Commit graph

12007 commits

Author SHA1 Message Date
pulse-triage[bot]
e5d0843851
Show and inspect single stored History readings (#2405)
Some checks are pending
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Provider pair Docker acceptance (push) Blocked by required conditions
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Build and Test / Backend tests (api-2) (push) Blocked by required conditions
Build and Test / Backend tests (api-3) (push) Blocked by required conditions
Build and Test / Backend tests (api-4) (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
## What changed and why
A History chart with one stored reading now shows a visible marker and
its actual timestamp, including a measured zero. Pointer and keyboard
inspection use the same real timestamp instead of an invented
one-millisecond window. Multiple readings, empty results, request
ownership and existing keyboard access remain intact.

Inspection of the existing production chart reproduced a blank series
for a real one-point response. This repairs an existing History surface;
it adds no collection, polling, access or new product surface, and does
not establish resolution of every PBS or TrueNAS symptom.

## Included source
- Reviewed Web candidate `20261002T182804Z-web-product`:
`b112524cd2`, based on
`ad7f7a1063`.
- Complete unpublished range:
`761f714af8f0409c7efff0e95da9f1adc7e3b104..34257d19f64d9bf44e666c1af1663293c0aa19f9`,
including additive integration
`34257d19f6`.
- Reviewed commit identities are preserved. Final frontend source and
dependency manifests exactly match the reviewed candidate. The only
candidate-to-integration differences are the signing-preflight workflow
and its README, already present on current published main.

## Validation and limits
- Recorded reviewed proof `source-sph989yd`: 21,709 tests passed, three
skipped; typecheck, lint, production/embedded builds and budgets passed.
The recorded outcome establishes complete hash-matched output and guest
shutdown.
- Recorded Chromium and WebKit predecessor controls reproduce the
missing series; final desktop/phone checks pass 12 states covering
visible pixels, singleton/zero, pointer and keyboard inspection,
multiple readings, empty response and restored singleton. Representative
screenshots were inspected during review.
- Publication provenance, range whitespace and the full-range
browser-verification guard passed. Final runtime hashes match the
committed browser receipt and reviewed candidate. Sufficient
heavy/browser evidence was not replayed solely for publication.
- Required exact-head CI remains a landing gate. Native panels,
installed acceptance and containing release qualification remain
separate. This PR does not change the frozen v6.4.6 packet or publish a
release.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 19:21:39 +00:00
pulse-triage[bot]
34257d19f6 Merge reviewed single-observation History repair
Change-source: pulse-maintainer
2026-10-02 20:00:39 +01:00
rcourtman
761f714af8
Add a non-publishing Apple signing and notary preflight (#2403)
v6.4.6-rc.1 failed notarization today because the Apple developer
agreement had lapsed, and nothing noticed until a release hit it. This
adds a workflow_dispatch-only check on the hosted macOS runner that
imports the Developer ID certificate into a throwaway keychain, checks
the identity and that the cert has 30 days left, signs and verifies a
throwaway probe binary, and calls notarytool history, which fails while
an agreement is unsigned. It builds, uploads and publishes nothing, has
contents read only, and never runs on pull requests. The maintainer's
nightly release rehearsal dispatches it.
2026-10-02 19:48:24 +01:00
pulse-triage[bot]
b112524cd2 Keep single History observations visible and inspectable
A one-point stored History response drew no visible series and pointer inspection mapped it into a fictional one-millisecond window. Show a centred marker and one real timestamp, including measured zero, and share timestamp geometry with pointer inspection. Preserve multi-point rendering, keyboard access, empty states and request ownership.

Chromium and WebKit reproduce the predecessor defect. Twelve final desktop and phone states verify real canvas pixels, pointer and keyboard inspection, and sparse-to-empty refreshes. Synthetic presentation proof does not establish native collection or release availability.

Change-source: pulse-maintainer
2026-10-02 19:38:38 +01:00
rcourtman
b74789fcc6 Add a non-publishing Apple signing and notary preflight
On 2 Oct 2026 v6.4.6-rc.1 failed notarization because the Apple developer
agreement was unsigned, about an hour into the release. The maintainer's
nightly release rehearsal now dispatches release-signing-preflight.yml from
main on a hosted macos-15 runner. It imports the Developer ID certificate
into a throwaway keychain, requires the identity to be valid and at least 30
days from expiry, signs and verifies a probe binary with a secure timestamp,
and reads the notary submission history with the release key, which Apple
refuses while an agreement is unsigned or the key is revoked. The four
checks are independent and each reports one titled outcome, so one night
names every broken credential. It builds, uploads and publishes nothing.
2026-10-02 19:24:29 +01:00
pulse-triage[bot]
ad7f7a1063
Keep disk temperatures visible without extended SMART attributes (#2401)
## What changed and why
Disk Overview now displays a valid reported temperature even when
extended SMART attributes are missing or empty. Previously an early
return hid that independent reading. Units and configured thresholds are
preserved; invalid readings do not create cards, and the existing
unavailable-details message returns when no details remain. This repairs
the existing storage presentation, without changing collection or adding
a new surface.

