#3126
Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
7h ago
#3124
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
12h ago
#3123
Accept usernames for user subjects in grant files
13h ago
#3122
Docs: enable-managed-config should say to re-run config migrate when its push fails
13h ago
#3121
Docs: grant file reference shows a stale format and omits resources and subjects
13h ago
#3120
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
14h ago
#3119
extension quality and push crash with IsADirectory when additionalFiles lists a directory
14h ago
#3118
extension push: a required global argument renders with a stray "" ("text": "string""")
14h ago
#3116
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
14h ago
#3114
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
15h ago
#3112
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
15h ago
#3111
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
15h ago
#3110
Show signal waits to remote clients and the dashboard
15h ago
#3109
Settle expired signal waits from swamp serve
15h ago
#3108
Resume signalled workflow runs automatically under swamp serve
15h ago
#3107
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
15h ago
#3104
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
16h ago
#3103
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
16h ago
#3102
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
16h ago
#3100
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
17h ago
#3095
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
18h ago
#3088
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
19h ago
#3080
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
21h ago
#3074
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
21h ago
#3073
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
21h ago
#3069
extension push: version-drift check reports 'no previously published version found' when the registry call failed
22h ago
#3067
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
22h ago
#3065
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
23h ago
#3062
Workflow load errors print the raw Zod issue dump instead of a readable message
1d ago
#3060
Decide a stricter naming rule for workflow step and job names
15h ago
#3046
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
1d ago
#3045
Show expired approval gates as expired, with a Cancel action in the dashboard
1d ago
#3041
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
1d ago
#3040
extension promote accepts a yanked version and reports it promoted
1d ago
#3036
Docs: doctor install reports a stale or failing autoupdate scheduler
1d ago
#3017
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
1d ago
#3013
auto-resolve: the Installing line prints the extension's entire multi-line description
1d ago
#3010
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
2d ago
#3004
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
Team3d ago
#3000
Let agent-runner drive more agent CLIs (Kilo Code and others)
4d ago
#2998
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
4d ago
#2993
Feedback: Swamp as an approval-gated control plane for a small fleet
1d ago
#2965
extension safety analyzer's Deno.Command( warning is a plain substring match
4d ago
#2922
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
5d ago
#2908
Run from a git worktree: definitions from the worktree, state from the shared repo
5d ago
#2907
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
5d ago
#2906
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
5d ago
#2900
Tell the pushing client when its extension contentMetadata fails validation
5d ago
#2892
Extension datastore: query still returns an item after its delete is pulled
5d ago
#2867
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
6d ago
#2865
Tracking: test baseline required before the datastore refactor (commit-log design)
4d ago
#2863
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
6d ago
#2844
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
6d ago
#2754
serve: define and supply the collective and owner grant condition variables
7d ago
#2749
No first-class workflow primitive for spawning a permission-scoped agent session
7d ago
#2746
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
7d ago
#2727
Decorative animations outside the Lab still repaint on the main thread
7d ago
#2683
s3/gcs datastore: pullChanged overwrites dirty, unpushed cache files
7d ago
#2671
Concurrent first runs in a fresh repo log 'Catalog migration to per-extension-aggregate-v3 failed (database is locked)'
8d ago
#2643
Codegen/DigitalOcean: create-only required fields block list/get/delete in generated DigitalOcean models
8d ago
#2623
Codegen/AWS: create-only required fields block list/get/delete in generated AWS models
8d ago
#2618
End a collective's trial when it begins a paid subscription
8d ago
#2606
A collective that cancels inside its 30-day trial window regains trial access to private extensions
8d ago
#2592
s3-datastore: SWAMP_S3_REQUEST_TIMEOUT_MS does not appear to apply to ListObjectsV2 during pull
8d ago
#2591
s3-datastore: S3Lock.acquire overshoots maxWaitMs by up to a full backoff interval
8d ago
#2590
s3-datastore: a model-scoped pull still lists, walks and indexes the whole namespace
8d ago
#2586
Run the web dashboard locally from the CLI without swamp serve
s8d ago
#2583
verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
6d ago
#2582
issue-lifecycle skill: prepare-to-ship documents a fast_forward method that does not exist
8d ago
#2573
S3 datastore rejects valid cache paths as traversal on Windows
Team5d ago
#2564
swamp-club: unknown collective API token returns 422 instead of the documented 404
11d ago
#2563
Partial extension catalog saves delete rows for sources mounted from outside the repo
11d ago
#2560
extensions: cold-path catalog rebuild skips sources whose type is not a string literal, dropping them for one process lifetime
11d ago
#2540
serve: rotate the external token-secrets key
