Docs only; no code exists yet, so there is nothing to deploy. next holds four changes to SPEC.md and README.md:
#9: the spec rewritten to your rulings through 28 September, including the country lists, GeoJS as the default lookup source and one listener for everything. Choices made where your words left a gap are listed in that PR's body.
#32: your deploy model. An app's Dockerfile builds FROM the smallwebwaf image, runit runs smallwebwaf on :8080 in front of the app on 127.0.0.1:8081, no setting is required, and every setting carries the SWWAF_ prefix.
#35: the spec follows your milestones. The build order starts with milestones 1 and 2, the body-size settings are one per direction, and GeoJS answers stay in memory until a later milestone.
#37: the image is built on the newest Ubuntu LTS, 26.04 today, pinned by digest and moved at each new LTS, with nixpkgs installed and pinned to one commit.
EVALUATION.md is unchanged. Open points found in review are collected in #30, #33, #36 and #38.
Model: opus-5-5
Docs only; no code exists yet, so there is nothing to deploy. `next` holds four changes to `SPEC.md` and `README.md`:
- https://git.eeqj.de/sneak/smallwebwaf/pulls/9: the spec rewritten to your rulings through 28 September, including the country lists, GeoJS as the default lookup source and one listener for everything. Choices made where your words left a gap are listed in that PR's body.
- https://git.eeqj.de/sneak/smallwebwaf/pulls/32: your deploy model. An app's Dockerfile builds `FROM` the smallwebwaf image, runit runs smallwebwaf on `:8080` in front of the app on `127.0.0.1:8081`, no setting is required, and every setting carries the `SWWAF_` prefix.
- https://git.eeqj.de/sneak/smallwebwaf/pulls/35: the spec follows your milestones. The build order starts with milestones 1 and 2, the body-size settings are one per direction, and GeoJS answers stay in memory until a later milestone.
- https://git.eeqj.de/sneak/smallwebwaf/pulls/37: the image is built on the newest Ubuntu LTS, 26.04 today, pinned by digest and moved at each new LTS, with nixpkgs installed and pinned to one commit.
`EVALUATION.md` is unchanged. Open points found in review are collected in https://git.eeqj.de/sneak/smallwebwaf/issues/30, https://git.eeqj.de/sneak/smallwebwaf/issues/33, https://git.eeqj.de/sneak/smallwebwaf/issues/36 and https://git.eeqj.de/sneak/smallwebwaf/issues/38.
Model: opus-5-5
SPEC.md and README.md now state the resolutions of the old questions section and sneak's later requirements: seven-day bans for clear signs of attack and short, tripling bans for broken limits; state files that follow memory and take in edits while running; ban notes and per-client history; size and time limits in both directions; country deny and allow-only lists; GeoJS as the default lookup source; one listener for everything. The defaults are chosen so that a sidecar with only UPSTREAM_URL set protects an app on the open internet; the Core Rule Set reads no request bodies by default. Choices made where his words left a gap are listed in the PR. Gitea requests the defaults may still refuse are collected in a follow-up issue.
Model: opus-5-5
SPEC.md and README.md now describe sneak's recommended deploy: an app's Dockerfile builds FROM the smallwebwaf image, and runit, started by runsvinit, runs smallwebwaf on :8080 in front of the app on 127.0.0.1:8081, so no setting is required. The spec covers what the app's Dockerfile adds, the users each process runs as, restarts, the health check, ports, the state directory and its volume, the app trusting loopback for forwarded headers, and upaas needing no change. An example app Dockerfile replaces the docker-compose examples. Every setting carries the SWWAF_ prefix, the file form too, and "sidecar" no longer names the deploy shape.
Model: opus-5-5
clawbot
changed title from Spec update: SPEC.md and README.md to sneak's rulings to Spec: SPEC.md and README.md to sneak's rulings and his deploy model2026-09-29 01:49:11 +02:00
SPEC.md now follows sneak's milestones. The build order starts with milestone 1 and milestone 2, each described briefly and linked, then the earlier stages less what the two milestones build; milestone 2 carries the container image, runit and the health check on /_smallwebwaf/healthz. The four body-size settings become SWWAF_REQUEST_MAX_BYTES and SWWAF_RESPONSE_MAX_BYTES, since smallwebwaf passes bodies through unchanged; the four timeouts stay. GeoJS answers are kept in memory, and writing them to lookups.json comes in milestone 3 or later, as he ruled. README.md loses the two sentences this made wrong.
Model: opus-5-5
clawbot
changed title from Spec: SPEC.md and README.md to sneak's rulings and his deploy model to Spec: SPEC.md and README.md to sneak's rulings, deploy model and milestones2026-09-29 02:10:55 +02:00
The smallwebwaf image is now built on the newest Ubuntu LTS release, 26.04 today, pinned by digest and moved to the next LTS when that ships, with Nix and nixpkgs installed, as sneak ruled. nixpkgs is pinned to one commit of its newest release branch with a hash the build checks, so an app's build gives the same packages each time. The example app Dockerfiles add a package from nixpkgs and create the app's user with useradd, and every run script is bash with set -euo pipefail, as the style guide asks. The new base settles two of the Alpine points of the deploy follow-up. Building the image stays with milestone 2.
Model: opus-5-5
clawbot
changed title from Spec: SPEC.md and README.md to sneak's rulings, deploy model and milestones to Spec: SPEC.md and README.md to sneak's rulings, deploy model, milestones and Ubuntu base2026-09-29 02:44:17 +02:00
sneak
merged commit fd77e76177 into main2026-09-29 02:57:58 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Docs only; no code exists yet, so there is nothing to deploy.
nextholds four changes toSPEC.mdandREADME.md:FROMthe smallwebwaf image, runit runs smallwebwaf on:8080in front of the app on127.0.0.1:8081, no setting is required, and every setting carries theSWWAF_prefix.EVALUATION.mdis unchanged. Open points found in review are collected in #30, #33, #36 and #38.Model: opus-5-5
Spec update: SPEC.md and README.md to sneak's rulingsto Spec: SPEC.md and README.md to sneak's rulings and his deploy modelSpec: SPEC.md and README.md to sneak's rulings and his deploy modelto Spec: SPEC.md and README.md to sneak's rulings, deploy model and milestonesSpec: SPEC.md and README.md to sneak's rulings, deploy model and milestonesto Spec: SPEC.md and README.md to sneak's rulings, deploy model, milestones and Ubuntu base