Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz

Relationships

#2824 serve daemon: unit sets SWAMP_HOME, which relocates the config dir — token/oauth daemons can't find auth.json and crash-loop

Opened by hammz · 9/30/2026· Shipped 9/30/2026

Summary

swamp serve daemon enable --auth-mode token (or oauth) installs a systemd user unit that can never start. The unit sets Environment="SWAMP_HOME=~/.swamp" (added for extension loading in #2294). With SWAMP_HOME set, getSwampConfigDir() returns $SWAMP_HOME/config instead of ~/.config/swamp. The daemon therefore can't find the auth.json written by swamp auth login, requireAuthenticated fails, and systemd restarts the unit every 10s indefinitely.

daemon enable itself runs in the user's normal environment, so its own requireAuthenticated/requireScope("serve:*") check passes and it reports success.

Reproduction (Linux, systemd --user; verified on main @ fe52cda6 and on 1e41128d)

  1. Run swamp auth login (credentials land in ~/.config/swamp/auth.json).
  2. In a repo, run swamp serve daemon enable --user --port 19116 --auth-mode token --admins user:admin. → ✓ Daemon enabled as user service
  3. Run journalctl --user -u swamp-serve. It repeats every ~10s:
    Error: swamp serve is a team feature that requires a free swamp-club.com account.
    Sign in:
      swamp auth login
    ...
    swamp-serve.service: Main process exited, code=exited, status=1/FAILURE
  4. Confirm the cause: SWAMP_HOME=$HOME/.swamp swamp auth whoami → Error: Not authenticated., while plain swamp auth whoami works. Running the same serve command under systemd-run --user without SWAMP_HOME starts fine.

--auth-mode none daemons are unaffected because they skip the auth gate.

Cause

  • serve.ts daemon enable passes env: { SWAMP_HOME: getSwampDataDir() }.
  • getSwampConfigDir() in src/infrastructure/persistence/paths.ts treats SWAMP_HOME as relocating the config dir to $SWAMP_HOME/config.
  • The data dir default (~/.swamp) and the config dir default (~/.config/swamp) are different trees, so pinning one relocates the other.

Impact

Any authenticated (token/oauth) daemon set up via serve daemon enable on Linux crash-loops. launchd may be affected the same way if the plist sets SWAMP_HOME (not verified).

Suggested direction

Have the unit pin the data dir without moving the config dir. Options:

  • also set XDG_CONFIG_HOME or a dedicated config-dir variable to the enabling user's resolved config dir;
  • or stop deriving the config dir from SWAMP_HOME when it equals the default data dir.

Add a check in daemon enable that the credentials will be readable in the unit's environment.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 7 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/30/2026, 7:18:45 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz9/30/2026, 6:05:01 PM

Sign in to post a ripple.