check / check (push) Successful in 4m22s
smallwebwaf now copies its state to bans.json, clients.json and lookups.json in SWWAF_STATE_DIR, as "Persistent state" in SPEC.md describes, and reads them back at start, so a restart lifts no ban and gives no client a fresh allowance. Each client gains a history, and a ban's notes count the netblock's requests. bans.json is written SWWAF_STATE_WRITE_DELAY after a ban, and every file every SWWAF_STATE_COUNTER_INTERVAL and at the stop. A ban read back is masked to its netblock and refuses every client in it, whatever SWWAF_BAN_SCOPE_V4_PREFIX is now. A file that does not parse, an unknown version or an unwritable directory stops the start. Deviation: no AS number or name, and no ban cause, reason or lifting yet. Model: opus-5-5
17 lines
610 B
AMPL
Executable File
17 lines
610 B
AMPL
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
# runit's run script for smallwebwaf, run again whenever smallwebwaf
|
|
# exits; the wait spaces out the restarts. The state directory and every
|
|
# file in it are given to the smallwebwaf user, so that a volume mounted
|
|
# there needs no change of owner; chown -R changes a symbolic link itself,
|
|
# never what it points to. exec, so that the signal `sv stop` sends
|
|
# reaches smallwebwaf itself.
|
|
main() {
|
|
sleep 1
|
|
chown -R smallwebwaf:smallwebwaf "${SWWAF_STATE_DIR:-/var/lib/smallwebwaf}"
|
|
exec chpst -u smallwebwaf:smallwebwaf /usr/local/bin/smallwebwaf
|
|
}
|
|
|
|
main "$@"
|