srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests/test_summarize.cpp
diff options
context:
space:
mode:
Diffstat (limited to 'tests/test_summarize.cpp')
-rw-r--r--tests/test_summarize.cpp30
1 files changed, 30 insertions, 0 deletions
diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp
index 9eef454..f180f87 100644
--- a/tests/test_summarize.cpp
+++ b/tests/test_summarize.cpp
@@ -186,6 +186,36 @@ TEST_CASE("summarize_packet decodes an ARP request end to end") {
"ARP who-has 10.0.0.2 tell 10.0.0.1 (aa:bb:cc:dd:ee:ff)");
}
+TEST_CASE("summarize_packet falls back to the RTCP heuristic on an unmatched UDP port") {
+ std::vector<unsigned char> rtcp = {0x80, 0xC9, 0x00, 0x01, 0, 0, 0, 0}; // RR, len=1 -> 8 bytes
+
+ std::vector<unsigned char> udp(8, 0);
+ udp[0] = 0x4E; udp[1] = 0x20; // src port 20000: not any registered L7 port
+ udp[2] = 0x4E; udp[3] = 0x21; // dst port 20001: likewise unregistered
+ std::uint16_t udp_len = static_cast<std::uint16_t>(8 + rtcp.size());
+ udp[4] = static_cast<unsigned char>(udp_len >> 8);
+ udp[5] = static_cast<unsigned char>(udp_len & 0xFF);
+
+ std::vector<unsigned char> ip(20, 0);
+ ip[0] = 0x45;
+ ip[8] = 64;
+ ip[9] = packeteer::net::kProtoUdp;
+ ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1;
+ ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2;
+
+ std::vector<unsigned char> eth = {
+ 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x00,
+ };
+
+ std::vector<unsigned char> frame = eth;
+ frame.insert(frame.end(), ip.begin(), ip.end());
+ frame.insert(frame.end(), udp.begin(), udp.end());
+ frame.insert(frame.end(), rtcp.begin(), rtcp.end());
+
+ auto line = packeteer::summarize_packet(frame, DLT_EN10MB);
+ CHECK(line.find("RTCP? RR") != std::string::npos);
+}
+
TEST_CASE("summarize_packet decodes IGMP directly on IP (not through a TCP/UDP port)") {
std::vector<unsigned char> igmp = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250}; // v2 report