.engines[0].rules_loaded: 1
stats.detect.engines[0].rules_failed: 0

- filter:
requires:
min-version: 8
count: 1
match:
event_type: stats
stats.detect.engines[0].rules_skipped: 1
stats.detect.engines[0].rules_loaded: 0
stats.detect.engines[0].rules_failed: 0
4 changes: 4 additions & 0 deletions tests/requires-unknown/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
Test that unknown requirements are treated as unsatisfied leading to the rule
being skipped.

Simple standalone test.
1 change: 1 addition & 0 deletions tests/requires-unknown/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert http any any -> any any (content:"uid=0"; requires: foo bar; sid:9; rev:1;)
14 changes: 14 additions & 0 deletions tests/requires-unknown/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
requires:
min-version: 7.0.8

pcap: ../eve-metadata/testmyids.pcap

checks:

- filter:
count: 1
match:
event_type: stats
stats.detect.engines[0].rules_skipped: 1
stats.detect.engines[0].rules_loaded: 0
stats.detect.engines[0].rules_failed: 0
Loading