Skip to content

Fix disjunction split across pipeline boundary with deferred regex branch - #78

Merged
thomaspatzke merged 2 commits into
mainfrom
copilot/fix-deferred-expressions-disjunction
Sep 20, 2026
Merged

thomaspatzke merged 2 commits into
mainfrom
copilot/fix-deferred-expressions-disjunction

Conversation

Copilot AI commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

When a rule condition is a top-level disjunction and one branch contains a |re modifier, the deferred rex/eval hoisting logic in finalize_query_default incorrectly extracted the first disjunct as a prefix, leaving | search OR ... — invalid SPL that also silently inverts the logic from OR to AND.

Root cause: finalize_query_default greedily matched leading field=value tokens to hoist before the deferred pipeline stages, without checking whether the remaining suffix began with OR (i.e., whether it was splitting a disjunction).

Fix (sigma/backends/splunk/splunk.py):

  • After collecting candidate prefix parts, skip hoisting entirely if remaining_query.lstrip().startswith("OR") — keeps the full disjunction intact in the trailing | search clause.

Test (tests/test_backend_splunk.py):

  • Regression test for A or (B and not <regex-filter>) shape, asserting \n| search OR never appears and both disjuncts are present in the final search stage.

Before:

Image="*\\hdiutil.exe"
| rex field=CommandLine "(?<CommandLineMatch>...)"
| eval CommandLineCondition=if(isnotnull(CommandLineMatch), "true", "false")
| search OR Image="*\\openssl.exe" NOT CommandLineCondition="true"

After:

| rex field=CommandLine "(?<CommandLineMatch>...)"
| eval CommandLineCondition=if(isnotnull(CommandLineMatch), "true", "false")
| search Image="*\\hdiutil.exe" OR Image="*\\openssl.exe" NOT CommandLineCondition="true"

…ferred regex (#74)

Co-authored-by: thomaspatzke <1845601+thomaspatzke@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix deferred expressions split across pipeline boundary Fix disjunction split across pipeline boundary with deferred regex branch Sep 19, 2026
Copilot AI requested a review from thomaspatzke September 19, 2026 23:13
@thomaspatzke
thomaspatzke marked this pull request as ready for review September 20, 2026 08:32
@thomaspatzke
thomaspatzke merged commit 197526d into main Sep 20, 2026
4 checks passed
@thomaspatzke
thomaspatzke deleted the copilot/fix-deferred-expressions-disjunction branch September 20, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deferred expressions split a disjunction across a pipeline boundary: '| search OR ...' and an authored OR becomes an AND

2 participants