Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
datastore config migrate checks the sentinel in the stale local cache and re-runs a full migration over a shared S3 datastore
datastore config migrate writes its sentinel before pushing; after a failed push a re-run reports 'already completed' and never publishes
extension quality, fmt --check and push disagree: bare-specifier severity, cache hit skips gates, gate failure hides the rubric, fmt ignores project config
Docs: grant file reference shows a stale format and omits resources and subjects
Docs: extension push dry-run reference and how-to need the registry checks, API-call list and content hash from Lab #3016
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Resolve non-admin actors in dashboard audit logs
A nested structural swamp still waits on its run's lock when the lock holder is not a same-host ancestor (cross-host worker, --server into a non-ancestor serve)
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
Docs: serve authorization page should cover expression-reference checks and the vault.get trust boundary
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
Docs: channel-aware extension push prompts and promote with a manifest (follow-up to #2939)
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
Deliver workflow signals through a write-once outcome record instead of writing the run record
Shell steps: a vault.get on a continuation line of a multi-line double-quoted string inside a here-doc is wrapped in quotes
extension push: testing-completeness warns once per generated model (262 warnings in 25 extensions) with no way to mark a package generated
extension push: declare accepted lint warnings where the finding is (inline swamp-review-ignore comments, a sidecar review file beside the manifest), reported in quality, push and the registry
Docs: manual describes the old extension push path resolution (manifest argument, --extensions-dir scope, global skill fallback) after swamp-club#3018
extension push: --extensions-dir is ignored for bundled workflows
extension push: sub-directory extensions cannot be found from outside their directory (manifest path, directory argument, --extensions-dir for workflows and skills)
GCP bigquery datasets update cannot target the dataset: reads the id from a name field datasets do not have
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
Extension bundler rewrites zod import text inside string/template literals, breaking code-generating extensions
s3-datastore: pull never removes files deleted on the remote, so a peer's next push re-uploads them and undoes `swamp data gc`
swamp-testing withMockedCommand: record env and cwd in CapturedCommandCall
Forward held-lock identity over --server so a loopback nested swamp does not wait on its caller's lock
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
Share dashboard authentication across tabs for deep links
Docs: vault.get shell references are placed per occurrence, and every single-quoted use is warned about
A nested structural swamp on a same-host remote worker waits on its own step's lock held by swamp serve
Scheduled flaky-test detection is failing
Docs: declared acceptances for extension push warnings (quality.yaml sidecar, swamp-quality-ignore comments, For next time report)
Docs: describe the private-entitlement registry check and the refusal wording in the extension publishing reference
Fail fast when nested structural commands under parallel runs wait on each other's locks
Use whoami entitlement to explain private-extension push refusals
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
@swamp/digitalocean/space-key: update and sync call /v2/spaces/keys/undefined
knowledge-base retrieve persists query output into the state resource, with lifetime infinite and the query text in the instance name
Docs: remove followUpActions from the MethodResult reference in the extension model manual
signal_test: already-settled test fails by chance when a random UUID spells the sender name
Add a wait_for_signal workflow step that pauses a run for a JSON message
Deliver workflow signals through swamp serve
Docs: serve authorization of expression references, env and direct-type runs (swamp-club#2786)
run doctor through serve interrupts a live run of another serve instance when no heartbeats are recorded
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
Docs: dispatch-env-allow and how remote shell steps receive secrets (swamp-club#2760, swamp-club#2791)
Flaky test: WalSink replayed segments are delivered before events written after replay leaves one WAL segment
