Expand description
§rsigma-ir
Intermediate representation for Sigma rules — a shared canonical form between evaluation and conversion backends.
The IR lives between the parser AST (rsigma-parser) and the eval engine and convert backends:
YAML ─► parser(AST) ─► pipeline(AST transformations) ─► lower(HIR) ─► compile(CompiledRule)
│
convert(Backend queries)The HIR captures modifier resolution, quantified selectors, and array-scope
detections in a serializable form. Compiled matchers (Regex, IpNet)
are elided from the IR; they are materialised in the compile step.
§Architecture
-
IrRule— the top-level shape, a superset ofSigmaRulemetadata with a resolution-free detection tree (IrDetection) and conditions (IrCondition) that preserve quantified selectors. -
IrMatcher— modifier-resolved matchers. Each field modifier that changes comparison (contains, startswith, endswith, cidr, re, numeric operators, exists, fieldref, timestamp parts) produces an explicit enum variant rather than being encoded as a combination of raw values and an opaqueModifiersbitfield. -
IrDetection— mirrors the compiler’sCompiledDetectionat the semantic level:AllOf,AnyOf,Keywords,ArrayMatch,And, andConditional. Array-scope quantifiers (any/all/all-or-empty/none) are preserved. -
IrMatcher— a faithful, lossless match model. String matches keep a wildcard-aware, original-casehir::IrPattern; encoding modifiers stay explicit ashir::IrEncodingsteps. Nothing is lowercased, regex-compiled, or encoding-expanded during lowering, so both eval (at compile time) and convert (at emit time) can render it exactly.
§Constraints
- Sync-only. No tokio, reqwest, or other async-runtime dependencies.
- HIR values are literal-only on the default lowering path; deferred
DynamicSourceRefvalues are produced only whenlower::LowerOptions::permissive_placeholdersis enabled.
Re-exports§
pub use cache::CacheError;pub use cache::HIR_SCHEMA_VERSION;pub use cache::HirCacheHeader;pub use cache::decode_rules;pub use cache::encode_rules;pub use error::IrError;pub use lower::LowerOptions;pub use lower::lower_conditions;pub use lower::lower_rule;pub use optimize::CseReport;pub use optimize::RepeatedItem;pub use optimize::common_subexpressions;pub use optimize::eliminate_dead_detections;pub use optimize::flatten_condition;pub use optimize::optimize_rule;pub use raise::RaiseOptions;pub use raise::ir_pattern_to_sigma;pub use raise::raise_rule;pub use hir::*;
Modules§
- cache
- Versioned serialization of lowered rules, the HIR cache.
- encoding
- Expansion of encoding modifiers into plain string matches.
- error
- Error types for the lowering pipeline.
- hir
- Intermediate representation types for Sigma rules.
- lower
- Lowering: parser AST → HIR.
- optimize
- Pure-data optimization passes over an
IrRule. - raise
- Raising: HIR → parser AST.