#3126
Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
3h ago
#3124
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
8h ago
#3123
Accept usernames for user subjects in grant files
9h ago
#3122
Docs: enable-managed-config should say to re-run config migrate when its push fails
9h ago
#3121
Docs: grant file reference shows a stale format and omits resources and subjects
9h ago
#3120
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
10h ago
#3119
extension quality and push crash with IsADirectory when additionalFiles lists a directory
10h ago
#3118
extension push: a required global argument renders with a stray "" ("text": "string""")
10h ago
#3116
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
10h ago
#3114
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
11h ago
#3112
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
11h ago
#3111
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
11h ago
#3110
Show signal waits to remote clients and the dashboard
11h ago
#3109
Settle expired signal waits from swamp serve
11h ago
#3108
Resume signalled workflow runs automatically under swamp serve
11h ago
#3107
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
11h ago
#3104
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
12h ago
#3103
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
12h ago
#3102
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
12h ago
#3100
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
13h ago
#3095
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
14h ago
#3088
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
15h ago
#3080
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
17h ago
#3074
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
17h ago
#3073
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
17h ago
#3069
extension push: version-drift check reports 'no previously published version found' when the registry call failed
18h ago
#3067
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
18h ago
#3065
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
19h ago
#3062
Workflow load errors print the raw Zod issue dump instead of a readable message
20h ago
#3060
Decide a stricter naming rule for workflow step and job names
11h ago
#3046
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
1d ago
#3045
Show expired approval gates as expired, with a Cancel action in the dashboard
1d ago
#3041
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
1d ago
#3040
extension promote accepts a yanked version and reports it promoted
1d ago
#3036
Docs: doctor install reports a stale or failing autoupdate scheduler
1d ago
#3017
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
1d ago
#3013
auto-resolve: the Installing line prints the extension's entire multi-line description
1d ago
#3010
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
2d ago
#3004
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
Team3d ago
#3000
Let agent-runner drive more agent CLIs (Kilo Code and others)
4d ago
#2998
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
4d ago
#2993
Feedback: Swamp as an approval-gated control plane for a small fleet
1d ago
#2965
extension safety analyzer's Deno.Command( warning is a plain substring match
4d ago
#2922
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
5d ago
#2908
Run from a git worktree: definitions from the worktree, state from the shared repo
5d ago
#2907
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
5d ago
#2906
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
5d ago
#2900
Tell the pushing client when its extension contentMetadata fails validation
5d ago
#2892
Extension datastore: query still returns an item after its delete is pulled
5d ago
#2867
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
6d ago
#2865
Tracking: test baseline required before the datastore refactor (commit-log design)
4d ago
#2863
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
6d ago
#2844
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
6d ago
#2754
serve: define and supply the collective and owner grant condition variables
6d ago
#2749
No first-class workflow primitive for spawning a permission-scoped agent session
7d ago
#2746
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
7d ago
#2727
Decorative animations outside the Lab still repaint on the main thread
7d ago
#2683
s3/gcs datastore: pullChanged overwrites dirty, unpushed cache files
