Relationships
#2829 serve daemon enable writes a unit that crash-loops when serve args are invalid (e.g. missing --admins)
Opened by hammz · 9/30/2026· Shipped 9/30/2026
Description
swamp serve daemon enable writes and starts the service unit without checking the serve arguments it bakes into ExecStart. When those arguments are invalid, enable still prints ✓ Daemon enabled and exits 0. The service then fails on every start and systemd restarts it every RestartSec=10 (the unit has Restart=always), so it crash-loops with nothing shown in the terminal. The error only appears in journalctl.
Found while verifying swamp-club#2824 against a real systemd --user unit.
Steps to reproduce
- Log in:
swamp auth login - Enable in token mode without
--admins:
Output:swamp serve daemon enable --user --auth-mode token --port 19091 --host 127.0.0.1 --repo-dir <repo>✓ Daemon enabled as user service, exit 0. journalctl --user -u swamp-serveshows the service failing about every 10s:swamp[...]: Error: --admins is required when --auth-mode is "token" systemd[...]: swamp-serve.service: Main process exited, code=exited, status=1/FAILURE systemd[...]: swamp-serve.service: Scheduled restart job, restart counter is at 2.- An
--adminsvalue in the wrong format does the same thing (--admins hammz):Error: Invalid --admins value "hammz": expected format "user:<id>", "group:<name>", or "idp-group:<name>"
swamp serve daemon status is the only CLI place this shows up. It's easy to miss because enable reported success.
Expected
daemon enable rejects arguments that swamp serve would reject at startup, and does so before writing or starting the unit. The user should get the same UserError they'd see from running swamp serve in the foreground.
Suggested fix
The auth checks live in buildServeAuthConfig (src/domain/access/serve_auth_config.ts), a pure function that can run up front. The daemon enable action in src/cli/commands/serve.ts could call it on the same options before scheduler.enable(...). Other startup checks that don't depend on runtime state (duration parsing, TLS cert/key pairing, and so on) could also be run early.
Environment
- swamp built from main @ fe52cda6 (+ swamp-club#2824 branch)
- Linux (CachyOS), systemd user manager,
--usermode
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.