From 7d979ed09cdc718c641d4ce6f75fc4650c348624 Mon Sep 17 00:00:00 2001 From: Philippe Antoine Date: Mon, 13 Jul 2026 22:06:49 +0200 Subject: [PATCH] test: adds test for lua http2 library Ticket: 6409 --- tests/lua/lua-http2lib-01/README.md | 5 ++++ tests/lua/lua-http2lib-01/http-lua.rules | 7 +++++ tests/lua/lua-http2lib-01/http2.lua | 19 ++++++++++++++ tests/lua/lua-http2lib-01/httpx.lua | 21 +++++++++++++++ tests/lua/lua-http2lib-01/httpx1.lua | 21 +++++++++++++++ tests/lua/lua-http2lib-01/httpx2.lua | 21 +++++++++++++++ tests/lua/lua-http2lib-01/input.pcap | Bin 0 -> 3521 bytes tests/lua/lua-http2lib-01/test.yaml | 31 +++++++++++++++++++++++ 8 files changed, 125 insertions(+) create mode 100644 tests/lua/lua-http2lib-01/README.md create mode 100644 tests/lua/lua-http2lib-01/http-lua.rules create mode 100644 tests/lua/lua-http2lib-01/http2.lua create mode 100644 tests/lua/lua-http2lib-01/httpx.lua create mode 100644 tests/lua/lua-http2lib-01/httpx1.lua create mode 100644 tests/lua/lua-http2lib-01/httpx2.lua create mode 100644 tests/lua/lua-http2lib-01/input.pcap create mode 100644 tests/lua/lua-http2lib-01/test.yaml diff --git a/tests/lua/lua-http2lib-01/README.md b/tests/lua/lua-http2lib-01/README.md new file mode 100644 index 0000000000..196bd0124c --- /dev/null +++ b/tests/lua/lua-http2lib-01/README.md @@ -0,0 +1,5 @@ +https://redmine.openinfosecfoundation.org/issues/6409 + +Test lua HTTP/2 support + +Pcap with both HTTP1 and HTTP2 traffic diff --git a/tests/lua/lua-http2lib-01/http-lua.rules b/tests/lua/lua-http2lib-01/http-lua.rules new file mode 100644 index 0000000000..ed651f10f0 --- /dev/null +++ b/tests/lua/lua-http2lib-01/http-lua.rules @@ -0,0 +1,7 @@ +alert http2:stream:request_headers any any -> any any (msg: "Test HTTP2 Lua"; lua: http2.lua; sid:1;) +alert http1:request_line any any -> any any (msg: "Test HTTP2 Lua"; lua: http2.lua; sid:2;) + +alert http any any -> any any (msg: "Test HTTPX Lua"; lua: httpx.lua; sid:3;) + +alert http any any -> any any (msg: "Test HTTPX1 Lua"; lua: httpx1.lua; sid:4;) +alert http any any -> any any (msg: "Test HTTPX2 Lua"; lua: httpx2.lua; sid:5;) diff --git a/tests/lua/lua-http2lib-01/http2.lua b/tests/lua/lua-http2lib-01/http2.lua new file mode 100644 index 0000000000..0ba722c153 --- /dev/null +++ b/tests/lua/lua-http2lib-01/http2.lua @@ -0,0 +1,19 @@ +-- simple http or http2 match on request_uri_raw +local http = require("suricata.http") + +function init (args) + return {} +end + +function match(args) + local tx = http.get_tx() + uriraw, err = tx:request_uri_raw() + + if #uriraw > 0 then + if uriraw:find("/toto") then + return 1 + end + end + + return 0 +end diff --git a/tests/lua/lua-http2lib-01/httpx.lua b/tests/lua/lua-http2lib-01/httpx.lua new file mode 100644 index 0000000000..45267bd22b --- /dev/null +++ b/tests/lua/lua-http2lib-01/httpx.lua @@ -0,0 +1,21 @@ +-- simple http or http2 match on request_uri_raw +local http = require("suricata.http") + +function init (args) + local needs = {} + needs["http.uri"] = true + return needs +end + +function match(args) + local tx = http.get_tx() + uriraw, err = tx:request_uri_raw() + + if #uriraw > 0 then + if uriraw:find("/toto") then + return 1 + end + end + + return 0 +end diff --git a/tests/lua/lua-http2lib-01/httpx1.lua b/tests/lua/lua-http2lib-01/httpx1.lua new file mode 100644 index 0000000000..c074bd0f9d --- /dev/null +++ b/tests/lua/lua-http2lib-01/httpx1.lua @@ -0,0 +1,21 @@ +-- simple http or http2 match on request_uri_raw +local http = require("suricata.http") + +function init (args) + local needs = {} + needs["http.uri"] = true + return needs +end + +function match(args) + local tx = http.get_h1_tx() + uriraw, err = tx:request_uri_raw() + + if #uriraw > 0 then + if uriraw:find("/toto") then + return 1 + end + end + + return 0 +end diff --git a/tests/lua/lua-http2lib-01/httpx2.lua b/tests/lua/lua-http2lib-01/httpx2.lua new file mode 100644 index 0000000000..1f64fe7ab6 --- /dev/null +++ b/tests/lua/lua-http2lib-01/httpx2.lua @@ -0,0 +1,21 @@ +-- simple http or http2 match on request_uri_raw +local http = require("suricata.http") + +function init (args) + local needs = {} + needs["http.uri"] = true + return needs +end + +function match(args) + local tx = http.get_h2_tx() + uriraw, err = tx:request_uri_raw() + + if #uriraw > 0 then + if uriraw:find("/toto") then + return 1 + end + end + + return 0 +end diff --git a/tests/lua/lua-http2lib-01/input.pcap b/tests/lua/lua-http2lib-01/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..d50a68448a111f370b9cd67f29c1ebd628b9cf39 GIT binary patch literal 3521 zcmd6qZ%i9?7{`A{JJy{x0}@S*ke);wGAR8swps%#g@qM2ZCF_roWY|z7zEm`y|N+V z{=^x=i%Hn#G;;xyO%qKNjmis?5uJ(2iY!wmZZmFsv1B@;#_Wwkz~{O9UFn_0-rfm3 zK<i?n^xTzePT-b~7yO&q z^5PF}_f?K|IxmJk)kW2Zw5Np|*66q6s;xUuVfj zpaqNS`QShGSU}IHT2I54AXh0y#K?NFWTQjmH%Ivx-&5VocPE4=gm9>uZx@Bw`gj!1 zh6HYFFc_$G*c@hdYa}juIEQnS%?_UqkK69Ho7v{L5UZ%|5W;XSl!$d#x@``Z4NlaC zLP8V{mQ|LSSu>0B9|QT>>`b#^6l}Pw*qLs_*>RRMFhnZZ2BuDHgNkFZ++Erv+W?$e zj9BT5bK33PbI+LB9YU;EhcOeBB3k z&6s9fFy?vG)AVU}Jt|JVYV3Rpr%MNi`ZEUp)M@-#0DpYV4r|x(w@q2M-|Tto@V%k{ zjCJPiH_`vc6rRIPh0HZ)vNNs2v*!(b@=@T{XWD+>jeO4|S7DX_Guu2+o%O&ignm=o z4>`y~ZB;rrR9hixOXnz>kne>$+%U>xPw z`IoLWN1wF*wQH`(zQ5?B+Q0CJyXcyTV*y{f%7atv8edQ6~y~tHe~TNDe-N{foFFHXJ&mTEecs7^r+y=4ZI>re$j=}|=RBY>s$C5trePjJ z$f-JK!gqsG(S{&Auj-v4O-$y%qkXX|m6*g)#(*L4)(4?JfMyd%T^a+oZ)w~{m!^@^ z3!Ef~!=mE8(TY=X&}~>zxPY)htrq70^X$jg26b3OeZOVkr|_NbFUm4X&+i^^ zn!p|`Y7yMp-c0$)91C!K+WhiY!=EpI#P=q|J(2xkDNORN-Y}6wBvcH zVI@5d;P|0uEb1KG2x{k492~Bvw8LdeIhWd5+W=e+P%H|De^Jz6 Q+UNpYLISW177Gda2Pw3kx&QzG literal 0 HcmV?d00001 diff --git a/tests/lua/lua-http2lib-01/test.yaml b/tests/lua/lua-http2lib-01/test.yaml new file mode 100644 index 0000000000..2a1300678e --- /dev/null +++ b/tests/lua/lua-http2lib-01/test.yaml @@ -0,0 +1,31 @@ +requires: + features: + - HAVE_LUA + min-version: 9 + +args: + - --set security.lua.allow-rules=true + - --set default-rule-path=${TEST_DIR} + - -k none + +checks: + - filter: + count: 1 + match: + alert.signature_id: 1 + - filter: + count: 1 + match: + alert.signature_id: 2 + - filter: + count: 2 + match: + alert.signature_id: 3 + - filter: + count: 1 + match: + alert.signature_id: 4 + - filter: + count: 1 + match: + alert.signature_id: 5