## Included source
- Reviewed Web candidate `20261002T163042Z-web-product`:
`442717f409`.
- Complete unpublished range:
`005eb08cb9bce5a8ab8a07379f2a2414c92596b4..68272db93bfba4819438b35171d9b34478bc7a9b`
(candidate plus additive integration commits
`d69aae6347` and
`68272db93bfba4819438b35171d9b34478bc7a9b`).
- The proposal tree exactly matches the reviewed candidate and validated
source `547c255612`; reconciliation retained all reviewed commit
identities. Current upstream main is incorporated unchanged.

## Validation
- Recorded source proof `source-17es3j79`: 2,869 tests across 182 files,
typecheck, lint, production/embedded build and budgets passed, with
complete output and guest shutdown.
- Predecessor Chromium/WebKit controls reproduce the hidden temperature.
Final browser checks passed ten desktop/phone states covering standalone
temperature, critical thresholds, Fahrenheit, missing readings and full
SMART data; screenshots were inspected in the reviewed evidence.
- Publication provenance and range whitespace checks passed. Exact tree
equality makes repeating these checks unnecessary.
- Exact-head PR checks must pass before landing. Synthetic presentation
proof does not establish native appliance collection, whole PBS/TrueNAS
issue resolution, installed acceptance or release availability. This
does not alter the frozen v6.4.6 candidate.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 18:23:37 +00:00
pulse-triage[bot]
68272db93b Merge supplied published main frontier preserving reviewed disk temperature repair
Change-source: pulse-maintainer
2026-10-02 18:12:37 +01:00
pulse-triage[bot]
005eb08cb9
Show failed History refreshes without hiding the last successful readings (#2397)
## What changed
History now distinguishes a successful empty response from a failed
background refresh. Empty charts no longer promise that collection is
running. If a refresh fails, the chart keeps its last successful
readings and source visible, with an accessible warning until recovery
or a target change. Initial load failures remain distinct.

This addresses two misleading states found while improving the existing
Storage/PBS History surface; it does not claim to repair native
collection or resolve every symptom in #1723.

## Included source
- Range:
`1a41c8f0e0c84ac9c9465df2918c88e6b11b48f7..6e410d8430c3aa4db26904005d9e4b61b75935f7`.
- Runtime candidate `c6edeee869`;
assertion and browser-evidence correction
`df18123e7d`.
- Additive integration `6e410d8430`
preserves those commits and incorporates published main. Its complete
tree equals the validated candidate tree.

## Validation
- Recorded offline source proof: 2,814 tests across 181 files,
typecheck, lint, production/embedded build and budgets passed, with
complete output and guest shutdown.
- Recorded Chromium desktop and WebKit phone checks cover 16 states,
including predecessor reproduction, failed/pending refresh, recovery,
target change and initial failure; screenshots were inspected by the
source owner.
- Publication checks: provenance, complete-range browser receipt/content
coverage, canonical contract guard, tree equality and whitespace checks
passed.
- Earlier obsolete-copy assertion, browser selector and timestamp
failures remain recorded; corrected proofs followed them.

These are synthetic source/presentation checks, not native PBS
acceptance or release qualification. Exact-head PR checks and review
remain required before landing. Release placement is separate.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 17:07:55 +00:00
pulse-triage[bot]
d69aae6347 Merge reviewed disk temperature presentation repair
Change-source: pulse-maintainer
2026-10-02 17:47:08 +01:00
pulse-triage[bot]
442717f409 Show disk temperature without extended SMART attributes
Treat optional SMART counters independently from a reported temperature. Preserve units, configured thresholds and the unavailable-details fallback. Cover live snapshot transitions and bind desktop/mobile browser proof.

Contract-Neutral: Existing disk-detail presentation bug fix; no shared frontend primitive, API, ownership, or entitlement boundary changes.
Change-source: pulse-maintainer
2026-10-02 17:37:38 +01:00
pulse-triage[bot]
6e410d8430 Merge supplied published main frontier without changing reviewed source
Preserve exact reviewed History commits and their browser receipts while incorporating the published frontier present at batch start.

Change-source: pulse-maintainer
2026-10-02 17:34:19 +01:00
pulse-triage[bot]
1a41c8f0e0
Keep History readings on target and accessible by keyboard (#2393)
## Outcome
Keep Storage History readings tied to the selected target, and make
individual readings usable without a mouse.

Late responses and polling from a previous target could replace the
selected target's data. The reviewed repair invalidates superseded
requests and clears stale readings while retaining pointer inspection
during matching live refreshes. Keyboard focus, arrows, Home/End and
Escape now inspect actual samples; polite announcements and a taller
tooltip keep timestamp/value readings usable. This improves the existing
History surface, not a new feature.

