The review of the deploy-model spec, #32 (merged for #12), noticed points the spec leaves open. None blocked it; each is settled here, in SPEC.md, or when milestone 2 (#14) builds the image.
The container's health check and the "Ports" paragraph assume SWWAF_LISTEN_ADDR keeps its default :8080. The spec should say what happens when it is changed, or that it must not be.
The example run scripts use #!/bin/sh without strict mode. The org style guide asks for #!/usr/bin/env bash with set -euo pipefail; Alpine has no bash until the image installs it, so the image should install it and the examples follow the guide.
The spec says a token file readable only by the smallwebwaf user keeps the token from the app, but not how an operator delivers a file with that owner and mode, in general or through upaas.
The smallwebwafrun script takes ownership of the state directory; the spec does not say whether files already in it change owner too, which matters for a host directory holding files from an earlier owner.
For whoever builds the image: Alpine does not package runsvinit, so the image builds or fetches it; and the image must use Alpine's runit package or set SVDIR, or sv stop finds no services and smallwebwaf is killed without writing its state.
Update: the image is now built on Ubuntu with nixpkgs (#37, for #34). That settles the bash point (Ubuntu ships bash, and the example run scripts use it with set -euo pipefail) and the SVDIR point (Ubuntu's runit looks in /etc/service). runsvinit is still packaged by neither Ubuntu nor nixpkgs; the spec builds it from source. Points for the new base are in #38.
Model: opus-5-5
The review of the deploy-model spec, https://git.eeqj.de/sneak/smallwebwaf/pulls/32 (merged for https://git.eeqj.de/sneak/smallwebwaf/issues/12), noticed points the spec leaves open. None blocked it; each is settled here, in `SPEC.md`, or when milestone 2 (https://git.eeqj.de/sneak/smallwebwaf/issues/14) builds the image.
- The container's health check and the "Ports" paragraph assume `SWWAF_LISTEN_ADDR` keeps its default `:8080`. The spec should say what happens when it is changed, or that it must not be.
- The example `run` scripts use `#!/bin/sh` without strict mode. The org style guide asks for `#!/usr/bin/env bash` with `set -euo pipefail`; Alpine has no bash until the image installs it, so the image should install it and the examples follow the guide.
- The spec says a token file readable only by the `smallwebwaf` user keeps the token from the app, but not how an operator delivers a file with that owner and mode, in general or through upaas.
- The `smallwebwaf` `run` script takes ownership of the state directory; the spec does not say whether files already in it change owner too, which matters for a host directory holding files from an earlier owner.
- For whoever builds the image: Alpine does not package `runsvinit`, so the image builds or fetches it; and the image must use Alpine's runit package or set `SVDIR`, or `sv stop` finds no services and smallwebwaf is killed without writing its state.
Update: the image is now built on Ubuntu with nixpkgs (https://git.eeqj.de/sneak/smallwebwaf/pulls/37, for https://git.eeqj.de/sneak/smallwebwaf/issues/34). That settles the bash point (Ubuntu ships bash, and the example `run` scripts use it with `set -euo pipefail`) and the `SVDIR` point (Ubuntu's runit looks in `/etc/service`). `runsvinit` is still packaged by neither Ubuntu nor nixpkgs; the spec builds it from source. Points for the new base are in https://git.eeqj.de/sneak/smallwebwaf/issues/38.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 01:49:01 +02:00
Plan. Docs only, one PR to next changing SPEC.md (and README.md where it repeats the same text). The bash, SVDIR and runsvinit points are settled above; the rest, decided:
SWWAF_LISTEN_ADDR may change the port, and its address part stays empty (:9000, never 127.0.0.1:9000), so smallwebwaf keeps listening on every address: traefik reaches it on the container's address and the health check on 127.0.0.1. The image's health check takes its port from SWWAF_LISTEN_ADDR, and traefik's port label must name the same port. The "Ports" paragraph says so, and the README.md bullet repeats it. (Address part added after the first review of #41.)
A token file: the operator makes it on the host, owned by uid 65532 (the smallwebwaf user) with mode 0400, and mounts the directory that holds it read-only; the container sees the same owner and mode. For upaas, the worker checks upaas's own README for mounted directories and writes what applies; where it offers none, the spec says the token goes in the plain setting, which the app can read.
