Session-start 'swamp model search --json' in the AGENTS.md template is unfulfillable - wire it to a hook or drop it
Flaky property test: analyzeExpression dot/bracket agreement fails when the generated model name is a CEL keyword
Accept usernames for user subjects in grant files
Docs: enable-managed-config should say to re-run config migrate when its push fails
datastore config migrate checks the sentinel in the stale local cache and re-runs a full migration over a shared S3 datastore
datastore config migrate writes its sentinel before pushing; after a failed push a re-run reports 'already completed' and never publishes
extension quality, fmt --check and push disagree: bare-specifier severity, cache hit skips gates, gate failure hides the rubric, fmt ignores project config
Docs: grant file reference shows a stale format and omits resources and subjects
Docs: extension push dry-run reference and how-to need the registry checks, API-call list and content hash from Lab #3016
Flaky property test: analyzeExpression hyphenated dot access fails when modelName generates a CEL keyword ("in")
extension quality and push crash with IsADirectory when additionalFiles lists a directory
extension push: a required global argument renders with a stray "" ("text": "string""")
Resolve non-admin actors in dashboard audit logs
A nested structural swamp still waits on its run's lock when the lock holder is not a same-host ancestor (cross-host worker, --server into a non-ancestor serve)
Docs: extension publishing reference is stale on bare specifiers, quality output and fmt config (swamp-club#3022)
Docs: serve authorization page should cover expression-reference checks and the vault.get trust boundary
swamp-extensions: replace bare import specifiers with npm:/jsr: specifiers in first-party extensions
Docs: channel-aware extension push prompts and promote with a manifest (follow-up to #2939)
extension push: 'Requested visibility' line prints to stdout without the logger prefix, twice per run
A nested structural swamp that outlives the run that started it keeps skipping that run's lock while the holder writes
Show signal waits to remote clients and the dashboard
Settle expired signal waits from swamp serve
Resume signalled workflow runs automatically under swamp serve
extension push/quality: structured acceptances for agents, a clearer title than For next time, and an optional reason
Deliver workflow signals through a write-once outcome record instead of writing the run record
Shell steps: a vault.get on a continuation line of a multi-line double-quoted string inside a here-doc is wrapped in quotes
extension push: testing-completeness warns once per generated model (262 warnings in 25 extensions) with no way to mark a package generated
extension push: declare accepted lint warnings where the finding is (inline swamp-review-ignore comments, a sidecar review file beside the manifest), reported in quality, push and the registry
Docs: manual describes the old extension push path resolution (manifest argument, --extensions-dir scope, global skill fallback) after swamp-club#3018
extension push: --extensions-dir is ignored for bundled workflows
extension push: sub-directory extensions cannot be found from outside their directory (manifest path, directory argument, --extensions-dir for workflows and skills)
GCP bigquery datasets update cannot target the dataset: reads the id from a name field datasets do not have
extension push: the undecided private-entitlement verdict still says the registry may start a trial at publish
seed:collective cannot produce a superseded personal trial or a returned trial, so the UAT cannot cover them
Replayable state fragments: Git-reviewable desired state for resources changed by model methods
Extension bundler rewrites zod import text inside string/template literals, breaking code-generating extensions
s3-datastore: pull never removes files deleted on the remote, so a peer's next push re-uploads them and undoes `swamp data gc`
swamp-testing withMockedCommand: record env and cwd in CapturedCommandCall
Forward held-lock identity over --server so a loopback nested swamp does not wait on its caller's lock
extension push: registry metadata and content hash label files relative to the repo dir, so a push with --extensions-dir records ../ paths
Share dashboard authentication across tabs for deep links
Docs: vault.get shell references are placed per occurrence, and every single-quoted use is warned about
A nested structural swamp on a same-host remote worker waits on its own step's lock held by swamp serve
Scheduled flaky-test detection is failing
Docs: declared acceptances for extension push warnings (quality.yaml sidecar, swamp-quality-ignore comments, For next time report)
Docs: describe the private-entitlement registry check and the refusal wording in the extension publishing reference
Fail fast when nested structural commands under parallel runs wait on each other's locks
Use whoami entitlement to explain private-extension push refusals
registry: store and show declared acceptances sent in contentMetadata.acceptances at confirm (swamp-club#3021)
@swamp/digitalocean/space-key: update and sync call /v2/spaces/keys/undefined
knowledge-base retrieve persists query output into the state resource, with lifetime infinite and the query text in the instance name
Docs: remove followUpActions from the MethodResult reference in the extension model manual
signal_test: already-settled test fails by chance when a random UUID spells the sender name
Add a wait_for_signal workflow step that pauses a run for a JSON message
Deliver workflow signals through swamp serve
Docs: serve authorization of expression references, env and direct-type runs (swamp-club#2786)
run doctor through serve interrupts a live run of another serve instance when no heartbeats are recorded
extension push --dry-run: authentication verdict prints 'Signed in as .' when the credential is an API key with no username
Docs: dispatch-env-allow and how remote shell steps receive secrets (swamp-club#2760, swamp-club#2791)
Flaky test: WalSink replayed segments are delivered before events written after replay leaves one WAL segment
Remove followUpActions: no model or extension can produce them
Workflow schedule watcher and workflow edit symlink lookup ignore the managed config workflows dir
main is red: repository_dirty_coverage_test fails for UnifiedData.collectGarbage(orphaned deferred write)
isProcessGone always reports alive on Linux under the test task permissions, failing 9 tests on main
Flaky test: WalSink replayed segments are delivered before events written after replay