7d ago
#2671
Concurrent first runs in a fresh repo log 'Catalog migration to per-extension-aggregate-v3 failed (database is locked)'
7d ago
#2643
Codegen/DigitalOcean: create-only required fields block list/get/delete in generated DigitalOcean models
8d ago
#2623
Codegen/AWS: create-only required fields block list/get/delete in generated AWS models
8d ago
#2618
End a collective's trial when it begins a paid subscription
8d ago
#2606
A collective that cancels inside its 30-day trial window regains trial access to private extensions
8d ago
#2592
s3-datastore: SWAMP_S3_REQUEST_TIMEOUT_MS does not appear to apply to ListObjectsV2 during pull
8d ago
#2591
s3-datastore: S3Lock.acquire overshoots maxWaitMs by up to a full backoff interval
8d ago
#2590
s3-datastore: a model-scoped pull still lists, walks and indexes the whole namespace
8d ago
#2586
Run the web dashboard locally from the CLI without swamp serve
s8d ago
#2583
verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
6d ago
#2582
issue-lifecycle skill: prepare-to-ship documents a fast_forward method that does not exist
8d ago
#2573
S3 datastore rejects valid cache paths as traversal on Windows
Team5d ago
#2564
swamp-club: unknown collective API token returns 422 instead of the documented 404
11d ago
#2563
Partial extension catalog saves delete rows for sources mounted from outside the repo
11d ago
#2560
extensions: cold-path catalog rebuild skips sources whose type is not a string literal, dropping them for one process lifetime
11d ago
#2540
serve: rotate the external token-secrets key
11d ago
#2535
serve: server token GC follow-ups (upgrade backlog holds the sync gate, not-found matching, owner lookup, UX)
11d ago
#2534
serve: without a remote datastore the token GC is not serialized against token rotate/re-mint
11d ago
#2528
Workflow evaluation rejects another templating system's ${{ }} text, so the #2491 pass-through never reaches workflow steps
11d ago
#2527
@swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
11d ago
#2513
worker prune: remote datastore keeps deleted worker records (no-path markDirty() skips deletions)
12d ago
#2501
Orphaned data record survives a model type migration and is unreachable by data delete/versions/prune
12d ago
#2499
Link each swamp-club panel to its manual page with a header DOCS link
12d ago
#2495
managedConfig: extension lockfile writes lose updates, and auto-resolved installs never reach the shared lockfile
h6d ago
#2487
Generated @swamp/aws StateSchemas mark conditional and create-only properties as required, producing schema warnings on every read
12d ago
#2486
Registry catalog silently drops models whose version is not a literal in the export const model block
12d ago
#2478
Namespace names are not reserved against cache/datastore layout directories (e.g. data)
12d ago
#2477
Clear error when hydrateFile reports success but the file is missing
12d ago
#2465
workflows: a nested workflow step should inherit the caller's placement when the child declares none
13d ago
#2463
Windows: concurrent data save can fail with Access is denied renaming the latest marker
13d ago
#2461
Supported vault-write API for extension model methods (per-instance vault target)
13d ago
#2450
verify-reviews gives no usable error when the local Claude Code predates the pinned review model
13d ago
#2435
serve: boot hydration ignores `hydrationStrategy: lazy` and downloads every payload
13d ago
#2421
datastore sync: repositories mark paths dirty before writing, so a concurrent ungated push can drop the write
13d ago
#2419
gcs-datastore: push spends almost all its time in an untraced gap between index read and first upload (81s in the #2408 login, up to 836s)
13d ago
#2418
serve: after lazy hydration, scoped poller pulls never take the fast path, and the login mint waits behind them on the sync gate
13d ago
#2416
datastore extensions: full pushes re-hash every pulled file on every run because index mtimes never match pulled copies
13d ago
#2410
Extension catalog caches a datastore bundle with an empty type, so the repo fails with Unknown datastore type when addressed by its realpath
13d ago
#2382
model delete resolves auto-definitions from repo-local .swamp instead of the datastore cache
14d ago
#2379
Let a method inside serve start a workflow run: context.runWorkflow
14d ago
#2349
s3/gcs datastore: no safe recovery when _meta.json v2 lists a shard missing from the bucket
