Settles the points left open by the review of #35, as decided in #36 (comment).
SPEC.md build order: milestone 2 keeps the header size and the idle time fixed at their defaults. The first stage after it makes them settings and brings SWWAF_ALLOW_NETS with the static lists; from then on SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES refuses a client on a private, loopback or link-local address unless SWWAF_ALLOW_NETS lists it. The group of stages after milestone 2 is now headed "Milestone 3 and later", so every "milestone 3 or later" in both documents has something to point at.
SPEC.md size and time limits: while a request body is on its way, a request timeout that runs out answers 408 if smallwebwaf was waiting on the client and 504 if it was waiting on the app. This is what milestone 1's code on next does, and its tests cover all four cases. The gitea upload note now says the same.
README.md: the list of state kept in files now says the files come in milestone 3 or later, with the rate counters and GeoJS answers kept in memory only until then. Both mentions of "milestone 3 or later" point at the build order. The private-address paragraph now says milestone 2's country lists skip such clients.
Judgement calls:
The state-file note covers the rate counters as well as the GeoJS answers, since milestone 2 writes neither to disk.
The README's private-address paragraph also gets the milestone 2 caveat, which the plan put only in the build order.
Which stages fall into which later milestone is left open.
Model: opus-5-5
Settles the points left open by the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/35, as decided in https://git.eeqj.de/sneak/smallwebwaf/issues/36#issuecomment-115640.
- `SPEC.md` build order: milestone 2 keeps the header size and the idle time fixed at their defaults. The first stage after it makes them settings and brings `SWWAF_ALLOW_NETS` with the static lists; from then on `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses a client on a private, loopback or link-local address unless `SWWAF_ALLOW_NETS` lists it. The group of stages after milestone 2 is now headed "Milestone 3 and later", so every "milestone 3 or later" in both documents has something to point at.
- `SPEC.md` size and time limits: while a request body is on its way, a request timeout that runs out answers `408` if `smallwebwaf` was waiting on the client and `504` if it was waiting on the app. This is what milestone 1's code on `next` does, and its tests cover all four cases. The gitea upload note now says the same.
- `README.md`: the list of state kept in files now says the files come in milestone 3 or later, with the rate counters and GeoJS answers kept in memory only until then. Both mentions of "milestone 3 or later" point at the build order. The private-address paragraph now says milestone 2's country lists skip such clients.
Judgement calls:
- The state-file note covers the rate counters as well as the GeoJS answers, since milestone 2 writes neither to disk.
- The README's private-address paragraph also gets the milestone 2 caveat, which the plan put only in the build order.
- Which stages fall into which later milestone is left open.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 02:49:05 +02:00
The header size and the idle time stay fixed at their defaults through
milestone 2 and become settings in the first stage after it, which also
brings SWWAF_ALLOW_NETS and with it the allow-only country list's refusal
of private addresses. While a request body is on its way, a request
timeout answers 408 or 504 by the side smallwebwaf was waiting on, as
milestone 1's code does. The README says the state files, the GeoJS
answers among them, come in milestone 3 or later, and points at the
build order.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Settles the points left open by the review of #35, as decided in #36 (comment).
SPEC.mdbuild order: milestone 2 keeps the header size and the idle time fixed at their defaults. The first stage after it makes them settings and bringsSWWAF_ALLOW_NETSwith the static lists; from then onSWWAF_EXCLUSIVELY_ALLOWED_COUNTRIESrefuses a client on a private, loopback or link-local address unlessSWWAF_ALLOW_NETSlists it. The group of stages after milestone 2 is now headed "Milestone 3 and later", so every "milestone 3 or later" in both documents has something to point at.SPEC.mdsize and time limits: while a request body is on its way, a request timeout that runs out answers408ifsmallwebwafwas waiting on the client and504if it was waiting on the app. This is what milestone 1's code onnextdoes, and its tests cover all four cases. The gitea upload note now says the same.README.md: the list of state kept in files now says the files come in milestone 3 or later, with the rate counters and GeoJS answers kept in memory only until then. Both mentions of "milestone 3 or later" point at the build order. The private-address paragraph now says milestone 2's country lists skip such clients.Judgement calls:
Model: opus-5-5
Review passed.
Model: opus-5-5