Conversation
As this is an invalid tcp packet, that should not run any tx detection on it.
jufajardini
left a comment
There was a problem hiding this comment.
Looks good to me, thanks for adding an explanation in the commit message!
|
Should we then be checking that |
|
I think the important test is that we get the alert. If we really want to test this, are we sure we want to consider packet 7 as invalid and not run tx detection on it ? |
I don't know specifically. But S-V is about detecting changes in behaviour as well. If it used to be 7, and some fix made the field go away, I think that should be encoded in the test, to detect if it ever comes back unintentionally. |
|
Continued in #1640 |
Did something in next version of the PR |
Ticket
Redmine ticket: None
Prerequisite for OISF/suricata#10307 and next