From: Jeff Lucovsky Date: Fri, 16 Dec 2022 14:31:34 +0000 (-0500) Subject: decode: Tests for unknown/arp counters X-Git-Tag: suricata-6.0.10~12 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=cc7ac3ae028db234f07958b7e298faf3e9159f1d;p=thirdparty%2Fsuricata-verify.git decode: Tests for unknown/arp counters Issue: 5761 This commit adds tests for decode counters which are new - decode.arp - decode.unknown_ethertype --- diff --git a/tests/decode-arp-1/input.pcap b/tests/decode-arp-1/input.pcap new file mode 100644 index 000000000..34f8d974e Binary files /dev/null and b/tests/decode-arp-1/input.pcap differ diff --git a/tests/decode-arp-1/test.rules b/tests/decode-arp-1/test.rules new file mode 100644 index 000000000..9ccfe5756 --- /dev/null +++ b/tests/decode-arp-1/test.rules @@ -0,0 +1 @@ +alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;) diff --git a/tests/decode-arp-1/test.yaml b/tests/decode-arp-1/test.yaml new file mode 100644 index 000000000..5a765b94b --- /dev/null +++ b/tests/decode-arp-1/test.yaml @@ -0,0 +1,14 @@ +requires: + min-version: 7 + +args: +- -k none + +checks: + - filter: + count: 1 + match: + event_type: stats + - stats: + decoder.ethernet: 1 + decoder.arp: 1 diff --git a/tests/decode-unknown-1/input.pcap b/tests/decode-unknown-1/input.pcap new file mode 100644 index 000000000..d3c406f7c Binary files /dev/null and b/tests/decode-unknown-1/input.pcap differ diff --git a/tests/decode-unknown-1/test.rules b/tests/decode-unknown-1/test.rules new file mode 100644 index 000000000..9ccfe5756 --- /dev/null +++ b/tests/decode-unknown-1/test.rules @@ -0,0 +1 @@ +alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;) diff --git a/tests/decode-unknown-1/test.yaml b/tests/decode-unknown-1/test.yaml new file mode 100644 index 000000000..8e826e230 --- /dev/null +++ b/tests/decode-unknown-1/test.yaml @@ -0,0 +1,14 @@ +requires: + min-version: 7 + +args: +- -k none + +checks: + - filter: + count: 1 + match: + event_type: stats + - stats: + decoder.ethernet: 1 + decoder.unknown_ethertype: 1