srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests/test_smtp.cpp
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-07-01 00:40:00 +0200
committersrdusr <[email protected]>2025-07-01 00:40:00 +0200
commit407249eb5d654b5a951c43bc1722fd397d5d922c (patch)
treec367bf95c3855152d477a7eed5e709b3094a427c /tests/test_smtp.cpp
parent9046e6a10fd2d987cf6f6dc601ed3a75d286793f (diff)
downloadpacketeer-407249eb5d654b5a951c43bc1722fd397d5d922c.tar.gz
packeteer-407249eb5d654b5a951c43bc1722fd397d5d922c.zip
Add FTP, SMTP, TFTP, and IGMP; fix an IGMPv3 group-address misparse
FTP and SMTP share HTTP's line-based response-code-or-command shape but keep their own command vocabularies in separate files rather than sharing a parser. FTP passwords are shown as-is, not redacted - FTP sends them in the clear regardless, matching Wireshark's own behavior. TFTP is a small binary opcode protocol (RFC 1350) instead. IGMP sits directly on IP like ICMP, so it's dispatched by protocol number rather than through the port-keyed L7Registry the other three use. Live-verified: FTP/SMTP against minimal real TCP servers written for this (nothing installed locally), a full command/response exchange decoded correctly in both directions. TFTP against a real atftpd server and atftp client - the RRQ decoded correctly even though the transfer itself didn't complete (an atftpd sandbox issue, not this code). IGMP against real multicast traffic on wlp1s0, including a genuine query from the actual router. That live IGMP traffic caught a real bug before it shipped further: parse_igmp() read bytes[4:8] as a group address for every message type, but IGMPv3 reports use those bytes for Reserved+RecordCount instead - a real V3 report showed "group=0.0.0.1" (0 reserved, 1 record, misread as an IP). Fixed by only populating group for the types where it's genuinely an address; re-verified against the same live traffic, and a regression test locks in the exact pattern.
Diffstat (limited to 'tests/test_smtp.cpp')
-rw-r--r--tests/test_smtp.cpp51
1 files changed, 51 insertions, 0 deletions
diff --git a/tests/test_smtp.cpp b/tests/test_smtp.cpp
new file mode 100644
index 0000000..610ed4e
--- /dev/null
+++ b/tests/test_smtp.cpp
@@ -0,0 +1,51 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/l7/smtp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> to_bytes(const std::string& s) {
+ return std::vector<unsigned char>(s.begin(), s.end());
+}
+
+} // namespace
+
+TEST_CASE("parse_smtp decodes a greeting response") {
+ auto msg = parse_smtp(to_bytes("220 mail.example.com ESMTP\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->is_response);
+ CHECK(msg->command_or_code == "220");
+ CHECK(msg->argument == "mail.example.com ESMTP");
+}
+
+TEST_CASE("parse_smtp decodes a MAIL FROM command") {
+ auto msg = parse_smtp(to_bytes("MAIL FROM:<[email protected]>\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK_FALSE(msg->is_response);
+ CHECK(msg->command_or_code == "MAIL");
+ CHECK(msg->argument == "FROM:<[email protected]>");
+}
+
+TEST_CASE("parse_smtp decodes a multi-line response's first line, dash included") {
+ auto msg = parse_smtp(to_bytes("250-mail.example.com Hello\r\n250-PIPELINING\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->command_or_code == "250");
+ CHECK(msg->argument == "mail.example.com Hello");
+}
+
+TEST_CASE("parse_smtp rejects an unrecognized command word") {
+ CHECK_FALSE(parse_smtp(to_bytes("BOGUS foo\r\n")).has_value());
+}
+
+TEST_CASE("SmtpDissector claims port 25") {
+ SmtpDissector dissector;
+ CHECK(dissector.port() == kSmtpPort);
+
+ auto summary = dissector.summarize(to_bytes("EHLO client.example.com\r\n"));
+ REQUIRE(summary.has_value());
+ CHECK(*summary == "SMTP EHLO client.example.com");
+}