Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
Docs: grant file reference shows a stale format and omits resources and subjects
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
extension push: version-drift check reports 'no previously published version found' when the registry call failed
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
Workflow load errors print the raw Zod issue dump instead of a readable message
Decide a stricter naming rule for workflow step and job names
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
Show expired approval gates as expired, with a Cancel action in the dashboard
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
extension promote accepts a yanked version and reports it promoted
Docs: doctor install reports a stale or failing autoupdate scheduler
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
auto-resolve: the Installing line prints the extension's entire multi-line description
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
Let agent-runner drive more agent CLIs (Kilo Code and others)
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
Feedback: Swamp as an approval-gated control plane for a small fleet
extension safety analyzer's Deno.Command( warning is a plain substring match
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
Run from a git worktree: definitions from the worktree, state from the shared repo
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
Tell the pushing client when its extension contentMetadata fails validation
Extension datastore: query still returns an item after its delete is pulled
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
Tracking: test baseline required before the datastore refactor (commit-log design)
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
serve: define and supply the collective and owner grant condition variables
No first-class workflow primitive for spawning a permission-scoped agent session
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
Decorative animations outside the Lab still repaint on the main thread
s3/gcs datastore: pullChanged overwrites dirty, unpushed cache files
Concurrent first runs in a fresh repo log 'Catalog migration to per-extension-aggregate-v3 failed (database is locked)'
Codegen/DigitalOcean: create-only required fields block list/get/delete in generated DigitalOcean models
Codegen/AWS: create-only required fields block list/get/delete in generated AWS models
End a collective's trial when it begins a paid subscription
A collective that cancels inside its 30-day trial window regains trial access to private extensions
s3-datastore: SWAMP_S3_REQUEST_TIMEOUT_MS does not appear to apply to ListObjectsV2 during pull
s3-datastore: S3Lock.acquire overshoots maxWaitMs by up to a full backoff interval
s3-datastore: a model-scoped pull still lists, walks and indexes the whole namespace
Run the web dashboard locally from the CLI without swamp serve
verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
issue-lifecycle skill: prepare-to-ship documents a fast_forward method that does not exist
S3 datastore rejects valid cache paths as traversal on Windows
swamp-club: unknown collective API token returns 422 instead of the documented 404
Partial extension catalog saves delete rows for sources mounted from outside the repo
extensions: cold-path catalog rebuild skips sources whose type is not a string literal, dropping them for one process lifetime
serve: rotate the external token-secrets key
serve: server token GC follow-ups (upgrade backlog holds the sync gate, not-found matching, owner lookup, UX)
serve: without a remote datastore the token GC is not serialized against token rotate/re-mint
Workflow evaluation rejects another templating system's ${{ }} text, so the #2491 pass-through never reaches workflow steps
@swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
worker prune: remote datastore keeps deleted worker records (no-path markDirty() skips deletions)
Orphaned data record survives a model type migration and is unreachable by data delete/versions/prune
Link each swamp-club panel to its manual page with a header DOCS link
managedConfig: extension lockfile writes lose updates, and auto-resolved installs never reach the shared lockfile
Generated @swamp/aws StateSchemas mark conditional and create-only properties as required, producing schema warnings on every read
Registry catalog silently drops models whose version is not a literal in the export const model block
Namespace names are not reserved against cache/datastore layout directories (e.g. data)
Clear error when hydrateFile reports success but the file is missing
workflows: a nested workflow step should inherit the caller's placement when the child declares none
Windows: concurrent data save can fail with Access is denied renaming the latest marker
Supported vault-write API for extension model methods (per-instance vault target)
verify-reviews gives no usable error when the local Claude Code predates the pinned review model
serve: boot hydration ignores `hydrationStrategy: lazy` and downloads every payload
datastore sync: repositories mark paths dirty before writing, so a concurrent ungated push can drop the write
Relationships
≡ duplicated by #2289#2583 verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it
Opened by skunk-ape · 9/28/2026
verification/workflow-verify-reviews.yaml decides whether to run the adversarial review by matching changed paths against a hard-coded list of directories (agent-runner/, deno-runner/, ..., software-factory/, typesafe-ai/, extensions/). A new extension directory is not on the list until someone remembers to add it, and until then its changes get no adversarial review. Nothing fails or warns: the step shows as skipped (guarded), which looks the same as a legitimate skip.
This happened on PR #327 (swamp-club #2576): gatorwalk-factory/ was missing, the first verify-reviews run skipped the adversarial review, and it was only noticed by reading the checklist. It was added to the list by hand in that PR.
verification/checks.yaml already has the complete list of extension directories (scripts/verification_harness_test.ts enforces that every extension has a target). Fix options: derive the guard's directory list from checks.yaml targets, or add a harness test asserting every extensions/vaults/datastores target in checks.yaml is matched by the adversarial guard.
Open
No activity in this phase yet.
skunk-ape commented 9/30/2026, 4:49:55 PM
#2289 was closed as a duplicate of this issue. It is the specific case where the guard omits extensions/, so bundled extension changes skip review. Make sure the fix covers it.
Sign in to post a ripple.