[packages/nginx] Rel 2; mod_http_modsecurity: enable the engine on install
arekm
arekm at pld-linux.org
Fri Sep 11 09:35:04 CEST 2026
commit 824d77f8068c416702621cf758231a34bdb3ca06
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Fri Sep 11 09:27:21 2026 +0200
Rel 2; mod_http_modsecurity: enable the engine on install
nginx-modsecurity-local.conf | 1 +
nginx-modsecurity-main.conf | 3 ++
nginx-modsecurity-pld.patch | 70 ++++++++++++++++++++++++++++++++++++++++++++
nginx-modsecurity.conf | 4 +++
nginx.spec | 25 +++++++++++++++-
5 files changed, 102 insertions(+), 1 deletion(-)
---
diff --git a/nginx.spec b/nginx.spec
index 92ca379..a7318c6 100644
--- a/nginx.spec
+++ b/nginx.spec
@@ -54,7 +54,7 @@ Summary(pl.UTF-8): Serwer HTTP i odwrotne proxy o wysokiej wydajności
# http://nginx.org/en/download.html
Name: nginx
Version: 1.31.5
-Release: 1
+Release: 2
License: BSD-like
Group: Networking/Daemons/HTTP
Source0: https://nginx.org/download/%{name}-%{version}.tar.gz
@@ -72,6 +72,9 @@ Source18: %{name}.service
Source19: macros.%{name}
Source33: https://github.com/SpiderLabs/ModSecurity-nginx/releases/download/v%{modsecurity_version}/modsecurity-%{name}-v%{modsecurity_version}.tar.gz
# Source33-md5: 500c37fefb2e3c8afa1245fff3b0d86d
+Source34: %{name}-modsecurity.conf
+Source35: %{name}-modsecurity-main.conf
+Source36: %{name}-modsecurity-local.conf
Source101: https://github.com/arut/nginx-rtmp-module/archive/v%{rtmp_version}/%{name}-rtmp-module-%{rtmp_version}.tar.gz
# Source101-md5: 9bb7a06aede38d9e36ad13dc1354d8f9
Source102: https://github.com/vozlt/nginx-module-vts/archive/v%{vts_version}.tar.gz
@@ -86,6 +89,7 @@ Source105: https://github.com/nginx/njs/archive/%{njs_version}/njs-%{njs_version
Source106: https://github.com/bellard/quickjs/archive/%{quickjs_commit}/quickjs-%{quickjs_commit}.tar.gz
# Source106-md5: 913c3fc48570d2660d5b243e9b6e6d7a
Patch0: %{name}-no-Werror.patch
+Patch1: %{name}-modsecurity-pld.patch
URL: https://nginx.org/
BuildRequires: mailcap
BuildRequires: pcre2-8-devel
@@ -98,6 +102,8 @@ BuildRequires: GeoIP-devel
BuildRequires: gd-devel
%endif
%if %{with modsecurity}
+# modsecurity.conf-recommended in /usr/share/libmodsecurity
+BuildRequires: libmodsecurity >= 3.0.16-4
BuildRequires: libmodsecurity-devel
%endif
%if %{with njs}
@@ -364,6 +370,10 @@ Plik monitrc do monitorowania serwera WWW nginx.
%prep
%setup -q %{?with_rtmp:-a101} %{?with_modsecurity:-a33} %{?with_vts:-a102} %{?with_headers_more:-a103} -a104 %{?with_njs:-a105 -a106}
%patch -P0 -p0
+%if %{with modsecurity}
+cp -p %{_datadir}/libmodsecurity/modsecurity.conf-recommended %{name}-modsecurity.conf
+%patch -P1 -p1
+%endif
%if %{with rtmp}
mv nginx-rtmp-module-%{rtmp_version} nginx-rtmp-module
@@ -534,6 +544,11 @@ load_module stream
%endif
%if %{with modsecurity}
load_module http_modsecurity
+install -d $RPM_BUILD_ROOT{%{_sysconfdir}/modsecurity/rules.d,/var/lib/%{name}/modsecurity}
+cp -p %{SOURCE34} $RPM_BUILD_ROOT%{_sysconfdir}/conf.d/modsecurity.conf
+cp -p %{SOURCE35} $RPM_BUILD_ROOT%{_sysconfdir}/modsecurity/main.conf
+cp -p %{name}-modsecurity.conf $RPM_BUILD_ROOT%{_sysconfdir}/modsecurity/modsecurity.conf
+cp -p %{SOURCE36} $RPM_BUILD_ROOT%{_sysconfdir}/modsecurity/rules.d/00_local.conf
%endif
load_module http_cache_purge
%if %{with njs}
@@ -714,7 +729,15 @@ fi
%defattr(644,root,root,755)
%doc ModSecurity-nginx-v%{modsecurity_version}/{AUTHORS,CHANGES,README.md}
%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/modules.d/mod_http_modsecurity.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/conf.d/modsecurity.conf
+%dir %{_sysconfdir}/modsecurity
+%dir %{_sysconfdir}/modsecurity/rules.d
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/modsecurity/main.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/modsecurity/modsecurity.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/modsecurity/rules.d/00_local.conf
%attr(755,root,root) %{_libdir}/%{name}/modules/ngx_http_modsecurity_module.so
+%dir /var/lib/%{name}
+%attr(770,nginx,root) %dir /var/lib/%{name}/modsecurity
%if %{with njs}
%files mod_http_js
diff --git a/nginx-modsecurity-local.conf b/nginx-modsecurity-local.conf
new file mode 100644
index 0000000..0620b42
--- /dev/null
+++ b/nginx-modsecurity-local.conf
@@ -0,0 +1 @@
+# Drop your local rules in here. This file also keeps the rules.d/*.conf glob non-empty.
diff --git a/nginx-modsecurity-main.conf b/nginx-modsecurity-main.conf
new file mode 100644
index 0000000..3afdfb0
--- /dev/null
+++ b/nginx-modsecurity-main.conf
@@ -0,0 +1,3 @@
+# engine settings, then rule sets (CRS from nginx-mod_http_modsecurity_crs, local rules)
+Include /etc/nginx/modsecurity/modsecurity.conf
+Include /etc/nginx/modsecurity/rules.d/*.conf
diff --git a/nginx-modsecurity-pld.patch b/nginx-modsecurity-pld.patch
new file mode 100644
index 0000000..a83ae8d
--- /dev/null
+++ b/nginx-modsecurity-pld.patch
@@ -0,0 +1,70 @@
+PLD paths for the engine config copied from libmodsecurity modsecurity.conf-recommended;
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+
+--- a/nginx-modsecurity.conf 2026-09-11 08:50:17.243723202 +0200
++++ b/nginx-modsecurity.conf 2026-09-11 08:50:17.246745296 +0200
+@@ -4,7 +4,7 @@
+ # only to start with, because that minimises the chances of post-installation
+ # disruption.
+ #
+-SecRuleEngine DetectionOnly
++SecRuleEngine On
+
+
+ # -- Request body handling ---------------------------------------------------
+@@ -194,13 +194,13 @@
+ # This default setting is chosen due to all systems have /tmp available however,
+ # this is less than ideal. It is recommended that you specify a location that's private.
+ #
+-SecTmpDir /tmp/
++SecTmpDir /var/lib/nginx/modsecurity
+
+ # The location where ModSecurity will keep its persistent data. This default setting
+ # is chosen due to all systems have /tmp available however, it
+ # too should be updated to a place that other users can't access.
+ #
+-SecDataDir /tmp/
++SecDataDir /var/lib/nginx/modsecurity
+
+
+ # -- File uploads handling configuration -------------------------------------
+@@ -209,7 +209,7 @@
+ # location must be private to ModSecurity. You don't want other users on
+ # the server to access the files, do you?
+ #
+-#SecUploadDir /opt/modsecurity/var/upload/
++#SecUploadDir /var/lib/nginx/modsecurity/upload/
+
+ # By default, only keep the files that were determined to be unusual
+ # in some way (by an external inspection script). For this to work you
+@@ -229,7 +229,7 @@
+ # The default debug log configuration is to duplicate the error, warning
+ # and notice messages from the error log.
+ #
+-#SecDebugLog /opt/modsecurity/var/log/debug.log
++#SecDebugLog /var/log/nginx/modsec_debug.log
+ #SecDebugLogLevel 3
+
+
+@@ -249,10 +249,10 @@
+ # assumes that you will use the audit log only ocassionally.
+ #
+ SecAuditLogType Serial
+-SecAuditLog /var/log/modsec_audit.log
++SecAuditLog /var/log/nginx/modsec_audit.log
+
+ # Specify the path for concurrent audit logging.
+-#SecAuditLogStorageDir /opt/modsecurity/var/audit/
++#SecAuditLogStorageDir /var/log/nginx/modsec_audit/
+
+
+ # -- Miscellaneous -----------------------------------------------------------
+@@ -274,7 +274,7 @@
+ # to properly map encoded data to your language. Properly setting
+ # these directives helps to reduce false positives and negatives.
+ #
+-SecUnicodeMapFile unicode.mapping 20127
++SecUnicodeMapFile /usr/share/libmodsecurity/unicode.mapping 20127
+
+ # Improve the quality of ModSecurity by sharing information about your
+ # current ModSecurity version and dependencies versions.
diff --git a/nginx-modsecurity.conf b/nginx-modsecurity.conf
new file mode 100644
index 0000000..dd360b2
--- /dev/null
+++ b/nginx-modsecurity.conf
@@ -0,0 +1,4 @@
+# ModSecurity engine for every server{}; rules chain in /etc/nginx/modsecurity/main.conf
+modsecurity on;
+modsecurity_rules_file /etc/nginx/modsecurity/main.conf;
+modsecurity_transaction_id "$request_id";
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/nginx.git/commitdiff/824d77f8068c416702621cf758231a34bdb3ca06
More information about the pld-cvs-commit
mailing list