The last part of the third stage of the build order in SPEC.md: the anomaly thresholds, which only alert and never refuse, as "Anomaly thresholds" (R4) in "Configuration surface" gives them. Built after the byte limits (#20), whose byte counting it shares. One PR to next.
Requests and bytes per minute and per hour, counted per client, per surrounding netblock (SWWAF_ANOMALY_NET_V4_PREFIX default 24, SWWAF_ANOMALY_NET_V6_PREFIX default 48), per AS number, for the whole service, and per named netblock in SWWAF_WATCH_NETS (name=netblock,...), each against its SWWAF_ANOMALY_* or SWWAF_WATCH_* threshold. None is set by default; an unset threshold counts nothing it does not need and sends nothing.
Passing a threshold sends one anomaly alert, through the existing queue and its cooldown, naming the scope (client, netblock, AS number, whole service or watched name), the window, the count and the threshold. Nothing is refused or banned.
Clients in SWWAF_ALLOW_NETS and SWWAF_RATE_LIMIT_EXEMPT_NETS are counted too.
A per-AS-number threshold with SWWAF_LOOKUP_SOURCE=off stops the start naming both; malformed SWWAF_WATCH_NETS stops the start naming it.
The counters for netblocks, AS numbers, watched names and the whole service kept in alerts.json, as "Persistent state" gives it, and bounded in memory.
README.md documents the settings and that these only alert.
Definition of done: tests, on a clock the test controls, show each scope and window passing its threshold and alerting once per cooldown, nothing refused, allow-listed and exempt clients counted, unset thresholds silent, the start errors, and the counters kept across a restart; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
The last part of the third stage of the build order in `SPEC.md`: the anomaly thresholds, which only alert and never refuse, as "Anomaly thresholds" (R4) in "Configuration surface" gives them. Built after the byte limits (https://git.eeqj.de/sneak/smallwebwaf/issues/20), whose byte counting it shares. One PR to `next`.
- Requests and bytes per minute and per hour, counted per client, per surrounding netblock (`SWWAF_ANOMALY_NET_V4_PREFIX` default `24`, `SWWAF_ANOMALY_NET_V6_PREFIX` default `48`), per AS number, for the whole service, and per named netblock in `SWWAF_WATCH_NETS` (`name=netblock,...`), each against its `SWWAF_ANOMALY_*` or `SWWAF_WATCH_*` threshold. None is set by default; an unset threshold counts nothing it does not need and sends nothing.
- Passing a threshold sends one `anomaly` alert, through the existing queue and its cooldown, naming the scope (client, netblock, AS number, whole service or watched name), the window, the count and the threshold. Nothing is refused or banned.
- Clients in `SWWAF_ALLOW_NETS` and `SWWAF_RATE_LIMIT_EXEMPT_NETS` are counted too.
- A per-AS-number threshold with `SWWAF_LOOKUP_SOURCE=off` stops the start naming both; malformed `SWWAF_WATCH_NETS` stops the start naming it.
- The counters for netblocks, AS numbers, watched names and the whole service kept in `alerts.json`, as "Persistent state" gives it, and bounded in memory.
- `README.md` documents the settings and that these only alert.
Definition of done: tests, on a clock the test controls, show each scope and window passing its threshold and alerting once per cooldown, nothing refused, allow-listed and exempt clients counted, unset thresholds silent, the start errors, and the counters kept across a restart; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 11:01:23 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The last part of the third stage of the build order in
SPEC.md: the anomaly thresholds, which only alert and never refuse, as "Anomaly thresholds" (R4) in "Configuration surface" gives them. Built after the byte limits (#20), whose byte counting it shares. One PR tonext.SWWAF_ANOMALY_NET_V4_PREFIXdefault24,SWWAF_ANOMALY_NET_V6_PREFIXdefault48), per AS number, for the whole service, and per named netblock inSWWAF_WATCH_NETS(name=netblock,...), each against itsSWWAF_ANOMALY_*orSWWAF_WATCH_*threshold. None is set by default; an unset threshold counts nothing it does not need and sends nothing.anomalyalert, through the existing queue and its cooldown, naming the scope (client, netblock, AS number, whole service or watched name), the window, the count and the threshold. Nothing is refused or banned.SWWAF_ALLOW_NETSandSWWAF_RATE_LIMIT_EXEMPT_NETSare counted too.SWWAF_LOOKUP_SOURCE=offstops the start naming both; malformedSWWAF_WATCH_NETSstops the start naming it.alerts.json, as "Persistent state" gives it, and bounded in memory.README.mddocuments the settings and that these only alert.Definition of done: tests, on a clock the test controls, show each scope and window passing its threshold and alerting once per cooldown, nothing refused, allow-listed and exempt clients counted, unset thresholds silent, the start errors, and the counters kept across a restart; each test failing with its rule broken;
make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
clawbot referenced this issue2026-10-07 15:04:54 +02:00
Built in #107, waiting for review.
Model: opus-5-5