Skip to main content

rsigma_ir/
lib.rs

1//! # rsigma-ir
2//!
3//! Intermediate representation for Sigma rules — a shared canonical form
4//! between evaluation and conversion backends.
5//!
6//! The IR lives between the parser AST (rsigma-parser) and the eval engine
7//! and convert backends:
8//!
9//! ```text
10//! YAML ─► parser(AST) ─► pipeline(AST transformations) ─► lower(HIR) ─► compile(CompiledRule)
11//!                                                              │
12//!                                                          convert(Backend queries)
13//! ```
14//!
15//! The HIR captures modifier resolution, quantified selectors, and array-scope
16//! detections in a serializable form.  Compiled matchers (`Regex`, `IpNet`)
17//! are elided from the IR; they are materialised in the compile step.
18//!
19//! ## Architecture
20//!
21//! - **`IrRule`** — the top-level shape, a superset of `SigmaRule` metadata
22//!   with a resolution-free detection tree (`IrDetection`) and conditions
23//!   (`IrCondition`) that preserve quantified selectors.
24//!
25//! - **`IrMatcher`** — modifier-resolved matchers.  Each field modifier that
26//!   changes comparison (contains, startswith, endswith, cidr, re, numeric
27//!   operators, exists, fieldref, timestamp parts) produces an explicit enum
28//!   variant rather than being encoded as a combination of raw values and an
29//!   opaque `Modifiers` bitfield.
30//!
31//! - **`IrDetection`** — mirrors the compiler's `CompiledDetection` at the
32//!   semantic level: `AllOf`, `AnyOf`, `Keywords`, `ArrayMatch`, `And`, and
33//!   `Conditional`.  Array-scope quantifiers (`any`/`all`/`all-or-empty`/`none`)
34//!   are preserved.
35//!
36//! - **`IrMatcher`** — a faithful, lossless match model. String matches keep a
37//!   wildcard-aware, original-case [`hir::IrPattern`]; encoding modifiers stay
38//!   explicit as [`hir::IrEncoding`] steps. Nothing is lowercased,
39//!   regex-compiled, or encoding-expanded during lowering, so both eval (at
40//!   compile time) and convert (at emit time) can render it exactly.
41//!
42//! ## Constraints
43//!
44//! - Sync-only. No tokio, reqwest, or other async-runtime dependencies.
45//! - HIR values are literal-only on the default lowering path; deferred
46//!   `DynamicSourceRef` values are produced only when
47//!   [`lower::LowerOptions::permissive_placeholders`] is enabled.
48
49pub mod cache;
50pub mod encoding;
51pub mod error;
52pub mod hir;
53pub mod lower;
54pub mod optimize;
55pub mod raise;
56
57pub use cache::{CacheError, HIR_SCHEMA_VERSION, HirCacheHeader, decode_rules, encode_rules};
58pub use error::IrError;
59pub use hir::*;
60pub use lower::{LowerOptions, lower_conditions, lower_rule};
61pub use optimize::{
62    CseReport, RepeatedItem, common_subexpressions, eliminate_dead_detections, flatten_condition,
63    optimize_rule,
64};
65pub use raise::{RaiseOptions, ir_pattern_to_sigma, raise_rule};