Spec after the milestones: points left open, from the review of issue 16 #36

Open
opened 2026-09-29 02:10:49 +02:00 by clawbot · 2 comments
Collaborator

The review of #35 (merged for #16, the spec following milestones 1 and 2) and its worker noticed points the spec leaves open. None blocked it.

  • The header size and the idle time are settings in SPEC.md (SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES, SWWAF_CLIENT_IDLE_TIMEOUT), but milestone 1 fixes them at their defaults and no later stage in the build order makes them settings.
  • With the size limits, the PR removed "of two matching limits the lower one acts first". That still applies to the paired client and app timeouts: a slow upload also slows the send to the app, and the spec no longer says whether it then gets 408 or 504.
  • README.md still lists the GeoJS answers among what the state files keep "so a restart loses nothing", without the "milestone 3 or later" its lookup section now has.
  • README.md says "milestone 3 or later" without saying what the milestones are; a pointer to the build order in SPEC.md would settle it.
  • Milestone 2 skips clients on private addresses in the country lists, while the full design has the allow-only list refuse them; the spec does not say which stage brings the full behaviour.

Model: opus-5-5

The review of https://git.eeqj.de/sneak/smallwebwaf/pulls/35 (merged for https://git.eeqj.de/sneak/smallwebwaf/issues/16, the spec following milestones 1 and 2) and its worker noticed points the spec leaves open. None blocked it. - The header size and the idle time are settings in `SPEC.md` (`SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES`, `SWWAF_CLIENT_IDLE_TIMEOUT`), but milestone 1 fixes them at their defaults and no later stage in the build order makes them settings. - With the size limits, the PR removed "of two matching limits the lower one acts first". That still applies to the paired client and app timeouts: a slow upload also slows the send to the app, and the spec no longer says whether it then gets `408` or `504`. - `README.md` still lists the GeoJS answers among what the state files keep "so a restart loses nothing", without the "milestone 3 or later" its lookup section now has. - `README.md` says "milestone 3 or later" without saying what the milestones are; a pointer to the build order in `SPEC.md` would settle it. - Milestone 2 skips clients on private addresses in the country lists, while the full design has the allow-only list refuse them; the spec does not say which stage brings the full behaviour. Model: opus-5-5
clawbot self-assigned this 2026-09-29 02:10:49 +02:00
Author
Collaborator

Plan. Docs only, one PR to next changing SPEC.md and README.md. Each point, decided:

  • Header size and idle time: they stay settings in the full design, fixed at their defaults in milestones 1 and 2. The build order lists them in the first stage after milestone 2.
  • Paired request timeouts: when the request body is still streaming and a request timeout runs out, the answer names the side smallwebwaf was waiting on at that moment: 408 if it was waiting for the client to send more, 504 if it was waiting for the app to take what it had. Milestone 1 (#13) builds the same rule.
  • README.md's list of what the state files keep marks the GeoJS answers as written to disk from milestone 3 or later, as its lookup section already says.
  • README.md points "milestone 3 or later" at the build order in SPEC.md.
  • Private addresses and the allow-only country list: the full behaviour (refused unless listed in SWWAF_ALLOW_NETS) comes in the first stage after milestone 2, together with the static lists that bring SWWAF_ALLOW_NETS. The build order says so.

Model: opus-5-5

Plan. Docs only, one PR to `next` changing `SPEC.md` and `README.md`. Each point, decided: - Header size and idle time: they stay settings in the full design, fixed at their defaults in milestones 1 and 2. The build order lists them in the first stage after milestone 2. - Paired request timeouts: when the request body is still streaming and a request timeout runs out, the answer names the side smallwebwaf was waiting on at that moment: `408` if it was waiting for the client to send more, `504` if it was waiting for the app to take what it had. Milestone 1 (https://git.eeqj.de/sneak/smallwebwaf/issues/13) builds the same rule. - `README.md`'s list of what the state files keep marks the GeoJS answers as written to disk from milestone 3 or later, as its lookup section already says. - `README.md` points "milestone 3 or later" at the build order in `SPEC.md`. - Private addresses and the allow-only country list: the full behaviour (refused unless listed in `SWWAF_ALLOW_NETS`) comes in the first stage after milestone 2, together with the static lists that bring `SWWAF_ALLOW_NETS`. The build order says so. Model: opus-5-5
Author
Collaborator

Opened #46 for this.

Model: opus-5-5

Opened https://git.eeqj.de/sneak/smallwebwaf/pulls/46 for this. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#36