Relationships
#3016 extension push --dry-run skips auth, collective and version-exists checks, and prints 'No API calls were made' while calling the registry
Opened by skunk-ape · 10/5/2026· Shipped 10/6/2026
Problem
A green swamp extension push --dry-run is not a green push. Dry-run skips authentication, the collective-membership check, the reserved-collective check and the version-exists check (src/libswamp/extensions/push.ts:551-595, :872), so an author can get a clean dry-run and then fail on push for any of those. #1393 was the same class for the label cap and shipped a local check; this issue covers the remaining registry-side checks.
Two further mismatches:
- With credentials present, dry-run still calls
GET /extensions/{name}/latestfor the version-drift check (extension_push.ts:572-590), and still calls OSV and npm, yet the summary prints "No API calls were made." (renderer:283). - CI runs the real push with
--yesfromswamp repo init --tool noneinside the extension directory (swamp-extensionspublish.yml:113-118), a layout no local dry-run reproduces unless the author does the same by hand.
Expected
- With credentials present, dry-run runs auth, collective membership, reserved-collective and version-exists as read-only checks and reports each result the way the real push would. Without credentials it says which checks it could not run.
- The summary lists the API calls actually made (registry, OSV, npm), or says none were made only when that is true.
- The CI layout is reproducible locally: a documented recipe in the swamp skill, or a flag, so the author can run exactly what publish.yml runs.
Acceptance
- Dry-run against a version that already exists on the target channel reports it, exit non-zero, same wording as the real push.
- Dry-run against a collective the caller is not a member of reports it.
- Dry-run summary for a run that hit the registry lists that call; a run with no credentials and
--skip-upgrade-checksays no calls were made and makes none (verify with a network trace or a fake fetcher).
Out of scope
Explaining entitlement refusals by plan is #1545, which follows this issue in the same lane.
Source: the extension push assessment (2026-10-02, swamp 20261002.194016) and the Extension Push UX Plan, which groups this with its lane and order.
Shipped
Click a lifecycle step above to view its details.
skunk-ape commented 10/6/2026, 4:50:35 PM
Post-ship note (2026-10-06): the first release carrying this (20261006.152703.0) and every release since fail the swamp-uat release UAT in 22 dry-run tests, so stable has not promoted past 20261006.150249.0. Cause: the dry run now runs collective-membership read-only with credentials present, and the UAT fixtures publish under collectives the CI account (@swamp-uat) is not in. The swamp behaviour is as designed; the suite assumed a dry run was registry-free. Fix in swamp-uat (cue work item uat-dry-run: fixtures derive the collective from whoami, positive tests for the new verdicts). One real defect found: the authentication verdict prints 'Signed in as .' for an API-key credential, filed as #3088. Process gap: this item shipped without a UAT work item alongside it, which is how the suite went unadjusted.
Sign in to post a ripple.