Merge remote-tracking branch 'origin/topic/awelzel/dpd-analyzer-merger'

* origin/topic/awelzel/dpd-analyzer-merger:
  analyzer/dpd: Address review comments
  Remove @load base/frameworks/dpd from tests
  frameworks/dpd: Move to frameworks/analyzer/dpd, load by default
  scripts/dce-rpc,ntlm: Do not load base/frameworks/dpd
  btest: Remove unnecessary loading of frameworks/dpd
This commit is contained in:
Robin Sommer 2022-09-07 14:29:32 +02:00
commit a60d569f7b
76 changed files with 328 additions and 372 deletions

View file

@ -7,7 +7,6 @@
@load base/protocols/conn
@load base/protocols/dns
@load base/protocols/ssh
@load base/frameworks/dpd
redef Analyzer::disabled_analyzers += { Analyzer::ANALYZER_SSH };

View file

@ -2,7 +2,6 @@
# @TEST-EXEC: btest-diff out
@load base/frameworks/config
@load base/frameworks/dpd
type Color: enum { RED, GREEN, BLUE };

View file

@ -8,7 +8,6 @@ DPD::ignore_violations Analyzer::ANALYZER_SYSLOG
@TEST-END-FILE
@load base/frameworks/config
@load base/frameworks/dpd
redef exit_only_after_terminate = T;
redef InputConfig::empty_field = "EMPTY";

View file

@ -12,4 +12,3 @@
@load base/protocols/http
@load base/protocols/dns
@load base/protocols/conn
@load base/frameworks/dpd

View file

@ -4,7 +4,6 @@
@load base/protocols/conn
@load base/protocols/smtp
@load base/protocols/dns
@load base/frameworks/dpd
@load base/frameworks/netcontrol
event NetControl::init()

View file

@ -5,7 +5,6 @@
@load base/protocols/conn
@load base/protocols/ftp
@load base/frameworks/dpd
# Make sure we're tracking the CWD correctly.
event ftp_reply(c: connection, code: count, msg: string, cont_resp: bool) &priority=10

View file

@ -6,4 +6,3 @@
@load base/protocols/conn
@load base/protocols/ftp
@load base/frameworks/dpd

View file

@ -6,4 +6,3 @@
@load base/protocols/conn
@load base/protocols/ftp
@load base/frameworks/dpd

View file

@ -10,4 +10,3 @@
@load base/protocols/http
@load base/protocols/ssl
@load base/protocols/tunnels
@load base/frameworks/dpd

View file

@ -10,4 +10,3 @@
@load base/protocols/http
@load base/protocols/smtp
@load base/protocols/tunnels
@load base/frameworks/dpd

View file

@ -5,7 +5,6 @@
@load base/protocols/conn
@load base/protocols/http
@load base/frameworks/dpd
event http_request(c: connection, method: string, original_URI: string, unescaped_URI: string, version: string)
{

View file

@ -7,4 +7,3 @@
@load base/protocols/conn
@load base/protocols/http
@load base/frameworks/dpd

View file

@ -3,7 +3,6 @@
@load base/protocols/ssl
@load base/protocols/conn
@load base/frameworks/dpd
@load base/protocols/imap
event imap_capabilities(c: connection, capabilities: string_vec)

View file

@ -6,7 +6,6 @@
@load base/protocols/ssl
@load base/protocols/conn
@load base/frameworks/dpd
@load base/protocols/imap
redef SSL::log_include_server_certificate_subject_issuer=T;

View file

@ -8,7 +8,6 @@
@load base/protocols/conn
@load base/protocols/irc
@load base/frameworks/dpd
# dcc mime types are irrelevant to this test, so filter it out
event zeek_init()

View file

@ -4,6 +4,5 @@
# @TEST-EXEC: btest-diff x509.log
@load base/protocols/conn
@load base/frameworks/dpd
@load base/protocols/ssl
@load base/protocols/irc

View file

@ -4,4 +4,3 @@
@load base/protocols/krb
@load base/protocols/conn
@load base/frameworks/dpd

View file

@ -9,7 +9,6 @@
@load base/protocols/modbus
@load base/protocols/conn
@load base/frameworks/dpd
redef DPD::ignore_violations_after = 1;

View file

@ -4,7 +4,6 @@
# @TEST-EXEC: btest-diff x509.log
@load base/protocols/conn
@load base/frameworks/dpd
@load base/protocols/ssl
module POP3;

View file

@ -4,7 +4,6 @@
@load base/protocols/rdp
@load base/protocols/conn
@load base/frameworks/dpd
event rdpeudp_syn(c: connection)
{

View file

@ -4,7 +4,6 @@
@load base/protocols/rdp
@load base/protocols/conn
@load base/frameworks/dpd
event rdpeudp_syn(c: connection)
{

View file

@ -4,7 +4,6 @@
@load base/protocols/rdp
@load base/protocols/conn
@load base/frameworks/dpd
event rdpeudp_syn(c: connection)
{

View file

@ -5,7 +5,6 @@
# @TEST-EXEC: zeek -b -r $TRACES/tls/tls-13draft19-early-data.pcap %INPUT
# @TEST-EXEC: btest-diff .stdout
@load base/frameworks/dpd
@load base/frameworks/signatures
@load-sigs base/protocols/ssl/dpd.sig
@load-sigs policy/protocols/ssl/dpd-v2.sig

View file

@ -5,7 +5,6 @@
# @TEST-EXEC: btest-diff .stdout
@load base/protocols/ssl
@load base/frameworks/dpd
redef SSL::log_include_client_certificate_subject_issuer = T;
redef SSL::log_include_server_certificate_subject_issuer = T;

View file

@ -7,4 +7,3 @@
@load base/protocols/ssl
@load base/files/x509
@load base/frameworks/dpd

View file

@ -1,7 +1,6 @@
# @TEST-EXEC: zeek -C -b -r $TRACES/tls/xmpp-starttls.pcap %INPUT
# @TEST-EXEC: btest-diff ssl.log
@load base/frameworks/dpd
@load base/frameworks/signatures
@load base/protocols/ssl
@load base/protocols/conn

View file

@ -1,7 +1,6 @@
# @TEST-EXEC: zeek -C -b -r $TRACES/tls/xmpp-dialback-starttls.pcap %INPUT
# @TEST-EXEC: btest-diff ssl.log
@load base/frameworks/dpd
@load base/frameworks/signatures
@load base/protocols/ssl
@load base/protocols/conn

View file

@ -4,6 +4,5 @@
# @TEST-EXEC: btest-diff x509.log
@load base/protocols/conn
@load base/frameworks/dpd
@load base/protocols/ssl
@load base/protocols/xmpp