zeek/testing/btest/scripts/policy
Arne Welzel 88bb527026 btest/dump-events: Run in bare mode, load conn and smtp scripts only
The dump-events baseline changes are pure noise and have spurred confusion
for internal and external contributors. For example, adding new
analyzers have perturbed orderings of sets holding analyzer tags.

Running in non-bare mode, the baselines change almost whenever any of the
record types attached to connections change in the default scripts. This
causes continuous and seemingly little useful updates to the baselines.

This change switches the test to run in bare mode and explicitly loads
just base/protocols/conn and base/protocols/smtp. The primary intention
of the test should be testing the functionality of the misc/dump-events
script, not the raised events of all loaded default scripts (for that the
used PCAP is too narrow).

Protocol specific scripts that do want to leverage misc/dump-events for
baseline creation of their or their analyzer's events can add additional
specific tests with suitable PCAP files.
2023-10-09 12:20:10 +02:00
..
frameworks Merge remote-tracking branch 'origin/topic/jazoff/gh-3268t ' 2023-09-04 14:01:23 +02:00
misc btest/dump-events: Run in bare mode, load conn and smtp scripts only 2023-10-09 12:20:10 +02:00
protocols Update Mozilla CA and Google CT lists 2023-05-03 10:46:41 +01:00