Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
datastore config migrate checks the sentinel in the stale local cache and re-runs a full migration over a shared S3 datastore
datastore config migrate writes its sentinel before pushing; after a failed push a re-run reports 'already completed' and never publishes
extension quality, fmt --check and push disagree: bare-specifier severity, cache hit skips gates, gate failure hides the rubric, fmt ignores project config
Docs: grant file reference shows a stale format and omits resources and subjects
Docs: extension push dry-run reference and how-to need the registry checks, API-call list and content hash from Lab #3016
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Resolve non-admin actors in dashboard audit logs
A nested structural swamp still waits on its run's lock when the lock holder is not a same-host ancestor (cross-host worker, --server into a non-ancestor serve)
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
Docs: serve authorization page should cover expression-reference checks and the vault.get trust boundary
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
Docs: channel-aware extension push prompts and promote with a manifest (follow-up to #2939)
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
Deliver workflow signals through a write-once outcome record instead of writing the run record
Shell steps: a vault.get on a continuation line of a multi-line double-quoted string inside a here-doc is wrapped in quotes
extension push: testing-completeness warns once per generated model (262 warnings in 25 extensions) with no way to mark a package generated
extension push: declare accepted lint warnings where the finding is (inline swamp-review-ignore comments, a sidecar review file beside the manifest), reported in quality, push and the registry
Docs: manual describes the old extension push path resolution (manifest argument, --extensions-dir scope, global skill fallback) after swamp-club#3018
extension push: --extensions-dir is ignored for bundled workflows
extension push: sub-directory extensions cannot be found from outside their directory (manifest path, directory argument, --extensions-dir for workflows and skills)
GCP bigquery datasets update cannot target the dataset: reads the id from a name field datasets do not have
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
Extension bundler rewrites zod import text inside string/template literals, breaking code-generating extensions
s3-datastore: pull never removes files deleted on the remote, so a peer's next push re-uploads them and undoes `swamp data gc`
swamp-testing withMockedCommand: record env and cwd in CapturedCommandCall
Forward held-lock identity over --server so a loopback nested swamp does not wait on its caller's lock
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
Share dashboard authentication across tabs for deep links
Docs: vault.get shell references are placed per occurrence, and every single-quoted use is warned about
A nested structural swamp on a same-host remote worker waits on its own step's lock held by swamp serve
Scheduled flaky-test detection is failing
Docs: declared acceptances for extension push warnings (quality.yaml sidecar, swamp-quality-ignore comments, For next time report)
Docs: describe the private-entitlement registry check and the refusal wording in the extension publishing reference
Fail fast when nested structural commands under parallel runs wait on each other's locks
Use whoami entitlement to explain private-extension push refusals
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
@swamp/digitalocean/space-key: update and sync call /v2/spaces/keys/undefined
knowledge-base retrieve persists query output into the state resource, with lifetime infinite and the query text in the instance name
Docs: remove followUpActions from the MethodResult reference in the extension model manual
signal_test: already-settled test fails by chance when a random UUID spells the sender name
Add a wait_for_signal workflow step that pauses a run for a JSON message
Deliver workflow signals through swamp serve
Docs: serve authorization of expression references, env and direct-type runs (swamp-club#2786)
run doctor through serve interrupts a live run of another serve instance when no heartbeats are recorded
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
Docs: dispatch-env-allow and how remote shell steps receive secrets (swamp-club#2760, swamp-club#2791)
Flaky test: WalSink replayed segments are delivered before events written after replay leaves one WAL segment
Remove followUpActions: no model or extension can produce them
Workflow schedule watcher and workflow edit symlink lookup ignore the managed config workflows dir
main is red: repository_dirty_coverage_test fails for UnifiedData.collectGarbage(orphaned deferred write)
isProcessGone always reports alive on Linux under the test task permissions, failing 9 tests on main
Flaky test: WalSink replayed segments are delivered before events written after replay
serve: relative tls cert-file/key-file and --config resolve against the working directory, not the repository
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
findBySpec/findByTag lose a workflow step's output after a version is deleted, pruned or rolled back
extension push --dry-run skips auth, collective and version-exists checks, and prints 'No API calls were made' while calling the registry
serve: a failed pull in acquireModelLocks leaves the per-model lock held until serve exits
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
Relationships
#2981 Fail fast when nested structural commands under parallel runs wait on each other's locks
Opened by hammz · 10/2/2026· Shipped 10/6/2026
Follow-up to swamp-club#2955. Once a nested swamp skips only the per-model locks held for the run or step that spawned it, two parallel workflow steps (or two concurrent swamp serve runs) that each spawn a nested structural command (data gc, workflow evaluate --all, datastore sync, and so on) wait on each other's step lock in the first drain of waitForPerModelLocks (src/cli/repo_context.ts). Each sibling holds its step lock until its own child exits, so both block until SWAMP_LOCK_TIMEOUT_MS and then fail with LockTimeoutError. #2955 makes that timeout error say what happened and documents the pattern. This issue is to detect the cycle and fail fast instead. One direction: each nested drain writes a short-lived draining marker listing the lock nonces it inherited, and a drain waiting on a lock whose nonce another active drain lists fails immediately. A deterministic tie-break lets one side proceed.
Shipped
Click a lifecycle step above to view its details.