Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesskunk-ape

Relationships

#2494 Install rollback recursively deletes pre-existing skill dirs that pull merged into

Opened by hammz · 9/24/2026· Shipped 9/24/2026

Description

Split from the swamp-club#2489 adversarial review (ADV-16). #2489 covers lockfile-driven deletes; this one is registry-driven.

When a pull or install hits a DuplicateTypeError, InstallExtensionService.rollbackOnCollision (src/libswamp/extensions/install_extension_service.ts ~371-422) runs a recursive Deno.remove over every path in extractedFiles. For skills, installExtension copies archive skills INTO pre-existing directories (src/libswamp/extensions/pull.ts ~1093-1104) and records only the skill root, for example .claude/skills/foo. If the user already had their own .claude/skills/foo, or another installed extension ships the same skill name, the rollback deletes that whole directory, including files the failed install never wrote.

A committed lockfile that pins two extensions with colliding types reaches this during swamp extension install.

Expected

Rollback deletes only what the failed install created. Record which skill roots and files did not exist before extraction, delete only those, and route the deletion through the symlink-safe sink that #2489 adds (deleteWithinRoot). Skill dirs that existed before stay, perhaps with a warning that their contents were overwritten.

Notes

  • Pull also overwrites a pre-existing skill dir of the same name without a conflict check. That write-side behaviour is related and may belong in the same fix.
  • It depends on the deleteWithinRoot sink and the skill ownership marker from #2489.
02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 10 MOREREVIEW+ 14 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/24/2026, 9:47:57 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
skunk-ape assigned skunk-ape9/24/2026, 5:21:22 PM

Sign in to post a ripple.