Relationships
#2916 Auth gate follow-ups: fail closed when the fail-open window can't be recorded, UX polish (swamp-club#2231)
Opened by stack72 · 10/1/2026· Shipped 10/2/2026
Follow-ups from the verification reviews of the auth gate (swamp-club#2231, swamp PR #2777). Design: design/surfaces/auth-gate.md.
Fail closed when the 24-hour window cannot be recorded (medium)
Without a valid proof, a 5xx from swamp-club passes as offline and records the start of a 24-hour window in auth_fail_open.json. When that write cannot happen, the window never starts, and every run passes for the length of the outage. Two cases: a process that does not own the config dir (a root system daemon on the enabling user's dir), or a read-only config dir. The design doc lists this as an accepted trade-off. The proposed fix: when markFailOpen is due but cannot be persisted, block (reusing unverified_for_a_day or a dedicated reason) instead of passing.
Smaller items
- Ownership: other
runInvocationwrites still ignore config-dir ownership, for examplesaveIdentityCacheand telemetry state. So a root system daemon can still create root-owned files in the user's dir. This is the same as serve daemons today. - The "failing for over 24 hours" message should point at
swamp auth whoami, like the other messages. - The first-time "no account" message is long for interactive users. Move the CI and daemon guidance below the main line, or shorten it to a docs pointer.
- The offline warning is stderr only. Consider a structured signal for JSON consumers.
- A blocked hook (
audit record) exits 0 silently, so users can't tell why their audit trail is empty. Add a troubleshooting note or a one-time hint. buildCommandTree()must run before the real CLI registers the shared command instances. Add a comment saying the order matters.- Point
embedded_public_key.tsat a key-rotation runbook.
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.