## Included source
Base `1ecb0d6e49` → proposed
`65a36dd4e7`.
- Target ownership candidate `9dc6bd0ffe..1177e4d143`, integrated by
`cf5d6cdf06`.
- Keyboard/tooltip candidate `0be430813f..65a36dd4e7`, including
corrected geometry and empty-announcement regression assertions.
All reviewed commit identities and ancestry are retained.

## Validation
Recorded exact-source proof `source-haln3xw5`: 1,405 tests, typecheck,
lint, production/embedded builds and budgets passed with complete output
and guest stop. Recorded Chromium/WebKit parent/final browser controls
cover 14 keyboard navigation states plus linked/empty charts and focus
exit; target-selection regressions cover delayed responses and refresh
ownership. Initial browser setup and assertion failures remain recorded
with their corrections.

Publication checks: provenance, whitespace, aggregate completion guard
and committed-range browser receipt validation passed. Existing
sufficient proofs were not replayed. Required exact-head CI and
independent review still apply. Synthetic browser/DOM checks are not
screen-reader or native PBS acceptance, and this PR does not establish
release availability or whole-issue resolution.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 16:21:44 +00:00
pulse-triage[bot]
df18123e7d Align History guardrails and record valid UTC browser proof
A fresh two-engine browser pass verifies the unchanged runtime source. Update the cross-surface empty-state assertions to the truthful copy.

Contract-Neutral: Verification and receipt corrections only; runtime source and subsystem contracts are unchanged.
Change-source: pulse-maintainer
2026-10-02 16:53:57 +01:00
pulse-triage[bot]
c6edeee869 Distinguish empty History from failed background refreshes
Keep the last successful readings and source visible with an accessible warning until recovery or selection replacement. Stop promising future collection for empty history. Cover failure and recovery with request-state and two-engine browser controls.

Change-source: pulse-maintainer
2026-10-02 16:52:26 +01:00
pulse-triage[bot]
65a36dd4e7 Align History regressions with wrapped tooltips and empty announcements
Retain exact geometry controls for the taller tooltip and assert empty announcement text rather than absence of Solid's empty text node.

Contract-Neutral: Test-only expectations for the existing keyboard inspection and tooltip repair; no runtime or interface change.
Change-source: pulse-maintainer
2026-10-02 16:06:13 +01:00
pulse-triage[bot]
6ec5efe0f8 Assert the full History tooltip geometry
Update the prior fixed-height assertion for the taller wrapped-timestamp tooltip and verify its centre remains aligned with the selected sample.

Contract-Neutral: Test-only geometry expectation for the keyboard inspection contract already updated in the parent; no runtime or interface delta.
Change-source: pulse-maintainer
2026-10-02 16:04:03 +01:00
pulse-triage[bot]
0be430813f Make storage History readings inspectable by keyboard
Add focus, bounded sample navigation and polite timestamp/value announcements without changing pointer or target ownership. Keep wrapped tooltip readings inside their box. Validate parent failure and final desktop/phone browser states.

Change-source: pulse-maintainer
2026-10-02 16:02:38 +01:00
pulse-triage[bot]
cf5d6cdf06 Integrate reviewed History selection ownership repair
Change-source: pulse-maintainer
2026-10-02 15:31:48 +01:00
pulse-triage[bot]
1ecb0d6e49
Show storage capacity truthfully and keep PBS diagnostics safe (#2392)
## Outcome
Show missing storage capacity as unavailable rather than as an empty
pool, give PBS users a safe way to distinguish empty History data from
request/display errors, and close gaps in qualification source binding.

- Pool detail rows retain independent valid byte observations, show
`n/a` for missing values, and preserve real zero readings. This repairs
a reproduced misleading display on partial collector snapshots, without
adding a new UI surface.
- The repository and shipped PBS guides address #1723's
live-values-versus-stored-History confusion using the existing signed-in
browser. They explicitly avoid credential exports, Debug logging,
re-enrolment and deleting history. This is diagnostic guidance, not a
claim that the reported PBS failure is fixed.
- The rootful qualification manifest now binds four omitted install-test
files and eleven transitive package roots found by exact closure
validation. Assertions and product runtime are not weakened.

## Included source
Complete unpublished range
`f8eee0c1d562c42ae63bacaba3c461155b462148..46d2727828d20680cdc6d3a1ff1b419c3ec2bca4`:
- Source closure corrections `2ef2afef6a`
and `830d2c6c88`.
- PBS guidance candidate `679e561ea7`,
integrated by `027deda747`.
- Capacity repair `60a6c933e0` and
receipt/documentation correction
`ba36925af8`, integrated by
`b731e32e49`.
- Additive reconciliation `3b42a3da67`
retains the published frontier and every reviewed commit unchanged.

