From 91620486aa4ac7103efc4dc644a5e6317b1619af Mon Sep 17 00:00:00 2001 From: Philippe Antoine Date: Fri, 1 Jul 2022 13:21:21 +0200 Subject: [PATCH] Adds regression test against forced filestore Cf https://redmine.openinfosecfoundation.org/issues/5408 --- tests/filestore-5408/README.md | 8 ++++++++ tests/filestore-5408/input.pcap | Bin 0 -> 67409 bytes tests/filestore-5408/suricata.yaml | 13 +++++++++++++ tests/filestore-5408/test.yaml | 8 ++++++++ 4 files changed, 29 insertions(+) create mode 100644 tests/filestore-5408/README.md create mode 100644 tests/filestore-5408/input.pcap create mode 100644 tests/filestore-5408/suricata.yaml create mode 100644 tests/filestore-5408/test.yaml diff --git a/tests/filestore-5408/README.md b/tests/filestore-5408/README.md new file mode 100644 index 000000000..3abd7ebb0 --- /dev/null +++ b/tests/filestore-5408/README.md @@ -0,0 +1,8 @@ +# Description + +Test against bug 5408 with forced filestore + +# PCAP + +The pcap comes from https://tcpreplay.appneta.com/wiki/captures.html#bigflows-pcap +The bigFlows.pcap was reduced to the pair of ip addresses causing the bug diff --git a/tests/filestore-5408/input.pcap b/tests/filestore-5408/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..eca84a48b50852a86384d1d1ab7f16f2bb1113e9 GIT binary patch literal 67409 zc-rk<378bswJsPK0Rh1cOw^1h6N&UpZM^{lQ@!u|E~crjs^0gmUiAr)7%}4Rb4gx| zCUHw#qA^M|8ndcIaf4{oxWq(FUgAq)5;Yom_ts29_bdeij2WQ)EV{b8=C4z?@A=QU z=bn4+_MhH!<8)*O()@4dP6U|-UKvc{j8pRv6*z|na@qRT)1Th{@UP9M)n_4E1R+-k z29XWj-(PwAg7amj`bGJVPDC6x{Ql$V@Zt^Adyv~NLy+k+X5Krkt84nSX)~rnM3YJs zF(@Fe*oAl!;@BKWoZCe7-Z&a@^Rv4Vhp>il0b&nABFG>j?_R}2G>D2gK00yZS?Y^` zoLw7^KK|)NUWJJuU-qW?z(h5to8E|M6dPq^k;K?B3kcHM2mEWTf^0u_yEn;dK2t` zl=ds71w3hKXe(ZiO7BX0tG-m)9ZBWAA)k-5WlRB^FQ0S;Tzn8^?X)iMvw3uZNT!5Z zu(a15NQZnnAL;SueXJJa{Ta;eY*1B?&!u9~TELZw!|zc~+EoNN;QGAXg=y>lOx|U6 zD{6L)k+5oFHLHfH+BC7cHJPeflMH5Q7;$TZsoB(un$42}-v=u;wbJj-n6y@nv1;?0 zoU|Y1LmC@t%eowlo-a8urQO;{$E^l7N@Fga7fqLK8C#Y~u}Mp{KW2@yxftGHvz|o4 z?