From b2775eb7c2df53b9b148302c121696bdda44fe13 Mon Sep 17 00:00:00 2001 From: Juliana Fajardini Date: Fri, 13 Sep 2024 18:27:50 -0300 Subject: [PATCH] rules/test: add app-layer-protocol negated test To complement bug-7241 tests. --- tests/lua/lua-transform-05/README.md | 1 + tests/lua/lua-transform-05/test.rules | 1 + tests/lua/lua-transform-05/test.yaml | 17 +++++++++++++++++ tests/lua/lua-transform-05/transform.lua | 8 ++++++++ 4 files changed, 27 insertions(+) create mode 100644 tests/lua/lua-transform-05/README.md create mode 100644 tests/lua/lua-transform-05/test.rules create mode 100644 tests/lua/lua-transform-05/test.yaml create mode 100644 tests/lua/lua-transform-05/transform.lua diff --git a/tests/lua/lua-transform-05/README.md b/tests/lua/lua-transform-05/README.md new file mode 100644 index 000000000..4c158e284 --- /dev/null +++ b/tests/lua/lua-transform-05/README.md @@ -0,0 +1 @@ +Ensure Lua transform that returns nil is treated as though no transformation took place and the buffer is unchanged. diff --git a/tests/lua/lua-transform-05/test.rules b/tests/lua/lua-transform-05/test.rules new file mode 100644 index 000000000..c3588b920 --- /dev/null +++ b/tests/lua/lua-transform-05/test.rules @@ -0,0 +1 @@ +alert http any any -> any any (msg:"TEST"; http.uri; luaxform:transform.lua, bytes 0, offset 2;content:"exec_post.php"; sid:1; rev:1;) diff --git a/tests/lua/lua-transform-05/test.yaml b/tests/lua/lua-transform-05/test.yaml new file mode 100644 index 000000000..5c54f08b6 --- /dev/null +++ b/tests/lua/lua-transform-05/test.yaml @@ -0,0 +1,17 @@ +requires: + min-version: 8 + +args: + - --set default-rule-path=${TEST_DIR} + - --set security.lua.allow-rules=true + +pcap: ../lua-transform-01/test.pcap + +checks: + + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 + http.url: /exec_post.php diff --git a/tests/lua/lua-transform-05/transform.lua b/tests/lua/lua-transform-05/transform.lua new file mode 100644 index 000000000..fc7f577c4 --- /dev/null +++ b/tests/lua/lua-transform-05/transform.lua @@ -0,0 +1,8 @@ +function init (args) + local needs = {} + return needs +end + +function transform(input_len, input, argc, args) + return nil +end -- 2.47.2