Remove followUpActions: no model or extension can produce them
Workflow schedule watcher and workflow edit symlink lookup ignore the managed config workflows dir
main is red: repository_dirty_coverage_test fails for UnifiedData.collectGarbage(orphaned deferred write)
isProcessGone always reports alive on Linux under the test task permissions, failing 9 tests on main
Flaky test: WalSink replayed segments are delivered before events written after replay
serve: relative tls cert-file/key-file and --config resolve against the working directory, not the repository
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
findBySpec/findByTag lose a workflow step's output after a version is deleted, pruned or rolled back
extension push --dry-run skips auth, collective and version-exists checks, and prints 'No API calls were made' while calling the registry
serve: a failed pull in acquireModelLocks leaves the per-model lock held until serve exits
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
serve HA: a server token minted on one replica is rejected by the other replicas until they restart (auto-definitions/ is only pulled at boot)
data_query_stale_limit_test fails on Linux: a limited page returns names in b, a order
extension push: version-drift check reports 'no previously published version found' when the registry call failed
Run tracker keeps some interrupted workflow rows forever: retention waits for markSettled, which several paths never call
run doctor reads every run record on each run to rebuild the run indexes
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
verify-reviews: whole-extension rubric review for changed hand-written extensions, carried in the attestation and read by publish (design: Lab #3023)
Docs: step and job name rules in the workflows reference
Design: verify the extension push adversarial review through the attestation (whole-extension rubric review as a local verification step, carried in the attestation, read by publish and the push gate)
Workflow load errors print the raw Zod issue dump instead of a readable message
Decide a stricter naming rule for workflow step and job names
Datastore rework Phase 2: find, wrap and warn on hooked writes outside a unit of work (route 2), without removing it (no behaviour change)
stagecraft: read records with data query --single once it ships
Serve audit: WAL replay at startup deletes segments before the store confirms them
Datastore rework Phase 2: one flush path, so every push is a root's flush or checkpoint (no behaviour change)
Flaky test: usePreviewFetch in-flight fetch for A is discarded after switching to cached B
Serve audit: delivered WAL segments are only deleted at shutdown, so a long-running serve fills the WAL
Serve audit: sink filter config in serve.yaml is never validated
Serve audit: two sinks with the same name share one emitter cursor, so the second never receives events
Serve audit: a durable sink write that times out is retried while the first call is still pending, so the store can hold duplicate sequences
Datastore rework Phase 2: root units can checkpoint, and the CLI token commands push mid-command through it (no behaviour change)
extension push: restore --yes waiving warnings (revert the 20261005.154947.0 flag split), keep the accepted-warnings record, --accept-warnings stays as an optional alias
Flaky test: ModelResolver data accessors for a renamed model return the earlier id's record from findBySpec
serve: workflow trigger get/set ignore --config and read/write <repo>/.swamp/serve.yaml, so they disagree with the scheduler
serve --hot-reload: a changed trigger override schedule is logged as applied but the built-in cron keeps firing
serve: a suspended run with an expired gate from a previous serve instance cannot be cancelled by any path
server tokens: concurrent mints of the same name can pair one mint's record with the other's secret, so a credential authenticates as the wrong principal
Docs: data query reference lists a --limit default of 100 and omits --single
data query --limit returns fewer live records than exist and reports limited: false when stale catalog rows fall inside the limit
data get: help example passes --run latest, which is not a recognised run id
Datastore rework Phase 2: remaining serve direct pushes commit through root units (no behaviour change)
macOS autoupdate LaunchAgent fails with EX_CONFIG after self-update; doctor install still reports HEALTHY
workflow reject leaves sibling gates waiting_approval and dependents pending in a failed, retryable run
extension push: credentials-sensitive-field has no word boundaries and flags secretName, TokenReference, credential_id (fourth fix to the rule)
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
Show expired approval gates as expired, with a Cancel action in the dashboard
swamp-extensions publish.yml: pass --accept-warnings alongside --yes now that --yes no longer waives warnings
Serve audit: emitter breaks the durable hash chain and drops WAL events when a non-durable sink fails or lags
digitalocean codegen leaves an orphaned security_secret.ts model file after its endpoint left the spec
extension promote accepts a yanked version and reports it promoted
workflow cancel cannot cancel a suspended run whose workflow file was deleted, and cancel --all silently skips it
Datastore rework Phase 2: serve handlers commit through the unit of work (no behaviour change)
CEL data.version, data.listVersions and data.findBySpec drop data written before a model instance rename
Docs: doctor install reports a stale or failing autoupdate scheduler
Datastore rework Phase 2: CLI commands stop marking and pushing directly (no behaviour change)
A job alone in its level starts after the abort, and its unstarted step is recorded as a real failure instead of settledByAbort
workflow approve racing workflow cancel loses the cancel: the run returns to suspended after cancel reported cancelled
Datastore rework Phase 2: commit pushes through a root unit of work per command or request (no behaviour change)
extension push: --accept-warnings separate from --yes, and --json exits non-zero instead of skipping the warnings prompt
workflow approve/resume hint lines wrap + quote names, breaking copy-paste
Datastore rework Phase 2: use cases open and commit the unit of work (no behaviour change)
extension push: workflows listed with a shared directory prefix collapse into one workflows.yaml; all but the last are silently dropped
digitalocean codegen: app-platform and database spec secret fields are not marked sensitive
dashboard: approved autoResume run shows Resume and needs-inputs hint while serve already resumed it (status running)
repo upgrade does not remove superseded skills from the repo-local skills dir, so its own warning never clears
readModelData silently drops data written before a model instance rename
Docs: manual approval pages show old quoted approve/approvals hints
Docs: extension push --accept-warnings is separate from --yes (manual pages)
data query: does not follow data rename forwarding that data get follows
vault migrate: report missing required --config fields clearly, before installing the target type
Unit tests share fixed /tmp catalog paths, so concurrent runs corrupt them and fail every later run
extension push output: double-quoted adjacent interpolations, repo-relative paths, and --json emits three JSON documents
vault read-secret: to a pipe or file, drops the last line of a multi-line value when that line is 1024+ chars with no trailing newline (exit 0)
Docs: vault create and vault migrate name missing required --config fields and prompt for them
auto-resolve: the Installing line prints the extension's entire multi-line description
s3-datastore/serve: readResource without a version returns an older version; the latest marker is rewritten backwards
Publish agent-facing projections of the manual: /llms.txt, .md pages, and llms-full.txt
CLI tells signed-in callers to sign in when the registry rate-limits them
Let agent-runner drive more agent CLIs (Kilo Code and others)
Datastore rework Phase 1 close-out: lock repository marks at zero, remove dead helpers, document the end state (no behaviour change)
Installer and README present required Swamp Club login as optional
s3-datastore: every fast-path miss re-downloads every _index shard, so a busy serve pulls the whole index every poll (~230 GB/day S3 egress)
data query: renamed data items are not found by their old name
data query: model lookup by id and orphan recovery parity with data get
Datastore rework Phase 1 move C2: the vault config repository stages typed changes, serve stops marking vault files by hand (no behaviour change)
Model add-ons that extend a built-in model type never attach in CLI processes
deployments: sync fails after adopt/get because stored state has id, not uid
workflow approve on a run that is not suspended prints a fatal error with a stack trace
data query: no way to target a workflow's latest run
Datastore rework Phase 1 move C1: the workflow run repository stages typed changes (no behaviour change)
data query: binary content lacks contentEncoding/base64 parity with data get
data query: no fallback from spec name to data instance name
data query: no definitionHash or garbageCollection fields in query results
Add a subprocessors page at /subprocessors
Feedback: Swamp as an approval-gated control plane for a small fleet
stagecraft: publish @swamp/stagecraft: manifest, Lab exclusion, real-tree checks, packaged install, merge
Datastore rework Phase 1 move B: definition, workflow and evaluated repositories stage typed changes (no behaviour change)
Add self._index to forEach expression context
Datastore rework Phase 1 move A: data and output repositories stage typed changes (no behaviour change)
A nested structural swamp spawned by swamp serve skips every lock serve holds, including other runs' locks
stagecraft studio work-item page: follow-ups from the #2944 reviews
gatorwalk-factory studio: Simulate follow-ups from #2808's reviews (stuck Run tab on an unrunnable walk, settling states)
stagecraft studio work-item page: follow-ups from the #2956 reviews
data query: confirm catalog parity with data get for custom datastores
Docs: document self._index for forEach steps in the manual
data query: single-result --json mode for scripts migrating from data get
stagecraft: stop relying on the CLI's swamp data get
extension push: Credentials & Secrets review flags token-count fields (inputTokens, outputTokens, totalTokens) as secrets
stagecraft studio: serve refuses to start without queryData, and printed start commands can coerce a title
Datastore rework Phase 1: optional ambient unit of work in repositories (no behaviour change)
stagecraft studio: a Ticket tab on the work-item page (description, comments, relations), and the nav shows where you are
extension push: eval()/new Function() safety check is a substring match and blocks obj.eval( method calls in bundled libraries
Extension content extractor truncates metadata when a string, comment or regex contains an unpaired brace
Datastore rework Phase 1: UnitOfWork port and legacy adapter (no behaviour change)
Versions written by different steps of one workflow run all stay isLatest=true (data query / readModelData / queryData return stale "latest")
`swamp repo upgrade` adds its canonical Claude audit hook next to an existing variant, so every command is recorded twice
Docs: document data query --single and fix the stale --limit default in reference/data.md
acquireModelLocks writes SWAMP_LOCK_HOLDER_PID to process-global env, so concurrent runs in one process clobber each other
`swamp issue bug` redactor treats the file name `settings.local.json` as a hostname and rewrites it to `[HOST-1].json`
stagecraft: short work-item ids: a tracker prefix plus a counter (blog-12), the ticket's id for external trackers (abc-12), and -2 for later work on the same ticket
data get --workflow silently returns an arbitrary step's data when several steps share a data name
stagecraft studio: long work-item keys overflow Board cards, and the built-in tracker ref repeats the key
swamp doctor workflows misses nested and .yml extension workflows that the loader reads
verify-reviews reports provider-error when a passing review mentions swamp's own invalid_api_key error code
auth whoami says the stored API key is no longer valid when auth.json only holds an env-key identity cache
extension safety analyzer's Deno.Command( warning is a plain substring match
Docs: swamp skill says cancelling a parent run cancels its nested child runs; the child is left suspended
stagecraft studio: a work-item view showing where one item is in its factory and how it got there
audit_deps does not scan gatorwalk-factory's lockfile
stagecraft: prepare for publication: manifest, swamp's extension checks (fmt, quality, push --dry-run), repo verification, packaged install
Show the redaction diff and ask for confirmation before submitting an issue in log mode
stagecraft skill: getting started asks every question at once; it should ask one at a time
stagecraft studio: a Board view of every work item by stage
Namespace advice in the slow-lock warning is wrong for a single repo on a local datastore
stagecraft: the Linear adapter assigns the issue when work starts
stagecraft: a user-facing README for first release (what it is, getting started, studio, trackers)
gatorwalk-factory skill: an interactive getting-started walkthrough for a first factory, modelled on swamp-getting-started
--json stderr mixes an offline auth-gate warning line with the pretty-printed error, so it can't be parsed
gatorwalk-factory: rename to stagecraft (@swamp/stagecraft) for first release
@swamp/tailscale: follow-ups from the initial release verification review
Filter/sort extensions by "new" on swamp-club.com/extensions
Method-run records left running by a dead owner are never reaped