~kU4MnfAXDTkcuErF)Mq)H5x^)lcTml1M|?9CSw3^(9)qqSg_vPSDwvrR46=bS22 zq#&`$iK596liNxre^o>E5_u*y5a;>)ivE6@Wzq>I)fekybLB{y8+w=J_IsWqNZGIGU&#ttl!An8rp_683cz_YD;SCHV;*^7AO^I zFNEZj!$>)^F)F6cQB{3GWl^X+N>w}?jF!TzDiVmee8FfvulIS`vLkP^FSe1{$uiG8IMx zfn++DOSsexjV4FC6IDa5Zf6{hU=WvS^+AJ~caof}UiMV8)~HgQ3b>L!Wq_*3xM)7& zE`*7CCJ@T#!d9KC#A!0wNKmHC_(@sXmdNE?QG+WIv#0g3LX0=_#sr;aYI>R0CDR*9 z7F>amY}p(yy8>#fyjZ5tAg@nI)D90(3E0SnI~r3_dP-GNrxcu?#8^77s)C; z2+*N$LMg*=DT?9nXJ^aBG`OP2;PE*6u|90x97C?eujq*+Se7gHWoSOm)3H7#mzg)m zTjGimDh4oD^jLF^L^@6POZ(8C)BTAoo2!<3Y@QxjAGWf`Z}-c{l|9AE3QXCDF6+^A zOe)upqZkVQ$9i;$A{Wio`r()J=1>gyNdY3y)%gB6pGhyL^LfxuX+Dw5_SfJiXVgZ1 znn|xL44{3=<)7>SoN%US0!b`%Hddx%+=?D9EAhIQb6Md6>8=a3StiFOvauCCu|^`l zyocqYX`1Ke&2e#2uE-Tv^bBiHsoLl((P_F^htJCl4Wkr6l`Yg!&_uk#c{BL&MFEIb&!DWRAf(WqSrnnS`uqfVoA97d(LMfG>gA*<9 zR`wWN7R3O87fg*vRS}e9CAW*zqkct!31@ZkJd61#T|Gj3t)R=ggE87!&4qH#M3M1H zoUq}tS&o4XyrL(?ad`=yPE^3JJZ}zstiQcFL34Z3$*;(IfDvC0&F$<5N1NMwUlTRA z>jZPVW`s+y9-y8AP2?%ER&(pyFdwl22Lv7?rJFw3^F0KSPYXWKl&)*W4WC7T8P@i6 zXP_xAbwBvZn5G!~ASb-vF~x_oDP}?Mx>M36=FELbaOSv$2r_Jj4xM8Ga`fQ!O&fdRH&NE3eCdbbu=pjHK+x@Ahp66QBd-$*80?mMaFBzg5NexGr zx4#D}>*k6TsF7ByO4CpD;W%WB@qdj~L!L!XsmKg08P?)Tf~)q?Je%PKEv6`Ue*%8i zPZAjTpHRs9SwKh(zp|R>ljDk&@kE~z?MJbGpgVF@fuVAgRN%N0#pTj9f(31w*LUjy|Xe6%;3KlBIC z{)0b&A}+lFx7l*Y{11sU|8WBI z-`CFk#=$1@UkCnbJYMJ>W(9$^mhJ^3bjAgpalz2Iptq^_O_K+@#|UE@%k7gT1$qf| zo&!1@jsU$)E$NN%E1?Dg)!LK&-e>c@q`!HWej1*AcG*h69{odNN!{@GoKaEuDwet6CCkomuHbvyIh{w^^8Vr0?ZA3%^phz3@#f&|d&Tuc@h z^z^S@)lY+Cx7rU!CRaBdiq?BGY<5`Lz=$Lf9f}FC6+RyZSM?=JYZ$&ZKq{3|RNl*E z@&lMmDwoR?Lm@pmfy#RGX=VV!aRnGq;WD|R7yN1iy#gnIe=G1Z0s~y30Pjl0$^b40 z%^m}zoB;yujqu=n0K5!+*UJ=n;h!uJ7o5bi>49FL9pJ+}#DmPz3xuO%K-d9UAJzwi z9M=`v&49ztJ@$3&&CwU(fS1M&g+@R(slzr{NweYV0Bm}25+6{aE14XmKyZ=;uY^pY zT*)!?E*d;%DA;+<5J$F1A`Gl`*Ub={AGuVRA6d{IFPLH2c$V`~7Xo2e4jz zWtvC?d(C2qb?0;AVQu`~K@h>VR;@{G!`3ijHVs8sJx;=wG}f9CY-@e5BiIvdBv@T{>-wDwvo` z9aa@ROjb`QD5WczPv+%LK5t2ylxCaFT2Oi=6{(h_N<=xOvyzsms+b6+(mbV;VuU^t zlq>u`S>1r5HW^l7c%4h(tfRojdvt6pYYn22x=UFsv80znGct>+UbDE(fuN&c$E8jq zDygL$d2N-CRgAfM#UC+JN`KfKq+=1LkTXD+nIm%M*{ON9$fb5lL#_aY<$W^qT!?7wt2c(62QGe62K33Cjrb? z4<`Y90UE$k_k;7tG=QKPJ~g*v01sya2zysGJ4?)k`Y*wS%8r+=a{KoVh8|S2CR3zU zW5w(ms$tW_Fk2%e3_>d~T0P0H6oi)f5VP5Sp^YC}YK)2vcgZ8g^Qw6-z~({{s+7zVkraZoO=n9JMM_Tk+|_u-K*rsM zq_xOqNPp5DiTlEZXf+&D*_le1j60MuEmLCTsZudu591|eh?M7QMrlf83;H<)N7)ql zG?}#9^laV{_ZF&HybAaAwlL?9a4{KYRN7_XvWfPaN-Ryu zb!O6LG8=ssL$vNSq&y~>$;oEa>V%w;(>i&YO<298#v{ojt$f}|x!pDn_)Dr76`}GD zL%eJY_zO;ET>pu%vkW26%3_(a$8T@M0!6xL)pr@a4^x@fk@O#V{|7>UaqKO)8R6!@$#+2PFV zS_2NxUn`206tIpP18WDI&k6ml73-**W{b=XJ(Yr3v328NZ9aFxSpoP&vI3ep1bfN~ zAW3}USpgV1<+1_@3|E5QCz731$5klgTy`9Lz;lNo6t!UIN)gl zqtty*^MjE2B{z#Qe_CMva69v_+|gwIi!2E83C=QhsG&1*IKUHzqm<^8$Qu}a)5**m zm@qGNH2P52Xvq8p!2GMa5aAff{9S!dWgzn>=e9FHb)mrgi;+eDH48xwZ(f+JM1nEy z+({&u!ifY>mrnimY>`BQHD4AM9vn9!ezD`^S2UNx$o1S}b1WVOSg)!Pu_*X&geds@ zP9i~P9;K5=&`Bid1i}xEKsaRnKb|{HY@OF4VVzgJJx|m5C`={*WAT%gAJb|@PTL@w zl<Cndl~{r$4(V$HT#XtvnsW}9;(Xtq<&h_^P|L)dh&MG_|nizMzD59`8T zOmZL`-OE6@RB`YukCV5!!UT#!R~XRaurG|_7$L`{Bnq4^xeUklH4;7&XJjOtn39q3 zj*D>6xCnb%GbidQ9Q46(ptrk&;XvA{5Dg!x@~u%XqCM&bng3p?DD!_xVE((?ncshQ zllf=<1wlUX*ja}jIwOdE3w%w;<{q$!_{8oysUh(RkV8kU4`H>2%>MykeoGf39HRo^ ztFQUAusqJz&irTf3(UV5IaPfLf^^8?0ENXTcu+m&AOjs>M z7Fjm7V%>AxG!eNdp;+=gx-kOwmk9y;LMzr6j~B%fiW=Xe9TRIIz{%ER;=?sH&-k!a-t9yVcL0ZomSwrg~+KV{-G6%J!7ueGlqp{9310! z)Cs@iZ(FfmTrP?wRHeLU&6rrAy;4|s~-Z!Ave&X9rtRn2I3ucNG z&{p}NTz3!blIwcJQF~{@1X zT=d(SB5kJ<%7)*qA0gu=fO-r39m)f(&%1W#Op%Eum7oLPxnex5V@^I8YAym#$4T0f zUexAc2&>220O!?xskvxHoqWj8S6MCE2xfdyyT{nz0u0J&t*E8iA0|0TSx>r3)lxde z&;}XmvQ-RNm?u+vTyDX{C{vMv%PrFOvQw4tr(~79(wB;6yy>!ES`F-9&BeSnP-T+9 zpJa%LsU&x!l!2}p4Mw%{6DrMMrGP)FHbnF8sx}5ZXl0Ss$qM$M)*g@)GmImrZY1sc zYRwvQs6ENLAI(|iK8LGnR~hJFt|%*})ov^iuhUdfZ7-9fG@<4RS=C09yq zv?j&lntZCrdR@h$hIANfQP%0sOJsgs6{nMg(P*?(8mQK#ODGBI;Llp6G?_ZvxHI=Ro1LlT<7$d6D1;V zuO_9TQa#%#y7-CDD!DnJVZ139ndr3A@O;v8@U4}aLPZxL^PdHn|1m)NkBwzT9#9D$ z%Xh!m&ir3mB{2Wu!DV-^Ly)OA69k_tdw;ixH!