Skip to content

Commit

Permalink
tests: Updates for 6555
Browse files Browse the repository at this point in the history
This commit provides updates needed for issue 6555. Previously, the gap
handling was restricted to master; 6555 adds those changes to main-7.0.x

Most of the changes are to extend the version; the
eve-payload-07-http-gap tests adds version-based checks as a new output
value payload_length is not available in main-7.0.x
  • Loading branch information
jlucovsky committed Aug 27, 2024
1 parent e4f9762 commit 014f3d6
Show file tree
Hide file tree
Showing 14 changed files with 59 additions and 14 deletions.
2 changes: 1 addition & 1 deletion tests/eve-overlap-payload-01/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-overlap-payload-02-policy-oldlinux/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-overlap-payload-03-ips/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-overlap-payload-04-partial-overlap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7


args:
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-overlap-payload-05-gap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7


args:
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-payload-01-tcp-exact-overlap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-payload-03-tcp-exact-overlap-ips/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- -k none
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-payload-04-partial-overlap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7


args:
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-payload-05-tcp-data-gap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7


args:
Expand Down
2 changes: 1 addition & 1 deletion tests/eve-payload-06-tcp-data-leading-gap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7


args:
Expand Down
47 changes: 46 additions & 1 deletion tests/eve-payload-07-http-gap/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

pcap: ../http-gap-beyond-body/input.pcap

Expand All @@ -14,39 +14,84 @@ checks:
alert.signature_id: 1
- filter:
count: 1
min-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
payload_length: 40
- filter:
count: 1
min-version: 7.0.7
lt-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
- filter:
count: 1
min-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /2 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
payload_length: 80
- filter:
count: 1
min-version: 7.0.7
lt-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /2 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
- filter:
count: 1
min-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /2 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /3 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
payload_length: 120
- filter:
count: 1
min-version: 7.0.7
lt-version: 8.0
match:
event_type: alert
alert.signature_id: 1
payload_printable: "GET /1 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /2 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\nGET /3 HTTP/1.0\r\nUser-Agent: Mozilla\r\n\r\n"
- filter:
count: 1
min-version: 8.0
match:
event_type: alert
alert.signature_id: 2
payload_printable: "HTTP/1.0 200 OK\r\nDate: Mon, 31 Aug 2009 20:25:50 GMT\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\n"
payload_length: 136
- filter:
count: 1
min-version: 7.0.7
lt-version: 8.0
match:
event_type: alert
alert.signature_id: 2
payload_printable: "HTTP/1.0 200 OK\r\nDate: Mon, 31 Aug 2009 20:25:50 GMT\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\n"
- filter:
count: 1
min-version: 8.0
match:
event_type: alert
alert.signature_id: 3
payload_printable: "HTTP/1.0 200 OK\r\nDate: Mon, 31 Aug 2009 20:25:50 GMT\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\n[127 bytes missing]AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHTTP/1.0 200 OK\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\nHello People\r\n"
payload_length: 324
- filter:
count: 1
min-version: 7.0.7
lt-version: 8.0
match:
event_type: alert
alert.signature_id: 3
payload_printable: "HTTP/1.0 200 OK\r\nDate: Mon, 31 Aug 2009 20:25:50 GMT\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\n[127 bytes missing]AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHTTP/1.0 200 OK\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\nHello People\r\n"
- filter:
count: 1
match:
Expand Down
2 changes: 1 addition & 1 deletion tests/smb2-frames-gap-payload-logging-02/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- --set stream.midstream=true
Expand Down
2 changes: 1 addition & 1 deletion tests/smb2-frames-gap-payload-logging/test.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
requires:
min-version: 8
min-version: 7.0.7

args:
- --set stream.midstream=true
Expand Down

0 comments on commit 014f3d6

Please sign in to comment.