serve: relative tls cert-file/key-file and --config resolve against the working directory, not the repository
serve --remote-only: step output from workers is never persisted to the run log (history logs always empty)
findBySpec/findByTag lose a workflow step's output after a version is deleted, pruned or rolled back
extension push --dry-run skips auth, collective and version-exists checks, and prints 'No API calls were made' while calling the registry
serve: a failed pull in acquireModelLocks leaves the per-model lock held until serve exits
serve HA: worker enrollment on a replica that lacks the enrollment token's definition may create a second definition (unverified)
serve HA: pull a token's definition on an auth miss so a peer accepts a new token at once
serve HA: a server token minted on one replica is rejected by the other replicas until they restart (auto-definitions/ is only pulled at boot)
data_query_stale_limit_test fails on Linux: a limited page returns names in b, a order
extension push: version-drift check reports 'no previously published version found' when the registry call failed
Run tracker keeps some interrupted workflow rows forever: retention waits for markSettled, which several paths never call
run doctor reads every run record on each run to rebuild the run indexes
Search and list output follows directory iteration order in the definition, workflow, vault and output repositories
extension push: accept attestation-backed adversarial-review evidence (lookup by extension and content hash), generated provenance, and carry the evidence to the registry at confirm (design: Lab #3023)
verify-reviews: whole-extension rubric review for changed hand-written extensions, carried in the attestation and read by publish (design: Lab #3023)
Docs: step and job name rules in the workflows reference
Design: verify the extension push adversarial review through the attestation (whole-extension rubric review as a local verification step, carried in the attestation, read by publish and the push gate)
Workflow load errors print the raw Zod issue dump instead of a readable message
Decide a stricter naming rule for workflow step and job names
Datastore rework Phase 2: find, wrap and warn on hooked writes outside a unit of work (route 2), without removing it (no behaviour change)
stagecraft: read records with data query --single once it ships
Serve audit: WAL replay at startup deletes segments before the store confirms them
Datastore rework Phase 2: one flush path, so every push is a root's flush or checkpoint (no behaviour change)
Flaky test: usePreviewFetch in-flight fetch for A is discarded after switching to cached B
Serve audit: delivered WAL segments are only deleted at shutdown, so a long-running serve fills the WAL
Serve audit: sink filter config in serve.yaml is never validated
Serve audit: two sinks with the same name share one emitter cursor, so the second never receives events
Serve audit: a durable sink write that times out is retried while the first call is still pending, so the store can hold duplicate sequences
Datastore rework Phase 2: root units can checkpoint, and the CLI token commands push mid-command through it (no behaviour change)
extension push: restore --yes waiving warnings (revert the 20261005.154947.0 flag split), keep the accepted-warnings record, --accept-warnings stays as an optional alias
Flaky test: ModelResolver data accessors for a renamed model return the earlier id's record from findBySpec
serve: workflow trigger get/set ignore --config and read/write <repo>/.swamp/serve.yaml, so they disagree with the scheduler
serve --hot-reload: a changed trigger override schedule is logged as applied but the built-in cron keeps firing
serve: a suspended run with an expired gate from a previous serve instance cannot be cancelled by any path
server tokens: concurrent mints of the same name can pair one mint's record with the other's secret, so a credential authenticates as the wrong principal
Docs: data query reference lists a --limit default of 100 and omits --single
data query --limit returns fewer live records than exist and reports limited: false when stale catalog rows fall inside the limit
data get: help example passes --run latest, which is not a recognised run id
Datastore rework Phase 2: remaining serve direct pushes commit through root units (no behaviour change)
macOS autoupdate LaunchAgent fails with EX_CONFIG after self-update; doctor install still reports HEALTHY
workflow reject leaves sibling gates waiting_approval and dependents pending in a failed, retryable run
extension push: credentials-sensitive-field has no word boundaries and flags secretName, TokenReference, credential_id (fourth fix to the rule)
serve: run scheduled workflows concurrently (per-workflow serialization), and report queue delay
Show expired approval gates as expired, with a Cancel action in the dashboard
swamp-extensions publish.yml: pass --accept-warnings alongside --yes now that --yes no longer waives warnings
Serve audit: emitter breaks the durable hash chain and drops WAL events when a non-durable sink fails or lags
Relationships
#3054 Serve audit: WAL replay at startup deletes segments before the store confirms them
Opened by stack72 · 10/5/2026· Shipped 10/6/2026
WalSink.replay (src/serve/audit_sinks/wal_sink.ts) runs at serve startup and, for each WAL segment left from the previous session, calls downstream.write and then deletes the segment straight away. StoreSink.write only appends events to its in-memory batch unless the batch is full, so the segment is deleted before its events are written to any store. If the store put then fails, or serve exits before the batch is flushed, those events are lost from both the WAL and the store. Live delivery no longer has this gap after swamp-club#3039/#3052: a checkpoint deletes a segment only after StoreSink.flush confirms its events. Expected: replay follows the same rule, for example by queuing replayed segments through the normal delivery loop so the next checkpoint confirms them before they are deleted. Found in agent review of the swamp-club#3039 change, which does not change replay.
Shipped
Click a lifecycle step above to view its details.
stack72 commented 10/5/2026, 11:46:43 PM
When this is fixed, check the WalSink paragraph in design/enablers/serve-audit.md (from swamp-club#3039). It says the WAL holds only events the store has not confirmed, which is true for live delivery but not yet for startup replay. Once replayed segments go through the same checkpoint as live ones, that sentence holds everywhere; until then it needs a qualifier.
Sign in to post a ripple.