Top-level swamp init never earns repo-init quest or tier credit
Scheduled flaky-test detection is failing
Flaky: usecase_sync_characterization_data_test 'data gc (serve)' asserts markDirty order that varies under parallel load
Docs: account-requirement manual page after the auth gate follow-ups (swamp-club#2916)
Auth gate follow-ups: fail closed when the fail-open window can't be recorded, UX polish (swamp-club#2231)
Codegen/Vercel: create-only required fields block read methods in generated Vercel models
Worker dispatch rebuilds the definition with Definition.create, so a legacy-named model cannot run on a worker
A cancelled workflow exits before its steps stop, leaving their method-run records at running
Nested swamp structural command in a shell step times out on its parent's per-model lock (SWAMP_LOCK_HOLDER_PID is stripped)
Auth gate blocks nested swamp in workflow shell steps when the credential is in SWAMP_API_KEY
swamp workflow create crashes with an [FTL] ZodError stack trace on an invalid (uppercase) workflow name
swamp model create crashes with an [FTL] ZodError stack trace on an invalid (uppercase) model name
model cancel SIGTERMs a running swamp serve process when the method run belongs to a serve-run workflow
Follow-up action retries ignore the run's abort signal and can outlast a cancel
model cancel --all on a running workflow leaves its method-run records at running, or records them failed instead of cancelled
model cancel SIGKILLs the owner 2 s after SIGTERM, before the step executor's own 3 s kill grace, so the run never records its own cancellation
workflow cancel and supersede of a suspended run leave its jobs running in the cancelled record
Auth gate: enforce authentication and add background proof refresh
Tell timeouts apart from cancels in method-run records, and review the hidden 30 s fallback timer for step-called model methods
gatorwalk-factory: project a work item parked by its dispatch cap (GW-17 follow-up)
gatorwalk-factory: remove the static design page (design_page and its Mermaid renderer); the studio is the only visualization
A force-exited workflow run stays running with a dead pid: resume, recover and run doctor --fix cannot clear it
Server fallback content extraction drops quoted method keys and lists nested objects as methods
gatorwalk-factory: claim can wedge a ticket on a reservation whose factory no longer loads (GW-18 follow-ups)
gatorwalk-factory studio: file-watch and page edge cases left from #2806's reviews
A nested workflow that suspends on manual approval forwards its suspended event into the parent run's stream
gatorwalk-factory studio: a replaced directory that gets the same inode number is still not watched again
gatorwalk-factory: lifecycle entries carry issue-lifecycle's versions, counts and attempts
gatorwalk-factory: mark a duplicate and move its work to the primary
gatorwalk-factory skill: an eval suite (claude plugin eval) that keeps authoring and driving behaviour from regressing
workflow cancel SIGKILLs the run 2 s after SIGTERM, cutting off always/completed cleanup jobs mid-step
gatorwalk-factory studio: a factory whose model file is briefly invalid YAML drops off the list, and the page jumps to another factory
gatorwalk-factory: publish can undo a manual status move after a lost cursor write (GW-17 follow-up)
Docs: account requirement and auth gate (swamp-club#2231)
gatorwalk-factory: publish explains a stuck status step, and every refused lifecycle copy (GW-17 follow-up)
Run from a git worktree: definitions from the worktree, state from the shared repo
Conformance: behavioural round-trip suite for DatastoreSyncService in packages/testing
Tests: remote failures during sync keep local writes dirty and the next flush uploads them (every flush path)
Tests: two repos on one remote datastore: writes, deletes, renames and gc propagate through the real flush path and catalog
Tests: every file a datastore repository changes on disk is covered by a markDirty (pin today's unmarked paths)
Scheduled flaky-test detection is failing
gatorwalk-factory skill: authoring's Show it step uses the studio once it lands
gatorwalk-factory: small driving fixes from the #2711 dogfood
S3/GCS datastore: a push that fails after uploading drops its recorded deletes, so the retry brings deleted data back
Tests: bring the in-memory remote's default semantics up to @swamp/s3-datastore and @swamp/gcs-datastore 2026.10.01.1
gatorwalk-factory: metrics count an open manual exit as a wait on a person
Warn when datastore setup keeps managedConfig but the new datastore has no config tier
Docs: telemetry reference — the envelope we send and our redaction policy
