[packages/apache-mod_security] - config restructured: thin loader + upstream modsecurity.conf with PLD paths (patch); IncludeOption

arekm arekm at pld-linux.org
Fri Sep 11 00:02:50 CEST 2026


commit f79edaab47dc6069b8e45c4272f5050c9de9243d
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Thu Sep 10 23:27:18 2026 +0200

    - config restructured: thin loader + upstream modsecurity.conf with PLD paths (patch); IncludeOptional
    - ship unicode.mapping

 apache-mod_security.conf | 58 +++------------------------------------
 apache-mod_security.spec | 13 ++++++---
 pld-config.patch         | 70 ++++++++++++++++++++++++++++++++++++++++++++++++
 3 files changed, 82 insertions(+), 59 deletions(-)
---
diff --git a/apache-mod_security.spec b/apache-mod_security.spec
index ab0ee57..b85705f 100644
--- a/apache-mod_security.spec
+++ b/apache-mod_security.spec
@@ -1,7 +1,7 @@
 #
 # Conditional build:
 %bcond_without	tests		# unit tests
-%bcond_with	regression_tests	# regression tests (start httpd on localhost; unverified on builders)
+%bcond_with	regression_tests	# regression tests
 
 %define		mod_name	security
 %define		apxs		/usr/sbin/apxs
@@ -16,6 +16,7 @@ Source0:	https://github.com/owasp-modsecurity/ModSecurity/releases/download/v%{v
 # Source0-md5:	8d9cc060d0056b21f2463dc1e02a940d
 Source1:	%{name}.conf
 Patch0:		apu-crypto-includes.patch
+Patch1:		pld-config.patch
 URL:		http://www.modsecurity.org/
 BuildRequires:	apache-devel
 BuildRequires:	autoconf
@@ -71,6 +72,7 @@ This package contains the ModSecurity Audit Log Collector.
 %prep
 %setup -q -n modsecurity-v%{version}
 %patch -P0 -p1
+%patch -P1 -p1
 
 %build
 %{__libtoolize}
@@ -105,7 +107,9 @@ install -d $RPM_BUILD_ROOT{%{apachelibdir},%{apacheconfdir}/modsecurity.d/activa
 install apache2/.libs/mod_%{mod_name}2.so $RPM_BUILD_ROOT%{apachelibdir}
 cp -a %{SOURCE1} $RPM_BUILD_ROOT%{apacheconfdir}/90_mod_%{mod_name}.conf
 
-cp -a modsecurity.conf-recommended $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d
+cp -p modsecurity.conf-recommended $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d/modsecurity.conf
+# code-point table for SecUnicodeMapFile (t:utf8toUnicode in CRS 4 rules)
+cp -p unicode.mapping $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d
 echo '# Drop your local rules in here.' > $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d/modsecurity_localrules.conf
 
 install mlogc/mlogc $RPM_BUILD_ROOT%{_bindir}
@@ -126,10 +130,11 @@ fi
 %files
 %defattr(644,root,root,755)
 %doc CHANGES README.* modsecurity* doc/* tools
-%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/*_mod_%{mod_name}.conf
+%attr(640,root,root) %config %{apacheconfdir}/*_mod_%{mod_name}.conf
 %dir %{apacheconfdir}/modsecurity.d
 %dir %{apacheconfdir}/modsecurity.d/activated_rules
-%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity.d/*.*
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity.d/*.conf
+%{apacheconfdir}/modsecurity.d/unicode.mapping
 %attr(755,root,root) %{apachelibdir}/*.so
 %attr(770,http,root) %dir /var/lib/%{name}
 
diff --git a/apache-mod_security.conf b/apache-mod_security.conf
index 3a905a6..0db64c1 100644
--- a/apache-mod_security.conf
+++ b/apache-mod_security.conf
@@ -1,61 +1,9 @@
 # Configuration file for the mod_security Apache module
 
-#LoadFile LIBDIR/libxml2.so.2
-
 LoadModule security2_module modules/mod_security2.so
 
