Skip to content

feat(engine): run phase 5 (logging) after a disruptive verdict - #10

Merged
ndreno merged 2 commits into
mainfrom
feat/phase-5-after-block
Sep 12, 2026
Merged

ndreno merged 2 commits into
mainfrom
feat/phase-5-after-block

Conversation

@ndreno

@ndreno ndreno commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Closes #9.

What

ModSecurity treats phase 5 (logging) as special: it runs on every transaction, including one intercepted in an earlier phase, so a blocked transaction is still logged and its correlation rules (CRS 980xxx) run. run_phase previously returned early on any non-Allow verdict, which stopped every later phase, logging included.

Change

  • run_phase lets Phase::Logging past the stop-after-block guard.
  • A disruptive action in phase 5 is ignored (phase != Logging on the intercept arm), so logging never intercepts and never disturbs an earlier verdict.
  • Phases 3 and 4 still skip after an earlier block; only phase 5 is exempt.

Tests

  • phase_five_logging_runs_after_a_block: a phase-2 block, then phase 5 runs and applies its setvar, with the verdict unchanged.
  • a_disruptive_action_in_phase_five_does_not_change_the_verdict.
  • a_phase_three_block_still_skips_phase_four.
  • Full suite: 247 pass; clippy clean.

Downstream

Enables barbacane's WAF audit log to carry CRS correlation output on blocked transactions. A barbacane-waf 0.1.1 release follows so barbacane can bump the dep.

ModSecurity treats phase 5 as special: the logging phase runs on every
transaction, including one intercepted in an earlier phase, so a blocked
transaction is still logged and its correlation rules (CRS 980xxx) run.
run_phase previously returned early on any non-Allow verdict, stopping every
later phase including logging.

- run_phase lets Phase::Logging past the stop-after-block guard.
- A disruptive action in phase 5 is ignored, so logging never intercepts and
  never disturbs an earlier verdict.
- Phases 3 and 4 still skip after an earlier block; only phase 5 is exempt.

Tests: phase 5 runs and applies its setvar after a phase-2 block with the
verdict unchanged; a disruptive phase-5 rule does not change an allowed
verdict; a phase-3 block still skips phase 4.

Closes #9
@ndreno
ndreno merged commit cf11252 into main Sep 12, 2026
9 checks passed
@ndreno
ndreno deleted the feat/phase-5-after-block branch September 12, 2026 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Run phase 5 (logging) after a disruptive verdict

1 participant