Docs: run doctor --fix and workflow recover settle runs left running by a force-exited process
serve: a relative grants-dir resolves against the working directory, not the repository
gatorwalk-factory: the swamp-club adapter links the pull request on the Lab issue, as issue-lifecycle's link_pr does
Tell the pushing client when its extension contentMetadata fails validation
gatorwalk-factory: main's embedded studio build is stale after #2792 and #2807 crossed
Tests: property test for buildMarkDirtyHook path mapping
Tests: characterise marks and pushes for every libswamp write use case via CLI and serve compositions
Tests: characterise stale catalogs when two repos or serve nodes share a filesystem datastore
Fitness: ratchet markDirty call sites, repository constructions outside the factory, and unhooked datastore writers
gatorwalk-factory studio: Simulate mode
workflow resume cleanup mode can run an always-gated teardown before a suspended job's approved work
Docs: serve-flags.md should state that relative grants-dir and grants-file resolve against the repository
Extension datastore: query still returns an item after its delete is pulled
gatorwalk-factory: scrub the swamp-club Lab from everything a public user sees, so it never reads as an option
gatorwalk-factory: a factory definition's name field duplicates the factory's model name
gatorwalk-factory: swamp-club-swamp-extensions stages read stale inputs (notify summary, review context, plan.submit)
gatorwalk-factory: validate warns on a way back with no description and on a product with no schema
managedConfig: extension writes update the shared lockfile from a stale cache and overwrite peers' entries
model method run draws an empty report box when a report returns no markdown
gatorwalk-factory: the factory definition lives in the factory model, with its schema, not in a separate file
gatorwalk-factory: publish assigns the issue when work starts
gatorwalk-factory: main's embedded studio bundle is stale after #2792, so studio_assets_test fails
gatorwalk-factory: `--log` prints every method's output twice, and writes don't print the status that follows
gatorwalk-factory studio: Design mode
gatorwalk-factory: warn when a product only CEL reads is not produced on every path to the reading stage
Docs: document serve and worker trace structure in the OpenTelemetry reference
Test infra: shared in-memory remote datastore fake and recording sync service for pre-refactor datastore tests
CEL: an expression naming the identifier cel returns {} instead of the context value
Scheduled flaky-test detection is failing
gatorwalk-factory: parent, blocked-by, related and duplicate relations in every tracker
swamp-extensions build-attestation rejects every run: evaluated workflows carry sensitiveFormat (port of swamp-club #2815)
gatorwalk-factory: skill command check knows each tracker adapter's own methods
managedConfig: model/vault create and other bulk-push commands re-upload a stale extension lockfile and erase peers' entries
gatorwalk-factory: a lifecycle chooses its tracker, and status shows projection lag
gatorwalk-factory: check that CEL product references name declared products
Cancel, reject and supersede of a parent run should settle its suspended nested child runs
Docs: SWAMP_API_KEY_FILE and serve --club-api-key-file
gatorwalk-factory: plan prompt can add the same feedback to feedbackIncorporated twice after revise then rework
Tracking: test baseline required before the datastore refactor (commit-log design)
CI: run swamp-uat's datastore suite against the PR binary for PRs touching datastore code
Tests: serve pollers make a peer's writes, deletes and grants visible with a real catalog (before Phase 5)
Docs: document mount-independent file grant sources for --grants-dir and --grants-file
Telemetry opt-out scope: one user-level setting that disables telemetry everywhere
Telemetry: mark paths where errors are built so redaction needs no guessing
gatorwalk-factory skill: stop on repeated automatic rework, and lay out every exit neutrally at human stops
datastore setup extension overwrites the shared config tier with the repo-local copy and drops managedConfig from .swamp.yaml
gatorwalk-factory: keep a person's plan feedback and hand it to the next plan
serve reload keeps a removed extension's add-on methods on built-in and local model types
Docs: telemetry opt-out is user-level and applies everywhere (swamp-club#2831)
gatorwalk-factory: a tracker-side check that a factory definition fits its bound tracker
datastore setup can overwrite an existing remote config tier when it moves an in-repo tier into an extension datastore
