A one-point stored History response drew no visible series and pointer inspection mapped it into a fictional one-millisecond window. Show a centred marker and one real timestamp, including measured zero, and share timestamp geometry with pointer inspection. Preserve multi-point rendering, keyboard access, empty states and request ownership.
Chromium and WebKit reproduce the predecessor defect. Twelve final desktop and phone states verify real canvas pixels, pointer and keyboard inspection, and sparse-to-empty refreshes. Synthetic presentation proof does not establish native collection or release availability.
Change-source: pulse-maintainer
A fresh two-engine browser pass verifies the unchanged runtime source. Update the cross-surface empty-state assertions to the truthful copy.
Contract-Neutral: Verification and receipt corrections only; runtime source and subsystem contracts are unchanged.
Change-source: pulse-maintainer
Keep the last successful readings and source visible with an accessible warning until recovery or selection replacement. Stop promising future collection for empty history. Cover failure and recovery with request-state and two-engine browser controls.
Change-source: pulse-maintainer
Add focus, bounded sample navigation and polite timestamp/value announcements without changing pointer or target ownership. Keep wrapped tooltip readings inside their box. Validate parent failure and final desktop/phone browser states.
Change-source: pulse-maintainer
Reset pointer state only when the selection changes, not on supplied sample updates. Add a mounted pointer-refresh regression and recheck delayed-target browser states.
Change-source: pulse-maintainer
Use the guard-required UTC receipt format and verify previous readings disappear from the mounted chart while the next target loads. Runtime bytes are unchanged from the completed browser pass.
Change-source: pulse-maintainer
Invalidate superseded requests and polling, clear stale samples on selection changes, and exercise late completions in runtime and browser regressions.
Contract-Neutral: Correct request ownership in the existing shared chart without changing API, props, entitlements or public surface; dedicated runtime regressions accompany the repair.
Change-source: pulse-maintainer
The browser run already covered these exact runtime bytes. Correct its UTC timestamp and bind this receipt-only correction to its own parent. Document that missing capacity remains unavailable without changing shared row APIs or layout.
Change-source: pulse-maintainer
Do not turn absent used capacity into an empty pool or invented free space.
Preserve independently observed bytes and explicit percentages, with guarded
derivation only from known inputs. Cover live drawer transitions and
desktop/phone browser states.
Contract-Neutral: Correct presentation of existing nullable capacity fields; no shared primitive API, layout, collector schema or recovery authority changes.
Change-source: pulse-maintainer
The keyed platform renderer preserves row owners, but the disk table captured mount-time presentation. Derive current health, readings, placement and target bindings reactively without discarding focus or expanded detail. Cover snapshot replacement, in-place updates, missing evidence and attention-filter recovery; record desktop and phone browser acceptance.
Change-source: pulse-maintainer
Extract the Windows-independent Docs repair from candidate 136d039de4a1f8f7debfb1f82d4fffd8bf610083. Add trusted scope after sanitization without expanding document-controlled attributes. Preserve table-local scrolling and verify the current eight-header plans table in desktop Chromium and phone WebKit; native Windows work remains separate.
Change-source: pulse-maintainer
Split two existing instructions into plain sentences without changing private-token handling, host-local removal or file ownership requirements. Verify the actual installer and removed-agent guidance and clipboard outputs in desktop Chromium and phone WebKit.
Contract-Neutral: Copy-only sentence changes preserve credential transport, installation and removal contracts.
Change-source: pulse-maintainer
Replace literal credential bootstraps with the exercised bounded Core private-entry pattern, preserve a checked local private-file route for non-terminal FreeBSD command fields, and consolidate Unix repair, upgrade and removal transport without changing token issuance, TLS choice or host identity. Removal does not depend on a new binary preflight. Windows credential transport remains the next rework step. Add executable PTY/file/lifecycle proofs and the missing DOMPurify after-attributes detached-subtree regression, with parent-bound browser evidence.
Change-source: pulse-maintainer
Separate PVE/PBS setup and telemetry credentials from shell source and download URLs. Use silent root/sudo input, private-file handoff, complete downloads and the agent preflight; preserve scope, TLS defaults, single-line paste and coherent rolling-upgrade metadata. Reveal tokens through the existing dialog and discard late issuance after close. Pin executable shell, history, TLS/registration and browser contracts without using real credentials.
Change-source: pulse-maintainer
Use the fulfilled API window and a common observed envelope across metric groups so sparse samples cannot look like a full selected range. Show dated endpoints, retain them with matching failed-refresh data, and clear them on range replacement. Preserve edge observations and reject non-date geometry.
Pin mounted/model regressions, update both affected contracts, and retain production PBS drawer browser proof with its installed-acceptance limits.
Change-source: pulse-maintainer
Resolve pointer inspection against the group's actual stored timestamps. Missing series stay unavailable instead of borrowing neighbours or live readings, while keyboard focus, single samples and scoped refresh recovery remain intact. Add mounted regressions, the shared contract and exact-content browser receipts.
Change-source: pulse-maintainer
Preserve exact reviewed candidate d38e2ec61a and retain both History and update-progress browser evidence. Only the shared receipt file needed resolution; frontend runtime content matches the candidate receipt.
Change-source: pulse-maintainer
Expose existing stored history through labelled native observation controls and dated accessible descriptions. Keep missing samples distinct from live or neighbouring readings, preserve the selected timestamp through refreshes and reset selection at resource/range boundaries. Cover input state and real native browser interaction without changing collection or licence gates.
Change-source: pulse-maintainer
Preserve accepted History recovery and current upstream ancestry after the publication boundary detected an upstream advance. Resolve the browser receipt collision by retaining both original parent-bound records without claiming new browser execution.
