mirror of
https://github.com/falcosecurity/falco.git
synced 2025-10-21 19:44:57 +00:00
Add automated tests for plugins
Test infrastructure and sample confs/rules/traces for plugins automated tests: New test cases are in falco_tests_plugins.yaml and cover: - Listing plugins and fields when plugins are loaded. - Basic cloudtrail + json plugin on a fake cloudtrail json file and a sample rule that uses both plugins. - Conflicts between source/extractor plugins - Incompatible plugin api - Wrong plugin path - Checking for warnings when reading rules with unnown sources (e.g. when plugins are not loaded) Some test-only plugins written in C are in test/plugins and built on the fly. (They aren't included in packages of course). The test framework needed some small changes to handle these tests: - Add a mode to not check detection counts at all (for --list/--list-plugins) - addl_cmdline_opts to allow specifying --list/--list-plugins - Using DOTALL when matching stderr/stdout (allows multi-line matches more easily) Signed-off-by: Mark Stemm <mark.stemm@gmail.com>
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
add_subdirectory(k8s_audit)
|
||||
add_subdirectory(psp)
|
||||
add_subdirectory(plugins)
|
||||
|
||||
# Note: list of traces is created at cmake time, not build time
|
||||
file(GLOB test_trace_files
|
||||
@@ -16,4 +17,4 @@ foreach(trace_file_path ${test_trace_files})
|
||||
endforeach()
|
||||
|
||||
add_custom_target(trace-files-base-scap ALL)
|
||||
add_dependencies(trace-files-base-scap ${BASE_SCAP_TRACE_FILES_TARGETS})
|
||||
add_dependencies(trace-files-base-scap ${BASE_SCAP_TRACE_FILES_TARGETS})
|
||||
|
16
test/trace_files/plugins/CMakeLists.txt
Normal file
16
test/trace_files/plugins/CMakeLists.txt
Normal file
@@ -0,0 +1,16 @@
|
||||
# Note: list of traces is created at cmake time, not build time
|
||||
file(GLOB test_trace_files
|
||||
"${CMAKE_CURRENT_SOURCE_DIR}/*.json")
|
||||
|
||||
foreach(trace_file_path ${test_trace_files})
|
||||
get_filename_component(trace_file ${trace_file_path} NAME)
|
||||
add_custom_target(test-trace-${trace_file} ALL
|
||||
DEPENDS ${CMAKE_CURRENT_BINARY_DIR}/${trace_file})
|
||||
add_custom_command(OUTPUT ${CMAKE_CURRENT_BINARY_DIR}/${trace_file}
|
||||
COMMAND ${CMAKE_COMMAND} -E copy ${trace_file_path} ${CMAKE_CURRENT_BINARY_DIR}/${trace_file}
|
||||
DEPENDS ${trace_file_path})
|
||||
list(APPEND PLUGINS_TRACE_FILES_TARGETS test-trace-${trace_file})
|
||||
endforeach()
|
||||
|
||||
add_custom_target(trace-files-plugins ALL)
|
||||
add_dependencies(trace-files-plugins ${PLUGINS_TRACE_FILES_TARGETS})
|
31
test/trace_files/plugins/alice_start_instances.json
Normal file
31
test/trace_files/plugins/alice_start_instances.json
Normal file
@@ -0,0 +1,31 @@
|
||||
{"Records": [{
|
||||
"eventVersion": "1.0",
|
||||
"userIdentity": {
|
||||
"type": "IAMUser",
|
||||
"principalId": "EX_PRINCIPAL_ID",
|
||||
"arn": "arn:aws:iam::123456789012:user/Alice",
|
||||
"accessKeyId": "EXAMPLE_KEY_ID",
|
||||
"accountId": "123456789012",
|
||||
"userName": "Alice"
|
||||
},
|
||||
"eventTime": "2014-03-06T21:22:54Z",
|
||||
"eventSource": "ec2.amazonaws.com",
|
||||
"eventType": "AwsApiCall",
|
||||
"eventName": "StartInstances",
|
||||
"awsRegion": "us-east-2",
|
||||
"sourceIPAddress": "205.251.233.176",
|
||||
"userAgent": "ec2-api-tools 1.6.12.2",
|
||||
"requestParameters": {"instancesSet": {"items": [{"instanceId": "i-ebeaf9e2"}]}},
|
||||
"responseElements": {"instancesSet": {"items": [{
|
||||
"instanceId": "i-ebeaf9e2",
|
||||
"currentState": {
|
||||
"code": 0,
|
||||
"name": "pending"
|
||||
},
|
||||
"previousState": {
|
||||
"code": 80,
|
||||
"name": "stopped"
|
||||
}
|
||||
}]}}
|
||||
}]}
|
||||
|
32
test/trace_files/plugins/alice_start_instances_bigevent.json
Normal file
32
test/trace_files/plugins/alice_start_instances_bigevent.json
Normal file
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user