The smallwebwafrun script makes the state directory and every file in it belong to the smallwebwaf user, so files left by an earlier owner can be read and replaced.
#38 changes the same section and follows once this is on next.
Model: opus-5-5
Plan. Docs only, one PR to `next` changing `SPEC.md` (and `README.md` where it repeats the same text). The bash, `SVDIR` and `runsvinit` points are settled above; the rest, decided:
- `SWWAF_LISTEN_ADDR` may change the port, and its address part stays empty (`:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps listening on every address: traefik reaches it on the container's address and the health check on `127.0.0.1`. The image's health check takes its port from `SWWAF_LISTEN_ADDR`, and traefik's port label must name the same port. The "Ports" paragraph says so, and the `README.md` bullet repeats it. (Address part added after the first review of https://git.eeqj.de/sneak/smallwebwaf/pulls/41.)
- A token file: the operator makes it on the host, owned by uid 65532 (the `smallwebwaf` user) with mode `0400`, and mounts the directory that holds it read-only; the container sees the same owner and mode. For upaas, the worker checks upaas's own README for mounted directories and writes what applies; where it offers none, the spec says the token goes in the plain setting, which the app can read.
- The `smallwebwaf` `run` script makes the state directory and every file in it belong to the `smallwebwaf` user, so files left by an earlier owner can be read and replaced.
https://git.eeqj.de/sneak/smallwebwaf/issues/38 changes the same section and follows once this is on `next`.
Model: opus-5-5
Built as #41, to next: the three points of the plan comment in SPEC.md, and the README.md bullet on ports.
Model: opus-5-5
Built as https://git.eeqj.de/sneak/smallwebwaf/pulls/41, to `next`: the three points of the plan comment in `SPEC.md`, and the `README.md` bullet on ports.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The review of the deploy-model spec, #32 (merged for #12), noticed points the spec leaves open. None blocked it; each is settled here, in
SPEC.md, or when milestone 2 (#14) builds the image.SWWAF_LISTEN_ADDRkeeps its default:8080. The spec should say what happens when it is changed, or that it must not be.runscripts use#!/bin/shwithout strict mode. The org style guide asks for#!/usr/bin/env bashwithset -euo pipefail; Alpine has no bash until the image installs it, so the image should install it and the examples follow the guide.smallwebwafuser keeps the token from the app, but not how an operator delivers a file with that owner and mode, in general or through upaas.smallwebwafrunscript takes ownership of the state directory; the spec does not say whether files already in it change owner too, which matters for a host directory holding files from an earlier owner.runsvinit, so the image builds or fetches it; and the image must use Alpine's runit package or setSVDIR, orsv stopfinds no services and smallwebwaf is killed without writing its state.Update: the image is now built on Ubuntu with nixpkgs (#37, for #34). That settles the bash point (Ubuntu ships bash, and the example
runscripts use it withset -euo pipefail) and theSVDIRpoint (Ubuntu's runit looks in/etc/service).runsvinitis still packaged by neither Ubuntu nor nixpkgs; the spec builds it from source. Points for the new base are in #38.Model: opus-5-5
Plan. Docs only, one PR to
nextchangingSPEC.md(andREADME.mdwhere it repeats the same text). The bash,SVDIRandrunsvinitpoints are settled above; the rest, decided:SWWAF_LISTEN_ADDRmay change the port, and its address part stays empty (:9000, never127.0.0.1:9000), sosmallwebwafkeeps listening on every address: traefik reaches it on the container's address and the health check on127.0.0.1. The image's health check takes its port fromSWWAF_LISTEN_ADDR, and traefik's port label must name the same port. The "Ports" paragraph says so, and theREADME.mdbullet repeats it. (Address part added after the first review of #41.)smallwebwafuser) with mode0400, and mounts the directory that holds it read-only; the container sees the same owner and mode. For upaas, the worker checks upaas's own README for mounted directories and writes what applies; where it offers none, the spec says the token goes in the plain setting, which the app can read.smallwebwafrunscript makes the state directory and every file in it belong to thesmallwebwafuser, so files left by an earlier owner can be read and replaced.#38 changes the same section and follows once this is on
next.Model: opus-5-5
Built as #41, to
next: the three points of the plan comment inSPEC.md, and theREADME.mdbullet on ports.Model: opus-5-5
clawbot referenced this issue2026-10-04 01:43:22 +02:00