 <IfModule mod_security2.c>
-	# ModSecurity Core Rules Set configuration
-
-	Include conf.d/modsecurity.d/*.conf
-	Include conf.d/modsecurity.d/activated_rules/*.conf
-
-	# Default recommended configuration
-	SecRuleEngine On
-	SecRequestBodyAccess On
-	SecRule REQUEST_HEADERS:Content-Type "text/xml" \
-		"id:'200000',phase:1,t:none,t:lowercase,pass,nolog,ctl:requestBodyProcessor=XML"
-	SecRequestBodyLimit 13107200
-	SecRequestBodyNoFilesLimit 131072
-	SecRequestBodyInMemoryLimit 131072
-	SecRequestBodyLimitAction Reject
-	SecRule REQBODY_ERROR "!@eq 0" \
-		"id:'200001', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2"
-	SecRule MULTIPART_STRICT_ERROR "!@eq 0" \
-		"id:'200002',phase:2,t:none,log,deny,status:44,msg:'Multipart request body \
-		failed strict validation: \
-		PE %{REQBODY_PROCESSOR_ERROR}, \
-		BQ %{MULTIPART_BOUNDARY_QUOTED}, \
-		BW %{MULTIPART_BOUNDARY_WHITESPACE}, \
-		DB %{MULTIPART_DATA_BEFORE}, \
-		DA %{MULTIPART_DATA_AFTER}, \
-		HF %{MULTIPART_HEADER_FOLDING}, \
-		LF %{MULTIPART_LF_LINE}, \
-		SM %{MULTIPART_MISSING_SEMICOLON}, \
-		IQ %{MULTIPART_INVALID_QUOTING}, \
-		IP %{MULTIPART_INVALID_PART}, \
-		IH %{MULTIPART_INVALID_HEADER_FOLDING}, \
-		FL %{MULTIPART_FILE_LIMIT_EXCEEDED}'"
-
-	SecRule MULTIPART_UNMATCHED_BOUNDARY "!@eq 0" \
-		"id:'200003',phase:2,t:none,log,deny,status:44,msg:'Multipart parser detected a possible unmatched boundary.'"
-
-	SecPcreMatchLimit 1000
-	SecPcreMatchLimitRecursion 1000
-
-	SecRule TX:/^MSC_/ "!@streq 0" \
-		"id:'200004',phase:2,t:none,deny,msg:'ModSecurity internal error flagged: %{MATCHED_VAR_NAME}'"
-
-	SecResponseBodyAccess Off
-	SecDebugLog /var/log/httpd/modsec_debug.log
-	SecDebugLogLevel 0
-	SecAuditEngine RelevantOnly
-	SecAuditLogRelevantStatus "^(?:5|4(?!04))"
-	SecAuditLogParts ABIJDEFHZ
-	SecAuditLogType Serial
-	SecAuditLog /var/log/httpd/modsec_audit.log
-	SecArgumentSeparator &
-	SecCookieFormat 0
-	SecTmpDir /var/lib/mod_security
-	SecDataDir /var/lib/mod_security
+	# engine settings (modsecurity.conf), CRS setup, local rules
+	IncludeOptional conf.d/modsecurity.d/*.conf
+	IncludeOptional conf.d/modsecurity.d/activated_rules/*.conf
 </IfModule>
diff --git a/pld-config.patch b/pld-config.patch
new file mode 100644
index 0000000..a75eeb8
--- /dev/null
+++ b/pld-config.patch
@@ -0,0 +1,70 @@
+PLD paths for the shipped engine config (logs/ is ServerRoot-relative as in httpd.conf; SecUnicodeMapFile is not);
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+
+--- modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-10 23:55:11.935535749 +0200
++++ modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-10 23:55:11.936658773 +0200
+@@ -4,7 +4,7 @@
+ # only to start with, because that minimises the chances of post-installation
+ # disruption.
+ #
+-SecRuleEngine DetectionOnly
++SecRuleEngine On
+ 
+ 
+ # -- Request body handling ---------------------------------------------------
+@@ -147,13 +147,13 @@
+ # This default setting is chosen due to all systems have /tmp available however, 
+ # this is less than ideal. It is recommended that you specify a location that's private.
+ #
+-SecTmpDir /tmp/
++SecTmpDir /var/lib/apache-mod_security
+ 
+ # The location where ModSecurity will keep its persistent data.  This default setting 
+ # is chosen due to all systems have /tmp available however, it
+ # too should be updated to a place that other users can't access.
+ #
+-SecDataDir /tmp/
++SecDataDir /var/lib/apache-mod_security
+ 
+ 
+ # -- File uploads handling configuration -------------------------------------
+@@ -162,7 +162,7 @@
+ # location must be private to ModSecurity. You don't want other users on
+ # the server to access the files, do you?
+ #
+-#SecUploadDir /opt/modsecurity/var/upload/
++#SecUploadDir /var/lib/apache-mod_security/upload/
+ 
+ # By default, only keep the files that were determined to be unusual
+ # in some way (by an external inspection script). For this to work you
+@@ -182,7 +182,7 @@
+ # The default debug log configuration is to duplicate the error, warning
+ # and notice messages from the error log.
+ #
+-#SecDebugLog /opt/modsecurity/var/log/debug.log
++#SecDebugLog logs/modsec_debug.log
+ #SecDebugLogLevel 3
+ 
+ 
+@@ -202,10 +202,10 @@
+ # assumes that you will use the audit log only ocassionally.
+ #
+ SecAuditLogType Serial
+-SecAuditLog /var/log/modsec_audit.log
++SecAuditLog logs/modsec_audit.log
+ 
+ # Specify the path for concurrent audit logging.
+-#SecAuditLogStorageDir /opt/modsecurity/var/audit/
++#SecAuditLogStorageDir logs/modsec_audit/
+ 
+ 
+ # -- Miscellaneous -----------------------------------------------------------
+@@ -227,7 +227,7 @@
+ # to properly map encoded data to your language. Properly setting
+ # these directives helps to reduce false positives and negatives.
+ #
+-SecUnicodeMapFile unicode.mapping 20127
++SecUnicodeMapFile /etc/httpd/conf.d/modsecurity.d/unicode.mapping 20127
+ 
+ # Improve the quality of ModSecurity by sharing information about your
+ # current ModSecurity version and dependencies versions.
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security.git/commitdiff/f79edaab47dc6069b8e45c4272f5050c9de9243d



More information about the pld-cvs-commit mailing list