Commit graph

1735 commits

Author SHA1 Message Date
pulse-triage[bot]
07d54cd345 fix(installer): discard unneeded config backup when staging cannot start
backup_existing snapshots the configuration before the update stages, but a
staging disk-headroom failure then exited and left that snapshot behind. On a
small root filesystem each automatic retry added another full backup and made
the low-space condition progressively worse until updates could no longer run
(#2127). Record the snapshot and remove it when download_pulse aborts at the
headroom check, before anything was replaced. Add regression coverage.

Change-source: pulse-maintainer
2026-09-20 17:44:43 +01:00
pulse-triage[bot]
9b004cc787 fix(updates): clear RETURN trap so a successful auto-update exits 0
The RETURN trap installed inside perform_update is shell-global and was left
installed after the function returned. It fired again when a later function
returned, expanding the now out-of-scope local installer_tmp/signature_tmp
under set -u, so pulse-update.service reported a successful install as failed
with 'installer_tmp: unbound variable' (#2128). Clear the trap as it runs and
cover it with a regression test.

Change-source: pulse-maintainer
2026-09-20 17:44:40 +01:00
pulse-triage[bot]
6fdd41b59d chore(governance): register unified disk SMART completion pair
Record the unified physical-disk SMART runtime commit abaca8f9c0 and its
contract/proof follow-up 33260be25b as one reviewed completion unit so the
per-commit canonical guard evaluates the pair together.

Change-source: pulse-maintainer
2026-09-20 16:08:26 +01:00
pulse-triage[bot]
26628bfbcc chore(governance): register private-pair preflight completion pair
Bind the create-release pair preflight commit to the follow-up contract and proof commit as one reviewed completion unit, matching the existing canonical completion history entries.

Change-source: pulse-maintainer
2026-09-20 14:32:56 +01:00
pulse-triage[bot]
a23ba2f5dc docs(release): record the private Pro pair preflight contract
The create-release prepare job now verifies that pulse-enterprise declares docs/release-source-pairs/<expected_source_sha>.json and that it names the frozen public commit before any draft release object exists. Record that obligation in the deployment-installability contract and add the release-promotion policy proof that guards the step and its ordering ahead of create_release.

Change-source: pulse-maintainer
2026-09-20 14:32:46 +01:00
pulse-triage[bot]
a830992573 Merge reviewed candidate 20260920T070025Z-delivery-trust (pulse be6179c2d2)
Refresh reviewed GitHub Actions pins: actions/setup-go 6.4.0 -> 7.0.0, signpath/github-action-submit-signing-request v2 -> v3.0, actions/github-script 8.0.0 -> 9.0.0 with their reviewed pin constants, release-consumer manifest and installer/promotion governance assertions. Clears Dependabot #2094/#2095/#2096.

Change-source: pulse-maintainer
2026-09-20 08:25:11 +01:00
pulse-triage[bot]
be6179c2d2 build(ci): refresh reviewed GitHub Actions pins
Dependabot #2094, #2095 and #2096 bump actions/setup-go 6.4.0 -> 7.0.0, signpath/github-action-submit-signing-request 2 -> 3.0 and actions/github-script 8.0.0 -> 9.0.0. Each proposal is blocked only by the reviewed pin constants, the workflow-trust allowlist, the release-consumer action manifest and the installer governance assertions that hard-code the previous revisions. Carry all three bumps with those artifacts in one commit so the proposals can be closed as superseded.

All three actions keep the node24 runtime and their existing inputs and outputs; no consumer interface, installer behaviour or public contract changes. The deployment-installability and agent-lifecycle workflow references are pin-only.

Contract-Neutral: Reviewed action pin refresh with identical node24 consumer interfaces and unchanged inputs/outputs; no public-contract or installer-behaviour delta.
Change-source: pulse-maintainer
2026-09-20 08:16:44 +01:00
pulse-triage[bot]
4b20362dad chore(governance): register TrueNAS legacy-REST completion pair
Register the reviewed completion pair for the TrueNAS legacy-REST memory telemetry runtime commit and its contract/proof follow-up so canonical governance evaluates them as one unit without rewriting history.

Change-source: pulse-maintainer
2026-09-20 08:10:24 +01:00
pulse-triage[bot]
fbfa870b95 build(deps): pin Playwright to the offline browser runtime line
The npm-minor-patch group (Dependabot #2115) has been held since 17 Sep
because it bundles @playwright/test, playwright and playwright-core
1.56.1 -> 1.63.0 with 12 safe frontend updates. The offline
browser-verification runtime is pinned to Playwright 1.56.1, so a lockfile
bump breaks browser-proof parity; holding the whole group blocked the safe
updates instead.

