SWWAF_IPV6_GROUP_PREFIX, SWWAF_MAX_TRACKED_CLIENTS and SWWAF_LOG_LEVEL #112

Open
opened 2026-10-07 22:47:30 +02:00 by clawbot · 1 comment
Collaborator

Three settings of "Configuration surface" in SPEC.md that next does not read yet, though the features they tune are built: the IPv6 client group is a fixed /64, the table of clients a fixed 20,000 (maxClients in internal/ratelimit), and the process log has no level. Found in review of #111. One PR to next.

  • SWWAF_IPV6_GROUP_PREFIX (default 64): the IPv6 group that is one client everywhere a client is grouped (rate and byte limits, bans, history, reputation checks, anomaly counters); a value outside a sensible range (for example 32 to 128) stops the start naming it.
  • SWWAF_MAX_TRACKED_CLIENTS (default 20000): clients held in memory and in clients.json, the least recently seen dropped first; zero or a negative number stops the start.
  • SWWAF_LOG_LEVEL (default info: debug, info, warn, error): filters the process's own lines, never the request log.
  • README.md documents each.

Definition of done: tests show a client grouped by another prefix in the limits and in a ban, the table holding no more than the setting, a process line filtered by level while request lines are not, and each start error; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

Three settings of "Configuration surface" in `SPEC.md` that `next` does not read yet, though the features they tune are built: the IPv6 client group is a fixed /64, the table of clients a fixed 20,000 (`maxClients` in `internal/ratelimit`), and the process log has no level. Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/111. One PR to `next`. - `SWWAF_IPV6_GROUP_PREFIX` (default `64`): the IPv6 group that is one client everywhere a client is grouped (rate and byte limits, bans, history, reputation checks, anomaly counters); a value outside a sensible range (for example 32 to 128) stops the start naming it. - `SWWAF_MAX_TRACKED_CLIENTS` (default `20000`): clients held in memory and in `clients.json`, the least recently seen dropped first; zero or a negative number stops the start. - `SWWAF_LOG_LEVEL` (default `info`: `debug`, `info`, `warn`, `error`): filters the process's own lines, never the request log. - `README.md` documents each. Definition of done: tests show a client grouped by another prefix in the limits and in a ban, the table holding no more than the setting, a process line filtered by level while request lines are not, and each start error; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-07 22:47:30 +02:00
Author
Collaborator

The three settings are read and documented in #113, waiting for review.

Model: opus-5-5

The three settings are read and documented in https://git.eeqj.de/sneak/smallwebwaf/pulls/113, waiting for review. Model: opus-5-5
Sign in to join this conversation.