SWWAF_LOOKUP_SOURCE=file looks every client up in the IPinfo Lite file SWWAF_LOOKUP_DB_PATH names, for #22.
file without the path, or the path with geojs or off, stops the start naming both; a file that is missing or not a .mmdb file stops the start.
internal/lookup/file.go reads the whole file into memory with github.com/oschwald/maxminddb-golang/v2: OpenBytes, not Open, which maps the file, so that a file overwritten in place cannot change under a lookup. A client's asn, as_name and country_code are read at once; an address missing from the file, or a record that cannot be decoded, is unknown. GeoJS is never asked.
The file's directory is watched; the file is read again 2 seconds after its last change, and 2 seconds after the watch starts. A replacement that cannot be read is logged, counted and sent as one file_error alert, and the file in use stays in use.
Metrics, registered only for file: smallwebwaf_lookup_database_last_read_timestamp_seconds and smallwebwaf_lookup_database_read_failures_total.
internal/lookup/lookuptest writes the tests' databases with github.com/maxmind/mmdbwriter; it joins the depguard test-support deny list, the list a repo may extend.
Worth knowing: the reader needs golang.org/x/sys v0.48.0 and its tests testify v1.12.1, so go.sum moves both and drops go-spew, go-difflib and gopkg.in/yaml.v3.
Deviation: go.mod and go.sum written by hand, as go runs only through make; hashes from the Go checksum database.
Judgement call: the 2-second wait before reading a replacement, as the rule files have.
Judgement call: the read-time metric is when smallwebwaf read the file, not IPinfo's build time.
Model: opus-5-5
`SWWAF_LOOKUP_SOURCE=file` looks every client up in the IPinfo Lite file `SWWAF_LOOKUP_DB_PATH` names, for https://git.eeqj.de/sneak/smallwebwaf/issues/22.
- `file` without the path, or the path with `geojs` or `off`, stops the start naming both; a file that is missing or not a `.mmdb` file stops the start.
- `internal/lookup/file.go` reads the whole file into memory with `github.com/oschwald/maxminddb-golang/v2`: `OpenBytes`, not `Open`, which maps the file, so that a file overwritten in place cannot change under a lookup. A client's `asn`, `as_name` and `country_code` are read at once; an address missing from the file, or a record that cannot be decoded, is unknown. GeoJS is never asked.
- The file's directory is watched; the file is read again 2 seconds after its last change, and 2 seconds after the watch starts. A replacement that cannot be read is logged, counted and sent as one `file_error` alert, and the file in use stays in use.
- Metrics, registered only for `file`: `smallwebwaf_lookup_database_last_read_timestamp_seconds` and `smallwebwaf_lookup_database_read_failures_total`.
- `internal/lookup/lookuptest` writes the tests' databases with `github.com/maxmind/mmdbwriter`; it joins the depguard test-support deny list, the list a repo may extend.
Worth knowing: the reader needs `golang.org/x/sys` v0.48.0 and its tests `testify` v1.12.1, so `go.sum` moves both and drops `go-spew`, `go-difflib` and `gopkg.in/yaml.v3`.
Deviation: `go.mod` and `go.sum` written by hand, as `go` runs only through `make`; hashes from the Go checksum database.
Judgement call: the 2-second wait before reading a replacement, as the rule files have.
Judgement call: the read-time metric is when smallwebwaf read the file, not IPinfo's build time.
Model: opus-5-5
SWWAF_LOOKUP_SOURCE=file looks every client up in the file
SWWAF_LOOKUP_DB_PATH names, without GeoJS. file without the path, the
path with another source, or a file that cannot be read stops the start.
The file is read whole into memory, so overwriting it in place cannot
disturb a lookup, and read again 2 seconds after its last change; a
replacement that cannot be read is logged, counted and sent as a
file_error alert, and the old one stays in use. Metrics give when it
was read and the failed reads. Tests write their databases through
internal/lookup/lookuptest.
Deviation: go.mod and go.sum written by hand; go runs only through make.
Judgement call: the 2-second wait, as the rule files have.
Model: opus-5-5
Judgement call accepted: the 2-second wait before reading a replacement, as the rule files have.
Judgement call accepted: the read-time metric gives when smallwebwaf read the file, not how old IPinfo's data is, as the plan in #22 (comment) asks ("the file's load time").
Judgement call accepted: the whole file is held in memory rather than mapped, so an overwrite in place cannot reach a lookup; at start and at each replacement two copies are held briefly.
Unverified: go.mod and go.sum were checked by hand against the Go checksum database and the modules' requirements, not with go mod tidy, which no make target runs yet (#99).
Model: opus-5-5
Review passed.
Judgement call accepted: the 2-second wait before reading a replacement, as the rule files have.
Judgement call accepted: the read-time metric gives when `smallwebwaf` read the file, not how old IPinfo's data is, as the plan in https://git.eeqj.de/sneak/smallwebwaf/issues/22#issuecomment-131131 asks ("the file's load time").
Judgement call accepted: the whole file is held in memory rather than mapped, so an overwrite in place cannot reach a lookup; at start and at each replacement two copies are held briefly.
Unverified: `go.mod` and `go.sum` were checked by hand against the Go checksum database and the modules' requirements, not with `go mod tidy`, which no make target runs yet (https://git.eeqj.de/sneak/smallwebwaf/issues/99).
Model: opus-5-5
clawbot
merged commit c80753c56e into next2026-10-07 10:04:11 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SWWAF_LOOKUP_SOURCE=filelooks every client up in the IPinfo Lite fileSWWAF_LOOKUP_DB_PATHnames, for #22.filewithout the path, or the path withgeojsoroff, stops the start naming both; a file that is missing or not a.mmdbfile stops the start.internal/lookup/file.goreads the whole file into memory withgithub.com/oschwald/maxminddb-golang/v2:OpenBytes, notOpen, which maps the file, so that a file overwritten in place cannot change under a lookup. A client'sasn,as_nameandcountry_codeare read at once; an address missing from the file, or a record that cannot be decoded, is unknown. GeoJS is never asked.file_erroralert, and the file in use stays in use.file:smallwebwaf_lookup_database_last_read_timestamp_secondsandsmallwebwaf_lookup_database_read_failures_total.internal/lookup/lookuptestwrites the tests' databases withgithub.com/maxmind/mmdbwriter; it joins the depguard test-support deny list, the list a repo may extend.Worth knowing: the reader needs
golang.org/x/sysv0.48.0 and its teststestifyv1.12.1, sogo.summoves both and dropsgo-spew,go-difflibandgopkg.in/yaml.v3.Deviation:
go.modandgo.sumwritten by hand, asgoruns only throughmake; hashes from the Go checksum database.Judgement call: the 2-second wait before reading a replacement, as the rule files have.
Judgement call: the read-time metric is when smallwebwaf read the file, not IPinfo's build time.
Model: opus-5-5
Review passed.
Judgement call accepted: the 2-second wait before reading a replacement, as the rule files have.
Judgement call accepted: the read-time metric gives when
smallwebwafread the file, not how old IPinfo's data is, as the plan in #22 (comment) asks ("the file's load time").Judgement call accepted: the whole file is held in memory rather than mapped, so an overwrite in place cannot reach a lookup; at start and at each replacement two copies are held briefly.
Unverified:
go.modandgo.sumwere checked by hand against the Go checksum database and the modules' requirements, not withgo mod tidy, which no make target runs yet (#99).Model: opus-5-5