Ignore Playwright version updates on the governed 1.56.1 line, matching the
docker governed-tag policy, so the remaining grouped updates can be reviewed
on their own. Security updates stay covered by the weekly npm-audit scan and
the frontend dependencySecurity proof. Extend the dependabot config guard to
lock the policy in.

Change-source: pulse-maintainer
2026-09-20 03:23:38 +01:00
pulse-triage[bot]
277caa8833 chore(governance): register FreeBSD checksum completion pair
Register the reviewed completion pair for the FreeBSD checksum-tool fallback runtime commit and its contract/proof follow-up so canonical governance evaluates them as one unit without rewriting history.

Change-source: pulse-maintainer
2026-09-20 02:57:37 +01:00
pulse-triage[bot]
a6a15a64ea docs(installer): record FreeBSD checksum tool contract
FreeBSD base ships sha256(1) but not GNU sha256sum or Perl shasum. Record the fallback contract for the unified and MCP installers and add the MCP installer proof the deployment-installability verification policy requires.

Change-source: pulse-maintainer
2026-09-20 02:57:17 +01:00
pulse-triage[bot]
84b2787ba6 fix(installer): verify checksums on FreeBSD without coreutils
FreeBSD base ships sha256(1) but not GNU sha256sum or Perl shasum, so a
fresh pfSense/FreeBSD host without coreutils failed the download checksum
and refused to install. Route every installer checksum through
installer_file_sha256 and fall back through sha256sum, sha256 -q, shasum and
openssl dgst. install-mcp.sh gets the same sha256 branch. Add a focused test
that hides sha256sum/shasum and asserts the FreeBSD fallback returns the
digest.

Change-source: pulse-maintainer
2026-09-20 02:43:57 +01:00
pulse-triage[bot]
baf6c89dd2 Merge reviewed candidate 20260919T200006Z-core-runtime (pulse bc3da3ad49)
Integrate the reviewed ai-runtime prompt-cache repair (248ada3cc6) with its transport contract (f08b96b968) and registered completion pair (bc3da3ad49). Merge resolved the canonical completion registry against the rehearsal-timeout completion pair already on main by keeping both entries.

Change-source: pulse-maintainer
2026-09-19 22:20:35 +01:00
pulse-triage[bot]
bc3da3ad49 chore(governance): register ai-runtime prompt-cache completion pair
Register 248ada3cc6 as completed by f08b96b968, which records the
Anthropic stable-system-prefix prompt-cache transport contract, so the reviewed
runtime repair is evaluated with its contract as one completion unit.

Change-source: pulse-maintainer
2026-09-19 22:02:19 +01:00
pulse-triage[bot]
712efe55d3 fix(governance): restore safe.directory for completion-history clone
The completion-history validator materialises its completion tree with a shared clone. The proof sandbox strips the maintainer read config and a linked worktree's gitdir sits outside the checkout, so the clone failed with dubious ownership and the preflight reported a history failure instead of validating the registered pair. Give every git subprocess a private config carrying the fixed safe.directory policy, and register the rehearsal backend package-timeout runtime commit together with its deployment-installability contract follow-up as one completion unit. Change-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-19 21:38:48 +01:00
pulse-triage[bot]
d0f138cf26 fix(release): give the rehearsal backend an explicit package timeout
The accelerated rehearsal profile runs the backend as one serial 'go test -json -p 1 ./...', whose Go default per-package timeout is 10m. internal/api exceeded that under ordinary shared-worker load (606.9s at loadavg 5.55 on 2026-09-19) and the run failed with 'panic: test timed out after 10m0s' despite zero test assertions failing. The release profile already budgets 30m per package via run-release-backend-tests.sh. Add PULSE_RELEASE_PREFLIGHT_REHEARSAL_TIMEOUT (default 30m) and pass it as -timeout, and update the worker contract test that pins the exact rehearsal command. Change-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-19 21:24:38 +01:00
pulse-triage[bot]
f569c6a8eb chore(governance): register metrics-store completion pair
The canonical per-commit guard requires pkg/metrics/store.go changes to carry
an accepted proof file in the same commit. The proof for the rollup, retry,
upsert and auto-vacuum repair landed in the follow-up 087bbf8c20
(pkg/metrics/store_additional_test.go). Register the runtime commit e1d97b361e
and its completion commit as one reviewed completion unit so the candidate
preflight validates the pair instead of rewriting history.

Change-source: pulse-maintainer
2026-09-19 19:24:46 +01:00
pulse-triage[bot]
af6e68c0d1 fix(governance): validate completion pairs without a linked worktree
The canonical completion history validator materialised the completion tree with 'git worktree add', which writes administrative files into the reviewed repository's git directory. That directory is read-only inside the maintainer proof sandbox, so the maintainer preflight could not consult the registry that canonical governance already honours. Materialise the tree with a shared local clone instead: it reads the reviewed objects through alternates and writes only inside the disposable temporary directory, so CI and the maintainer pipeline validate the same reviewed pair without relaxing the sandbox boundary.

Change-source: pulse-maintainer
2026-09-19 15:14:26 +01:00
pulse-triage[bot]
1778f7d16c test(release): assert hosted bundle and backend lanes
release_preflight_test still asserted the retired PVE runner labels after 051ce81a72 moved every release channel to GitHub-hosted runners. Assert runs-on: ubuntu-24.04 and the absence of self-hosted/pulse-pve so the test matches the governing workflow contract.

Change-source: pulse-maintainer
2026-09-19 13:50:50 +01:00
pulse-triage[bot]
6a611905be Scope the dedicated proof to quick security setup
Use an exact runtime-file policy before the general API fallback, so setup preservation evidence cannot substitute for unrelated API changes. Assert both setup routing and unchanged organization/RBAC verification requirements. Retain the original failed broader-registry test evidence.

Change-source: pulse-maintainer
2026-09-15 02:28:17 +01:00
pulse-triage[bot]
f04c230afb Bind maintenance stable releases to their soaked source
Apply existing candidate content-drift validation to every future stable promotion, including v6.4 patches. Preserve patch and minor soak durations and the explicit hotfix reason path. Extend regression cases to maintenance releases and give historical unit fixtures explicit source paths rather than reading the live checkout.

Change-source: pulse-maintainer
2026-09-15 00:36:23 +01:00
pulse-triage[bot]
7e21b005fa test(governance): synchronize lifecycle lookup proof fixture
Canonical Governance for PR2082 failed because the host-agent lifecycle lookup expectation omitted the registered physical-disk round-trip regression. Include that exact proof file while preserving strict list equality and the existing runtime implementation and registry.

Change-source: pulse-maintainer
2026-09-14 08:54:07 +01:00
pulse-triage[bot]
455089a81d test(governance): align physical disk proof expectations
Keep the canonical completion guard unit fixtures synchronized with the registered physical-disk runtime proof so governance validates the actual contract inventory.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-13 18:56:25 +01:00
pulse-triage[bot]
ae38b93c0c fix(release): stop public writer chain on workflow cancellation
Preserve successful qualification and optional skipped ancestors while rejecting workflow cancellation independently of completed needs. Cover tag, Docker, Helm, readiness, convergence dispatch and activation; retain evidence and cleanup joins.

Change-source: pulse-maintainer
2026-09-13 14:21:55 +01:00
pulse-triage[bot]
f9569426f5 fix(release): publish qualified tags after optional skipped checks
Use an explicit status guard while requiring successful preparation and qualification. Model the beta skipped-ancestor path and adverse direct prerequisites; retain immutable identity and all release gates.

Change-source: pulse-maintainer
2026-09-13 13:03:02 +01:00
rcourtman
c7c503994b
Merge pull request #2063 from rcourtman/fix/disposable-release-qualification
Some checks failed
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Has been cancelled
Unified Agent Native Verification / Linux x64 (push) Has been cancelled
Unified Agent Native Verification / Windows x64 (push) Has been cancelled
Unified Agent Native Verification / macOS ARM64 (push) Has been cancelled
Unified Agent Native Verification / macOS Intel (push) Has been cancelled
Unified Agent Native Verification / FreeBSD cross-build contract (push) Has been cancelled
Isolate release preparation and qualification on hosted VMs
2026-09-12 18:33:17 +01:00
rcourtman
9e87fae07b Align backend partition proof with hosted release isolation
The native installer suite still required the retired persistent runner
label. Require the fresh hosted runner while preserving the canonical
partition command, capacity checks, watchdogs and cache constraints.
2026-09-12 16:00:04 +01:00
rcourtman
051ce81a72 Isolate release preparation and qualification on hosted VMs
Persistent prerelease runners can retain state from earlier source execution
and influence later admission, build output or qualification. Use the
existing hosted stable-release path for every channel while preserving
exact-source checks, resource planning, watchdogs and release gates.
2026-09-12 15:44:11 +01:00
pulse-triage[bot]
34ba9a5ed9 Merge candidate 20260911T204017Z-core-runtime
Change-source: pulse-maintainer
2026-09-11 21:47:11 +01:00
pulse-triage[bot]
097422837b fix(release): preserve quarantined version identity
Reject historical draft reuse before PATCH when its retained target is not the exact checkout SHA, including missing targets and moving refs. Preserve same-source recovery and activation guards.

Depends on PR2056 qualification-first workflow and immutable tag checks. Executable absent-tag fixtures fail before repair and pass on PR head 9e5e18f0 plus this patch; 53 policy, 6 immutability and 42 trust tests pass. Update the deployment contract in the same commit.

Change-source: pulse-maintainer
2026-09-11 21:43:11 +01:00
rcourtman
9e5e18f008 fix(release): qualify candidates before public version writes
A draft GitHub release does not hide its public Git tag or registry
images. Publishing those before qualification consumed a beta identity
when the candidate later failed.

Stage drafts without Git refs, join exact-source checks before public
tag, Docker and Helm publication, and preserve exposed tag identities.
Keep final digest verification before release activation.
2026-09-11 21:04:46 +01:00
pulse-triage[bot]
45f76ed7a9 fix(release): map 6.4.5 reliability checkpoints to release line
The following notification reliability patch needs an explicit branch binding before selection. Keep 6.4.4 frozen and preserve historical and unlisted patch mappings while testing beta, RC and stable workflow resolution.

Change-source: pulse-maintainer
2026-09-11 00:23:11 +01:00
pulse-triage[bot]
3da2356dda fix(ci): archive durable root-pair candidate
The reviewed diagnostic named an ephemeral proposal commit that is no longer fetchable after its branch was retired, so a hosted checkout could not archive the fixed candidate. Use the merged main commit with the identical reviewed tree, retain the original evidence identity in metadata, and require an exactly balanced AB/BA contract.

Change-source: pulse-maintainer
2026-09-10 19:13:29 +01:00
pulse-triage[bot]
9902c204d0 ci: collect fixed hosted root-route pair evidence
The completed local study did not explain the adverse hosted root comparison. Add an exact-source root-only collector with matched builds, ten alternating samples and retained layout and host evidence, rather than repeat full qualification or relax its threshold. Eight focused mocked collector tests pass; hosted execution remains after independent review and protected landing.

Change-source: pulse-maintainer
2026-09-10 19:03:01 +01:00
rcourtman
bd37ae186a Preserve live agent state over saved enrollment history
Saved enrollment records can correlate with a live Proxmox host after a
reinstall. The continuity overlay then replaced its current agent payload
with an older offline identity, hiding metrics and marking the node offline.

Use canonical matching to add only absent continuity resources. Preserve
current identity, telemetry and provider links without deleting history or
changing token admission. Cover repeated reads and identity collisions.

Refs #1913
2026-09-10 16:00:36 +01:00
rcourtman
837a5b8843 Fix manual update freshness and unknown release dates
Manual checks previously bypassed only the browser cache, so a newly
published preview could remain hidden behind a fresh-looking server result.
Carry explicit freshness to the provider, retain prior evidence on failure,
and omit unknown dates instead of rendering year one.
2026-09-10 15:33:53 +01:00
rcourtman
bd678cfde6
Merge pull request #2026 from rcourtman/docs/release-reliability-priority
Prioritize dependable release delivery
2026-09-10 09:49:23 +01:00
rcourtman
5d862dfce8 Prioritize dependable release delivery
Record clean, consistent releases as the highest current objective.
Keep release consistency explicitly unconfirmed until actual release
and recovery evidence establishes dependable delivery.
2026-09-10 09:05:46 +01:00
pulse-triage[bot]
07ad2a8ea3 fix(alerts): discard pending history reads after clearing
A history request started before a successful clear can return deleted rows afterwards and repopulate the view. Invalidate those reads and settle loading only after the clear succeeds, preserving history on failure and allowing later refreshes.

Change-source: pulse-maintainer
2026-09-10 06:44:37 +01:00
pulse-triage[bot]
ad1cfd33c3 fix(ci): qualify grouped release action pin consumers
The grouped action upgrade leaves signing, network and publication consumer assertions on superseded pins. Align those contracts and check every consumer against reviewed immutable upstream manifests, retaining exact dispatch and release trust boundaries without claiming hosted execution.

Change-source: pulse-maintainer
2026-09-10 00:35:47 +01:00
pulse-triage[bot]
37d1874904 docs(msp): verify published evaluation bundle guidance
Replace obsolete v6.2.1 guidance using retained signed v6.4.1 delivery and payload evidence. Limit privacy claims to the evaluated licence request, synchronize the shipped guide, and adapt the registered deployment regression and contract without claiming installed onboarding acceptance.

Change-source: pulse-maintainer
2026-09-09 20:23:20 +01:00
pulse-triage[bot]
c418ee01c6 Merge setup-node v7 consumer qualification
Integrate the independently reviewed setup-node workflow and contract update alongside the Kubernetes dependency repair.

Change-source: pulse-maintainer
2026-09-09 19:47:11 +01:00
pulse-triage[bot]
e9a1310528 fix(deps): split Kubernetes update with discovery-compatible tests
client-go 0.37 extends the Discovery return interface, which broke the metrics test double in grouped dependency PR #1977. Use the real discovery client over an in-memory HTTP transport so the fixture follows the selected client API without losing metrics and error assertions.

Upgrade only the coordinated Kubernetes modules and their selected transitive dependencies. Leave the unrelated grouped updates unchanged and check cohort alignment in local runtime orchestration, including mixed and incomplete negative cases.

Change-source: pulse-maintainer
2026-09-09 19:30:02 +01:00
pulse-triage[bot]
9a6a5811a7 ci: qualify setup-node v7 consumer contracts
The standalone setup-node proposal lacked lifecycle and deployment evidence. Preserve Node 24, explicit cache controls and native Windows proof steps while upgrading the immutable action revision; add consumer regression coverage for the removed dummy auth-token assumption. Keep grouped signing and deployment action upgrades separate.

Change-source: pulse-maintainer
2026-09-09 19:29:17 +01:00
pulse-triage[bot]
f293d6fe33 fix(release): mark store-history SLO measurement windows
The failed exact rehearsal buffered the store-history latency assertion, preventing resource telemetry from locating its actual test interval. Extend the existing exact API lifecycle allowlist and cover both targets with synthetic pass/fail fixtures without rerunning product qualification or changing thresholds. This is prospective observability, not clearance of the retained latency or crash evidence.

Change-source: pulse-maintainer
2026-09-09 01:34:22 +01:00
pulse-triage[bot]
7de1195416 fix(web): align webhook test custom fields with saved configuration
Manually entered Pushover aliases were normalised on save but not on test, so the test could exercise a different payload. Apply the same normalisation and retain a failing-before parity regression; 56 focused webhook tests pass.

Change-source: pulse-maintainer
2026-09-08 23:29:31 +01:00
pulse-triage[bot]
6edaa56f4f fix(web): avoid prescribing permissions from update access failures
The update evidence reason represents generic permission errors and HTTP 403, not a verified missing Sys.Audit privilege. Report access denial without prescribing a role change, as illustrated by the new #1802 retest. Preserve unavailable and stale evidence semantics. Both focused presentation and drawer suites pass (6 tests).

Change-source: pulse-maintainer
2026-09-08 21:59:40 +01:00
pulse-triage[bot]
4462e43288 fix(release): retain streamed stress-test timing evidence
Buffered package logs cannot map the API stress-test failure to resource telemetry. Stream Go events and retain a bounded target lifecycle with distinct event, receipt and resource collection times, while preserving readable output and pipeline failure status. Synthetic decoder and worker tests cover pass, skip, failure and unavailable telemetry; this does not clear historical qualification or authorise a replay.

Change-source: pulse-maintainer
2026-09-08 20:45:07 +01:00
pulse-triage[bot]
a6f90ec181 fix(release): bound transient convergence API read retries
Scheduled reconciliation run 34264958741 aborted while listing releases after GitHub returned HTTP 504. Allow JSON API reads three attempts with bounded backoff so a transient gateway error need not strand this reconciliation until the next schedule. Discard partial pagination on failure and preserve terminal failure after exhaustion.

Only read helpers opt in; mutations, downloads, log reads and access failures retain their single-attempt behaviour. Focused reconciliation suite passes 42 tests, including new transient-read regressions that failed before the change.

Change-source: pulse-maintainer
2026-09-08 20:02:08 +01:00
pulse-triage[bot]
6988e486f2 fix(web): identify notification destination server failures
The queue and health API expose server_error, but the delivery UI treated it as unclassified. Preserve that diagnosis and direct operators to service availability and server logs before retrying retained deliveries. Add focused label and health guidance regression coverage.

Change-source: pulse-maintainer
2026-09-08 12:54:21 +01:00