Milestone 2, part 1: per-IP rate limits #43

Open
opened 2026-10-04 02:44:50 +02:00 by clawbot · 1 comment
Collaborator

Part 1 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to next.

What it builds

The per-IP rate limits of issue 14 ("What it adds", first bullet, and the three rate settings), as SPEC.md describes them under "Counting method" and "Configuration surface":

  • A client is one IPv4 address, or one IPv6 /64: the client milestone 1 already identifies.
  • Each client's requests are counted over a minute, an hour and a day: two buckets per window, the older one weighted by how much of it the window still covers.
  • A request that takes a client over any limit is refused with 429, and so is each request after it until the client is back under every limit. Refused requests count.
  • At most 20,000 clients are kept, the least recently seen dropped first. Nothing is written to disk.
  • The request log line gains limit_hit (which window) and the action value rate_limited.
  • SWWAF_RATE_LIMIT_PER_MINUTE (1000), SWWAF_RATE_LIMIT_PER_HOUR (10000), SWWAF_RATE_LIMIT_PER_DAY (50000); a value that is set but invalid stops the start with a message naming it.
  • README.md documents the three settings.

Not in this part: the country lists and GeoJS (part 2), the image and /_smallwebwaf/healthz (part 3), bans.

Definition of done

  • Tests show: each window refusing at its limit and letting the client back once it is under; refused requests counting; an IPv6 /64 counted as one client; the 20,000-client bound dropping the least recently seen; each setting's default; the start refused for invalid values. Time in tests comes from a clock the test controls, never real waiting.
  • make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).

Model: opus-5-5

Part 1 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14. The order of the three parts is on that issue's plan comment. One PR to `next`. ## What it builds The per-IP rate limits of issue 14 ("What it adds", first bullet, and the three rate settings), as `SPEC.md` describes them under "Counting method" and "Configuration surface": - A client is one IPv4 address, or one IPv6 /64: the client milestone 1 already identifies. - Each client's requests are counted over a minute, an hour and a day: two buckets per window, the older one weighted by how much of it the window still covers. - A request that takes a client over any limit is refused with `429`, and so is each request after it until the client is back under every limit. Refused requests count. - At most 20,000 clients are kept, the least recently seen dropped first. Nothing is written to disk. - The request log line gains `limit_hit` (which window) and the `action` value `rate_limited`. - `SWWAF_RATE_LIMIT_PER_MINUTE` (`1000`), `SWWAF_RATE_LIMIT_PER_HOUR` (`10000`), `SWWAF_RATE_LIMIT_PER_DAY` (`50000`); a value that is set but invalid stops the start with a message naming it. - `README.md` documents the three settings. Not in this part: the country lists and GeoJS (part 2), the image and `/_smallwebwaf/healthz` (part 3), bans. ## Definition of done - Tests show: each window refusing at its limit and letting the client back once it is under; refused requests counting; an IPv6 /64 counted as one client; the 20,000-client bound dropping the least recently seen; each setting's default; the start refused for invalid values. Time in tests comes from a clock the test controls, never real waiting. - `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-10-04 02:44:50 +02:00
Author
Collaborator

Built in #48, waiting for review.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/48, waiting for review. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#43