Reputation: DNS blocklists #104

Open
opened 2026-10-07 14:23:10 +02:00 by clawbot · 1 comment
Collaborator

Reputation from DNS blocklists, as "Reputation" in SPEC.md gives it. Built after the downloaded blocklists (#29). One PR to next.

  • SWWAF_DNSBL_ZONES (for example dnsbl.dronebl.org; a Spamhaus zone given as a name containing its key) and SWWAF_DNSBL_RESOLVER (optional resolver address). A client is looked up in each zone in the background; a first request is never delayed. IPv4 and IPv6 query names built as the zones expect.
  • SWWAF_REPUTATION_ACTION (default limit:25: deny, limit:<percent> or log) applied to a cached hit; SWWAF_REPUTATION_CACHE_TTL (default 24h) and SWWAF_REPUTATION_TIMEOUT (default 2s).
  • Verdicts kept in reputation.json with when each was fetched, as "Persistent state" gives it, and bounded in memory.
  • A zone that fails or refuses sends one source_failure alert per cooldown and gives no verdict; a hit sends a reputation_hit alert; the request log's reputation names the zone; metrics as "Metrics endpoint" gives them.
  • README.md warns, as SPEC.md does, against zones meant for mail.

Definition of done: tests, against a local stand-in DNS server on a clock the test controls, show a listed and an unlisted client for IPv4 and IPv6, no request delayed, each action, the cache and its expiry, the timeout, a failing zone, and verdicts kept across a restart; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

Reputation from DNS blocklists, as "Reputation" in `SPEC.md` gives it. Built after the downloaded blocklists (https://git.eeqj.de/sneak/smallwebwaf/issues/29). One PR to `next`. - `SWWAF_DNSBL_ZONES` (for example `dnsbl.dronebl.org`; a Spamhaus zone given as a name containing its key) and `SWWAF_DNSBL_RESOLVER` (optional resolver address). A client is looked up in each zone in the background; a first request is never delayed. IPv4 and IPv6 query names built as the zones expect. - `SWWAF_REPUTATION_ACTION` (default `limit:25`: `deny`, `limit:<percent>` or `log`) applied to a cached hit; `SWWAF_REPUTATION_CACHE_TTL` (default `24h`) and `SWWAF_REPUTATION_TIMEOUT` (default `2s`). - Verdicts kept in `reputation.json` with when each was fetched, as "Persistent state" gives it, and bounded in memory. - A zone that fails or refuses sends one `source_failure` alert per cooldown and gives no verdict; a hit sends a `reputation_hit` alert; the request log's `reputation` names the zone; metrics as "Metrics endpoint" gives them. - `README.md` warns, as `SPEC.md` does, against zones meant for mail. Definition of done: tests, against a local stand-in DNS server on a clock the test controls, show a listed and an unlisted client for IPv4 and IPv6, no request delayed, each action, the cache and its expiry, the timeout, a failing zone, and verdicts kept across a restart; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-07 14:23:10 +02:00
Author
Collaborator

Built in #110, for review.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/110, for review. Model: opus-5-5
Sign in to join this conversation.