Skip to content

Integrate libinjection: implement @detectSQLi and @detectXSS - #7

Merged
ndreno merged 1 commit into
mainfrom
feat/integrate-libinjection
Sep 11, 2026
Merged

ndreno merged 1 commit into
mainfrom
feat/integrate-libinjection

Conversation

@ndreno

@ndreno ndreno commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

The @detectSQLi and @detectXSS operators parsed but refused to compile,
so every CRS rule using them (rule 942100 and friends) was unenforceable.
This wires in the libinjectionrs port, now differential-tested to zero
divergence from the C library over its ~163k-input corpus, and implements
both operators.

Changes

  • @detectSQLi classifies with libinjectionrs::detect_sqli; when capture
    is requested it places the fingerprint in the first capture, as
    ModSecurity does.
  • @detectXSS classifies with libinjectionrs::detect_xss.
  • Dependency: a git pin on barbacane-dev/libinjectionrs (rev with all six
    char-semantics fixes), so downstream git consumers of parapet resolve it.

Conformance

Both operators compile now, so:

  • the two known refusals are gone (the operator gate's known set is empty),
  • the curated sqli tautology case is caught by rule 942100 rather than
    attributed as a gap.

CI re-measures the FTW pass rate with the operators live; the README's
figure will be refreshed from that.

The two libinjection operators parsed but refused to compile, so any CRS
rule using them was unenforceable. Wire in the libinjectionrs port (now
differential-tested to zero divergence from the C library over its corpus)
and implement both operators:

- @detectSQLi classifies with detect_sqli and, when capture is requested,
  places the fingerprint in the first capture, as ModSecurity does.
- @detectXSS classifies with detect_xss.

The dependency is a git pin on barbacane-dev/libinjectionrs so downstream
git consumers of parapet resolve it.

Conformance: the operators compile now, so the two known refusals are
gone, the curated `sqli tautology` case is caught by rule 942100 rather
than attributed as a gap, and the operator-refusal gate's known set is
empty (any future refusal is flagged).
@ndreno
ndreno merged commit 695ee8b into main Sep 11, 2026
9 checks passed
@ndreno
ndreno deleted the feat/integrate-libinjection branch September 11, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant