The vendored files are fetched from sneak/prompts commit dd4027b. This
repository's own entries are kept after the canonical content: /bin in
.dockerignore, the Go lines of .gitignore and [*.go] in .editorconfig;
the test-support deny list has no entries of its own. The lint phase
moves to golangci-lint v2.14.0. The build stage now takes the version
from git describe on the .git the build context carries, unless VERSION
is passed, and fails when .git is present but no version comes out. The
test phase drops -count=1, which the policy says it does not need, and
keeps its tmpfs build cache. One test calls Header.Get with X-Real-IP,
as canonicalheader asks.
Model: opus-5-5
useradd --system warns when the uid it is given is above SYS_UID_MAX,
999 on Ubuntu; --key raises that limit for this one call, so the uid
stays 65532.
minsysusers, which runit's install runs to create its _runit-log user,
prints a Perl warning because runit's sysusers line leaves out the
shell. It reads /etc/sysusers.d/runit.conf in place of runit's file, so
the image writes a copy of that line there, naming the shell minsysusers
gives anyway; the user it creates is unchanged.
The runsvinit warning stays, since it needs a change to runsvinit: its
reaper and its own wait on runsvdir race for the same exited process.
Model: opus-5-5
The test phase spends most of its time compiling with the race
detector from an empty build cache; then come writing the test image
and the internal/proxy tests.
- Go's build cache is on a tmpfs in the test phase, so its 137 MB are
no longer written into the test image.
- TestUpgradedConnectionOutlastsTheTimeouts waits until just past
shortTimeout after the answer to the upgrade was read, by when every
timeout has started, rather than 7.5 s, so it ends with the other
timing tests.
- shortTimeout is written as waitLimit / 2, as its comment says it is.
Model: opus-5-5
The Dockerfile's last stage is now the image of "Deployment" in SPEC.md:
Ubuntu 26.04 with ca-certificates, nix-bin and runit from a dated
snapshot whose InRelease files are checked by hash, nixpkgs from its
release file checked by SHA-256, runsvinit built at a fixed commit, and
smallwebwaf as a runit service. smallwebwaf answers
/_smallwebwaf/healthz, and `smallwebwaf healthcheck`, which takes no
further argument, is the image's HEALTHCHECK. script/example-app builds
an app on the image and checks it end to end.
The Nix profile comes last on the PATH: first, busybox from nixpkgs
replaced runit's own runsvdir and sv. SPEC.md is corrected to match
what was built.
Model: opus-5-5
Milestone 1, the repo's first code. smallwebwaf passes each request to the app and the answer back unchanged, streaming bodies and WebSocket upgrades, within four timeouts (client and app, request and response) and two size limits, and writes one JSON line per request to stdout. Every setting has an SWWAF_ name and a default, and an invalid value stops the start. The repo gets the standard layout: script/ entrypoints, make targets that call them, a Dockerfile that runs the checks, and the Gitea workflow.
Disclosure: SPEC.md changed. Go's server reads the request line and headers before smallwebwaf sees the request, so slow headers are closed without an answer, and neither slow nor oversized headers get a log line.
Disclosure: standard library only.
Model: opus-5-5