The running smallwebwaf takes in an admin's edit to its state files, as "Persistent state" in SPEC.md describes under "Edits while running". It follows #17, which writes the files and reads them at start; the build order in SPEC.md puts both in the first stage after milestone 2 ("the JSON state files with edits taken in while running").
What it builds
smallwebwaf watches SWWAF_STATE_DIR and notices a state file that is edited, replaced or added, telling its own writes from an admin's by comparing the file with what it last wrote.
An edit that parses is taken in at once: what the file says replaces what smallwebwaf held for that file. Removing a ban's entry from bans.json lifts the ban; adding an entry bans.
An edit that does not parse does not stop smallwebwaf: it keeps its state, renames the file to <name>.bad, writes the file again from memory, and logs the file and the position of the error. (The file_error alert comes with alerting.)
Before writing a file, smallwebwaf checks whether it changed on disk since it last read or wrote it, and takes that edit in first, so an admin's edit is never overwritten.
README.md says how to add and lift a ban by editing bans.json.
Definition of done
Tests show an edit taken in for each file, a ban added and one lifted through bans.json, a broken edit kept as .bad with the file rewritten, and an edit made just before a scheduled write surviving it.
make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
The running `smallwebwaf` takes in an admin's edit to its state files, as "Persistent state" in `SPEC.md` describes under "Edits while running". It follows https://git.eeqj.de/sneak/smallwebwaf/issues/17, which writes the files and reads them at start; the build order in `SPEC.md` puts both in the first stage after milestone 2 ("the JSON state files with edits taken in while running").
## What it builds
- `smallwebwaf` watches `SWWAF_STATE_DIR` and notices a state file that is edited, replaced or added, telling its own writes from an admin's by comparing the file with what it last wrote.
- An edit that parses is taken in at once: what the file says replaces what `smallwebwaf` held for that file. Removing a ban's entry from `bans.json` lifts the ban; adding an entry bans.
- An edit that does not parse does not stop `smallwebwaf`: it keeps its state, renames the file to `<name>.bad`, writes the file again from memory, and logs the file and the position of the error. (The `file_error` alert comes with alerting.)
- Before writing a file, `smallwebwaf` checks whether it changed on disk since it last read or wrote it, and takes that edit in first, so an admin's edit is never overwritten.
- `README.md` says how to add and lift a ban by editing `bans.json`.
## Definition of done
- Tests show an edit taken in for each file, a ban added and one lifted through `bans.json`, a broken edit kept as `.bad` with the file rewritten, and an edit made just before a scheduled write surviving it.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 02:47:45 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The running
smallwebwaftakes in an admin's edit to its state files, as "Persistent state" inSPEC.mddescribes under "Edits while running". It follows #17, which writes the files and reads them at start; the build order inSPEC.mdputs both in the first stage after milestone 2 ("the JSON state files with edits taken in while running").What it builds
smallwebwafwatchesSWWAF_STATE_DIRand notices a state file that is edited, replaced or added, telling its own writes from an admin's by comparing the file with what it last wrote.smallwebwafheld for that file. Removing a ban's entry frombans.jsonlifts the ban; adding an entry bans.smallwebwaf: it keeps its state, renames the file to<name>.bad, writes the file again from memory, and logs the file and the position of the error. (Thefile_erroralert comes with alerting.)smallwebwafchecks whether it changed on disk since it last read or wrote it, and takes that edit in first, so an admin's edit is never overwritten.README.mdsays how to add and lift a ban by editingbans.json.Definition of done
bans.json, a broken edit kept as.badwith the file rewritten, and an edit made just before a scheduled write surviving it.make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Built in #75.
Model: opus-5-5