check / check (push) Successful in 1m29s
Milestone 1, the repo's first code. smallwebwaf passes each request to the app and the answer back unchanged, streaming bodies and WebSocket upgrades, within four timeouts (client and app, request and response) and two size limits, and writes one JSON line per request to stdout. Every setting has an SWWAF_ name and a default, and an invalid value stops the start. The repo gets the standard layout: script/ entrypoints, make targets that call them, a Dockerfile that runs the checks, and the Gitea workflow. Disclosure: SPEC.md changed. Go's server reads the request line and headers before smallwebwaf sees the request, so slow headers are closed without an answer, and neither slow nor oversized headers get a log line. Disclosure: standard library only. Model: opus-5-5
24 lines
755 B
Bash
Executable File
24 lines
755 B
Bash
Executable File
#!/bin/sh
|
|
# script/lint: run the linter. Linting is a phase of the Dockerfile and
|
|
# this builds that phase alone; the linter is never installed or run on
|
|
# a developer host, where a shared result cache and a host-global lock
|
|
# make its answer untrustworthy.
|
|
#
|
|
# The phase is not the last stage in the file, so it is built only when
|
|
# --target names it. --no-cache because a cached lint layer is a lint
|
|
# that did not run. The tag makes each build replace the previous image
|
|
# instead of leaving a dangling one behind.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
docker build --no-cache \
|
|
--target lint \
|
|
-t "$("$SCRIPT_DIR/projectname")-lint" .
|
|
}
|
|
|
|
main "$@"
|