$!Fw6`DMIl|uF0-p^ouej@mR_pkz zIM%ZQ)*WMDZG)cJU9(%UF8@KdNNjQ7If(WC`{QA~wq>HTN`!PGvq}WHw?!ApiO(u2 zr(VrPFoaadq$C*JVN#$*=)Trm9Eo#Ktgh&I15?x+*uw;pxL43wO>y9hE{;_131>}1 z=Ku5qqRhWtVE*^onSaZfP3FJh?8z*;*r9^MbzpGd%B_u5l24@S;;5TWYSqR4=7Ej| zA8r~9ng2|{{6}^n!ZE5;&c6qCK<58&M?3RBe3Zcai;+dQy$QxxhY}A=TG_?Xckavz zP2trNP&FQYxLYiUE$rWQw`xTAVVenkMx^ zX11xb8CR8ZDOD(y2-f6U97~s_fjqu{t0hcDO_~+f2_}?ANyGyz9hxK6q-sP`#N=5z zEli5YX7WX6sop5L;|)|+K;5YlQ}fd-TF`oOUNfNtmZKtJv?-r8l}WH_Wk%*sn{X@_ z@{-0Nj++Y>#v_SUOn$vqZStEkoFW`VQ!bQIG9gaxkm@;HZP$A!#>(ZDl(S;-E6uD* z;bhBYZNVi^<9d^qGT0?dyymX)COv~jyz*SCnrHo3)Midvi&QmP3!y3|6<6y#wF(<4 z(NSJzYv2iESewb}Yeosi`mCJVr!E#!VJw|CguRxA!=S>`MoL+7nUZR6+T?1)QbkuP zqzcGwL@-^or=xnwQ2GL)^kl+Ozd>P?XGPK%h?-PS`x6m^gs)nO08yy1A#Jpr&KgtI zP8_=v$KIbfHe~)qfcbw3NdK2(S&@fSJB1+jk?qXC`8e|4NwCzO6kb^~mp_+XNSwe)Z_qf%j)t%o1_G)TaqM z_P%*gx?e}UCE85S3(a)v=w`Zj5lkxlO0~6_PWX71*aXlE!UWK}<6&*>pYYVbVnS2@ z^1WP8ilGO~)W4Dt$sxy;IEG54G8rn9qjCb1@9W(ENSu*#|FWq#_uugdrmjb@r(%kt zoMrsV1|5t$dKi!20$EXFR^9EiNrv4vkXZ|NF0`o6M zPK{oQAcrs+>`x-VL~q^61eglzLxm9NP%40|H5CA=%CTKyg%j0%!X!?iJ&JJgA`|)) z24m5d(^`kx7u+^aEUujw;@W4Ahjr=i5034FG+NBAfm;Z90W(`sYchrIL*c}HB;fL} z9#vHP{Qi5)(E?NFy0T2y^mG(v)*(SQ>Y5#!{-l;>L1D8&1elMYUBOt&_MyS=1UN9!E9A zO7j_0BO|=mu+xX2RjvP|_Ris8kBk z7;mr@Dlyf#b_&xOGYv30bVQ0Jw@Rw>6*DQh&f&|WcB&KA?nJfsZ$TSm{!M`S9|xrW z_*hotL3KfhMSr!O`LFn;!2F8`mwjmwf=tm!^m^lbu|$CTghYV*cP9e86&p?j$U$>g z>b~!>G0h!J1o&6S+#Sy5t^#`3+ta#43LdC05S*{MyL!-lh{GIRm1q_`_~}vY1rH!1 zzeN=BA^~yMF2ws0$9r?$i!>3}=0_t|S`hcDgu;D~uKnpHK+YsAp+K!_FQEVtKlg(! zF_&|*AmcG3o;nFog<9Q#`xK_|XS|+n_1l*-U zn=-1M8rvti&Vnl0By>aW3Fr-VzqO#PbHSuaipEkhcL~!K<=$AVW=|U;2}!hQ;aoh5 zsw!234>x23nWE8A)1x*e%T;_NCo8%AiCQ_}vK7+tM$r?nY2BW@$75CmV|A>Nl0{wV zq!E``{c?9LKt}K)TTan-Z<03a>Wyl=M5;Yyp5_X!vWvr1L7OBS2P9py`pQum?ofrW zjGJXNrL-gOcT>`$*n!LpC6C3Z9bk(M7oxr<7Pxx1duIYZCSsAEDk8t%L)azwdfc=08$k{vWq9|KsW=^Ao)Y zGKr~l9V$3nM+OIQ-{28S^2zKcKJuoMyPx=e@<2y}4>t{l%%1_wKer1Jj#07OkC)Dc z%zy0l?aaUJJ%RZbBa2=<6+sRy9+t=lWuw0vf{K?(& z|I;;&{Og8aUBmJ_fc&wzw9qNH3xDwwE50ft2q0+5IlZoH(x=#^^l$HQ{*K>qY@ z`QJ;ABfn+%b#PezRr?b?YPol2_r2ervA6d|F8h$woYr#hzH_SxBAvFXIzxLE(1`N^ z>Xz?+4e7t+PYleiYWX_M>Bpupiwd1^oyn zrhlqu){gba^1uIe=g#TdqVFxqoWywl6#laM?@w(0QsvthedV#0Cp>e@SEm_HSaJ19 z>9&59Ymw(+@qRS(`dxZ?