Three settings of "Configuration surface" in SPEC.md that next does not read yet, though the features they tune are built: the IPv6 client group is a fixed /64, the table of clients a fixed 20,000 (maxClients in internal/ratelimit), and the process log has no level. Found in review of #111. One PR to next.
SWWAF_IPV6_GROUP_PREFIX (default 64): the IPv6 group that is one client everywhere a client is grouped (rate and byte limits, bans, history, reputation checks, anomaly counters); a value outside a sensible range (for example 32 to 128) stops the start naming it.
SWWAF_MAX_TRACKED_CLIENTS (default 20000): clients held in memory and in clients.json, the least recently seen dropped first; zero or a negative number stops the start.
SWWAF_LOG_LEVEL (default info: debug, info, warn, error): filters the process's own lines, never the request log.
README.md documents each.
Definition of done: tests show a client grouped by another prefix in the limits and in a ban, the table holding no more than the setting, a process line filtered by level while request lines are not, and each start error; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
Three settings of "Configuration surface" in `SPEC.md` that `next` does not read yet, though the features they tune are built: the IPv6 client group is a fixed /64, the table of clients a fixed 20,000 (`maxClients` in `internal/ratelimit`), and the process log has no level. Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/111. One PR to `next`.
- `SWWAF_IPV6_GROUP_PREFIX` (default `64`): the IPv6 group that is one client everywhere a client is grouped (rate and byte limits, bans, history, reputation checks, anomaly counters); a value outside a sensible range (for example 32 to 128) stops the start naming it.
- `SWWAF_MAX_TRACKED_CLIENTS` (default `20000`): clients held in memory and in `clients.json`, the least recently seen dropped first; zero or a negative number stops the start.
- `SWWAF_LOG_LEVEL` (default `info`: `debug`, `info`, `warn`, `error`): filters the process's own lines, never the request log.
- `README.md` documents each.
Definition of done: tests show a client grouped by another prefix in the limits and in a ban, the table holding no more than the setting, a process line filtered by level while request lines are not, and each start error; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 22:47:30 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Three settings of "Configuration surface" in
SPEC.mdthatnextdoes not read yet, though the features they tune are built: the IPv6 client group is a fixed /64, the table of clients a fixed 20,000 (maxClientsininternal/ratelimit), and the process log has no level. Found in review of #111. One PR tonext.SWWAF_IPV6_GROUP_PREFIX(default64): the IPv6 group that is one client everywhere a client is grouped (rate and byte limits, bans, history, reputation checks, anomaly counters); a value outside a sensible range (for example 32 to 128) stops the start naming it.SWWAF_MAX_TRACKED_CLIENTS(default20000): clients held in memory and inclients.json, the least recently seen dropped first; zero or a negative number stops the start.SWWAF_LOG_LEVEL(defaultinfo:debug,info,warn,error): filters the process's own lines, never the request log.README.mddocuments each.Definition of done: tests show a client grouped by another prefix in the limits and in a ban, the table holding no more than the setting, a process line filtered by level while request lines are not, and each start error; each test failing with its rule broken;
make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
The three settings are read and documented in #113, waiting for review.
Model: opus-5-5