From abd966d7a9744d807ad81ef412b23e41a1e56b13 Mon Sep 17 00:00:00 2001 From: Philippe Antoine Date: Tue, 22 Apr 2025 14:45:20 +0200 Subject: [PATCH] http1: adds test about request line matching Ticket: 7668 Test that it matches as soon as possible --- tests/http-request-line-packet/README.md | 11 +++++++++++ tests/http-request-line-packet/test.rules | 1 + tests/http-request-line-packet/test.yaml | 16 ++++++++++++++++ 3 files changed, 28 insertions(+) create mode 100644 tests/http-request-line-packet/README.md create mode 100644 tests/http-request-line-packet/test.rules create mode 100644 tests/http-request-line-packet/test.yaml diff --git a/tests/http-request-line-packet/README.md b/tests/http-request-line-packet/README.md new file mode 100644 index 000000000..50e574eb7 --- /dev/null +++ b/tests/http-request-line-packet/README.md @@ -0,0 +1,11 @@ +# Test Description + +Test HTTP1 request line matches on earliest packet possible + +## Related issue + +https://redmine.openinfosecfoundation.org/issues/7668 + +## PCAP + +Reused from another test diff --git a/tests/http-request-line-packet/test.rules b/tests/http-request-line-packet/test.rules new file mode 100644 index 000000000..bdc6065a1 --- /dev/null +++ b/tests/http-request-line-packet/test.rules @@ -0,0 +1 @@ +alert http1 any any -> any any (http.method; content:"GET"; alert; sid:1;) diff --git a/tests/http-request-line-packet/test.yaml b/tests/http-request-line-packet/test.yaml new file mode 100644 index 000000000..9f7696df9 --- /dev/null +++ b/tests/http-request-line-packet/test.yaml @@ -0,0 +1,16 @@ +requires: + min-version: 7 + +pcap: ../firewall/ruletype-firewall-31-retrans-of-drop/input.pcap + +args: + - --simulate-ips + - -k none + +checks: +- filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 + pcap_cnt: 4 \ No newline at end of file -- 2.47.2