Relationships
↔ sibling #2927#2924 Auth gate blocks nested swamp in workflow shell steps when the credential is in SWAMP_API_KEY
Opened by hammz · 10/1/2026· Shipped 10/1/2026
Description
With the auth gate (swamp-club#2231), a swamp command run from a workflow's command/shell step is blocked when the credential is in the environment rather than in auth.json:
"code": "auth_gate_blocked", "reason": { "kind": "no_credential" }The outer swamp workflow run passes the gate. The shell model builds the child's environment with createSafeMethodEnv (src/domain/remote/environment_snapshot.ts), which strips every SWAMP_* variable, including SWAMP_API_KEY and SWAMP_SIGNIN_TOKEN, and keeps HOME and PATH. So the nested swamp passes the gate only if HOME has a saved login.
That breaks the setup the gate's own error message recommends for CI ("set SWAMP_API_KEY and SWAMP_SIGNIN_TOKEN"). Any workflow step that calls swamp fails in CI, while it keeps working for someone logged in with swamp auth login.
Stripping SWAMP_* from method children is right for external tools. It now also blocks swamp from calling itself, the case swamp-club#296 handled for locks by passing SWAMP_LOCK_HOLDER_PID to nested commands.
Steps to reproduce
- Put the credential only in the environment:
SWAMP_API_KEY=<key>, withHOMEandXDG_CONFIG_HOMEpointing at an empty directory. swamp repo init --tool none- Add a
command/shellmodel (shell-consumer,run: "echo default") and a workflow whose step runs that model'sexecutewith inputrun: "swamp model search --json". These are swamp-uat's fixturestests/cli/fixtures/models/shell-consumer.yamlandtests/cli/fixtures/workflows/nested-swamp-command.yaml. swamp workflow run nested-swamp-command
Expected: the workflow completes, as it does on 20261001.182044.0-sha.aa8acf26 (before the gate).
Actual on 20261001.202145.0-sha.a3515474: exit 1, "Failed workflow nested-swamp-command". The nested step prints auth_gate_blocked / no_credential.
swamp-uat's tests/cli/adversarial/subprocess_lock_test.ts (adversarial tier 6) fails the same way in CI: both of its tests, with SWAMP_API_KEY and SWAMP_SIGNIN_TOKEN set on the job.
Possible fixes
- Pass the credential to nested swamp processes, as
SWAMP_LOCK_HOLDER_PIDis passed, or - Allow
SWAMP_API_KEYandSWAMP_SIGNIN_TOKENthroughcreateSafeMethodEnv'sallowlist when the child is swamp itself.
Environment
- swamp 20261001.202145.0-sha.a3515474 (also 20261001.191636.0-sha.71c25269)
- Linux x86_64; reproduced locally and on GitHub Actions ubuntu-latest
Related
swamp-club#2916 lists the silent exit of a blocked audit record. In swamp-uat, that same behaviour makes swamp audit record --help print nothing on CI shards whose key has no matching signin token: hook mode checks locally only and gates --help too.
Shipped
Click a lifecycle step above to view its details.