serve daemon enable writes a unit that crash-loops when serve args are invalid (e.g. missing --admins)
gatorwalk-factory skill: authoring: the agent interviews, starts from an example, validates, and shows the factory
gatorwalk-factory: studio model type and its local serve method
gatorwalk-factory: record_usage cannot take the token count Claude Code reports, so no dispatch gets usage
Object-level refinements on globalArguments schemas are not enforced at execution time
gatorwalk-factory: review prompts define severity and scale to the change, so a small change doesn't loop on logistics findings
workflow reference.md documents removed --driver flag on swamp workflow run
Docs: remove stale Docker Execution Driver section from the extension model reference
Combat log: batch the extension visibility lookup into one query
Concurrent embedded deno extraction races: stale temp-file cleanup deletes another process's in-flight .deno.tmp file (chmod ENOENT)
Docs: manual approval gates inside nested workflows (swamp-club#2736)
Telemetry bridge drops a parent step's invocation when a nested workflow step has the same job and step names
gatorwalk-factory: a built-in tracker core that the Lab and Linear adapters build on
serve daemon: unit sets SWAMP_HOME, which relocates the config dir — token/oauth daemons can't find auth.json and crash-loop
gatorwalk-factory: dispatch fidelity: subagents get the rendered prompt and product contract, and their results are recorded as returned
gatorwalk-factory: saved scenarios next to a lifecycle, run by validate
gatorwalk-factory: built-in tracker create must not overwrite a ticket on an id collision
CLI telemetry redaction: user values still transmitted (errorMessage, workflowContext, init path, history args, private types) while command words are over-redacted
gatorwalk-factory: retarget a work item to another issue, journaled
Workflow step that times out on the model lock leaves its output and run-tracker row stuck at 'running'
gatorwalk-factory: a downgraded regression still sets the Lab regression flag
gatorwalk-factory: the lifecycle holder reads its lifecycle from lifecycles/<name>.yaml
serve: access reload tracks each grants-dir file under two names, and keeps a deleted file in its results
Docs: serve daemon enable pins SWAMP_CONFIG_DIR; document the SWAMP_CONFIG_DIR override
An extension upgrade that hits a type collision is rolled back to no version: roll back to the prior version with a commit/rollback install handle
gatorwalk-factory: decide whether 'lifecycle' should be called 'factory' before go-live
gatorwalk-factory: separate engine and tracker code behind a seam module the tests enforce
Telemetry bridge attributes a parent run's later method invocations to its nested child run
check_upgrades path test fails an extension that has no manifest instead of skipping it as unpublished
gatorwalk-factory: description fields on gates and work; move lifecycle comments into fields
software-factory: decide its future at gatorwalk-factory go-live: PR #318, support window, deprecation
sensitive_data_delivery_test fails where /bin/sh is bash: the final ps is exec'd and reports its own argv
build-attestation rejects every run: evaluated workflows now carry sensitiveFormat, which the provenance check treats as an uncommitted field
gatorwalk-factory: remove stage templates and apply; ship examples/ lifecycles instead
gatorwalk-factory: replace the Mermaid design page with a static studio export
gatorwalk-factory studio: Operate mode for live work items
gatorwalk-factory studio: example payloads from JSON Schema for Simulate walks
gatorwalk-factory: swamp-extensions stages load the issue-lifecycle skill, which starts a second driver
gatorwalk-factory: a breakdown stage files child issues and their dependencies
gatorwalk-factory: claim warns about open blockers and records an override
Docs: authorization reference should say access-control records need admin, not a data grant (swamp-club#2756)
gatorwalk-factory: the dispatch packet does not say which products the stage records or their schemas
gatorwalk-factory: subagent findings are retyped into record_artifact instead of recorded as returned
gatorwalk-factory: restart at triage keeping what was recorded (gap 7)
gatorwalk-factory: prepare to ship (fast_forward) for work already done
gatorwalk-factory: a workflow stage cannot say where its workflow lives (gap 3)
gatorwalk-factory: the Lab issue stays current only if the driver remembers assign and publish
DuplicateTypeError names the incoming extension as the existing claimant and reports a false ghost row when it sorts first
