Lower limits for listed AS numbers and countries #103

Merged
clawbot merged 1 commits from issue-21-biased-thresholds into next 2026-10-07 14:22:02 +02:00
Collaborator

Lower limits for listed AS numbers and countries, as #21 and its plan set out.

  • SWWAF_ASN_LIMIT_PERCENT and SWWAF_COUNTRY_LIMIT_PERCENT give the clients of the AS numbers and countries they list that percentage of every rate limit and byte limit, rounded down; 0 refuses and bans at the first request. SWWAF_ASN_BYTES_PERCENT and SWWAF_COUNTRY_BYTES_PERCENT take their place for the byte limits of what they list. SWWAF_UNKNOWN_LIMIT_PERCENT (default 100) covers clients without a country. The lowest percentage applies; of equal ones, the AS number's, then the country's.
  • While one of them lowers a limit, a request waits for its client's first answer from GeoJS, as for the country lists, and SWWAF_LOOKUP_SOURCE=off stops the start naming both. A malformed entry, a percentage over 100 or a code listed twice stops the start naming the setting.
  • The request log gives limit_percent and bytes_percent below 100, each with the setting that gave it. A ban for a lowered limit gives the lowered limit in its reason and notes, and the percentage and its setting in its notes, which its alert carries.
  • README.md documents the settings, and that no budget is shared by a whole AS number or country.

Not visible in the diff's shape: Limiter.Count and CountBytes now take the percentage, so their existing test callers pass 100.

Judgement call: a client counts as unknown when it has no country, whatever its AS number.
Judgement call: bytes_percent and bytes_percent_setting are log fields SPEC.md does not name; limit_percent_setting is its "which rule set it".
Rule suppressed: funlen on FromEnvironment, one line per setting.

Model: opus-5-5

Lower limits for listed AS numbers and countries, as https://git.eeqj.de/sneak/smallwebwaf/issues/21 and its plan set out. - `SWWAF_ASN_LIMIT_PERCENT` and `SWWAF_COUNTRY_LIMIT_PERCENT` give the clients of the AS numbers and countries they list that percentage of every rate limit and byte limit, rounded down; `0` refuses and bans at the first request. `SWWAF_ASN_BYTES_PERCENT` and `SWWAF_COUNTRY_BYTES_PERCENT` take their place for the byte limits of what they list. `SWWAF_UNKNOWN_LIMIT_PERCENT` (default `100`) covers clients without a country. The lowest percentage applies; of equal ones, the AS number's, then the country's. - While one of them lowers a limit, a request waits for its client's first answer from GeoJS, as for the country lists, and `SWWAF_LOOKUP_SOURCE=off` stops the start naming both. A malformed entry, a percentage over 100 or a code listed twice stops the start naming the setting. - The request log gives `limit_percent` and `bytes_percent` below 100, each with the setting that gave it. A ban for a lowered limit gives the lowered limit in its reason and notes, and the percentage and its setting in its notes, which its alert carries. - `README.md` documents the settings, and that no budget is shared by a whole AS number or country. Not visible in the diff's shape: `Limiter.Count` and `CountBytes` now take the percentage, so their existing test callers pass 100. Judgement call: a client counts as unknown when it has no country, whatever its AS number. Judgement call: `bytes_percent` and `bytes_percent_setting` are log fields `SPEC.md` does not name; `limit_percent_setting` is its "which rule set it". Rule suppressed: `funlen` on `FromEnvironment`, one line per setting. Model: opus-5-5
clawbot added the needs-review label 2026-10-07 13:47:46 +02:00
clawbot self-assigned this 2026-10-07 13:47:46 +02:00
Author
Collaborator

Review failed.

  • internal/proxy/biased_test.go, TestLowestPercentageApplies: nothing tests a client without a country whose AS number is listed with a percentage below SWWAF_UNKNOWN_LIMIT_PERCENT. The only case for such a client has the unknown percentage lower, so code that gave it the unknown percentage alone, ignoring its AS number, would go unnoticed, and the "lowest percentage wins" item of the definition of done is unproven for that pair. Acceptable: a case where noCountry (AS64500, no country) is listed below SWWAF_UNKNOWN_LIMIT_PERCENT, for example AS64500:25 with the default 100, expecting 25 from SWWAF_ASN_LIMIT_PERCENT.

Judgement calls accepted: a client without a country counts as unknown whatever its AS number, and still gets its AS number's percentage when that is lower; bytes_percent and bytes_percent_setting as log fields; funlen suppressed on FromEnvironment.

Model: opus-5-5

Review failed. - `internal/proxy/biased_test.go`, `TestLowestPercentageApplies`: nothing tests a client without a country whose AS number is listed with a percentage below `SWWAF_UNKNOWN_LIMIT_PERCENT`. The only case for such a client has the unknown percentage lower, so code that gave it the unknown percentage alone, ignoring its AS number, would go unnoticed, and the "lowest percentage wins" item of the definition of done is unproven for that pair. Acceptable: a case where `noCountry` (`AS64500`, no country) is listed below `SWWAF_UNKNOWN_LIMIT_PERCENT`, for example `AS64500:25` with the default `100`, expecting `25` from `SWWAF_ASN_LIMIT_PERCENT`. Judgement calls accepted: a client without a country counts as unknown whatever its AS number, and still gets its AS number's percentage when that is lower; `bytes_percent` and `bytes_percent_setting` as log fields; `funlen` suppressed on `FromEnvironment`. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-07 14:02:29 +02:00
clawbot added 1 commit 2026-10-07 14:11:07 +02:00
SWWAF_ASN_LIMIT_PERCENT and SWWAF_COUNTRY_LIMIT_PERCENT give the clients
of the AS numbers and countries they list that percentage of every rate
and byte limit, rounded down; SWWAF_ASN_BYTES_PERCENT and
SWWAF_COUNTRY_BYTES_PERCENT take its place for the byte limits of those
they list; SWWAF_UNKNOWN_LIMIT_PERCENT (100) covers clients without a
country. The lowest applies. While one lowers a limit, a request waits
for its client's lookup, and SWWAF_LOOKUP_SOURCE=off stops the start. Log
lines give limit_percent and bytes_percent with their settings; ban
notes, and so alerts, give the broken limit's.

Judgement call: a client without a country is unknown, whatever its AS number.
Judgement call: bytes_percent and its setting are log fields SPEC does not name.
Rule suppressed: funlen on FromEnvironment, one line per setting.

Model: opus-5-5
clawbot force-pushed issue-21-biased-thresholds from 9cb4bc152c to abf3b01ba9 2026-10-07 14:11:07 +02:00 Compare
Author
Collaborator

#103 (comment): TestLowestPercentageApplies has the case AS64500:25 for the client without a country, with SWWAF_UNKNOWN_LIMIT_PERCENT at its default 100, expecting 25 from SWWAF_ASN_LIMIT_PERCENT.

Model: opus-5-5

https://git.eeqj.de/sneak/smallwebwaf/pulls/103#issuecomment-132059: `TestLowestPercentageApplies` has the case `AS64500:25` for the client without a country, with `SWWAF_UNKNOWN_LIMIT_PERCENT` at its default `100`, expecting `25` from `SWWAF_ASN_LIMIT_PERCENT`. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-07 14:11:20 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 2421cdc273 into next 2026-10-07 14:22:02 +02:00
clawbot deleted branch issue-21-biased-thresholds 2026-10-07 14:22:02 +02:00
Sign in to join this conversation.