srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests/test_summarize.cpp
diff options
context:
space:
mode:
Diffstat (limited to 'tests/test_summarize.cpp')
-rw-r--r--tests/test_summarize.cpp28
1 files changed, 28 insertions, 0 deletions
diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp
index f180f87..baf4ed4 100644
--- a/tests/test_summarize.cpp
+++ b/tests/test_summarize.cpp
@@ -186,6 +186,34 @@ TEST_CASE("summarize_packet decodes an ARP request end to end") {
"ARP who-has 10.0.0.2 tell 10.0.0.1 (aa:bb:cc:dd:ee:ff)");
}
+TEST_CASE("summarize_packet reports a non-first IPv4 fragment without decoding fake TCP/UDP") {
+ // Payload here is arbitrary bytes - if this were mistakenly
+ // handed to a transport parser it would produce a plausible-
+ // looking but entirely fake TCP/UDP line. The point of this test
+ // is that it must not.
+ std::vector<unsigned char> fake_continuation_data = {0xDE, 0xAD, 0xBE, 0xEF, 0x00, 0x01, 0x02, 0x03};
+
+ std::vector<unsigned char> ip(20, 0);
+ ip[0] = 0x45;
+ ip[4] = 0x00; ip[5] = 0x7B; // identification = 123
+ ip[6] = 0x00; ip[7] = 0x08; // fragment_offset = 8 (byte offset 64), MF=0
+ ip[9] = packeteer::net::kProtoTcp;
+ ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1;
+ ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2;
+
+ std::vector<unsigned char> eth = {
+ 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x00,
+ };
+
+ std::vector<unsigned char> frame = eth;
+ frame.insert(frame.end(), ip.begin(), ip.end());
+ frame.insert(frame.end(), fake_continuation_data.begin(), fake_continuation_data.end());
+
+ auto line = packeteer::summarize_packet(frame, DLT_EN10MB);
+ CHECK(line.find("fragment id=123 offset=64") != std::string::npos);
+ CHECK(line.find("TCP") == std::string::npos); // must not have decoded the fake continuation data
+}
+
TEST_CASE("summarize_packet falls back to the RTCP heuristic on an unmatched UDP port") {
std::vector<unsigned char> rtcp = {0x80, 0xC9, 0x00, 0x01, 0, 0, 0, 0}; // RR, len=1 -> 8 bytes