summaryrefslogtreecommitdiff
path: root/statuspage/checks
diff options
context:
space:
mode:
authorbatsumaru <>2026-07-01 19:11:15 +0900
committerbatsumaru <>2026-07-01 19:11:15 +0900
commit126ba66a627a9625fae77c29abe99dce19477e7c (patch)
treeefb07d7db4a4a6626213d5f91aaf1980083b8170 /statuspage/checks
parent7904f1221e6bb35c8b1abf807a6030e70598ed33 (diff)
Document abbreviate_rule's nat/rdr blind spot and ddclient's log gapHEADmaster
From a fresh-agent review of AGENTS.md against two hypothetical tasks: - abbreviate_rule() in pf.sh has only ever been developed/tested against filter-rule (-sr) syntax, despite also running on -sn (nat/rdr) output. It degrades safely (unshortened passthrough) but a new nat/rdr rule shape isn't guaranteed to compress as tightly - noted both in the code comment and in AGENTS.md's compression writeup so this doesn't need rediscovering. - ddclient logging isn't enabled on the box, so "is the last DNS update actually succeeding" can't be built by tailing a log that doesn't exist - it'd need the cache file or a public-IP comparison instead. Recorded in AGENTS.md's topology section since ddclient.sh currently only checks the process is running, not update success. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat (limited to 'statuspage/checks')
-rwxr-xr-xstatuspage/checks/pf.sh7
1 files changed, 7 insertions, 0 deletions
diff --git a/statuspage/checks/pf.sh b/statuspage/checks/pf.sh
index 651b638..d1f22d1 100755
--- a/statuspage/checks/pf.sh
+++ b/statuspage/checks/pf.sh
@@ -21,6 +21,13 @@ DIR=$(dirname "$0")
# shipped. A rule shape this doesn't recognize just passes through
# unshortened - still correct, just longer.
#
+# Applied to both -sr (filter) and -sn (nat/rdr) output, but every regex
+# here was written and tested against filter-rule syntax only. NAT/rdr
+# shapes (e.g. `rdr on ... -> ...`) haven't been exercised against a real
+# ruleset - they'll degrade safely to unshortened text if a pattern
+# doesn't match, but don't assume a new nat/rdr rule will compress as
+# tightly as a filter rule without checking the rendered page.
+#
# State-tracking mode is tagged with a single bracketed letter rather
# than a symbol, since the four modes (no/keep/modulate/synproxy) have
# meaningfully different security properties and a bracket+letter reads