14d ago
#2345
worker secret allowlist rejects caller-chosen vault references resolved at run time (method args carrying {vaultName, secretKey})
7d ago
#2344
serve: default placement for steps that declare none (so one workflow runs both locally and via workers)
14d ago
#2339
s3-datastore: per-datastore AWS profile, so a serve audit store can use different credentials from the main datastore
14d ago
#2333
gcs-datastore: a failed lock read is reported as "unlocked" — #2298 in the GCS backend
15d ago
#2329
s3/gcs-datastore: clean up data left behind by deletes that silently no-opped before the swamp-club#2249 fix
15d ago
#2326
Expose Swamp as a REST/OpenAPI endpoint (for GPT Actions and other REST clients)
15d ago
#2323
Promote CodeBuddy and WorkBuddy from custom-tool configs to first-class Swamp clients
15d ago
#2299
s3-datastore: documented offline behaviour is unreachable — lock acquire fails closed before pull, while a mid-run outage exits 0 with the data stranded
15d ago
#2280
issue-lifecycle: swamp-club lifecycle post failures are logged but the method still reports success
18d ago
#2269
Periodic worker GC sweep prunes outside the sync gate
19d ago
#2259
Route log-mode output to stderr by default, with commands opting stdout back in
19d ago
#2257
-q does not suppress the update, auth-nudge and autoupdate banners
19d ago
#2255
Lab status never returns to shipped on merge — transitions are manual and drift silently
19d ago
#2232
Billing telemetry: surface scheduled cancellations (cancelAtPeriodEnd) and emit subscription_canceled reliably
19d ago
#2225
Swamp Club fresh-database startup aborts migrations on missing deviceCode and concurrent replica markers
20d ago
#2210
A pending platform invite that loses to the recruit lane is never consumed and leaks a pending slot
20d ago
#2209
Recruit links have no web surface — a CLI-less operative cannot get their link
20d ago
#2196
Workload identity (Kubernetes ServiceAccount / OIDC) for worker enrollment
20d ago
#2147
Feed grant projection stamps a site route that does not exist
21d ago
#2141
UAT coverage for workflow history outputs and expanded JSON schema
22d ago
#2102
Serve Audit Log - Phase 6: Full documentation
4d ago
#2096
Per-extension white listing
Team27d ago
#2077
Block temporary email services on signup
27d ago
#2027
Retire or rebuild /admin/nurture once the epic lands — it is a gate, and gates are single-use
1mo ago
← Back to list9/22/2026, 5:46:18 PM
01Issue
BugOpenExtensionsPublic
AssigneesNone
Relationships
#2349 s3/gcs datastore: no safe recovery when _meta.json v2 lists a shard missing from the bucket
Opened by hammz · 9/22/2026
Summary
Follow-up to #2327 (@swamp/s3-datastore, @swamp/gcs-datastore). #290 (swamp-club #2245) fixed the cause: pushes no longer delete shards, and index writes use compare-and-swap. But a bucket that is already in the state #2327 describes (_meta.json v2 lists a shard that has no object) still has no safe built-in repair.
Gaps
- Misleading hint.
assembleIndexFromShardsandassembleDirtyShardsOnlyindatastore/s3/extensions/datastores/_lib/s3_cache_sync.ts(~L1431, ~L1528) throwShard ... listed in _meta.json v2 but missing from S3 — index is corrupt. Run 'swamp datastore migrate-index' to rebuild.That command is unsafe here.migrateMonolithToShardsregroups the monolithic.datastore-index.jsonand rewrites every shard, so any entry newer than the monolith is lost. - Recovery is gated off.
recoverMetaFromListing, which rebuilds_meta.jsonfrom the shards that actually exist, runs only when the monolith has no entries (~L1334). A stale monolith makes it unreachable. The #2327 reporter had to rewrite_meta.jsonby hand. - Hard failure on a missing shard. Every pull,
preparePush, and push fails, which crash-loopsswamp serveon startup. It's worth deciding whether a missing listed shard should be treated as empty (with a warning and a meta repair on the next commit) rather than as fatal.
The GCS datastore has the same messages and gating, so check it too.
Suggested direction
- Give
migrate-index(or a new repair command) a mode that rebuilds_meta.jsonfrom the_index/listing, keepscommitSeq, writes with CAS, and never touches shard contents. Point the error message at that mode. - Don't suggest the monolith rebuild once a v2 meta with
commitSeq> 1 exists.
02Bog Flow
Open
No activity in this phase yet.
03Sludge Pulse
Sign in to post a ripple.