check / check (push) Successful in 3m53s
smallwebwaf now copies its state to bans.json, clients.json and lookups.json in SWWAF_STATE_DIR, as "Persistent state" in SPEC.md describes, and reads them back at start, so a restart lifts no ban and gives no client a fresh allowance. Each client gains a history, and a ban's notes count the netblock's requests. bans.json is written SWWAF_STATE_WRITE_DELAY after a ban, every file every SWWAF_STATE_COUNTER_INTERVAL and at the stop, each through a synced temporary file renamed over it. A file that does not parse, an unknown version or an unwritable directory stops the start. The image gets /var/lib/smallwebwaf, which the run script gives to the smallwebwaf user. Deviation: no AS number or name, and no ban cause, reason or lifting yet. Model: opus-5-5