## Validation and limits
- Exact combined-head offline frontend proof source-lhrez9r7: 24 focused
pool-presentation/component tests and TypeScript checking passed; output
collection and guest stop completed.
- Recorded browser verification covers five
partial/missing/empty/full/absent states using production components in
desktop Chromium and phone WebKit. Runtime bytes remain identical after
integration; this is synthetic browser evidence, not native storage
acceptance.
- Exact combined-head offline source-57crrlte passed all 21 rootful
attestation/source-closure and ten PBS guide tests; exit 0, complete
output and guest stop.
- Earlier source-imy4mgj2 passed ten PBS recipe/safety tests;
source-x6ah_13c passed 21 attestation tests after the initial closure
failure. That earlier failure remains part of the evidence.
- Provenance, whitespace and source comparisons pass. Required
exact-head CI and independent review remain landing gates. Source
binding checks are not actual rootful Docker qualification, release
readiness, or installed acceptance. The frozen v6.4.6 source is not
changed by this main-line proposal.

## Additive CI integration correction
Canonical Governance run 37016171545 failed because per-commit browser
validation rejected the original timestamp in `60a6c933`, despite the
valid receipt-only correction in `ba36925a`. Retrying unchanged source
would repeat that deterministic failure.

Commit `46d2727828` connects CI to the
existing integration-range browser guard. Every final changed frontend
file must match a valid, parent-bound, non-merge receipt within the
range. Invalid historical receipts contribute no coverage; merge-only
receipts, unverified final edits and missing bases remain rejected. The
guard implementation, browser evidence, runtime bytes and all previously
reviewed commits are unchanged. Canonical contract checks remain per
commit.

At the corrected head, confined native-Git fixtures pass all 19
browser-guard tests (including actual workflow-shell correction and
rejection controls) and all 59 workflow policy tests. Both changed
governance shell steps pass over the complete unpublished range.
Provenance and whitespace checks pass. Prior exact-source frontend,
source-closure and PBS proofs remain applicable because their material
source files are unchanged; no heavy checks were repeated solely for
batching. Independent review and new exact-head CI are still required.
The prior failed run is retained as adverse evidence, not relabelled a
pass.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 14:30:30 +00:00
pulse-triage[bot]
1177e4d143 Preserve History pointer inspection during matching live refreshes
Reset pointer state only when the selection changes, not on supplied sample updates. Add a mounted pointer-refresh regression and recheck delayed-target browser states.

Change-source: pulse-maintainer
2026-10-02 15:23:47 +01:00
pulse-triage[bot]
93531c9cd3 Bind History browser proof and cover accessible selection loading
Use the guard-required UTC receipt format and verify previous readings disappear from the mounted chart while the next target loads. Runtime bytes are unchanged from the completed browser pass.

Change-source: pulse-maintainer
2026-10-02 15:16:24 +01:00
pulse-triage[bot]
9dc6bd0ffe Keep shared History responses bound to the selected target
Invalidate superseded requests and polling, clear stale samples on selection changes, and exercise late completions in runtime and browser regressions.

Contract-Neutral: Correct request ownership in the existing shared chart without changing API, props, entitlements or public surface; dedicated runtime regressions accompany the repair.
Change-source: pulse-maintainer
2026-10-02 15:16:10 +01:00
pulse-triage[bot]
46d2727828 Validate final browser evidence without rewriting reviewed changes
Governance run 37016171545 rejected the original malformed timestamp even though a later reviewed receipt corrected it for identical runtime bytes. Use the existing fail-closed integration-range guard in CI while retaining per-commit canonical checks. Exercise the workflow shell with valid additive correction and invalid missing-base or unverified-content fixtures.

Change-source: pulse-maintainer
2026-10-02 15:04:12 +01:00
pulse-triage[bot]
3b42a3da67 Reconcile published Pulse frontier with retained reviewed integrations
Change-source: pulse-maintainer
2026-10-02 14:42:16 +01:00
pulse-triage[bot]
f8eee0c1d5
Keep TrueNAS polling responsive and disk health rows current (#2387)
## What changes
- Keep TrueNAS polling moving when a peer goes silent. RPC lock waits,
negotiation, exchanges and streams have bounded, cancellable waits; read
retry shares the operation budget, and timeouts retain their correct
classification. Cancelled callers do not dispatch actions or disturb
another caller's session.
- Keep existing physical-disk rows current across live snapshots.
Health, temperature, endurance, identity and detail links refresh
without losing the expanded row or keyboard focus; missing readings
remove obsolete values.

These address a reproduced silent-peer/shared-poll stall and stale keyed
disk rows found while improving storage monitoring. The stall is **not
an established cause of #2382**, and this does not claim appliance
acceptance or complete the broader disk-inventory requests.

## Included source
Complete main range
`8c538b5c2f162c4c57c964a65f9076565d542504..811961243e6418c858c80fd073faf4251fe838d3`:
- TrueNAS candidate `7e369d418f`, with
fixture correction `a291579190`.
- Disk-row candidate `3d77bb5b3c`, composed with current main as
`ffd7c9d993`.
- Reviewed integration `811961243e`.
All reviewed identities and ancestry are retained. Current upstream main
is included unchanged.

## Validation
Reused recorded candidate evidence rather than repeating sufficient
checks for a combined batch:
- TrueNAS: ten predecessor fault groups and corrected controls, complete
TrueNAS and selected monitoring correctness/races, vet/library builds,
and 315 governance tests. The combined audit originally failed on
checkout layout; audit-only `source-kckqy09j` corrected that layout. The
original failure remains recorded.
- Disk rows: `source-8kxzo43q` reports 1,438 tests across 85 files,
typecheck, lint, production/embedded build and budgets, exit 0 with
complete output and guest stop. Recorded desktop Chromium and
phone-emulated WebKit checks cover fault/missing/recovery, focus,
disclosure links and filtering. Retained output-bound/build warnings
remain, not failures silently erased.
- Fresh publication checks: provenance, clean trees, whitespace,
retained ancestry, all per-commit completion/browser guards and the
scoped registry audit pass. Backend files match the reviewed TrueNAS
candidate; the complete frontend matches the tested composition.

Required exact-head checks and independent review still govern merge.
Source and synthetic browser proof are not shipment, installed recovery
or reporter confirmation. Frozen v6.4.6 remains unchanged; compatible
follow-up placement and native acceptance stay separate.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 13:28:07 +00:00
pulse-triage[bot]
b731e32e49 Integrate reviewed storage capacity absence repair
Change-source: pulse-maintainer
2026-10-02 14:04:44 +01:00
pulse-triage[bot]
027deda747 Integrate reviewed PBS History diagnostic guidance
Change-source: pulse-maintainer
2026-10-02 14:04:43 +01:00
pulse-triage[bot]
ba36925af8 Correct storage browser receipt and shared-boundary documentation
The browser run already covered these exact runtime bytes. Correct its UTC timestamp and bind this receipt-only correction to its own parent. Document that missing capacity remains unavailable without changing shared row APIs or layout.

Change-source: pulse-maintainer
2026-10-02 13:59:26 +01:00
pulse-triage[bot]
60a6c933e0 Preserve missing capacity readings in storage pool details
Do not turn absent used capacity into an empty pool or invented free space.
Preserve independently observed bytes and explicit percentages, with guarded
derivation only from known inputs. Cover live drawer transitions and
desktop/phone browser states.

Contract-Neutral: Correct presentation of existing nullable capacity fields; no shared primitive API, layout, collector schema or recovery authority changes.
Change-source: pulse-maintainer
2026-10-02 13:58:40 +01:00
pulse-triage[bot]
830d2c6c88 Cover install-test transitive packages in rootful source binding
Exact closure validation also identified eleven uncovered package roots pulled into the install-test binary. Bind their Go/template inputs without changing runtime or relaxing the attestation assertions.

Contract-Neutral: Additive source-manifest coverage only; no runtime or subsystem contract change.
Change-source: pulse-maintainer
2026-10-02 13:56:45 +01:00
pulse-triage[bot]
679e561ea7 Explain safe PBS History request diagnostics
Distinguish live values, VM history, stored targets and chart request results without Debug logging, agent re-enrolment or credential exports.

Contract-Neutral: Documentation-only clarification of existing PBS History reads; no runtime, API, identity, permission or retention changes.
Change-source: pulse-maintainer
2026-10-02 13:56:30 +01:00
pulse-triage[bot]
2ef2afef6a Bind all compiled install tests into rootful qualification
Include the four current install-test inputs omitted from the rootful source manifest and report exact missing paths on future drift. Product and qualification assertions are unchanged.

Contract-Neutral: Additive qualification source closure and diagnostic-only assertion message; no runtime or subsystem contract change.
Change-source: pulse-maintainer
2026-10-02 13:55:15 +01:00
pulse-triage[bot]
811961243e Integrate reviewed bounded TrueNAS polling with live disk rows
Change-source: pulse-maintainer
2026-10-02 13:18:15 +01:00
pulse-triage[bot]
ffd7c9d993 Compose retained disk-row refresh repair with current main
Change-source: pulse-maintainer
2026-10-02 12:55:04 +01:00
rcourtman
8c538b5c2f
Remove the echo-only release joins and trim unused artifact retention (#2374)
Some checks are pending
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Provider pair Docker acceptance (push) Blocked by required conditions
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Helm CI / Lint and Render Chart (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
First step of the release simplification plan. create-release.yml loses
candidate_qualification and release_readiness, which only restated other
jobs' results. Their exact predicates move into publish_release_tag,
publish_docker, publish_helm_chart, activate_release and
release_commit_verdict, with cancellation unchanged.
recover-release-activation accepts both run shapes, so v6.4.6 and older
runs recover exactly as before. Failure-only diagnostics and the chart
artifact nobody downloads keep 3 days instead of 14 or 90. Only lines
cut from main after this land use it (release/v6.6 from 7 Oct). Reviewed
with gpt-6.1-sol, SAFE TO MERGE; predicate equivalence sampled over
2,784 cases.
2026-10-02 12:50:52 +01:00
pulse-triage[bot]
a291579190 Keep timeout fixtures specific to the stalled RPC surface
The first snapshot control also stalled the unrelated app-stat stream. Model its valid empty reply and the proper stream field shapes in the two-connection poller fixture without weakening timeout, session, inventory or recovery assertions. Clarify that initial transport negotiation is bounded separately from each serialized RPC operation; runtime timeout policy is unchanged.

Contract-Neutral: Correct synthetic fixture responses and clarify the existing budget description; no runtime or wire behaviour changes.
Change-source: pulse-maintainer
2026-10-02 12:37:03 +01:00
pulse-triage[bot]
7e369d418f Bound TrueNAS RPC operations and keep polling after silent peers
Apply the configured timeout to serialized JSON-RPC operations, subscriptions and permitted read retries. Let cancelled waiters leave without dispatching or poisoning the active session. Preserve modern transport selection and action no-replay; distinguish caller deadlines from successful bounded log tails.

A required-method timeout must preserve cached host identity and previous success while allowing the next connection and recovery poll to proceed. Optional telemetry remains unavailable without blocking usable inventory. This repairs reproduced source paths, not a verified diagnosis or native resolution of issue #2382.

Change-source: pulse-maintainer
2026-10-02 12:27:35 +01:00
pulse-triage[bot]
cdbf125267
Keep Apprise diagnostics private and signed setup instructions fail closed (#2385)
## What changed and why

Apprise diagnostics now retain safe outcome classes, HTTP status and
counts instead of notification targets, endpoint paths, provider output
or alert contents. Reproduced parent controls showed that those fields
could disclose credentials and private messages through logs, test
responses, delivery audits and dead letters. Delivery inputs,
authentication, TLS/SSRF checks and retry policy are preserved; this
does not clear historical records or establish previous production
exposure.

The English, German and Spanish getting-started instructions now stop if
either signed installer download or signature verification fails, rather
than executing stale local bytes. Existing plan descriptions and the
paired app's retirement guidance are corrected, with shipped
translations synchronized. Copied agent-guide regression checks require
a fresh receipt for each command, preventing a skipped command from
borrowing a previous installation's result. No new product feature or
entitlement change is introduced.

## Complete range

Published main `7acf982e81` through
proposed head `6cf72e6d88`:

- Fresh guide receipts: candidate
`98e489729a`, integration
`bbd7f62eed`.
- Getting-started safety and current guidance:
`439604c0bd` and mirror correction
`5ad50ea7d4`, integration
`5635f74043`.
- Apprise confidentiality: `1ce98f2693`,
additive fixture correction `2e331d594d`,
governance correction `b16e37820a`,
integration `33d6d729c1`.
- Additive upstream reconciliation
`1adc8abc42` and
`6cf72e6d88` retain the published
dependency-advisory setup-node caching correction.

Every reviewed commit and its author is preserved. The final Apprise,
guide-test and translated-mirror files match their reviewed candidates
exactly; upstream modifies a separate workflow.

## Validation and limits

- Recorded `source-9fzv58an` reproduced seven parent disclosure groups
and passed eight final Apprise groups plus races. `source-ivf9fh1q`
passed complete affected alerts/notifications/alerting correctness,
races, vet and library builds. `source-aghmc0ml` passed 333 governance
tests, final focused controls, vet and builds on the corrected
candidate. Complete outputs and guest teardown were recorded.
- Recorded `source-mbbiw5y1` passed all eight agent-guide tests and
rejected the skipped-profile adverse control that its parent accepted.
The unchanged documentation checks retain their separate eleven-profile,
request-ID and 25 Docs/link proofs. An older 97-pass/one-timeout guide
attempt remains adverse, not a suite pass or a diagnosed load problem.
- This gate passed the four getting-started fixture tests, the 211-file
public-documentation check and the 62-document shipped-mirror check on
composed source. An initial follow-on command used a nonexistent
hyphenated script name; the four fixture tests had already passed, and
the omitted checks then ran using their correct names.
- Provenance, whitespace, clean source, reviewed-tip ancestry and
candidate-byte preservation checks passed. Sufficient affected-source
proofs were not repeated merely for the batch merge.

Required exact-head CI and independent review still govern landing. This
is main-source maintenance, not release qualification, deployment or
installed notification acceptance. The frozen v6.4.6 release preparation
is unchanged; compatible release adaptation and installed follow-through
remain separate.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 11:24:26 +00:00
pulse-triage[bot]
6cf72e6d88 Compose reviewed alert diagnostics and setup guidance with upstream CI correction
Preserve every accepted commit while incorporating the published setup-node advisory-cache repair. Upstream changes a separate workflow; retain the proved runtime and documentation candidate bytes.

Change-source: pulse-maintainer
2026-10-02 12:05:07 +01:00
rcourtman
7acf982e81
Pin setup-node caching off in the dependency advisory watch (#2383)
The scheduled dependency advisory watch reads each release line's
lockfile in the default branch's cache scope, so it deliberately writes
no dependency cache. It sets no `cache` input, but the pinned
`actions/setup-node` enables npm caching on its own once `package.json`
names npm as its `packageManager`. Nothing declares that today; adding
it later would silently reopen a default-branch cache write here.

