Relationships
#2788 serve: access reload tracks each grants-dir file under two names, and keeps a deleted file in its results
Opened by mellens · 9/30/2026· Shipped 9/30/2026
Summary
With grants-dir set to an absolute path, swamp access reload reports each grants file twice: once by bare filename (admin.yaml) and once by absolute path (/path/to/repo/grants/admin.yaml). Every grant is then stored twice, with sources file:admin.yaml and file:/path/to/repo/grants/admin.yaml. A grants file that has been deleted from the directory keeps appearing in the reload results under both names, with entryCount: 0.
Environment
- swamp 20260930.100345.0-sha.d7b35116, macOS (arm64)
swamp serve --auth-mode token, running as a launchd daemon- serve config:
port: 9090 host: 127.0.0.1 grants-dir: /path/to/repo/grants grant-reload: manual
- The directory holds three grant files:
admin.yaml,baseline.yaml,builders.yaml
Steps to reproduce
- Start serve with the config above.
- Add a file
grants/zz-probe.yamlcontaining a grant, then runswamp access reload --server http://localhost:9090. - Delete
grants/zz-probe.yaml, then run the reload again. - Run
swamp access reload --server http://localhost:9090 --json | jq -c '.fileResults[] | {filename, entryCount, unchanged}'
Actual
{"filename":"admin.yaml","entryCount":1,"unchanged":1}
{"filename":"baseline.yaml","entryCount":2,"unchanged":2}
{"filename":"builders.yaml","entryCount":2,"unchanged":3}
{"filename":"/path/to/repo/grants/admin.yaml","entryCount":1,"unchanged":1}
{"filename":"/path/to/repo/grants/baseline.yaml","entryCount":2,"unchanged":2}
{"filename":"/path/to/repo/grants/builders.yaml","entryCount":2,"unchanged":3}
{"filename":"zz-probe.yaml","entryCount":0,"unchanged":1}
{"filename":"/path/to/repo/grants/zz-probe.yaml","entryCount":0,"unchanged":1}filesProcessedis 6, not 3, for three files on disk.grantCountis 11.swamp access grant list --jsonshows each file grant twice, once with each source form.zz-probe.yamlno longer exists, but it is still listed under both names. No active grant from it remains ingrant list.builders.yamlreportsentryCount: 2butunchanged: 3.
Expected
- Each file is tracked under one canonical source key.
filesProcessedequals the number of files ingrants-dir.- Each grant is stored once.
- A deleted file drops out of the results after its grants are revoked.
Impact
Access decisions are correct today, because the duplicate grants are identical. But the duplicates make grant list hard to audit. They also risk a manual grant revoke of one copy leaving the other in force; that case has not been tested. Setups that create and delete grant files regularly, such as per-resource grants, will build up stale entries.
Shipped
Click a lifecycle step above to view its details.
hammz commented 9/30/2026, 6:18:41 PM
Thanks @mellens for reporting this! We shipped: Stop serve reading the repository grants directory twice when grants-dir points at it, and stop the file-grant reconcile report from listing deleted files forever and counting revoked leftovers as unchanged. A new resolveExternalGrantsDir drops a grants-dir that is the same physical directory as /grants; serve.ts passes the result to startup load, the auto-reload poller and the manual reload handler, so one change covers all three. Existing absolute-path duplicates are revoked by the first reconcile after upgrade. The reconciler stops counting already-revoked grants as unchanged and reports a missing file only in the reload that revokes its grants.. The fix has been merged and a release is on its way. We appreciate your contribution to swamp.
Sign in to post a ripple.