Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
Docs: grant file reference shows a stale format and omits resources and subjects
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
extension push: version-drift check reports 'no previously published version found' when the registry call failed
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
Workflow load errors print the raw Zod issue dump instead of a readable message
Decide a stricter naming rule for workflow step and job names
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
Show expired approval gates as expired, with a Cancel action in the dashboard
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
extension promote accepts a yanked version and reports it promoted
Docs: doctor install reports a stale or failing autoupdate scheduler
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
auto-resolve: the Installing line prints the extension's entire multi-line description
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
Let agent-runner drive more agent CLIs (Kilo Code and others)
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
Feedback: Swamp as an approval-gated control plane for a small fleet
extension safety analyzer's Deno.Command( warning is a plain substring match
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
Run from a git worktree: definitions from the worktree, state from the shared repo
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
Tell the pushing client when its extension contentMetadata fails validation
Extension datastore: query still returns an item after its delete is pulled
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
Tracking: test baseline required before the datastore refactor (commit-log design)
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
serve: define and supply the collective and owner grant condition variables
No first-class workflow primitive for spawning a permission-scoped agent session
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
Decorative animations outside the Lab still repaint on the main thread
s3/gcs datastore: pullChanged overwrites dirty, unpushed cache files
Concurrent first runs in a fresh repo log 'Catalog migration to per-extension-aggregate-v3 failed (database is locked)'
Codegen/DigitalOcean: create-only required fields block list/get/delete in generated DigitalOcean models
Codegen/AWS: create-only required fields block list/get/delete in generated AWS models
End a collective's trial when it begins a paid subscription
A collective that cancels inside its 30-day trial window regains trial access to private extensions
s3-datastore: SWAMP_S3_REQUEST_TIMEOUT_MS does not appear to apply to ListObjectsV2 during pull
s3-datastore: S3Lock.acquire overshoots maxWaitMs by up to a full backoff interval
s3-datastore: a model-scoped pull still lists, walks and indexes the whole namespace
Run the web dashboard locally from the CLI without swamp serve
verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
issue-lifecycle skill: prepare-to-ship documents a fast_forward method that does not exist
S3 datastore rejects valid cache paths as traversal on Windows
swamp-club: unknown collective API token returns 422 instead of the documented 404
Partial extension catalog saves delete rows for sources mounted from outside the repo
extensions: cold-path catalog rebuild skips sources whose type is not a string literal, dropping them for one process lifetime
serve: rotate the external token-secrets key
serve: server token GC follow-ups (upgrade backlog holds the sync gate, not-found matching, owner lookup, UX)
serve: without a remote datastore the token GC is not serialized against token rotate/re-mint
Workflow evaluation rejects another templating system's ${{ }} text, so the #2491 pass-through never reaches workflow steps
@swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
worker prune: remote datastore keeps deleted worker records (no-path markDirty() skips deletions)
Orphaned data record survives a model type migration and is unreachable by data delete/versions/prune
Link each swamp-club panel to its manual page with a header DOCS link
managedConfig: extension lockfile writes lose updates, and auto-resolved installs never reach the shared lockfile
Relationships
#2447 Retry refusals print unquoted forEach template names in --from hints, which bash rejects
Opened by hammz · 9/23/2026· Shipped 9/29/2026
Problem
When swamp workflow resume <wf> --run <id> refuses to retry a failed run, two refusals suggest a --from step: the rejected-approval refusal (Add --from <gate> to ask again.) and the pending-step refusal (Add --from <step> to run it.). Both print the entry template name unquoted (selectRetryTemplates in src/domain/workflows/failed_step_retry.ts).
For a forEach step, the template name is the step name as written in the workflow, and it usually contains an expression, such as read-${{ self.plate }}. The printed hint Add --from read-${{ self.plate }} cannot be pasted into a shell: bash rejects it with bad substitution.
Found by the verification reviews of swamp-club#2409 (PR swamp-club/swamp#2582).
Expected
The printed --from value is shell-quoted when it needs quoting, so the hint runs as printed. quoteShellWord in src/cli/remote_run.ts already does this for printed --server and --repo-dir values; the refusal lives in the domain layer, so the quoting helper would need to be reachable from there, or the refusal could carry the step name for the caller to quote.
Shipped
Click a lifecycle step above to view its details.