mirror of
https://github.com/owasp-modsecurity/ModSecurity.git
synced 2025-08-14 13:56:01 +03:00
Improves the performance while loading the rules
Based on the findings listed on #1735
This commit is contained in:
parent
4e3a1f7153
commit
65aa7ae5e2
2
CHANGES
2
CHANGES
@ -1,6 +1,8 @@
|
|||||||
v3.0.3 - YYYY-MMM-DD (to be released)
|
v3.0.3 - YYYY-MMM-DD (to be released)
|
||||||
-------------------------------------
|
-------------------------------------
|
||||||
|
|
||||||
|
- Improves the performance while loading the rules
|
||||||
|
[Issue #1735 - @zimmerle, @p0pr0ck5, @victorhora]
|
||||||
- Allow empty strings to be evaluated by regex::searchAll
|
- Allow empty strings to be evaluated by regex::searchAll
|
||||||
[Issue #1799, #1785 - @victorhora, @XuanHuyDuong, @zimmerle]
|
[Issue #1799, #1785 - @victorhora, @XuanHuyDuong, @zimmerle]
|
||||||
- Adds basic pkg-config info
|
- Adds basic pkg-config info
|
||||||
|
@ -433,20 +433,27 @@ class RulesProperties {
|
|||||||
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
|
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
|
||||||
std::vector<modsecurity::Rule *> *rules_to = to+i;
|
std::vector<modsecurity::Rule *> *rules_to = to+i;
|
||||||
std::vector<modsecurity::Rule *> *rules_from = from+i;
|
std::vector<modsecurity::Rule *> *rules_from = from+i;
|
||||||
|
// TODO: std::vector could be replaced with something more efficient.
|
||||||
|
std::vector<int64_t> v;
|
||||||
|
v.reserve(rules_to->size());
|
||||||
|
for (size_t z = 0; z < rules_to->size(); z++) {
|
||||||
|
Rule *rule_ckc = rules_to->at(z);
|
||||||
|
if (rule_ckc->m_secMarker == false) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
v.push_back(rule_ckc->m_ruleId);
|
||||||
|
}
|
||||||
|
std::sort (v.begin(), v.end());
|
||||||
|
|
||||||
for (size_t j = 0; j < rules_from->size(); j++) {
|
for (size_t j = 0; j < rules_from->size(); j++) {
|
||||||
Rule *rule = rules_from->at(j);
|
Rule *rule = rules_from->at(j);
|
||||||
for (size_t z = 0; z < rules_to->size(); z++) {
|
if (std::binary_search (v.begin(), v.end(), rule->m_ruleId)) {
|
||||||
Rule *rule_ckc = rules_to->at(z);
|
if (err != NULL) {
|
||||||
if (rule_ckc->m_ruleId == rule->m_ruleId &&
|
*err << "Rule id: " \
|
||||||
rule_ckc->m_secMarker == false &&
|
<< std::to_string(rule->m_ruleId) \
|
||||||
rule->m_secMarker == false) {
|
<< " is duplicated" << std::endl;
|
||||||
if (err != NULL) {
|
|
||||||
*err << "Rule id: " \
|
|
||||||
<< std::to_string(rule->m_ruleId) \
|
|
||||||
<< " is duplicated" << std::endl;
|
|
||||||
}
|
|
||||||
return -1;
|
|
||||||
}
|
}
|
||||||
|
return -1;
|
||||||
}
|
}
|
||||||
amount_of_rules++;
|
amount_of_rules++;
|
||||||
rules_to->push_back(rule);
|
rules_to->push_back(rule);
|
||||||
|
Loading…
x
Reference in New Issue
Block a user