[packages/apache-mod_security] - config restructured: thin loader + upstream modsecurity.conf with PLD paths (patch); IncludeOption
arekm
arekm at pld-linux.org
Fri Sep 11 00:02:50 CEST 2026
commit f79edaab47dc6069b8e45c4272f5050c9de9243d
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Thu Sep 10 23:27:18 2026 +0200
- config restructured: thin loader + upstream modsecurity.conf with PLD paths (patch); IncludeOptional
- ship unicode.mapping
apache-mod_security.conf | 58 +++------------------------------------
apache-mod_security.spec | 13 ++++++---
pld-config.patch | 70 ++++++++++++++++++++++++++++++++++++++++++++++++
3 files changed, 82 insertions(+), 59 deletions(-)
---
diff --git a/apache-mod_security.spec b/apache-mod_security.spec
index ab0ee57..b85705f 100644
--- a/apache-mod_security.spec
+++ b/apache-mod_security.spec
@@ -1,7 +1,7 @@
#
# Conditional build:
%bcond_without tests # unit tests
-%bcond_with regression_tests # regression tests (start httpd on localhost; unverified on builders)
+%bcond_with regression_tests # regression tests
%define mod_name security
%define apxs /usr/sbin/apxs
@@ -16,6 +16,7 @@ Source0: https://github.com/owasp-modsecurity/ModSecurity/releases/download/v%{v
# Source0-md5: 8d9cc060d0056b21f2463dc1e02a940d
Source1: %{name}.conf
Patch0: apu-crypto-includes.patch
+Patch1: pld-config.patch
URL: http://www.modsecurity.org/
BuildRequires: apache-devel
BuildRequires: autoconf
@@ -71,6 +72,7 @@ This package contains the ModSecurity Audit Log Collector.
%prep
%setup -q -n modsecurity-v%{version}
%patch -P0 -p1
+%patch -P1 -p1
%build
%{__libtoolize}
@@ -105,7 +107,9 @@ install -d $RPM_BUILD_ROOT{%{apachelibdir},%{apacheconfdir}/modsecurity.d/activa
install apache2/.libs/mod_%{mod_name}2.so $RPM_BUILD_ROOT%{apachelibdir}
cp -a %{SOURCE1} $RPM_BUILD_ROOT%{apacheconfdir}/90_mod_%{mod_name}.conf
-cp -a modsecurity.conf-recommended $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d
+cp -p modsecurity.conf-recommended $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d/modsecurity.conf
+# code-point table for SecUnicodeMapFile (t:utf8toUnicode in CRS 4 rules)
+cp -p unicode.mapping $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d
echo '# Drop your local rules in here.' > $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity.d/modsecurity_localrules.conf
install mlogc/mlogc $RPM_BUILD_ROOT%{_bindir}
@@ -126,10 +130,11 @@ fi
%files
%defattr(644,root,root,755)
%doc CHANGES README.* modsecurity* doc/* tools
-%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/*_mod_%{mod_name}.conf
+%attr(640,root,root) %config %{apacheconfdir}/*_mod_%{mod_name}.conf
%dir %{apacheconfdir}/modsecurity.d
%dir %{apacheconfdir}/modsecurity.d/activated_rules
-%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity.d/*.*
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity.d/*.conf
+%{apacheconfdir}/modsecurity.d/unicode.mapping
%attr(755,root,root) %{apachelibdir}/*.so
%attr(770,http,root) %dir /var/lib/%{name}
diff --git a/apache-mod_security.conf b/apache-mod_security.conf
index 3a905a6..0db64c1 100644
--- a/apache-mod_security.conf
+++ b/apache-mod_security.conf
@@ -1,61 +1,9 @@
# Configuration file for the mod_security Apache module
-#LoadFile LIBDIR/libxml2.so.2
-
LoadModule security2_module modules/mod_security2.so
<IfModule mod_security2.c>
- # ModSecurity Core Rules Set configuration
-
- Include conf.d/modsecurity.d/*.conf
- Include conf.d/modsecurity.d/activated_rules/*.conf
-
- # Default recommended configuration
- SecRuleEngine On
- SecRequestBodyAccess On
- SecRule REQUEST_HEADERS:Content-Type "text/xml" \
- "id:'200000',phase:1,t:none,t:lowercase,pass,nolog,ctl:requestBodyProcessor=XML"
- SecRequestBodyLimit 13107200
- SecRequestBodyNoFilesLimit 131072
- SecRequestBodyInMemoryLimit 131072
- SecRequestBodyLimitAction Reject
- SecRule REQBODY_ERROR "!@eq 0" \
- "id:'200001', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2"
- SecRule MULTIPART_STRICT_ERROR "!@eq 0" \
- "id:'200002',phase:2,t:none,log,deny,status:44,msg:'Multipart request body \
- failed strict validation: \
- PE %{REQBODY_PROCESSOR_ERROR}, \
- BQ %{MULTIPART_BOUNDARY_QUOTED}, \
- BW %{MULTIPART_BOUNDARY_WHITESPACE}, \
- DB %{MULTIPART_DATA_BEFORE}, \
- DA %{MULTIPART_DATA_AFTER}, \
- HF %{MULTIPART_HEADER_FOLDING}, \
- LF %{MULTIPART_LF_LINE}, \
- SM %{MULTIPART_MISSING_SEMICOLON}, \
- IQ %{MULTIPART_INVALID_QUOTING}, \
- IP %{MULTIPART_INVALID_PART}, \
- IH %{MULTIPART_INVALID_HEADER_FOLDING}, \
- FL %{MULTIPART_FILE_LIMIT_EXCEEDED}'"
-
- SecRule MULTIPART_UNMATCHED_BOUNDARY "!@eq 0" \
- "id:'200003',phase:2,t:none,log,deny,status:44,msg:'Multipart parser detected a possible unmatched boundary.'"
