Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublicTeam
Assigneeshammz

Relationships

#2788 serve: access reload tracks each grants-dir file under two names, and keeps a deleted file in its results

Opened by mellens · 9/30/2026· Shipped 9/30/2026

Summary

With grants-dir set to an absolute path, swamp access reload reports each grants file twice: once by bare filename (admin.yaml) and once by absolute path (/path/to/repo/grants/admin.yaml). Every grant is then stored twice, with sources file:admin.yaml and file:/path/to/repo/grants/admin.yaml. A grants file that has been deleted from the directory keeps appearing in the reload results under both names, with entryCount: 0.

Environment

  • swamp 20260930.100345.0-sha.d7b35116, macOS (arm64)
  • swamp serve --auth-mode token, running as a launchd daemon
  • serve config:
    port: 9090
    host: 127.0.0.1
    grants-dir: /path/to/repo/grants
    grant-reload: manual
  • The directory holds three grant files: admin.yaml, baseline.yaml, builders.yaml

Steps to reproduce

  1. Start serve with the config above.
  2. Add a file grants/zz-probe.yaml containing a grant, then run swamp access reload --server http://localhost:9090.
  3. Delete grants/zz-probe.yaml, then run the reload again.
  4. Run swamp access reload --server http://localhost:9090 --json | jq -c '.fileResults[] | {filename, entryCount, unchanged}'

Actual

{"filename":"admin.yaml","entryCount":1,"unchanged":1}
{"filename":"baseline.yaml","entryCount":2,"unchanged":2}
{"filename":"builders.yaml","entryCount":2,"unchanged":3}
{"filename":"/path/to/repo/grants/admin.yaml","entryCount":1,"unchanged":1}
{"filename":"/path/to/repo/grants/baseline.yaml","entryCount":2,"unchanged":2}
{"filename":"/path/to/repo/grants/builders.yaml","entryCount":2,"unchanged":3}
{"filename":"zz-probe.yaml","entryCount":0,"unchanged":1}
{"filename":"/path/to/repo/grants/zz-probe.yaml","entryCount":0,"unchanged":1}
  • filesProcessed is 6, not 3, for three files on disk. grantCount is 11.
  • swamp access grant list --json shows each file grant twice, once with each source form.
  • zz-probe.yaml no longer exists, but it is still listed under both names. No active grant from it remains in grant list.
  • builders.yaml reports entryCount: 2 but unchanged: 3.

Expected

  • Each file is tracked under one canonical source key.
  • filesProcessed equals the number of files in grants-dir.
  • Each grant is stored once.
  • A deleted file drops out of the results after its grants are revoked.

Impact

Access decisions are correct today, because the duplicate grants are identical. But the duplicates make grant list hard to audit. They also risk a manual grant revoke of one copy leaving the other in force; that case has not been tested. Setups that create and delete grant files regularly, such as per-resource grants, will build up stale entries.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 2 MOREREVIEW+ 9 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/30/2026, 6:17:18 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz9/30/2026, 3:36:16 PM
Editable. Press Enter to edit.

hammz commented 9/30/2026, 6:18:41 PM

Thanks @mellens for reporting this! We shipped: Stop serve reading the repository grants directory twice when grants-dir points at it, and stop the file-grant reconcile report from listing deleted files forever and counting revoked leftovers as unchanged. A new resolveExternalGrantsDir drops a grants-dir that is the same physical directory as /grants; serve.ts passes the result to startup load, the auto-reload poller and the manual reload handler, so one change covers all three. Existing absolute-path duplicates are revoked by the first reconcile after upgrade. The reconciler stops counting already-revoked grants as unchanged and reports a missing file only in the reload that revokes its grants.. The fix has been merged and a release is on its way. We appreciate your contribution to swamp.

Sign in to post a ripple.