Skip to main content
← Back to list
01Issue
BugClosedSwamp CLIPublic
Assigneesstack72

Relationships

#2878 swamp-extensions build-attestation rejects every run: evaluated workflows carry sensitiveFormat (port of swamp-club #2815)

Opened by skunk-ape · 10/1/2026

Summary

With swamp 20260930.234450.0-sha.657fe527, deno task build-attestation in swamp-extensions refuses every verify-build run, so no PR here can be attested even when every verification step passes:

verify-build run 908c5b5c-14a1-43d3-aa27-791cea7b4d30 did not execute verification/workflow-verify-build.yaml as it stands at [REDACTED-SECRET-1]:
  sensitiveFormat is in the evaluated workflow but not the committed definition

Seen while verifying swamp-club #2780 (three verify-build runs, all green, all refused).

Cause

Same as swamp-club #2815, which was fixed in the swamp repo's copy of the harness. swamp now writes a root-level sensitiveFormat: 1 marker (and sometimes writtenReferences) into every persisted evaluated workflow. checkWorkflowProvenance in scripts/build_attestation.ts accepts evaluated-only keys only when isEmptyDefault holds, so sensitiveFormat (1) is reported as a provenance mismatch. origin/main's scripts/build_attestation.ts has no fix (last change #2625).

Fix direction

Port the #2815 fix: strip the persistence-only metadata keys (sensitiveFormat, writtenReferences) from the evaluated document before the provenance comparison, with a unit test in scripts/build_attestation_test.ts that an evaluated workflow carrying them still matches its committed definition.

02Bog Flow
✓OPEN✓TRIAGED○IN PROGRESS◉CLOSED+ 1 MOREASSIGNEDCLASSIFICATION

Closed

10/1/2026, 6:39:04 AM

No activity in this phase yet.

03Sludge Pulse
stack72 assigned stack7210/1/2026, 6:35:14 AM
Editable. Press Enter to edit.

stack72 commented 10/1/2026, 6:39:03 AM

Already fixed on main. The port of the swamp-club #2815 fix landed in 5368cb002 (#403, the gatorwalk-factory relations PR), which did not reference this issue.

What it does: scripts/build_attestation.ts now has RUN_METADATA_KEYS (sensitiveFormat, writtenReferences), and checkWorkflowProvenance skips those two keys only at the root of the evaluated workflow. The same keys nested deeper, and any other extra root key, are still refused. The three unit tests from swamp fe52cda6 were brought into scripts/build_attestation_test.ts.

Verified on main at 5368cb002:

  • scripts/build_attestation_test.ts passes 45/45.
  • Red check: with the skip line removed, the root-metadata test and the unknown-root-key test fail, so the tests do check the fix.

Closing as fixed by #403.

Sign in to post a ripple.