Skip to content

test(firewall): add IMAP app-layer firewall regression test - #3319

Open
yashda wants to merge 1 commit into
OISF:masterfrom
yashda:yashda/firewall-rules-imap
Open

test(firewall): add IMAP app-layer firewall regression test#3319
yashda wants to merge 1 commit into
OISF:masterfrom
yashda:yashda/firewall-rules-imap

Conversation

@yashda

@yashda yashda commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

IMAP is detection-only in Suricata: src/app-layer-imap.c registers protocol detection patterns but no parser, transactions or progress states. A firewall rule that hooks an IMAP app-layer state therefore loads without error yet can never match, and the app-layer firewall never engages for an IMAP flow.

This test loads a drop:flow rule on imap:request_started intending to block every IMAP flow and asserts the expected behaviour:

  • the flow is still detected as app_proto imap (control), and
  • the drop rule fires and blocks the flow (alert sid 2000, action blocked),
  • the flow is actually dropped (firewall drop_reason.rules and blocked >= 1).

It fails on affected builds (reproducing the bug) and will pass once the underlying issue is fixed.

Ticket

If your pull request is related to a Suricata ticket, please provide
the full URL to the ticket here so this pull request can monitor
changes to the ticket status:

Redmine ticket: https://redmine.openinfosecfoundation.org/issues/

IMAP is detection-only in Suricata: src/app-layer-imap.c registers protocol
detection patterns but no parser, transactions or progress states. A firewall
rule that hooks an IMAP app-layer state therefore loads without error yet can
never match, and the app-layer firewall never engages for an IMAP flow.

This test loads a drop:flow rule on imap:request_started intending to block
every IMAP flow and asserts the expected behaviour:
  - the flow is still detected as app_proto imap (control), and
  - the drop rule fires and blocks the flow (alert sid 2000, action blocked),
  - the flow is actually dropped (firewall drop_reason.rules and blocked >= 1).

It fails on affected builds (reproducing the bug) and will pass once the
underlying issue is fixed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant