From: Jeff Lucovsky Date: Thu, 10 Sep 2020 12:46:00 +0000 (-0400) Subject: tests: Add file_data/compress-ws transform tests X-Git-Tag: suricata-6.0.4~229 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=718d4d853898b1823d9678bcf4d4bdadf4f7be3f;p=thirdparty%2Fsuricata-verify.git tests: Add file_data/compress-ws transform tests --- diff --git a/tests/detect-compress_whitespace-01/input.pcap b/tests/detect-compress_whitespace-01/input.pcap new file mode 100644 index 000000000..cc069dc98 Binary files /dev/null and b/tests/detect-compress_whitespace-01/input.pcap differ diff --git a/tests/detect-compress_whitespace-01/input.rules b/tests/detect-compress_whitespace-01/input.rules new file mode 100644 index 000000000..6a9d1a361 --- /dev/null +++ b/tests/detect-compress_whitespace-01/input.rules @@ -0,0 +1 @@ +alert http any any -> any any (msg:"HTTP strip_whitespace 1"; flow:established; file_data; compress_whitespace; content:"embrace holistically"; sid:1;) diff --git a/tests/detect-compress_whitespace-01/test.yaml b/tests/detect-compress_whitespace-01/test.yaml new file mode 100644 index 000000000..3106bcd9d --- /dev/null +++ b/tests/detect-compress_whitespace-01/test.yaml @@ -0,0 +1,12 @@ +requires: + min-version: 6 + pcap: false + +exit-code: 1 +args: + - --engine-analysis + +checks: + - shell: + args: grep "incompatible with compress_whitespace transform" stderr| wc -l | xargs + expect: 1 diff --git a/tests/detect-compress_whitespace-02/input.pcap b/tests/detect-compress_whitespace-02/input.pcap new file mode 100644 index 000000000..cc069dc98 Binary files /dev/null and b/tests/detect-compress_whitespace-02/input.pcap differ diff --git a/tests/detect-compress_whitespace-02/input.rules b/tests/detect-compress_whitespace-02/input.rules new file mode 100644 index 000000000..b11de2c09 --- /dev/null +++ b/tests/detect-compress_whitespace-02/input.rules @@ -0,0 +1 @@ +alert http any any -> any any (msg:"HTTP compress_whitespace 2"; flow:established; file_data; compress_whitespace; content:"embrace holistically"; sid:1;) diff --git a/tests/detect-compress_whitespace-02/test.yaml b/tests/detect-compress_whitespace-02/test.yaml new file mode 100644 index 000000000..808abea47 --- /dev/null +++ b/tests/detect-compress_whitespace-02/test.yaml @@ -0,0 +1,12 @@ +requires: + min-version: 6 + +args: + - -k none + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1