- Set `package-manager-cache: false` on the watch's setup-node step, as
five release workflows already do.
- Assert it in `scripts/tests/test_dependency_advisory_watch.py`;
removing the line fails exactly that test.
- Note in the deployment-installability contract how the
no-dependency-cache promise is kept.
2026-10-02 11:45:56 +01:00
rcourtman
fc9d85c640 Pin setup-node caching off in the dependency advisory watch
The scheduled watch reads each release line's lockfile in the default
branch's cache scope, so it deliberately writes no dependency cache.
It sets no cache input, but the pinned setup-node enables npm caching
on its own once package.json names npm as its packageManager. Nothing
declares that today; adding it later would silently reopen a
default-branch cache write here. Set package-manager-cache: false, as
five release workflows already do, assert it in the workflow test, and
say how the contract's no-dependency-cache promise is kept.
2026-10-02 11:30:08 +01:00
pulse-triage[bot]
3d77bb5b3c Keep physical disk rows current across live snapshots
The keyed platform renderer preserves row owners, but the disk table captured mount-time presentation. Derive current health, readings, placement and target bindings reactively without discarding focus or expanded detail. Cover snapshot replacement, in-place updates, missing evidence and attention-filter recovery; record desktop and phone browser acceptance.

Change-source: pulse-maintainer
2026-10-02 11:17:00 +01:00
pulse-triage[bot]
33d6d729c1 Integrate reviewed Apprise diagnostic confidentiality repair
Change-source: pulse-maintainer
2026-10-02 10:57:53 +01:00
pulse-triage[bot]
1adc8abc42 Reconcile recorded upstream frontier with reviewed local integrations
Change-source: pulse-maintainer
2026-10-02 10:49:49 +01:00
pulse-triage[bot]
5635f74043 Integrate reviewed getting-started safety and retirement guidance
Change-source: pulse-maintainer
2026-10-02 10:48:57 +01:00
pulse-triage[bot]
b16e37820a Align API governance fixture with Apprise confidentiality coverage
Keep the exact backend-payload verification expectation aligned with the added alerting notification tests. Preserve every existing required path, policy and runtime blob; source-3jslpxf8 retained the prior one-of-170 assertion failure.

Change-source: pulse-maintainer
2026-10-02 10:29:18 +01:00
pulse-triage[bot]
2e331d594d Correct Apprise confidentiality queue and API fixtures
Handle nullable retry-row diagnostics while checking the actual attempt audit and DLQ error; verify omitted stored API keys through the established redacted response type and preserve authorised endpoint/target round-trips. Retain the original diagnostic repair and its adverse proof.

Change-source: pulse-maintainer
2026-10-02 10:17:49 +01:00
pulse-triage[bot]
1ce98f2693 Keep Apprise credentials and private payloads out of diagnostics
Suppress raw CLI targets/output, HTTP response bodies and credential-bearing endpoint paths across firing, recovery, tests, queue audits and settings logs. Preserve exact delivery inputs, typed causes and retry classification; retain structured status, counts and safe validation reasons.

Contract-Neutral: Shared agent-lifecycle and storage-recovery references are unchanged; this diagnostic repair alters no agent or storage behaviour, API schema, destination admission or delivery policy.
Change-source: pulse-maintainer
2026-10-02 03:34:36 +01:00
pulse-triage[bot]
b433165658
Restore TrueNAS CORE metrics and keep queued alerts within quiet hours (#2379)
Some checks are pending
Build and Test / Backend tests (api-3) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-2) (push) Blocked by required conditions
Build and Test / Backend tests (api-4) (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Helm CI / Lint and Render Chart (push) Waiting to run
Patrol Qualification Regression / Catalog, scorer, and replay regression (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
## Additional repair in this publication

Restore native TrueNAS CORE monitoring for #2077 across CPU, memory,
measured temperature, device-bound network/disk I/O, and History. Native
RRD rows use external timing and legends rather than embedded
timestamps; empty/null buckets remain distinct from measured zero. CPU
states are normalized, ARC stays aligned with free RAM, stale readings
are not presented as current, graph selection/splitting is bounded, and
absent device graphs cannot produce misleading partial host totals.
Measured temperature also reaches the existing local and persistent
Thermals paths.

The complete publication range is now
`4317db177e341a0ca52b649c258ac43bc0135d0b..b32a4369e7f55c39a4baed0f122336384185618d`.
It preserves every commit in the preceding proposal and adds native CORE
candidate commits `b50313c599`,
`c78840e371`,
`bab5cf77d6`,
`579eee2907`, and
`45eec9a20e`, integrated by
`b32a4369e7`.

The previous head completed its checks. Governance run `36949586647`
failed the remaining subsystem-lookup list assertion, while its reported
build/test, frontend, eight E2E shards/verdict, boundary, docs, security
and benchmark checks succeeded. Additive
`50c24260ca` aligns that assertion with
the existing startup verification, without removing coverage. Because a
corrected head is necessary, the independently reviewed CORE repair is
included now; this does not interrupt a still-checking head.

