A bans.json entry without a cause gets admin, at the start or from an edit, and is written back so.
Bans whose cause is admin are never dropped and do not count toward SWWAF_MAX_BANS. The ledger drops the earliest ban smallwebwaf made of the netblock seen longest ago, passing over netblocks holding only an admin's bans and looking at each netblock once at most, so the netblocks' LRU no longer has a size limit of its own.
reason: set on the bans the ledger makes, such as requests per minute over the limit of 1000 or matched the rule env-file; an admin's is kept.
lifted: the ban refuses nothing, is kept, and makes no later ban longer or permanent. The active and permanent ban gauges leave it out.
smallwebwaf_bans_made_total{cause="admin"} counts admin bans an edit adds while running, new by netblock and start. Bans read at the start are not counted, hence LoadEdit beside Load.
earlier_bans counts admin in place of without_cause.
README.md shows adding, keeping and lifting a ban in bans.json.
Disclosures:
Judgement call: lifted lifts at once, whatever time it gives.
Judgement call: a lifted ban still counts in earlier_bans.
Known gap: a ban dropped from behind an admin's ban on its netblock drops out of that netblock's later earlier_bans; keeping it needs a per-netblock count of dropped bans.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/smallwebwaf/issues/86.
- A `bans.json` entry without a `cause` gets `admin`, at the start or from an edit, and is written back so.
- Bans whose cause is `admin` are never dropped and do not count toward `SWWAF_MAX_BANS`. The ledger drops the earliest ban `smallwebwaf` made of the netblock seen longest ago, passing over netblocks holding only an admin's bans and looking at each netblock once at most, so the netblocks' LRU no longer has a size limit of its own.
- `reason`: set on the bans the ledger makes, such as `requests per minute over the limit of 1000` or `matched the rule env-file`; an admin's is kept.
- `lifted`: the ban refuses nothing, is kept, and makes no later ban longer or permanent. The active and permanent ban gauges leave it out.
- `smallwebwaf_bans_made_total{cause="admin"}` counts admin bans an edit adds while running, new by netblock and start. Bans read at the start are not counted, hence `LoadEdit` beside `Load`.
- `earlier_bans` counts `admin` in place of `without_cause`.
- `README.md` shows adding, keeping and lifting a ban in `bans.json`.
Disclosures:
- Judgement call: `lifted` lifts at once, whatever time it gives.
- Judgement call: a lifted ban still counts in `earlier_bans`.
- Known gap: a ban dropped from behind an admin's ban on its netblock drops out of that netblock's later `earlier_bans`; keeping it needs a per-netblock count of dropped bans.
Model: opus-5-5
internal/bans/admin_test.go, TestAdminsBansAreNeverDroppedAndDoNotCountTowardMaxBans: with bans whose cause is admin counted toward SWWAF_MAX_BANS, the test does not fail; dropOne loops for good, and the run ends only when the 90-second test timeout stops the whole package, losing the rest of its results. Acceptable: the test fails promptly with that rule broken, without relying on a timeout.
Judgement calls accepted:
lifted takes effect at once, whatever time it gives.
A lifted ban still counts in earlier_bans.
A ban dropped from behind an admin's ban on its netblock drops out of that netblock's later earlier_bans.
smallwebwaf_bans_made_total{cause="admin"} counts only the admin's bans an edit adds, through LoadEdit beside Load.
Model: opus-5-5
Review failed.
- `internal/bans/admin_test.go`, `TestAdminsBansAreNeverDroppedAndDoNotCountTowardMaxBans`: with bans whose cause is `admin` counted toward `SWWAF_MAX_BANS`, the test does not fail; `dropOne` loops for good, and the run ends only when the 90-second test timeout stops the whole package, losing the rest of its results. Acceptable: the test fails promptly with that rule broken, without relying on a timeout.
Judgement calls accepted:
- `lifted` takes effect at once, whatever time it gives.
- A lifted ban still counts in `earlier_bans`.
- A ban dropped from behind an admin's ban on its netblock drops out of that netblock's later `earlier_bans`.
- `smallwebwaf_bans_made_total{cause="admin"}` counts only the admin's bans an edit adds, through `LoadEdit` beside `Load`.
Model: opus-5-5
A bans.json entry without a cause gets the cause admin, written back so.
Bans whose cause is admin are never dropped and do not count toward
SWWAF_MAX_BANS, so setting a ban's cause to admin keeps it. Bans
smallwebwaf makes get a reason: the limit broken or the rule matched. A
lifted ban refuses nothing, is kept, and makes no later ban longer.
smallwebwaf_bans_made_total counts admin bans an edit adds while running;
earlier_bans counts admin in place of without_cause.
Judgement call: lifted lifts at once, whatever time it gives.
Judgement call: a lifted ban still counts in earlier_bans.
Known gap: a ban dropped from behind an admin's ban on its netblock leaves that netblock's later earlier_bans.
Model: opus-5-5
dropOne now looks at each netblock once at most, so with bans whose cause is admin counted toward SWWAF_MAX_BANS the test fails at once instead of hanging. Model: opus-5-5
`dropOne` now looks at each netblock once at most, so with bans whose cause is `admin` counted toward `SWWAF_MAX_BANS` the test fails at once instead of hanging. Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #86.
bans.jsonentry without acausegetsadmin, at the start or from an edit, and is written back so.adminare never dropped and do not count towardSWWAF_MAX_BANS. The ledger drops the earliest bansmallwebwafmade of the netblock seen longest ago, passing over netblocks holding only an admin's bans and looking at each netblock once at most, so the netblocks' LRU no longer has a size limit of its own.reason: set on the bans the ledger makes, such asrequests per minute over the limit of 1000ormatched the rule env-file; an admin's is kept.lifted: the ban refuses nothing, is kept, and makes no later ban longer or permanent. The active and permanent ban gauges leave it out.smallwebwaf_bans_made_total{cause="admin"}counts admin bans an edit adds while running, new by netblock and start. Bans read at the start are not counted, henceLoadEditbesideLoad.earlier_banscountsadminin place ofwithout_cause.README.mdshows adding, keeping and lifting a ban inbans.json.Disclosures:
liftedlifts at once, whatever time it gives.earlier_bans.earlier_bans; keeping it needs a per-netblock count of dropped bans.Model: opus-5-5
Review failed.
internal/bans/admin_test.go,TestAdminsBansAreNeverDroppedAndDoNotCountTowardMaxBans: with bans whose cause isadmincounted towardSWWAF_MAX_BANS, the test does not fail;dropOneloops for good, and the run ends only when the 90-second test timeout stops the whole package, losing the rest of its results. Acceptable: the test fails promptly with that rule broken, without relying on a timeout.Judgement calls accepted:
liftedtakes effect at once, whatever time it gives.earlier_bans.earlier_bans.smallwebwaf_bans_made_total{cause="admin"}counts only the admin's bans an edit adds, throughLoadEditbesideLoad.Model: opus-5-5
4290e76472tod5a6c74e4edropOnenow looks at each netblock once at most, so with bans whose cause isadmincounted towardSWWAF_MAX_BANSthe test fails at once instead of hanging. Model: opus-5-5Review passed.
Model: opus-5-5