Repository navigation
Conversation
The pin was `d5d1a0a5` from 2026-08-21 ("ci: request a dev deploy after
publishing"), nine commits behind swarf's `main`. Three of those nine are
firehose fixes, and ingot is the repo that consumes the firehose directly:
`revocation/consumer.go` streams UCAN revocations through
`swarf/pkg/client` and clears the affected access key's iam caches.
#17 raise the firehose client's SSE scanner limit, and read the stream
through one `sse.Scanner`
#18 bound the event `MaxEventBytes` names, and report the service's
error events
#19 report a failed firehose stream to the caller of the handler
returned, so the consumer could not tell a stream that had ended from one that
had broken -- and a silently-dead revocation feed means revoked access keys
keep working out of a stale cache.
Verified with `GOWORK=off`: `go build ./...`, `go vet ./...`,
`go vet -tags itest ./itest`, and `go test ./...` -- 18 packages ok, 0
failures. The Docker-backed `itest` suite was not run (no Docker here); it
needs CI.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CGAGAib517Ae1kg8SCdcEt
# Conflicts: # go.mod # go.sum
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[From Claude:]
The pin was
d5d1a0a5from 2026-08-21 (ci: request a dev deploy after publishing), nine commits behind swarf'smain. Three of those nine are firehose fixes, and ingot is the repo that consumes the firehose directly —revocation/consumer.gostreams UCAN revocations throughswarf/pkg/clientand clears the affected access key's iam caches.sse.ScannerMaxEventBytesnames, and report the service's error events#19 matters most here. Before it, a failed stream was swallowed rather than returned, so the consumer could not distinguish a stream that had ended from one that had broken. A silently-dead revocation feed means revoked access keys keep working out of a stale
iamcache — the consumer never learns it should be clearing them.Verification
All with
GOWORK=off, per this repo's convention:go build ./...— cleango vet ./...— cleango vet -tags itest ./itest— cleango test ./...— 18 packages ok, 0 failuresLimit: no Docker in my environment, so
make itestdid not run. CI covers it.Context, not part of this change
The stale pin was found while auditing in-repo dependency freshness for the fil-forge monorepo work, and the interesting part is why it was stale. This repo has weekly gomod dependabot. In its last 100 PRs, 35 are dependabot's and zero bump a
fil-forge/*module — all 35 are third-party (aws-sdk, moby, openbao, pgx, fasthttp).The cause looks like tagging rather than anything about this repo's config:
swarf,hiltandingoteach carry exactly one tag,v0.0.0. A pseudo-version likev0.0.1-0.20260821142121-d5d1a0a56f00sorts abovev0.0.0(it's a prerelease ofv0.0.1, andv0.0.1 > v0.0.0), so there is no newer tagged version for dependabot to offer.sprue,libforge,ucantone,smeltandguppyhave no tags at all.So every
fil-forge/*bump across the fleet is currently a manual pseudo-version edit by whoever happens to look. Noted here for the record; nothing in this PR addresses it.Opened as a draft so nobody feels obliged to review before Petra has looked.
🤖 Generated with Claude Code
https://claude.ai/code/session_01CGAGAib517Ae1kg8SCdcEt
Generated by Claude Code