Skip to content

🔧 chore(deps): bump rsigma from 0.22 to 0.23 - #100

Merged
frack113 merged 5 commits into
mainfrom
feat/rsigma-0.23-upgrade
Oct 4, 2026
Merged

frack113 merged 5 commits into
mainfrom
feat/rsigma-0.23-upgrade

Conversation

@frack113

@frack113 frack113 commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Overview

Bump rsigma from 0.22 to 0.23 (HIR cache schema 1→2, |neq semantics, daachorse-index feature) and clean up the tree around it: the lockfile is brought fully up to date within semver ranges, and debug leftovers from the bloom/pruning session are removed. No behavioral change for sigmacatch: zero SigmaHQ rules use |neq, and the HIR cache version bump is handled by the existing load_hir fallback (warn + recompile on first run).

What's new

sigmacatch — dependencies

  • rsigma + rsigma-parser 0.22 → 0.23 (sigmacatch/Cargo.toml)
  • Cargo.lock: 12 patches within semver ranges (tokio 1.53.2, libc 0.2.190, cc 1.6.0, uuid 1.27.0, serde_with 3.24.0, yoke-derive 0.8.4 unyanked, quinn-proto/udp, mio, lazy_static, tokio-rustls)
  • cargo audit: 0 vulnerabilities (residual: encoding 0.2.33 unmaintained, transitive via evtx — upstream)

sigmacatch — debug cleanup

  • runner.rs: drop BUILD_TIME stamp (never set by build.rs or CI — always logged "unknown")
  • build.rs: drop always-on ebpf_script_trace.txt / ebpf_build_failure.txt debug writes, dedupe comment
  • detection/mod.rs: remove 3 debug tests from the bloom/pruning session (−200 lines); the real Sysmon EventID 13 matching test is kept

sigmacatch — repo

  • plumbing/mod.rs: remove two no-op #[allow(unused_imports)] on pub(crate) re-exports; porcelain.rs now imports setup_sparse_checkout via the facade like every other plumbing call

Docs

  • Fixtures READMEs: point at sigmacatch/src/regression/evtx_writer.rs (the crates/sigmacatch-regression path predates the workspace merge), drop dangling sigmacatch-reggen skill pointer, rename sigmacatch-linux → sigmacatch in the .log regen recipe
  • CHANGELOG.md: [Unreleased] section

Changed files (10)

  • sigmacatch/Cargo.toml, Cargo.lock — rsigma 0.23 + lockfile patches
  • sigmacatch/src/runner.rs, sigmacatch/build.rs, sigmacatch/src/detection/mod.rs — debug leftovers
  • sigmacatch/src/repo/plumbing/mod.rs, sigmacatch/src/repo/porcelain.rs — dead allows, facade consistency
  • sigmacatch/tests/fixtures/README.md, sigmacatch/tests/fixtures/sigma/README.md — stale post-refactor references
  • CHANGELOG.md — [Unreleased]

Full list: git diff --stat main...HEAD (53 insertions, 260 deletions)

Testing

  • cargo fmt --check — passed
  • cargo clippy --all-targets -- -W warnings — passed
  • cargo clippy --no-default-features --features auditd,builtin,sysmon --all-targets — passed (no dead code in the Linux combo)
  • cargo clippy --no-default-features --features evtx --all-targets — passed
  • cargo test --locked — passed (380 tests, 0 failures; 3 debug tests removed)
  • cargo xwin build --release --target x86_64-pc-windows-msvc — deferred to CI (Linux host)
  • regressiondata-check against sigma/regression_data — deferred to CI (rules clone not present on this host)

How to build / run

# default (winevt, Windows only)
cargo build --release -p sigmacatch

# Linux collectors
cargo build --release -p sigmacatch --no-default-features --features auditd,builtin,sysmon

First run after the upgrade recompiles the HIR cache (schema 2) — expected one-time cold start, logged as a warning.

0.23.0 is API-compatible for sigmacatch: set_cross_rule_ac,
explain_rule, save_hir/load_hir and the parser surface are
unchanged. HIR cache schema moves 1 -> 2; the existing load
fallback (warn + recompile) covers the one-time cold start.
The |neq semantic fix affects zero rules in the SigmaHQ corpus.
Includes yoke-derive 0.8.3 -> 0.8.4, resolving the yanked-version
warning from cargo audit. No direct dependency pins changed;
ssh-key 0.7 is RC-only and skipped. Remaining audit warning is
encoding 0.2.33 (unmaintained, transitive via evtx — upstream).
- runner: drop the BUILD_TIME build-date stamp (never set by build.rs
  or CI, always logged as 'unknown')
- build.rs: drop the always-on ebpf_script_trace.txt /
  ebpf_build_failure.txt OUT_DIR traces (read by nothing) and a
  duplicated comment
- detection: delete the three debug_* registry tests left from the
  hidden-user bloom/pruning isolation; the real matching test stays
- repo/plumbing: remove two no-op #[allow(unused_imports)] on
  pub(crate) re-exports; import setup_sparse_checkout via the facade
  in porcelain.rs like every other plumbing call
- fixtures READMEs: point at sigmacatch/src/regression/evtx_writer.rs
  (crates/sigmacatch-regression no longer exists since the workspace
  merge), drop dangling .agents/skills/sigmacatch-reggen/ pointer,
  rename sigmacatch-linux to sigmacatch in the .log regen recipe
@frack113
frack113 merged commit 843cea0 into main Oct 4, 2026
43 checks passed
@frack113
frack113 deleted the feat/rsigma-0.23-upgrade branch October 4, 2026 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant