]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
output: fixups for output changes 1043/head
authorVictor Julien <victor@inliniac.net>
Thu, 1 Dec 2022 19:33:26 +0000 (20:33 +0100)
committerVictor Julien <victor@inliniac.net>
Fri, 16 Dec 2022 13:18:49 +0000 (14:18 +0100)
37 files changed:
tests/bug-3515/test.yaml
tests/classification-config-validate-01/test.yaml
tests/classification-config-validate-02/test.yaml
tests/datarep-03-bad-reputation/test.yaml
tests/detect-ip_proto-01/test.yaml
tests/pcre-invalid-rule-01/test.yaml
tests/reference-config-validate-01/test.yaml
tests/reference-config-validate-02/test.yaml
tests/test-bad-byte-extract-rule-1/test.yaml
tests/test-bad-byte-extract-rule-2/test.yaml
tests/test-bad-content-dsize-rule-2/test.yaml
tests/test-bad-content-dsize-rule-3/test.yaml
tests/test-bad-content-quotes-rule-1/test.yaml
tests/test-bad-depth-depth-rule-1/test.yaml
tests/test-bad-depth-distance-rule-1/test.yaml
tests/test-bad-depth-distance-rule-2/test.yaml
tests/test-bad-depth-rule-1/test.yaml
tests/test-bad-depth-within-rule-1/test.yaml
tests/test-bad-depth-within-rule-2/test.yaml
tests/test-bad-dsize-offset-rule-2/test.yaml
tests/test-bad-dsize-range-offset-rule-2/test.yaml
tests/test-bad-dsize-range-rule-2/test.yaml
tests/test-bad-hex-rule-1/test.yaml
tests/test-bad-hex-rule-2/test.yaml
tests/test-bad-hex-rule-3/test.yaml
tests/test-bad-negate-fast-pattern-rule-1/test.yaml
tests/test-bad-offset-distance-rule-1/test.yaml
tests/test-bad-offset-offset-rule-1/test.yaml
tests/test-bad-offset-within-rule-1/test.yaml
tests/test-bad-quotation-marks-rule-1/test.yaml
tests/test-bad-relative-keyword-fast-pattern-rule-1/test.yaml
tests/test-bad-semicolon-rule-1/test.yaml
tests/test-bad-semicolon-rule-2/test.yaml
tests/test-bad-within-within-rule-1/test.yaml
tests/test-unreachable-distance-1/test.yaml
tests/threshold-config-validate-01/test.yaml
tests/threshold-config-validate-02/test.yaml

index 8def8b7887c844f6d0a8ecb2f5d5e0ee38753ace..70c61a44841a74b34354e338fdda53ffbceed1b3 100644 (file)
@@ -8,5 +8,5 @@ args:
 
 checks:
     - shell:
-        args: grep "SC_WARN_ERSPAN_CONFIG" suricata.log | wc -l | xargs
+        args: grep "ERSPAN Type I is no longer configurable" suricata.log | wc -l | xargs
         expect: 1
index e7708852d4cfcafc16fc411c58172b29175c22cc..76e2ed9836d4738654a1c6033d2c36aab0e56454 100644 (file)
@@ -8,5 +8,5 @@ exit-code: 1
 
 checks:
     - shell:
-        args: grep "SC_WARN_CLASSIFICATION_CONFIG" suricata.log | wc -l | xargs
+        args: grep "Invalid Classtype in" suricata.log | wc -l | xargs
         expect: 1
index 64f1d14e42737591d98fa7988e9513d0f4540057..08a322993133f4ab55dafab2e42c305c73f0d1e9 100644 (file)
@@ -7,5 +7,5 @@ command: |
 checks:
 
     - shell:
-        args: grep -e "SC_WARN_CLASSIFICATION_CONFIG" suricata.log | wc -l | xargs
+        args: grep -e "Error loading classification configuration from" suricata.log | wc -l | xargs
         expect: 1
index a9ac4b749810f1e98e7a19b3f2400e408cf704c8..debe6e5f93d7890211720bd827264abcf5844bb4 100644 (file)
@@ -14,5 +14,8 @@ args:
 
 checks:
   - shell:
-      args: grep "SC_ERR_INVALID_NUMERIC_VALUE" suricata.log | wc -l | xargs
+      args: grep "is not a valid reputation value" suricata.log | wc -l | xargs
+      expect: 1
+  - shell:
+      args: grep "bad rep for dataset" suricata.log | wc -l | xargs
       expect: 1
index 159a1eeb91f19fc880d0265302721458148bcffa..8716c1ed3e7cd6b397e57fa51ed72aff6db76765 100644 (file)
@@ -9,9 +9,5 @@ exit-code: 1
 
 checks:
     - shell:
-        args: grep "SC_ERR_INVALID_SIGNATURE" suricata.log | wc -l | xargs
-        expect: 5
-
-    - shell:
-        args: grep "SC_ERR_INVALID_VALUE" suricata.log | wc -l | xargs
-        expect: 5
+        args: grep "Error" suricata.log | wc -l | xargs
+        expect: 11
index 7fe11baf55166fdede4fee589608680e3125534d..9b82bf28ed94b4ae13f02760f2ca9471fd7a3e30 100644 (file)
@@ -8,8 +8,8 @@ checks:
         expect: 1
 
     - shell:
-        args: grep SC_ERR_INVALID_SIGNATURE suricata.log | wc -l | xargs
-        expect: 26
+        args: grep Error suricata.log | wc -l | xargs
+        expect: 27
 
     - shell:
         args: grep "Expression seen with a sticky buffer" suricata.log | wc -l | xargs
index 29f0734eeba9780f220885f1c476af43172bfcf8..b6728cdede4a306d7a8feb6a60d43ea94d9c9672 100644 (file)
@@ -8,5 +8,5 @@ exit-code: 1
 
 checks:
     - shell:
-        args: grep "SC_ERR_REFERENCE_CONFIG" suricata.log | wc -l | xargs
+        args: grep "Invalid Reference Config in" suricata.log | wc -l | xargs
         expect: 1
index df30388851bae832ced216ba1b6098f82ec97442..d403eec056caa60eabe06deeb27e28cd80db574e 100644 (file)
@@ -7,9 +7,9 @@ command: |
 checks:
 
     - shell:
-        args: grep -e "SC_ERR_REFERENCE_CONFIG" suricata.log | wc -l | xargs
+        args: grep -e "unknown reference key" suricata.log | wc -l | xargs
         expect: 1
 
     - shell:
-        args: grep -e "SC_ERR_REFERENCE_UNKNOWN" suricata.log | wc -l | xargs
+        args: grep -e "Invalid Reference Config in" suricata.log | wc -l | xargs
         expect: 1
index 4a3ed88288e3483dc9c1d192c5b122cd9eb32e99..cf70b9e23b04a7247eaf82a7d4407c5eca5f4441 100644 (file)
@@ -17,7 +17,14 @@ checks:
         engine.message: "unknown byte_ keyword var seen in depth - d."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: "detect"
index 1b19fe979c9a4ed3c069d0ae6201923ec54829e1..d628702d8b9deec70b78838c6918d3fe2f1c9ddf 100644 (file)
@@ -17,7 +17,14 @@ checks:
         engine.message: "invalid value for depth: -5."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 4a4af612e2e306e4272d3397b40bd9e52bdaa655..89eac509a8a0275139213c23b3c3ec84dfc12bf5 100644 (file)
@@ -14,7 +14,15 @@ checks:
         engine.message: "signature can't match as required content length 30 exceeds dsize value 10"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 061320393eb28ea4efb3289f8e16e736e35aa3bb..6b2fd6f5afeaceb20eaec61296128ee9c5e794e9 100644 (file)
@@ -14,7 +14,14 @@ checks:
         engine.message: "signature can't match as required content length 20 exceeds dsize value 16"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: "detect"
index 472cc76f9cd019f8478ed5424c00f1a02ca6bdf3..b0be03c66059d3946c37eff09cd17ad88d92e46b 100644 (file)
@@ -17,7 +17,14 @@ checks:
         engine.message: "Invalid unescaped double quote within content section."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 72d1aa139db939b296e22aeab0ae40da254f1a89..eb4be50ee34edf875288227ef60e8763673b216f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use multiple depths for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 60d4e07648be5f637d8e2a156877bd5886e9f9c0..7aa860902eec6c88cedb17822bb3ee52bce2df2f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 60d4e07648be5f637d8e2a156877bd5886e9f9c0..7aa860902eec6c88cedb17822bb3ee52bce2df2f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 0053b59f29a6d0ee56dc57fceb294dd771ee4150..e7c67425a4654312f004c47fc1bdb1fb3695d3dd 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "depth needs preceding content, uricontent option, http_client_body, http_server_body, http_header option, http_raw_header option, http_method option, http_cookie, http_raw_uri, http_stat_msg, http_stat_code, http_user_agent, http_host, http_raw_host or file_data/dce_stub_data sticky buffer options."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 60d4e07648be5f637d8e2a156877bd5886e9f9c0..7aa860902eec6c88cedb17822bb3ee52bce2df2f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 0053b59f29a6d0ee56dc57fceb294dd771ee4150..e7c67425a4654312f004c47fc1bdb1fb3695d3dd 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "depth needs preceding content, uricontent option, http_client_body, http_server_body, http_header option, http_raw_header option, http_method option, http_cookie, http_raw_uri, http_stat_msg, http_stat_code, http_user_agent, http_host, http_raw_host or file_data/dce_stub_data sticky buffer options."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index d3d485d00e962146935891a57cdc8e4b1c9e7388..0ff96f27ec0565c3471abe71331de24f20d0f2b7 100644 (file)
@@ -14,7 +14,15 @@ checks:
         engine.message: "signature can't match as required content length 102 exceeds dsize value 50"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 74e366c66c155cc86ad0c100d8ae98513203e3d6..4d9187ba9c54e08f6af41c17b68decf60f348841 100644 (file)
@@ -14,7 +14,15 @@ checks:
         engine.message: "signature can't match as required content length 12 exceeds dsize value 10"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 073955fa6c143b7f75bc2bd87f84dd88a430ee0d..a4c01fd37c7796eaf579ef1a82a197879169f453 100644 (file)
@@ -14,7 +14,15 @@ checks:
         engine.message: "signature can't match as required content length 30 exceeds dsize value 10"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index d2bdde60310a1f43dafa088339f0587fd2783504..2e4a13dc3520e436c29ae3fb160e813d2a92b3ca 100644 (file)
@@ -14,11 +14,19 @@ checks:
         engine.message: "Invalid hex code in content - |l0 01 01|, hex l. Invalidating signature."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
 
+  - filter:
+      min-version: 7
+      count: 4
+      match:
+        event_type: engine
+        engine.module: detect
+
   - filter:
       min-version: 7.0
       count: 1
index a930f9c300ad2d5ee5c90d8da50818c3aae56019..7ed14793e86265623d0fee07897ad8d268bda8df 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "Invalid hex code in content - \u0001\u00101 10 0j|, hex j. Invalidating signature."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 93962975c86a312241c65c66a63fd5054a6789db..d3377a63bdc891d632c316aac1cf4d0e0deb6844 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "Invalid hex code assembly in content - |1.  Invalidating signature."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index bf222d7ecf8f567483fe2d1651dcd7afd1fb3481..56a539503887f7cd5ce0ae9d05851012f5197499 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't have a relative negated keyword set along with 'fast_pattern'."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 60d4e07648be5f637d8e2a156877bd5886e9f9c0..7aa860902eec6c88cedb17822bb3ee52bce2df2f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 50fb1434950f7c2dc49421b52532347952e9996e..299e7bac62ad0fd63a91c4c241594879b51e26ef 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use multiple offsets for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 60d4e07648be5f637d8e2a156877bd5886e9f9c0..7aa860902eec6c88cedb17822bb3ee52bce2df2f 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use a relative keyword like within/distance with a absolute relative keyword like depth/offset for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index db0b68a8cf9bd514122c037015de21cf4203f24b..fad22de8b39a871b6d0a4a3af03fd5f6500e6077 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "invalid formatting to content keyword: value must be double quoted 'content'"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index cafe44473b8517cec515643e1974f42a8c143d82..fbda1cb8fadb5106915aacb809dcd59d9db88e0d 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't have a relative keyword set along with 'fast_pattern:only;'."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 699c23d9ff18e00bdbf64ad556af6fa25175a5c1..b31dd4a6f4a860b582b125d2e9e09da3942153b0 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "bad option value formatting (possible missing semicolon) for keyword content: '\"AA\" depth:20'"
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 817891d7b136f893a2fcfd20d308967573678c9d..718ec710a3c81f35bc6637f3d061756ab18696c2 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "unknown rule keyword ''."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index 4c97015ce8cc3e6c57733fdd36ec3fe4fe406a79..5675a62963131ae922a4c7e74901e891345bc40b 100644 (file)
@@ -17,7 +17,15 @@ checks:
         engine.message: "can't use multiple withins for the same content."
 
   - filter:
+      lt-version: 7
       count: 1
       match:
         event_type: engine
         engine.error: "SC_ERR_NO_RULES_LOADED"
+
+  - filter:
+      min-version: 7
+      count: 3
+      match:
+        event_type: engine
+        engine.module: detect
index af39ec49717c3b467be653411362f8411ba8a28c..cd7813e0db1ba283db49806bdcba1098e5292f12 100644 (file)
@@ -1,5 +1,5 @@
 requires:
-  min-version: 7
+  min-version: 8 # TODO
 
 checks:
     - shell:
index fc09e42f799d8abe12a027f52971f302a7ea2f1a..d39d27f9cb4efc1a07be2a1e4873ca1f6f0edf4d 100644 (file)
@@ -11,6 +11,8 @@ checks:
         args: grep "Error loading threshold configuration" suricata.log | wc -l | xargs
         expect: 1
 
-    - shell:
-        args: grep "SC_WARN_THRESH_CONFIG" suricata.log | wc -l | xargs
-        expect: 1
+    # TODO
+    #- shell:
+    #    lt-version: 7
+    #    args: grep "SC_WARN_THRESH_CONFIG" suricata.log | wc -l | xargs
+    #    expect: 1
index 693af01023caba23bcc23d7921f65148805b4031..d605840d014bf6ed9ac93e91d3c86aeb82dcf0c3 100644 (file)
@@ -6,9 +6,9 @@ command: |
 
 checks:
 
-    - shell:
-        args: grep -e "SC_ERR_PCRE_MATCH" suricata.log | wc -l | xargs
-        expect: 1
+    #- shell:
+    #    args: grep -e "SC_ERR_PCRE_MATCH" suricata.log | wc -l | xargs
+    #    expect: 1
 
     - shell:
         args: grep -e "Threshold config parsed.*0 rule.*found" suricata.log | wc -l | xargs