Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
AssigneesNone

Relationships

↔ sibling #3039

#3037 Serve audit: two sinks with the same name share one emitter cursor, so the second never receives events

Opened by hammz · 10/5/2026· Shipped 10/6/2026

Summary

AuditEmitter (src/domain/serve_audit/audit_emitter.ts) keys its per-sink cursors by sink.name. When two sinks have the same name, the first successful write advances the shared cursor and the second sink gets an empty slice on every drain, so it never receives any events and nothing is logged.

WebhookSink derives its name from the URL hostname only (webhook:, src/serve/audit_sinks/webhook_sink.ts), so two webhook sinks pointed at different paths or ports on one host collide. SyslogSink uses host and port, so two syslog sinks with different formats to one collector collide as well. Extension audit sinks (swamp-club#2112) will make collisions easier to hit, since the name is chosen by the extension author.

Reproduction

In-process, against main: build an AuditEmitter with two non-durable collecting sinks that both report the name webhook:siem.example.com, emit one event, and flush. The first sink receives 1 event, the second receives 0.

Expected

Each configured sink receives every event. Either sink names are made unique (for example by including the full URL or a config index) and duplicates are rejected at config load, or the emitter keys delivery state by sink identity while keeping cursor continuity across hot-reload.

Found while triaging swamp-club#2988. Not fixed there, to keep that change scoped to the four defects it lists.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPEDLINKED+ 10 MOREPR_MERGED+ 1 MORESESSION_SUMMARIZED

Shipped

10/6/2026, 12:13:40 AM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 linked sibling of #303910/5/2026, 9:24:50 PM

Sign in to post a ripple.