11d ago
#2535
serve: server token GC follow-ups (upgrade backlog holds the sync gate, not-found matching, owner lookup, UX)
11d ago
#2534
serve: without a remote datastore the token GC is not serialized against token rotate/re-mint
11d ago
#2528
Workflow evaluation rejects another templating system's ${{ }} text, so the #2491 pass-through never reaches workflow steps
11d ago
#2527
@swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
12d ago
#2513
worker prune: remote datastore keeps deleted worker records (no-path markDirty() skips deletions)
12d ago
#2501
Orphaned data record survives a model type migration and is unreachable by data delete/versions/prune
12d ago
#2499
Link each swamp-club panel to its manual page with a header DOCS link
12d ago
#2495
managedConfig: extension lockfile writes lose updates, and auto-resolved installs never reach the shared lockfile
h6d ago
#2487
Generated @swamp/aws StateSchemas mark conditional and create-only properties as required, producing schema warnings on every read
12d ago
#2486
Registry catalog silently drops models whose version is not a literal in the export const model block
12d ago
#2478
Namespace names are not reserved against cache/datastore layout directories (e.g. data)
12d ago
#2477
Clear error when hydrateFile reports success but the file is missing
12d ago
#2465
workflows: a nested workflow step should inherit the caller's placement when the child declares none
13d ago
#2463
Windows: concurrent data save can fail with Access is denied renaming the latest marker
13d ago
#2461
Supported vault-write API for extension model methods (per-instance vault target)
13d ago
#2450
verify-reviews gives no usable error when the local Claude Code predates the pinned review model
13d ago
#2435
serve: boot hydration ignores `hydrationStrategy: lazy` and downloads every payload
13d ago
#2421
datastore sync: repositories mark paths dirty before writing, so a concurrent ungated push can drop the write
13d ago
#2419
gcs-datastore: push spends almost all its time in an untraced gap between index read and first upload (81s in the #2408 login, up to 836s)
13d ago
#2418
serve: after lazy hydration, scoped poller pulls never take the fast path, and the login mint waits behind them on the sync gate
13d ago
#2416
datastore extensions: full pushes re-hash every pulled file on every run because index mtimes never match pulled copies
13d ago
#2410
Extension catalog caches a datastore bundle with an empty type, so the repo fails with Unknown datastore type when addressed by its realpath
13d ago
#2382
model delete resolves auto-definitions from repo-local .swamp instead of the datastore cache
14d ago
#2379
Let a method inside serve start a workflow run: context.runWorkflow
14d ago
#2349
s3/gcs datastore: no safe recovery when _meta.json v2 lists a shard missing from the bucket
14d ago
#2345
worker secret allowlist rejects caller-chosen vault references resolved at run time (method args carrying {vaultName, secretKey})
7d ago
#2344
serve: default placement for steps that declare none (so one workflow runs both locally and via workers)
14d ago
#2339
s3-datastore: per-datastore AWS profile, so a serve audit store can use different credentials from the main datastore
14d ago
#2333
gcs-datastore: a failed lock read is reported as "unlocked" — #2298 in the GCS backend
15d ago
#2329
s3/gcs-datastore: clean up data left behind by deletes that silently no-opped before the swamp-club#2249 fix
15d ago
#2326
Expose Swamp as a REST/OpenAPI endpoint (for GPT Actions and other REST clients)
15d ago
#2323
Promote CodeBuddy and WorkBuddy from custom-tool configs to first-class Swamp clients
15d ago
#2299
s3-datastore: documented offline behaviour is unreachable — lock acquire fails closed before pull, while a mid-run outage exits 0 with the data stranded
15d ago
#2280
issue-lifecycle: swamp-club lifecycle post failures are logged but the method still reports success
18d ago
#2269
Periodic worker GC sweep prunes outside the sync gate
19d ago
#2259
Route log-mode output to stderr by default, with commands opting stdout back in
19d ago
#2257
-q does not suppress the update, auth-nudge and autoupdate banners
19d ago
#2255
Lab status never returns to shipped on merge — transitions are manual and drift silently
19d ago
#2232
Billing telemetry: surface scheduled cancellations (cancelAtPeriodEnd) and emit subscription_canceled reliably
19d ago
#2225
Swamp Club fresh-database startup aborts migrations on missing deviceCode and concurrent replica markers
20d ago
#2210
A pending platform invite that loses to the recruit lane is never consumed and leaks a pending slot
20d ago
← Back to list9/23/2026, 8:20:03 PM
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz
Relationships
#2425 serve: vault annotate --label over --server is rejected (CLI sends labels as an object, protocol expects string[])
Opened by hammz · 9/23/2026· Shipped 9/23/2026
Description
swamp vault annotate <vault> <key> --label k=v --server <url> fails with:
invalid_request: payload.labels: expected array, received objectsrc/cli/commands/vault_annotate.ts builds labels with parseLabels, which returns a Record of label to value, and sends it as payload.labels. The serve protocol's VaultAnnotatePayload.labels is string[]. handleVaultAnnotate (src/serve/handlers/vault_handlers.ts) converts that array back into a Record with empty values, so even a matching shape would drop the label values.
Steps to reproduce
- Start
swamp serveon a repo with a local_encryption vault that holds a secret. - Run
swamp vault annotate <vault> <key> --label team=infra --server http://127.0.0.1:<port>. - The server rejects the request with the error above.
--notesand--urlwork.
Expected
Labels (with their values) are applied over --server, the same as locally.
Found while reproducing swamp-club#2415 (log in /tmp/swamp-repro-issue-2415/logs/s2-vault-annotate-label-invalid-request).
02Bog Flow
Shipped
Click a lifecycle step above to view its details.
03Sludge Pulse