Skip to content

build(deps): bump swarf to 1778ec0 for the firehose fixes - #175

Draft
Peeja wants to merge 3 commits into
mainfrom
claude/forge-monorepo-poc-p9w0yr
Draft

Peeja wants to merge 3 commits into
mainfrom
claude/forge-monorepo-poc-p9w0yr

Conversation

@Peeja

@Peeja Peeja commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

[From Claude:]

The pin was d5d1a0a5 from 2026-08-21 (ci: request a dev deploy after publishing), nine commits behind swarf's main. Three of those nine are firehose fixes, and ingot is the repo that consumes the firehose directly — revocation/consumer.go streams UCAN revocations through swarf/pkg/client and clears the affected access key's iam caches.

#17 raise the firehose client's SSE scanner limit; read the stream through one sse.Scanner
#18 bound the event MaxEventBytes names, and report the service's error events
#19 report a failed firehose stream to the caller of the handler

#19 matters most here. Before it, a failed stream was swallowed rather than returned, so the consumer could not distinguish a stream that had ended from one that had broken. A silently-dead revocation feed means revoked access keys keep working out of a stale iam cache — the consumer never learns it should be clearing them.

Verification

All with GOWORK=off, per this repo's convention:

  • go build ./... — clean
  • go vet ./... — clean
  • go vet -tags itest ./itest — clean
  • go test ./... — 18 packages ok, 0 failures

Limit: no Docker in my environment, so make itest did not run. CI covers it.

Context, not part of this change

The stale pin was found while auditing in-repo dependency freshness for the fil-forge monorepo work, and the interesting part is why it was stale. This repo has weekly gomod dependabot. In its last 100 PRs, 35 are dependabot's and zero bump a fil-forge/* module — all 35 are third-party (aws-sdk, moby, openbao, pgx, fasthttp).

The cause looks like tagging rather than anything about this repo's config: swarf, hilt and ingot each carry exactly one tag, v0.0.0. A pseudo-version like v0.0.1-0.20260821142121-d5d1a0a56f00 sorts above v0.0.0 (it's a prerelease of v0.0.1, and v0.0.1 > v0.0.0), so there is no newer tagged version for dependabot to offer. sprue, libforge, ucantone, smelt and guppy have no tags at all.

So every fil-forge/* bump across the fleet is currently a manual pseudo-version edit by whoever happens to look. Noted here for the record; nothing in this PR addresses it.

Opened as a draft so nobody feels obliged to review before Petra has looked.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CGAGAib517Ae1kg8SCdcEt


Generated by Claude Code

The pin was `d5d1a0a5` from 2026-08-21 ("ci: request a dev deploy after
publishing"), nine commits behind swarf's `main`. Three of those nine are
firehose fixes, and ingot is the repo that consumes the firehose directly:
`revocation/consumer.go` streams UCAN revocations through
`swarf/pkg/client` and clears the affected access key's iam caches.

  #17  raise the firehose client's SSE scanner limit, and read the stream
       through one `sse.Scanner`
  #18  bound the event `MaxEventBytes` names, and report the service's
       error events
  #19  report a failed firehose stream to the caller of the handler

returned, so the consumer could not tell a stream that had ended from one that
had broken -- and a silently-dead revocation feed means revoked access keys
keep working out of a stale cache.

Verified with `GOWORK=off`: `go build ./...`, `go vet ./...`,
`go vet -tags itest ./itest`, and `go test ./...` -- 18 packages ok, 0
failures. The Docker-backed `itest` suite was not run (no Docker here); it
needs CI.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CGAGAib517Ae1kg8SCdcEt

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants