From: Jason Ish Date: Thu, 8 Jan 2026 21:18:54 +0000 (-0600) Subject: tests/dnp3: set min-version to 7.0.14 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=6dd15d2b3bf2fbd46c46143fa01ea295937bcba0;p=thirdparty%2Fsuricata-verify.git tests/dnp3: set min-version to 7.0.14 Remove backoff keywords as they don't work in 7, and are not critical to the tests. --- diff --git a/tests/dnp3/dnp3-flood/test.yaml b/tests/dnp3/dnp3-flood/test.yaml index 7fc4bd600..636fa1741 100644 --- a/tests/dnp3/dnp3-flood/test.yaml +++ b/tests/dnp3/dnp3-flood/test.yaml @@ -1,5 +1,5 @@ requires: - min-version: 9.0.0 + min-version: 7.0.14 checks: - filter: diff --git a/tests/dnp3/dnp3-max-objects/dnp3-events.rules b/tests/dnp3/dnp3-max-objects/dnp3-events.rules index d161e5394..ef937f99d 100644 --- a/tests/dnp3/dnp3-max-objects/dnp3-events.rules +++ b/tests/dnp3/dnp3-max-objects/dnp3-events.rules @@ -28,11 +28,9 @@ alert dnp3 any any -> any any (msg:"SURICATA DNP3 Unknown object"; \ # Too many points in an object. alert dnp3 any any -> any any (msg:"SURICATA DNP3 Too many points in object"; \ app-layer-event:dnp3.too_many_points; \ - threshold:type backoff, track by_flow, count 1, multiplier 10; \ classtype:protocol-command-decode; sid:2270005; rev:1;) # Too many objects. alert dnp3 any any -> any any (msg:"SURICATA DNP3 Too many objects"; \ app-layer-event:dnp3.too_many_objects; \ - threshold:type backoff, track by_flow, count 1, multiplier 10; \ classtype:protocol-command-decode; sid:2270006; rev:1;) diff --git a/tests/dnp3/dnp3-max-objects/test.yaml b/tests/dnp3/dnp3-max-objects/test.yaml index 541294545..e9859cb1f 100644 --- a/tests/dnp3/dnp3-max-objects/test.yaml +++ b/tests/dnp3/dnp3-max-objects/test.yaml @@ -1,5 +1,5 @@ requires: - min-version: 9.0.0 + min-version: 7.0.14 checks: - filter: diff --git a/tests/dnp3/dnp3-max-points/dnp3-events.rules b/tests/dnp3/dnp3-max-points/dnp3-events.rules index a6e2d9dac..e3acdc3d0 100644 --- a/tests/dnp3/dnp3-max-points/dnp3-events.rules +++ b/tests/dnp3/dnp3-max-points/dnp3-events.rules @@ -28,11 +28,9 @@ alert dnp3 any any -> any any (msg:"SURICATA DNP3 Unknown object"; \ # Too many points in a message. alert dnp3 any any -> any any (msg:"SURICATA DNP3 Too many points in message"; \ app-layer-event:dnp3.too_many_points; \ - threshold:type backoff, track by_flow, count 1, multiplier 10; \ classtype:protocol-command-decode; sid:2270005; rev:1;) # Too many objects. alert dnp3 any any -> any any (msg:"SURICATA DNP3 Too many objects"; \ app-layer-event:dnp3.too_many_objects; \ - threshold:type backoff, track by_flow, count 1, multiplier 10; \ classtype:protocol-command-decode; sid:2270006; rev:1;) diff --git a/tests/dnp3/dnp3-max-points/test.yaml b/tests/dnp3/dnp3-max-points/test.yaml index 7b0a2fb07..9aca3997f 100644 --- a/tests/dnp3/dnp3-max-points/test.yaml +++ b/tests/dnp3/dnp3-max-points/test.yaml @@ -1,5 +1,5 @@ requires: - min-version: 9.0.0 + min-version: 7.0.14 checks: - filter: