[packages/apache-mod_security_crs] - local exclusion hooks: REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf and RESPONSE-999-EXCLUSION-RULE

arekm arekm at pld-linux.org
Sat Sep 12 00:50:06 CEST 2026


commit 2c84a31d36c676721d7b7d402dd41ef9e0510e81
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Sat Sep 12 00:48:36 2026 +0200

    - local exclusion hooks: REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf and RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
    - rel 2

 REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf | 10 ++++++++++
 RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf |  6 ++++++
 apache-mod_security_crs.conf                |  5 ++++-
 apache-mod_security_crs.spec                |  7 ++++++-
 4 files changed, 26 insertions(+), 2 deletions(-)
---
diff --git a/apache-mod_security_crs.spec b/apache-mod_security_crs.spec
index a7f059a..3680ef2 100644
--- a/apache-mod_security_crs.spec
+++ b/apache-mod_security_crs.spec
@@ -4,10 +4,12 @@ Summary(pl.UTF-8):	Aktywacja OWASP Core Rule Set dla modułu mod_security Apache
 Name:		apache-mod_security_crs
 # loader layout follows CRS 4 (plugins/*-{config,before,after}.conf), not a CRS release
 Version:	4.0
-Release:	1
+Release:	2
 License:	Apache v2.0
 Group:		Networking/Daemons/HTTP
 Source0:	%{name}.conf
+Source1:	REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
+Source2:	RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
 URL:		https://coreruleset.org/
 # crs-setup.conf.example is copied at build time
 BuildRequires:	modsecurity-crs >= 4
@@ -44,6 +46,7 @@ install -d $RPM_BUILD_ROOT%{apacheconfdir}/{conf.d/modsecurity.d,modsecurity-crs
 cp -p %{SOURCE0} $RPM_BUILD_ROOT%{apacheconfdir}/conf.d/modsecurity.d/modsecurity_crs.conf
 # rule 901001 rejects every request unless a setup file is loaded before rules/
 cp -p %{_datadir}/modsecurity-crs/crs-setup.conf.example $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity-crs/crs-setup.conf
+cp -p %{SOURCE1} %{SOURCE2} $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity-crs
 
 %clean
 rm -rf $RPM_BUILD_ROOT
@@ -61,3 +64,5 @@ fi
 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/conf.d/modsecurity.d/modsecurity_crs.conf
 %dir %{apacheconfdir}/modsecurity-crs
 %attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/crs-setup.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
diff --git a/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf b/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
new file mode 100644
index 0000000..9e909e1
--- /dev/null
+++ b/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
@@ -0,0 +1,10 @@
+# Local rule exclusions evaluated BEFORE the CRS rules (loaded right after
+# crs-setup.conf and the plugins). Use this file for runtime exclusions with
+# ctl: actions, which must run before the rule they modify, e.g.
+#
+#   SecRule REQUEST_URI "@beginsWith /api/upload" \
+#       "id:10001,phase:1,pass,nolog,ctl:ruleRemoveById=920420"
+#   SecRule REQUEST_HEADERS:User-Agent "@endsWith (internal dummy connection)" \
+#       "id:10002,phase:1,pass,nolog,ctl:ruleEngine=Off"
+#
+# Use ids in the 1-99999 range; they are reserved for local rules.
diff --git a/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf b/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
new file mode 100644
index 0000000..97234c2
--- /dev/null
+++ b/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
@@ -0,0 +1,6 @@
+# Local rule exclusions evaluated AFTER the CRS rules are loaded. Use this file
+# for configure-time exclusions, which need the rule to exist already, e.g.
+#
+#   SecRuleRemoveById 950130
+#   SecRuleUpdateTargetById 942100 "!ARGS:password"
+#   SecRuleRemoveByTag "attack-protocol"
diff --git a/apache-mod_security_crs.conf b/apache-mod_security_crs.conf
index 0bd9a82..f7110da 100644
--- a/apache-mod_security_crs.conf
+++ b/apache-mod_security_crs.conf
@@ -1,7 +1,10 @@
 # OWASP Core Rule Set (modsecurity-crs) for Apache mod_security.
-# Order required by CRS: setup, plugin config, plugin before-rules, rules, plugin after-rules.
+# Order required by CRS: setup, plugin config, plugin before-rules, local before-rules,
+# rules, plugin after-rules, local after-rules.
 Include modsecurity-crs/crs-setup.conf
 Include /usr/share/modsecurity-crs/plugins/*-config.conf
 Include /usr/share/modsecurity-crs/plugins/*-before.conf
+Include modsecurity-crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
 Include /usr/share/modsecurity-crs/rules/*.conf
 Include /usr/share/modsecurity-crs/plugins/*-after.conf
+Include modsecurity-crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security_crs.git/commitdiff/2c84a31d36c676721d7b7d402dd41ef9e0510e81



More information about the pld-cvs-commit mailing list