*@tUhQMHV}Hpg{vmh{36Prk6=cR-#kh~tO<+=S<@xq9_A z*EkmZ`*Ns0xO~OhGK%8zQmJR?L~r#Boh(_t#M;mH*TH|_G`=E}>EU^B20s|OLNfGX zwZhjH`SZKw|KN;$*8_hI>cNVWf$V0e2akr28~lauxt*z7bay~Ku>J2|=m9XW7|lf^ z5@}Qp^ng^-5}Lpi5~);9$Y@%L;xbau1IV^F95q*L&hTkr&hXQnMF*WM%+8{N&Z2|P zq~W14X(;41-6Xb+o%&h9XMb|E&;HDljsuPHgq+x2CwCTdzo?+2#D|p!og*?+|-I?N5!&_Pu4@_Jy|(o zUD{@V$2t}wbKm-LE0zNjn{Cw$l`cMegj_7ZyI5F}_N^w?dVuxu%DG}eiPwan#Mj$N z;4@DO^MDJHMPJmkV$JZ1KBHcE z#=sa6xNSlN?(J5rg+5U%gMj596Kf&BdaD)dOS9)qti9kfZUcCC!@15cs+(9B0Ic^< zm?=_GL2HC^-D%n-*K3Gl>jxXLW<`aME^M!;01>?sQACS?sNaS7I^uZY{7au`BL0>h zjretG_r%tWzP4%8;9EdW9IhE%g}1L6g@{MXCW!cY&NK}Nay|(W8~+}Sc)Lt&&oQk{ zcxvZ}cEo|4Z$sU3-_iP;+$oM_7qA>7TJT9AApxiWfP^s0^Uqc z!-h(!5GFAwFgLk>n{nWJ&Ju5c5doWYo9%KxN*P#LP9LNA_Pj)8luo#6laQBaL1A8^ zBvO_Z)KXP~4Aa^K zP`Io$r@rAt-Em``FPDR;nOD>>Lk^?tXw_&hB`O}mkRv?~x566JvhkQ*Ue=Z^MTN;u zunD_YS=A;QOy1#VbT}KXC`^__iM7>rjM+q38HZDjrV3nCjcfU|oR_I|d5Seh{0h6- zfhnmG1E0OU~Fc`J!(^$xrGpPNRbis|P7?s-_ zs_60I(SWN+*Cka`p^*rpx9gI$9wI} zzv)eZ`4Rrh`uf4Ez56MbTHzp7a}bUdJ^38y^7Yn`Q!JN@r8zLt8-vmFp!?Bmi~O1v`M2*u{&$-4 zukD@Fbz8037S}^Uww;ub-F`H>Q238hJb^CQup^y8*?xKOV~Wz84MiGg8|sPtZ&W{8&0N$ z;pFX7%aI!O;JamSWcV2v?NYMF*PeWg8{aqu1uy4a5B`jfc$%59P53_MfRkqr^p4t`fLZE+^pfRXI+|qul4olyDVtcSn#EKrU{TL^7(@D+!JOCunQQyN*eT4ulVE(QyL^wtTVE^&M z?U4D;d8M8CEe?VC7b8cnxfekW2@=?^eHbTp=T6q=6evH_vJ0cUHR%(o#OzgK$#2?{ zkkGWeeY}6+08|SYHCC-?4yiW*toRX#7?!XF(4EJQ#3n5yw%XzUVmN_>;D0j CpWl-J literal 0 Hc-jL100001 diff --git a/tests/filestore-5408/suricata.yaml b/tests/filestore-5408/suricata.yaml new file mode 100644 index 000000000..c0378fa4f --- /dev/null +++ b/tests/filestore-5408/suricata.yaml @@ -0,0 +1,13 @@ +%YAML 1.1 +--- + +outputs: + - eve-log: + enabled: yes + types: + - files + - stats + - file-store: + version: 2 + enabled: yes + force-filestore: yes diff --git a/tests/filestore-5408/test.yaml b/tests/filestore-5408/test.yaml new file mode 100644 index 000000000..6b45ddac2 --- /dev/null +++ b/tests/filestore-5408/test.yaml @@ -0,0 +1,8 @@ +requires: + min-version: 6 + +checks: + - filter: + count: 5 + match: + event_type: fileinfo -- 2.47.2