The vendored files are fetched from sneak/prompts commit dd4027b, with
this repository's /bin carried forward in .dockerignore; the
test-support deny list has no entries of its own. The lint phase moves
to golangci-lint v2.14.0. The build stage now takes the version from
git describe on the .git the build context carries, unless VERSION is
passed, and fails when .git is present but no version comes out. The
test phase drops -count=1, which the policy says it does not need, and
keeps its tmpfs build cache. One test calls Header.Get with X-Real-IP,
as canonicalheader asks.
Deviation: the Go lines of .gitignore and .editorconfig are dropped;
they are not exempt from byte-identity.
Model: opus-5-5
Milestone 1, the repo's first code. smallwebwaf passes each request to the app and the answer back unchanged, streaming bodies and WebSocket upgrades, within four timeouts (client and app, request and response) and two size limits, and writes one JSON line per request to stdout. Every setting has an SWWAF_ name and a default, and an invalid value stops the start. The repo gets the standard layout: script/ entrypoints, make targets that call them, a Dockerfile that runs the checks, and the Gitea workflow.
Disclosure: SPEC.md changed. Go's server reads the request line and headers before smallwebwaf sees the request, so slow headers are closed without an answer, and neither slow nor oversized headers get a log line.
Disclosure: standard library only.
Model: opus-5-5