Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
Docs: grant file reference shows a stale format and omits resources and subjects
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
extension push: version-drift check reports 'no previously published version found' when the registry call failed
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
Workflow load errors print the raw Zod issue dump instead of a readable message
Decide a stricter naming rule for workflow step and job names
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
Show expired approval gates as expired, with a Cancel action in the dashboard
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
extension promote accepts a yanked version and reports it promoted
Docs: doctor install reports a stale or failing autoupdate scheduler
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
auto-resolve: the Installing line prints the extension's entire multi-line description
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
Let agent-runner drive more agent CLIs (Kilo Code and others)
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
Feedback: Swamp as an approval-gated control plane for a small fleet
extension safety analyzer's Deno.Command( warning is a plain substring match
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
Run from a git worktree: definitions from the worktree, state from the shared repo
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
Tell the pushing client when its extension contentMetadata fails validation
Extension datastore: query still returns an item after its delete is pulled
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
Tracking: test baseline required before the datastore refactor (commit-log design)
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
serve: define and supply the collective and owner grant condition variables
No first-class workflow primitive for spawning a permission-scoped agent session
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
Decorative animations outside the Lab still repaint on the main thread
s3/gcs datastore: pullChanged overwrites dirty, unpushed cache files
Concurrent first runs in a fresh repo log 'Catalog migration to per-extension-aggregate-v3 failed (database is locked)'
Codegen/DigitalOcean: create-only required fields block list/get/delete in generated DigitalOcean models
Codegen/AWS: create-only required fields block list/get/delete in generated AWS models
End a collective's trial when it begins a paid subscription
A collective that cancels inside its 30-day trial window regains trial access to private extensions
s3-datastore: SWAMP_S3_REQUEST_TIMEOUT_MS does not appear to apply to ListObjectsV2 during pull
s3-datastore: S3Lock.acquire overshoots maxWaitMs by up to a full backoff interval
s3-datastore: a model-scoped pull still lists, walks and indexes the whole namespace
Run the web dashboard locally from the CLI without swamp serve
verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
issue-lifecycle skill: prepare-to-ship documents a fast_forward method that does not exist
S3 datastore rejects valid cache paths as traversal on Windows
swamp-club: unknown collective API token returns 422 instead of the documented 404
Partial extension catalog saves delete rows for sources mounted from outside the repo
extensions: cold-path catalog rebuild skips sources whose type is not a string literal, dropping them for one process lifetime
serve: rotate the external token-secrets key
serve: server token GC follow-ups (upgrade backlog holds the sync gate, not-found matching, owner lookup, UX)
serve: without a remote datastore the token GC is not serialized against token rotate/re-mint
Workflow evaluation rejects another templating system's ${{ }} text, so the #2491 pass-through never reaches workflow steps
@swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
worker prune: remote datastore keeps deleted worker records (no-path markDirty() skips deletions)
Orphaned data record survives a model type migration and is unreachable by data delete/versions/prune
Link each swamp-club panel to its manual page with a header DOCS link
managedConfig: extension lockfile writes lose updates, and auto-resolved installs never reach the shared lockfile
Generated @swamp/aws StateSchemas mark conditional and create-only properties as required, producing schema warnings on every read
Registry catalog silently drops models whose version is not a literal in the export const model block
Namespace names are not reserved against cache/datastore layout directories (e.g. data)
Clear error when hydrateFile reports success but the file is missing
workflows: a nested workflow step should inherit the caller's placement when the child declares none
Windows: concurrent data save can fail with Access is denied renaming the latest marker
Supported vault-write API for extension model methods (per-instance vault target)
verify-reviews gives no usable error when the local Claude Code predates the pinned review model
serve: boot hydration ignores `hydrationStrategy: lazy` and downloads every payload
datastore sync: repositories mark paths dirty before writing, so a concurrent ungated push can drop the write
gcs-datastore: push spends almost all its time in an untraced gap between index read and first upload (81s in the #2408 login, up to 836s)
serve: after lazy hydration, scoped poller pulls never take the fast path, and the login mint waits behind them on the sync gate
datastore extensions: full pushes re-hash every pulled file on every run because index mtimes never match pulled copies
Extension catalog caches a datastore bundle with an empty type, so the repo fails with Unknown datastore type when addressed by its realpath
model delete resolves auto-definitions from repo-local .swamp instead of the datastore cache
Let a method inside serve start a workflow run: context.runWorkflow
s3/gcs datastore: no safe recovery when _meta.json v2 lists a shard missing from the bucket
worker secret allowlist rejects caller-chosen vault references resolved at run time (method args carrying {vaultName, secretKey})
serve: default placement for steps that declare none (so one workflow runs both locally and via workers)
s3-datastore: per-datastore AWS profile, so a serve audit store can use different credentials from the main datastore
gcs-datastore: a failed lock read is reported as "unlocked" — #2298 in the GCS backend
s3/gcs-datastore: clean up data left behind by deletes that silently no-opped before the swamp-club#2249 fix
Expose Swamp as a REST/OpenAPI endpoint (for GPT Actions and other REST clients)
Promote CodeBuddy and WorkBuddy from custom-tool configs to first-class Swamp clients
s3-datastore: documented offline behaviour is unreachable — lock acquire fails closed before pull, while a mid-run outage exits 0 with the data stranded
issue-lifecycle: swamp-club lifecycle post failures are logged but the method still reports success
Periodic worker GC sweep prunes outside the sync gate
Route log-mode output to stderr by default, with commands opting stdout back in
-q does not suppress the update, auth-nudge and autoupdate banners
Lab status never returns to shipped on merge — transitions are manual and drift silently
Billing telemetry: surface scheduled cancellations (cancelAtPeriodEnd) and emit subscription_canceled reliably
Swamp Club fresh-database startup aborts migrations on missing deviceCode and concurrent replica markers
Relationships
#2431 workflow recover crashes on every invocation: 'Path must be a string'
Opened by hammz · 9/23/2026· Shipped 9/23/2026
Problem
swamp workflow recover crashes on every invocation, before it looks up the workflow or the run:
$ swamp workflow recover <workflow>
[FTL] error: TypeError: Path must be a string, received "{"telemetry":true,"color":true,"acknowledgeUnknown":false,"assessOnly":false}"
at assertPath (https://jsr.io/@std/path/1.1.4/_common/assert_path.ts:6:11)
...--run <id>, --assess-only, and --acknowledge-unknown make no difference, and a workflow name that does not exist crashes the same way. That makes checkpoint recovery (swamp-club#2153) unreachable from the CLI. It is also the command serve's boot reaper tells operators to run: Boot: N workflow run(s) interrupted by crash — recover with 'swamp workflow recover <workflow>'.
Cause
src/cli/commands/workflow_recover.ts calls resolveRepoDir(options) with the whole options object. resolveRepoDir in src/cli/context.ts takes the --repo-dir value (string | undefined), and every other command passes options.repoDir. Type checking does not catch it because the action types options as AnyOptions. The command has no test file, so no test runs the action.
Present on main since the command was added in a3123298 (swamp-club#2153).
Fix approach
Pass options.repoDir as the other commands do, and add a command-level test that runs workflow recover against an initialized temp repo with an interrupted run, covering both --assess-only and a real recovery, so the action is exercised end to end.
Reproduction
- In any initialized repo,
swamp workflow recover <any-workflow-name>. - The command exits 1 with the
Path must be a stringTypeError above.
Shipped
Click a lifecycle step above to view its details.