-
- SecPcreMatchLimit 1000
- SecPcreMatchLimitRecursion 1000
-
- SecRule TX:/^MSC_/ "!@streq 0" \
- "id:'200004',phase:2,t:none,deny,msg:'ModSecurity internal error flagged: %{MATCHED_VAR_NAME}'"
-
- SecResponseBodyAccess Off
- SecDebugLog /var/log/httpd/modsec_debug.log
- SecDebugLogLevel 0
- SecAuditEngine RelevantOnly
- SecAuditLogRelevantStatus "^(?:5|4(?!04))"
- SecAuditLogParts ABIJDEFHZ
- SecAuditLogType Serial
- SecAuditLog /var/log/httpd/modsec_audit.log
- SecArgumentSeparator &
- SecCookieFormat 0
- SecTmpDir /var/lib/mod_security
- SecDataDir /var/lib/mod_security
+ # engine settings (modsecurity.conf), CRS setup, local rules
+ IncludeOptional conf.d/modsecurity.d/*.conf
+ IncludeOptional conf.d/modsecurity.d/activated_rules/*.conf
</IfModule>
diff --git a/pld-config.patch b/pld-config.patch
new file mode 100644
index 0000000..a75eeb8
--- /dev/null
+++ b/pld-config.patch
@@ -0,0 +1,70 @@
+PLD paths for the shipped engine config (logs/ is ServerRoot-relative as in httpd.conf; SecUnicodeMapFile is not);
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+
+--- modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-10 23:55:11.935535749 +0200
++++ modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-10 23:55:11.936658773 +0200
+@@ -4,7 +4,7 @@
+ # only to start with, because that minimises the chances of post-installation
+ # disruption.
+ #
+-SecRuleEngine DetectionOnly
++SecRuleEngine On
+
+
+ # -- Request body handling ---------------------------------------------------
+@@ -147,13 +147,13 @@
+ # This default setting is chosen due to all systems have /tmp available however,
+ # this is less than ideal. It is recommended that you specify a location that's private.
+ #
+-SecTmpDir /tmp/
++SecTmpDir /var/lib/apache-mod_security
+
+ # The location where ModSecurity will keep its persistent data. This default setting
+ # is chosen due to all systems have /tmp available however, it
+ # too should be updated to a place that other users can't access.
+ #
+-SecDataDir /tmp/
++SecDataDir /var/lib/apache-mod_security
+
+
+ # -- File uploads handling configuration -------------------------------------
+@@ -162,7 +162,7 @@
+ # location must be private to ModSecurity. You don't want other users on
+ # the server to access the files, do you?
+ #
+-#SecUploadDir /opt/modsecurity/var/upload/
++#SecUploadDir /var/lib/apache-mod_security/upload/
+
+ # By default, only keep the files that were determined to be unusual
+ # in some way (by an external inspection script). For this to work you
+@@ -182,7 +182,7 @@
+ # The default debug log configuration is to duplicate the error, warning
+ # and notice messages from the error log.
+ #
+-#SecDebugLog /opt/modsecurity/var/log/debug.log
++#SecDebugLog logs/modsec_debug.log
+ #SecDebugLogLevel 3
+
+
+@@ -202,10 +202,10 @@
+ # assumes that you will use the audit log only ocassionally.
+ #
+ SecAuditLogType Serial
+-SecAuditLog /var/log/modsec_audit.log
++SecAuditLog logs/modsec_audit.log
+
+ # Specify the path for concurrent audit logging.
+-#SecAuditLogStorageDir /opt/modsecurity/var/audit/
++#SecAuditLogStorageDir logs/modsec_audit/
+
+
+ # -- Miscellaneous -----------------------------------------------------------
+@@ -227,7 +227,7 @@
+ # to properly map encoded data to your language. Properly setting
+ # these directives helps to reduce false positives and negatives.
+ #
+-SecUnicodeMapFile unicode.mapping 20127
++SecUnicodeMapFile /etc/httpd/conf.d/modsecurity.d/unicode.mapping 20127
+
+ # Improve the quality of ModSecurity by sharing information about your
+ # current ModSecurity version and dependencies versions.
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security.git/commitdiff/f79edaab47dc6069b8e45c4272f5050c9de9243d
More information about the pld-cvs-commit
mailing list