mirror of
https://github.com/zeek/zeek.git
synced 2025-10-03 23:28:20 +00:00

When a fa_file object is created through the use of Input::add_analysis(), the fa_file's source is likely not valid representation of an analyzer's tag and a Files::describe() should not error and instead return an empty description. Add a new Analyzer::is_tag() helper that can be used to pre-check `f$source`.
36 lines
938 B
Text
36 lines
938 B
Text
# @TEST-DOC: Call create_file_info() and populate_file_info2() when a file has been added through Input::add_analysis()
|
|
|
|
# @TEST-EXEC: zeek -b %INPUT > output
|
|
# @TEST-EXEC: btest-diff output
|
|
# @TEST-EXEC: btest-diff files.log
|
|
# @TEST-EXEC: btest-diff notice.log
|
|
|
|
@load base/protocols/http
|
|
@load base/frameworks/files
|
|
|
|
redef enum Notice::Type += { NoticeTestType };
|
|
|
|
event file_new(f: fa_file)
|
|
{
|
|
Files::add_analyzer(f, Files::ANALYZER_SHA1);
|
|
}
|
|
|
|
event file_hash(f: fa_file, kind: string, hash: string)
|
|
{
|
|
print "file_hash", kind, f?$conns ? |f$conns| : 0;
|
|
local fi = Notice::create_file_info(f);
|
|
print fi;
|
|
local n: Notice::Info = Notice::Info($note=NoticeTestType, $msg="test");
|
|
Notice::populate_file_info2(fi, n);
|
|
NOTICE(n);
|
|
}
|
|
|
|
event zeek_init()
|
|
{
|
|
Input::add_analysis([$source="./myfile", $name="./myfile"]);
|
|
}
|
|
|
|
@TEST-START-FILE ./myfile
|
|
%PDF-1.5
|
|
This isn't an actual pdf, but it shows in files.log as such :-)
|
|
@TEST-END-FILE
|