Relationships
#3132 serve check-config: decide how to report restricted-model-types entries that cannot match
Opened by skunk-ape · 10/7/2026
Summary
Decide whether and how swamp serve check-config should report restricted-model-types entries that cannot match any model type.
Context
swamp-club#3129 makes restricted-model-types match a type whatever its leading @ spelling. It also makes swamp serve warn at startup about a bare entry (no leading @) that names no registered type, for example a typo such as comand/shell. Such an entry restricts nothing, so the type it was meant to lock down stays open to non-admins.
check-config is the pre-deploy check people actually run. Under #3129 it reports only restricted-commands entries that are not server request types. It does not check restricted-model-types, because:
- Knowing which model types exist means loading the model registry. That runs the extension loader, which can run catalog repair (a write), and opening the datastore can auto-resolve an extension-backed datastore.
- The
check-confighelp text promises that it reads only the repository's files and never contacts anything.
Under swamp daemon enable, the serve startup warning lands in the daemon log, which is rarely read.
Options
- Leave it as is. Typos are caught only by the serve startup warning.
- Check bare entries against built-in types only. These are compiled in, so no I/O is needed. A bare local-extension type cannot be seen this way, so the warning has to hedge ("not a built-in type; ignore this if it is a local extension type").
- Read the type list from the bundle catalog without running the loader. This stays read-only, but it is new code that must agree with the loader's view of which types exist.
- Load the registry as
swamp access checkdoes, and drop the read-only/offline promise from the help text.
Entries with a leading @ cannot be checked in any option, because extension types can be auto-resolved after startup.
Open
No activity in this phase yet.
Sign in to post a ripple.