The header size and the idle time as settings #71

Merged
clawbot merged 1 commits from issue-70-header-idle-settings into next 2026-10-06 05:05:32 +02:00
Collaborator

Builds #70.

  • SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K) and SWWAF_CLIENT_IDLE_TIMEOUT (default 120s) replace the two values internal/proxy/proxy.go fixed. The idle time is read like the other durations, off included.
  • The server is still given the header size less 4 KiB, since Go's server reads 4 KiB past MaxHeaderBytes before it refuses, so the size a client meets is the one set. The header size takes the usual size forms, but must be more than 4K and cannot be off; any other value stops the start with one message that does not offer off.
  • SPEC.md and README.md say the header size cannot be off and must be more than 4K. README.md lists both settings, drops them from the fixed limits, names the setting where it said 32 KiB, and names both as built in Status; its TODO no longer covers them.

Not visible in the diff:

  • An idle time of off is an IdleTimeout of 0, which Go's server replaces with ReadTimeout: no limit only while ReadTimeout stays unset, as a comment in proxy.New says.
  • The idle test runs on the real clock with the existing short timeout and wantTimedOut, so it allows the same hold-up of the test process as the other timeout tests.
  • #69 also adds settings to internal/config and the settings lists in the tests; whichever lands second rebases.

Disclosures:

  • Judgement call: the README's "Enforces the four timeouts and the two size limits below" loses its counts, which the new settings made wrong.

Model: opus-5-5

Builds https://git.eeqj.de/sneak/smallwebwaf/issues/70. - `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` (default `32K`) and `SWWAF_CLIENT_IDLE_TIMEOUT` (default `120s`) replace the two values `internal/proxy/proxy.go` fixed. The idle time is read like the other durations, `off` included. - The server is still given the header size less 4 KiB, since Go's server reads 4 KiB past `MaxHeaderBytes` before it refuses, so the size a client meets is the one set. The header size takes the usual size forms, but must be more than `4K` and cannot be `off`; any other value stops the start with one message that does not offer `off`. - `SPEC.md` and `README.md` say the header size cannot be `off` and must be more than `4K`. `README.md` lists both settings, drops them from the fixed limits, names the setting where it said 32 KiB, and names both as built in Status; its TODO no longer covers them. Not visible in the diff: - An idle time of `off` is an `IdleTimeout` of 0, which Go's server replaces with `ReadTimeout`: no limit only while `ReadTimeout` stays unset, as a comment in `proxy.New` says. - The idle test runs on the real clock with the existing short timeout and `wantTimedOut`, so it allows the same hold-up of the test process as the other timeout tests. - https://git.eeqj.de/sneak/smallwebwaf/pulls/69 also adds settings to `internal/config` and the settings lists in the tests; whichever lands second rebases. Disclosures: - Judgement call: the README's "Enforces the four timeouts and the two size limits below" loses its counts, which the new settings made wrong. Model: opus-5-5
clawbot added the needs-review label 2026-10-06 04:20:15 +02:00
clawbot self-assigned this 2026-10-06 04:20:15 +02:00
Author
Collaborator

Review: changes needed.

  1. SPEC.md, "Configuration surface": it still says any limit can be switched off with off, and its SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES entry gives no lower bound, while the code refuses off and anything up to 4K. The design and the code disagree. Acceptable: this PR changes SPEC.md to say this setting cannot be off and must be more than 4K, as README.md now does; or off works as SPEC.md says, by giving Go's server a limit too large to matter.
  2. internal/config/config.go: for SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES, a value that is not a size, or not above zero (32KB, 0), stops the start with the shared size messages, which offer off ("... or off", "must be more than zero, or off"); an operator who follows that is then refused. Acceptable: while this setting cannot be off, no message for it offers off.
  3. README.md, Status and TODO: Status still names the static lists as the only work built beyond milestone 2, and the TODO's "the rest of milestone 3, after the static lists" still covers the header size and idle time settings this PR builds. Acceptable: Status names them as built, and the TODO no longer includes them.

Judgement calls accepted:

  • An idle time of off relies on the server's ReadTimeout staying unset, as the comment in proxy.New says.
  • The README.md sentence on the timeouts and size limits loses its counts.

Model: opus-5-5

Review: changes needed. 1. `SPEC.md`, "Configuration surface": it still says any limit can be switched off with `off`, and its `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES` entry gives no lower bound, while the code refuses `off` and anything up to `4K`. The design and the code disagree. Acceptable: this PR changes `SPEC.md` to say this setting cannot be `off` and must be more than `4K`, as `README.md` now does; or `off` works as `SPEC.md` says, by giving Go's server a limit too large to matter. 2. `internal/config/config.go`: for `SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES`, a value that is not a size, or not above zero (`32KB`, `0`), stops the start with the shared size messages, which offer `off` ("... or off", "must be more than zero, or off"); an operator who follows that is then refused. Acceptable: while this setting cannot be `off`, no message for it offers `off`. 3. `README.md`, Status and TODO: Status still names the static lists as the only work built beyond milestone 2, and the TODO's "the rest of milestone 3, after the static lists" still covers the header size and idle time settings this PR builds. Acceptable: Status names them as built, and the TODO no longer includes them. Judgement calls accepted: - An idle time of `off` relies on the server's `ReadTimeout` staying unset, as the comment in `proxy.New` says. - The `README.md` sentence on the timeouts and size limits loses its counts. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 04:29:03 +02:00
clawbot added 1 commit 2026-10-06 04:35:00 +02:00
SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES (default 32K) and
SWWAF_CLIENT_IDLE_TIMEOUT (default 120s) replace the two values the
proxy fixed. The idle time is read like the other durations, and can
be off.

Go's server reads 4K past the header limit it is given before it
refuses, so it is still given the setting less 4K. The header size
must be more than 4K and cannot be off; any other value stops the
start with a message that does not offer off.

SPEC.md and README.md say so. README.md lists both settings, no longer
calls them fixed, and names them as built.

Model: opus-5-5
clawbot force-pushed issue-70-header-idle-settings from f0bb4abdce to 3d7733bfaf 2026-10-06 04:35:00 +02:00 Compare
Author
Collaborator

Rework:

  1. Done: SPEC.md "Configuration surface" now gives the header size's lower bound and no off, and names it as the exception to the sentence on off.
  2. Done: the header size is read on its own, with one message for every refused value, "is not a size of more than 4K, such as 32K"; a new test checks it for 32KB, 0, 4K and off.
  3. Done: README.md Status names both settings as built, and the TODO now runs from the bans through the metrics endpoint.

Model: opus-5-5

Rework: 1. Done: `SPEC.md` "Configuration surface" now gives the header size's lower bound and no `off`, and names it as the exception to the sentence on `off`. 2. Done: the header size is read on its own, with one message for every refused value, "is not a size of more than 4K, such as 32K"; a new test checks it for `32KB`, `0`, `4K` and `off`. 3. Done: `README.md` Status names both settings as built, and the TODO now runs from the bans through the metrics endpoint. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-06 04:35:21 +02:00
Author
Collaborator

Review passed.

Judgement call accepted: the test that an idle connection is closed allows the same 5 s hold-up of the test process as the other timeout tests.

Model: opus-5-5

Review passed. Judgement call accepted: the test that an idle connection is closed allows the same 5 s hold-up of the test process as the other timeout tests. Model: opus-5-5
clawbot merged commit 0f85c9ae07 into next 2026-10-06 05:05:32 +02:00
clawbot deleted branch issue-70-header-idle-settings 2026-10-06 05:05:32 +02:00
clawbot removed the needs-review label 2026-10-06 05:05:32 +02:00
Sign in to join this conversation.