Stop a WAF score below GREY_MIN escalating under the grey gate #3
Loading…
Reference in a new issue
No description provided.
Delete branch "grey-min-floor"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Under
CENTINELA_GATE=grey,CENTINELA_GREY_MINonly ever gated out score-0 requests. The pre-filter flagged any request with a positive WAF score, and the grey gate falls through to the pre-filter, so a score of 1 or more always reached the model.Seen on v0.1.3 with the embedded WAF at paranoia 3 and
GREY_MIN=4: 25 of 26 recent decisions for one host hadwaf_score3 (CRS 942420 on ordinary session cookies) and were all escalated, then failed open as "model unavailable" once the backend queued past the budget.Change
Suspicious()looks only at the request itself (method, path, query, headers, body). It no longer treats a WAF score as a marker.escalate()weighs the score per gate:grey: at or aboveGreyMin, or anything the pre-filter flags. A score below the floor with no marker passes without a model call.suspicious: unchanged, any positive score still escalates.always: unchanged.The eval harness already computed
score >= grey-min || suspicious; with the pre-filter no longer counting the score, it now matches the engine for--grey-minabove 1. Results at the default of 1 are unchanged.Tests
TestGreyGateMin(GreyMin=4): score 3 with no markers is not escalated; score 3 with a marker is; scores 4 and 7 are.TestSuspiciousGateWAFScore: the suspicious gate still escalates a positive score and passes score 0.TestSuspicious: a WAF score alone is no longer flagged by the pre-filter.make vetandmake testpass.Release note
Merging to
mainrunsbuild-and-push, which tags and publishes the next patch version.🔎 ojo scan results
Details (2)