[packages/apache-mod_security_crs] - local exclusion hooks: REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf and RESPONSE-999-EXCLUSION-RULE
arekm
arekm at pld-linux.org
Sat Sep 12 00:50:06 CEST 2026
commit 2c84a31d36c676721d7b7d402dd41ef9e0510e81
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Sat Sep 12 00:48:36 2026 +0200
- local exclusion hooks: REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf and RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
- rel 2
REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf | 10 ++++++++++
RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf | 6 ++++++
apache-mod_security_crs.conf | 5 ++++-
apache-mod_security_crs.spec | 7 ++++++-
4 files changed, 26 insertions(+), 2 deletions(-)
---
diff --git a/apache-mod_security_crs.spec b/apache-mod_security_crs.spec
index a7f059a..3680ef2 100644
--- a/apache-mod_security_crs.spec
+++ b/apache-mod_security_crs.spec
@@ -4,10 +4,12 @@ Summary(pl.UTF-8): Aktywacja OWASP Core Rule Set dla modułu mod_security Apache
Name: apache-mod_security_crs
# loader layout follows CRS 4 (plugins/*-{config,before,after}.conf), not a CRS release
Version: 4.0
-Release: 1
+Release: 2
License: Apache v2.0
Group: Networking/Daemons/HTTP
Source0: %{name}.conf
+Source1: REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
+Source2: RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
URL: https://coreruleset.org/
# crs-setup.conf.example is copied at build time
BuildRequires: modsecurity-crs >= 4
@@ -44,6 +46,7 @@ install -d $RPM_BUILD_ROOT%{apacheconfdir}/{conf.d/modsecurity.d,modsecurity-crs
cp -p %{SOURCE0} $RPM_BUILD_ROOT%{apacheconfdir}/conf.d/modsecurity.d/modsecurity_crs.conf
# rule 901001 rejects every request unless a setup file is loaded before rules/
cp -p %{_datadir}/modsecurity-crs/crs-setup.conf.example $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity-crs/crs-setup.conf
+cp -p %{SOURCE1} %{SOURCE2} $RPM_BUILD_ROOT%{apacheconfdir}/modsecurity-crs
%clean
rm -rf $RPM_BUILD_ROOT
@@ -61,3 +64,5 @@ fi
%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/conf.d/modsecurity.d/modsecurity_crs.conf
%dir %{apacheconfdir}/modsecurity-crs
%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/crs-setup.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
+%attr(640,root,root) %config(noreplace) %verify(not md5 mtime size) %{apacheconfdir}/modsecurity-crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
diff --git a/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf b/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
new file mode 100644
index 0000000..9e909e1
--- /dev/null
+++ b/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
@@ -0,0 +1,10 @@
+# Local rule exclusions evaluated BEFORE the CRS rules (loaded right after
+# crs-setup.conf and the plugins). Use this file for runtime exclusions with
+# ctl: actions, which must run before the rule they modify, e.g.
+#
+# SecRule REQUEST_URI "@beginsWith /api/upload" \
+# "id:10001,phase:1,pass,nolog,ctl:ruleRemoveById=920420"
+# SecRule REQUEST_HEADERS:User-Agent "@endsWith (internal dummy connection)" \
+# "id:10002,phase:1,pass,nolog,ctl:ruleEngine=Off"
+#
+# Use ids in the 1-99999 range; they are reserved for local rules.
diff --git a/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf b/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
new file mode 100644
index 0000000..97234c2
--- /dev/null
+++ b/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
@@ -0,0 +1,6 @@
+# Local rule exclusions evaluated AFTER the CRS rules are loaded. Use this file
+# for configure-time exclusions, which need the rule to exist already, e.g.
+#
+# SecRuleRemoveById 950130
+# SecRuleUpdateTargetById 942100 "!ARGS:password"
+# SecRuleRemoveByTag "attack-protocol"
diff --git a/apache-mod_security_crs.conf b/apache-mod_security_crs.conf
index 0bd9a82..f7110da 100644
--- a/apache-mod_security_crs.conf
+++ b/apache-mod_security_crs.conf
@@ -1,7 +1,10 @@
# OWASP Core Rule Set (modsecurity-crs) for Apache mod_security.
-# Order required by CRS: setup, plugin config, plugin before-rules, rules, plugin after-rules.
+# Order required by CRS: setup, plugin config, plugin before-rules, local before-rules,
+# rules, plugin after-rules, local after-rules.
Include modsecurity-crs/crs-setup.conf
Include /usr/share/modsecurity-crs/plugins/*-config.conf
Include /usr/share/modsecurity-crs/plugins/*-before.conf
+Include modsecurity-crs/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
Include /usr/share/modsecurity-crs/rules/*.conf
Include /usr/share/modsecurity-crs/plugins/*-after.conf
+Include modsecurity-crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security_crs.git/commitdiff/2c84a31d36c676721d7b7d402dd41ef9e0510e81
More information about the pld-cvs-commit
mailing list