Recorded CORE validation: `source-7of9at5x` passes full TrueNAS
correctness/races/vet and connected monitoring controls; every TrueNAS
blob is unchanged here. `source-6mf6bu65` reproduces the predetermined
parent thermal-write fault and passes final connected/writer
correctness/races/vet, including local/persistent History and the
local-window fast path. `source-d3jaf8_z` passes real embedded frontend
and server/agent builds using verified matching dependency inputs. The
integrated CORE/monitoring/registry source exactly matches that proved
candidate. Earlier ARC/cancellation failures were corrected, not
dismissed. `source-woncpjdu` remains overall failed after 44 frontend
cases/typecheck/assets passed, because it selected the wrong module's Go
cache; it is not a full pass. Native appliance/browser/containing-stable
acceptance remains separate, with compatible next-patch placement owned
rather than adding this work to the frozen v6.4.6 quartet.

Publication provenance passes; both available upstream tips match the
inventory and are retained ancestors. Current-workspace
registry/contract and per-commit completion guards pass. The gate's
confined native-Git executor passes all 163 subsystem lookup fixtures,
including the previously failed assertion. Earlier proposal evidence
remains applicable to its unchanged scope, as retained here:

## What changed and why

Queued alert notifications recheck the current quiet-hours schedule when
they become due, including continuous schedules and late replay. Held
items do not consume a provider attempt; mixed batches deliver only
eligible alerts, preserving destinations, retry budgets,
acknowledgements, cancellation and recovery. Startup binds saved policy
before persisted work starts. Schedule edits do not accelerate
already-future deadlines.

Agent troubleshooting distinguishes permission from an admitted,
connected command channel, addressing the confusion in discussion #2333.
Notification troubleshooting distinguishes a direct test from real alert
delivery, explains retained-failure recovery and duplicate-retry risks,
and replaces an unbounded email pipe that masked reader failures with
bounded local readers. Both Docker streams and exit status matter; raw
provider bodies may expose private information. Source guides and
shipped mirrors agree.

## Complete range and proposal repair

Published main base `4317db177e` through
proposal tip `57cd5171c2`:

- Quiet-hours runtime/tests/contracts
`5213b794b2`, registry-order correction
`c3f627d0d6`, integration
`defaa2344d`.
- Agent-channel guide `c08583dd54`,
integration `fc4deb6c17`.
- Notification guide/tests `76e1aea061`.
- Additive governance fixture corrections
`96986379d1` and
`57cd5171c2`.

The preceding proposal finished CI: governance run `36940673378` failed
two fixture expectations after the reviewed startup test was added to
the verification registry. The correction aligns all three affected
exact-list expectations, without changing policy, coverage or runtime.
Every previously reviewed identity and author is unchanged. All sixteen
files in the earlier proposal still match it exactly. The newer
independent guide is included now because a corrective proposal head is
needed, not merely to restart an already-running batch.

## Validation

- Recorded `source-5mneylzw` reproduced predetermined predecessor faults
and passed final affected alerts/notifications correctness/races,
bootstrap races, vet and package builds. `source-fmtyrqhz` passed
final-tip equivalence and focused replay/startup races.
- Recorded agent-guide controls and thirteen recipe tests passed in
`source-5y8u5a2z`; `source-059hcqfl` passed 25 documentation/mirror
cases. These are not native appliance recovery.
- This gate's confined native-Git fixture executor passed all 132
governance fixture tests and all 38
notification/request-log/mirror/agent-troubleshooting cases. The first
partial governance correction still failed the later monitoring
assertion; that failed attempt is retained, followed by the complete
correction and pass.
- Public-doc checker passed for 211 Markdown files. Publication
provenance, whitespace, each source commit's completion guard, registry
audit and contract audit passed. Browser guard explicitly skipped: no
user-visible frontend source changed.
- Earlier `source-t_33yywy` had 97 passes and an unchanged agent-profile
timeout; later omitted-check clients did not execute during gateway
restart. Relevant changed-guide checks are now complete; the unrelated
token-profile timeout and frontend-only self-chosen proof remain
separate follow-through, not full-suite passes.
- Optional `source-44iq3ddd` whole-profile VM audit remains failed on
unavailable repository identity/wider layout. Actual-workspace audits
pass, but do not change that receipt. Recorded Go proofs used 1.26.7,
not the declared 1.26.8 environment; no full application build is
claimed.

Exact-head CI must pass before landing. Natural schedule/day/DST,
destination/recipient and installed command-channel acceptance remain
separate. This neither changes the frozen v6.4.6 quartet nor approves
any release; compatible quiet-hours next-patch placement stays owned
separately.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 02:31:40 +00:00
pulse-triage[bot]
bbd7f62eed Integrate reviewed fresh-receipt checks for copied agent setup commands
Change-source: pulse-maintainer
2026-10-02 03:21:19 +01:00