Relationships
⊘ blocked by #2796#2832 gatorwalk-factory: built-in tracker create must not overwrite a ticket on an id collision
Opened by skunk-ape · 9/30/2026
Follow-up from the #2794 verification review (medium, non-blocking). builtinAdapter.create (gatorwalk-factory/extensions/models/_lib/tracker/backends/builtin.ts) reads issue- and writes it when absent. The read and write are not atomic. On one local repo swamp runs one method at a time per instance, so this is safe. With a shared datastore (the central swamp serve direction), two people filing tickets with the same title slug who draw the same 4-character suffix (about 1 in 32^4) both see no record, and the second write becomes a new version of the first ticket, replacing its title, body and type silently.
Fix options: write with a create-only or expected-version primitive if the datastore offers one, or re-read after writing and refuse when the stored record is not the one just written. Needs #2794.
Closed
No activity in this phase yet.
system commented 9/30/2026, 7:09:32 PM
Classified automatically when this issue was filed.
- Type: Bug
- Source: Extensions
If you feel this classification is incorrect, add a ripple to tell us so.
skunk-ape commented 10/1/2026, 6:32:33 PM
Closing: this race cannot happen. The tracker's create method is a mutating method kind, so swamp takes the per-model distributed lock before running it and holds it until the run ends, both from the CLI (model_method_run.ts, acquireModelLocks) and from swamp serve (serve/handlers/model_handlers.ts). The lock is datastore-wide: the S3 backend uses conditional writes. builtinAdapter.create only reads and writes the tracker instance's own data, and only the tracker's create method calls it, so two people filing tickets against one tracker on a shared datastore take turns, and the second sees the first's record before writing. No change needed.
Sign in to post a ripple.