Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz

Relationships

#2829 serve daemon enable writes a unit that crash-loops when serve args are invalid (e.g. missing --admins)

Opened by hammz · 9/30/2026· Shipped 9/30/2026

Description

swamp serve daemon enable writes and starts the service unit without checking the serve arguments it bakes into ExecStart. When those arguments are invalid, enable still prints ✓ Daemon enabled and exits 0. The service then fails on every start and systemd restarts it every RestartSec=10 (the unit has Restart=always), so it crash-loops with nothing shown in the terminal. The error only appears in journalctl.

Found while verifying swamp-club#2824 against a real systemd --user unit.

Steps to reproduce

  1. Log in: swamp auth login
  2. Enable in token mode without --admins:
    swamp serve daemon enable --user --auth-mode token --port 19091 --host 127.0.0.1 --repo-dir <repo>
    Output: ✓ Daemon enabled as user service, exit 0.
  3. journalctl --user -u swamp-serve shows the service failing about every 10s:
    swamp[...]: Error: --admins is required when --auth-mode is "token"
    systemd[...]: swamp-serve.service: Main process exited, code=exited, status=1/FAILURE
    systemd[...]: swamp-serve.service: Scheduled restart job, restart counter is at 2.
  4. An --admins value in the wrong format does the same thing (--admins hammz):
    Error: Invalid --admins value "hammz": expected format "user:<id>", "group:<name>", or "idp-group:<name>"

swamp serve daemon status is the only CLI place this shows up. It's easy to miss because enable reported success.

Expected

daemon enable rejects arguments that swamp serve would reject at startup, and does so before writing or starting the unit. The user should get the same UserError they'd see from running swamp serve in the foreground.

Suggested fix

The auth checks live in buildServeAuthConfig (src/domain/access/serve_auth_config.ts), a pure function that can run up front. The daemon enable action in src/cli/commands/serve.ts could call it on the same options before scheduler.enable(...). Other startup checks that don't depend on runtime state (duration parsing, TLS cert/key pairing, and so on) could also be run early.

Environment

  • swamp built from main @ fe52cda6 (+ swamp-club#2824 branch)
  • Linux (CachyOS), systemd user manager, --user mode
02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 2 MOREREVIEW+ 9 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/30/2026, 10:01:20 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz9/30/2026, 6:41:02 PM

Sign in to post a ripple.