Docs: use-the-audit-timeline should state the permission swamp audit --server needs
issue-lifecycle triage fails with 422 when the primary issue is already in_progress in swamp-club
Docs: worker-fleets TLS one-liner fails with KeyMismatch on macOS LibreSSL
Docs: sensitive values read through expressions are delivered like vault.get (swamp-club#2171)
serve: define and supply the collective and owner grant condition variables
managedConfig: most CLI config writes exit 0 when the push to the datastore fails, leaving the change unpublished
Leaderboard: top-tier username styling (tier-sovereign-text) reads like core-team styling
No first-class workflow primitive for spawning a permission-scoped agent session
gatorwalk-factory: add issue-lifecycle's complete shortcut to swamp-extensions.yaml as per-stage exits (gap 6)
gatorwalk-factory: work-item keys are a title slug plus a short random suffix
Install extensions by stage and swap, with a journal and crash recovery
gatorwalk-factory: drive a swamp-extensions Lab issue end to end through the swamp-club adapter (gap 1)
managedConfig: extension rm on one serve instance leaves the extension's types registered on its peers
A pulled extension can shadow a built-in type, and removing it leaves serve without the built-in
PulledExtensionsLock timeout names the lock file with a forward slash on Windows; Windows CI fails on main
definitions: delete() silently leaves an auto-definition file unless an earlier lookup cached its path
Docs: describe how enrollment token revoke disconnects connected workers
vault create/migrate --config help says local_encryption 'always uses' the server key source
Relationships
≡ duplicate of #2776#2779 gatorwalk-factory: the dispatch packet does not say which products the stage records or their schemas
Opened by skunk-ape · 9/30/2026
In the cue trial (work item cue-er7koww5), the first dispatch (plan, 22:06:40 UTC, jsonl line 55) printed the stage prompt and a packet of stage, cycle, mode, skills, subagents, values, inject, problems and ready. It said nothing about what the stage has to record. The driver said "I need the plan artifact's schema too" (22:06:43) and ran swamp data get cue-er7koww5 lifecycle --json | jq '.content // .' | head -300 (line 64) to find plan's required summary, steps[{description, files}] (with additionalProperties: false) and testingStrategy. For the review stages it copied the findings shape from driving.md:263-264 into every reviewer prompt, because the packet doesn't give a subagent the output contract either.
buildDispatch (_lib/dispatch.ts:92-110) builds the packet from stage.work alone. The stage's artifacts, evidence and resultEvidence are never read, and neither are the built-in contracts that apply to them: FINDINGS_SCHEMA for kind: findings (payload_schema.ts:561-582) and OUTCOME_SCHEMA for result evidence. status names a missing product only through a gate failure ("artifact 'plan' has not been recorded"), and only for products a gate reads. So the only full statement of what to record is the pinned lifecycle document, which the skill never tells the driver to read.
Fix direction: add products to DispatchPacket (dispatch.ts:35-55). It holds one entry per artifact and evidence the stage declares: kind (artifact or evidence), name, reviews when set, and schema, the effective contract used to validate a payload (the declared schema combined with the findings or outcome contract, the same pair validateArtifactPayload checks at payload_schema.ts:604-617). The dispatch log already prints the packet as JSON (work_item_ops.ts:1098-1104), so the driver sees it with no other change. driving.md "Do the stage's work" then says to record each entry in products, and to pass a product's schema to any subagent that produces it. Decision for the implementer: inline full schemas (simple, but a stage like cue's check has a 40-line evidence schema printed on every dispatch), or print name and kind plus one swamp data get command that shows the schemas. This goes together with the dispatch-prompt and record-without-retyping issues: if the packet also names a result path per product, the subagent's output contract is complete without the driver writing any of it.
Acceptance: dispatch on a stage with a declared artifact prints that artifact's name and effective schema. A findings stage shows the findings contract. A workflow stage shows the outcome contract for its result evidence. A test in dispatch_test.ts covers all three. In a trial, the driver records products without reading the pinned lifecycle.
Closed
No activity in this phase yet.