Change-source: pulse-maintainer
Updating to v6.4.5-rc.5 and then v6.4.5 left the progress modal on
"Downloading update... 10%" even though the update finished in the
background. The status stream could go silent behind a proxy (Tailscale
Serve, nginx buffering) and the modal only advanced on stream events.
Backend: the update SSE endpoint now sends the current status on connect,
writes events through one ordered writer with an explicit flush, sends a
15s heartbeat and sets X-Accel-Buffering: no.
Frontend: a silence watchdog falls back to status polling, the restart
phase is entered only on real restart evidence (restarting status, the
server going away, or a version change) rather than a single failed poll,
and the page never auto-reloads on unconfirmed completion without a
pre-update version baseline to compare against.
Retain only matching stored observations with an explicit refresh-failure warning and a keyboard-safe scoped retry. Settle latest-read loading when polling overtakes a foreground refresh. Preserve target isolation, licence gates and diagnostic containment with regressions and exact-content browser receipts.
Change-source: pulse-maintainer
Use the existing non-suspending query's source-isolation option so an uncached target or range cannot display or cache former-host observations. Forward AbortSignal to the Charts API without changing matching-cache or same-source polling behaviour.
The assigned-base VM regression has six failures, including former-host cache contamination; the final mock-backed PBS browser check covers delayed reads, withdrawal, failure, late response and locked ranges at desktop and phone widths. Update the shared frontend contract with real renderer/cancellation regressions. Installed #1723 acceptance and the separate exact-graph security repair remain unresolved.
Change-source: pulse-maintainer
Reject editable labels and endpoint token guesses, preserve current backend links and fresh exact reported machine names, and revoke ambiguous retention. Isolate each reconciled PBS row from reusable service/Agent DTOs so a join cannot corrupt its later service target. Desktop and phone browser proof covers three PBS services, nine Agents and present colliding guests after link withdrawal.
Contract-Neutral: No API, schema, route or canonical ownership delta; PBS presentation requires corroborated machine identity and isolates reconciled rows from source snapshots.
Change-source: pulse-maintainer
Retain the Agent target only while the corroborated PBS link remains unchanged. Cover three concurrent PBS guests and fail closed when that link disappears during a host-row refresh gap.
Contract-Neutral: No canonical API or schema delta; this only invalidates a stale frontend correlation when its backend evidence is withdrawn.
Change-source: pulse-maintainer
Do not infer success from a registry badge clearing while a receipt is pending. Keep the action review reachable from the row, preserve inconclusive outcomes, and show completion only from the recorded audit. Add focused state tests and desktop/phone browser proof.
Change-source: pulse-maintainer
Keep route-selected action details and inbox tabs bound to their latest reads so delayed replies cannot replace a newer review or reopen one after close. Preserve server-authored identity and prove the overlap in focused tests and responsive browser navigation.
Change-source: pulse-maintainer
Show an unknown-outcome warning for every receipt-pending review and offer a same-action status re-read without another dispatch. Keep aged audit closure behind its existing admin and server gates, and cover desktop and phone interactions.
Change-source: pulse-maintainer
Preserve the registry-corroborated PBS-to-Agent link on the service row while selecting the Agent host metrics target in the Backups drawer. Reject PVE-only name collisions and retain the target through a transient missing host row. Recompose the unchanged #1723 runtime repair on current main with fresh desktop and phone browser proof.
Change-source: pulse-maintainer
Relay left public checkout on 2026-09-29: it only ever connected the
Pulse Mobile app, which retires on 31 March 2027, and existing Relay
subscribers now carry Pro entitlements. The app still sold it. Every
Community install saw a "Get alerts on your phone ... Available with
Relay and Pro plans" upgrade panel on Alerts destinations, the plan
screen offered a Relay card with "Remote web access via Relay", and the
settings section was called Remote Access although Relay never reached
the web UI.
The Alerts push panel now renders only on instances that have the relay
feature, with no upsell. The settings section, nav, header and locale
catalogs say Pulse Mobile and carry the retirement date. Community sees
only the Pro comparison card and Relay-tier licenses see none; gated
mobile features name Pro as their minimum plan. The relay feature is
labelled "Pulse Relay (Mobile Connection)" in the catalog, plan copy no
longer claims remote web access, the backend pairing diagnostics point
at Settings > Pulse Mobile, and the user docs, including PRIVACY.md,
state that Relay does not provide remote web UI access.
Record fresh offline Chromium evidence for the exact merged web source at 2606c9d36a. The per-commit browser guard requires that verified parent, not the earlier assigned candidate base. Preserve the original protected merges and setup assertion without replaying the UI proof.
Change-source: pulse-maintainer
With AI switched off the empty Actions inbox still said "Patrol runs in
Watch only mode" and pitched Pulse Pro modes, because the autonomy
setting reads as monitor even when Patrol is not running at all. That
tells an AI-off user something untrue and turns an empty page into an
upsell for a feature they turned off (issue #905).
The guidance now requires the same assistantEnabled session capability
that gates the Assistant launcher and the Patrol navigation, and falls
back to the plain empty-state copy otherwise.
Issue #905 asked for every AI entry point to disappear when AI is
switched off, and the Assistant launcher still honours that through the
assistantEnabled session capability. Patrol did not: v6 added it as a
permanent top-level tab, mobile bottom-bar slot, g r shortcut and
command-palette entry, and the palette also kept offering Assistant
commands. Patrol cannot run without a configured provider, so an AI-off
install carried a tab that only led to an "off" page.
Gate all of those on the same capability as the Assistant launcher.
Settings keeps its Patrol and Assistant items and /patrol stays
reachable, so the path back to turning AI on is unchanged.
Also rename the System settings item "Pulse server updates" to
"Updates" and drop "runtime" from its description. The item already sits
in the System group, and the description still sends agent updates to
Infrastructure, which was the reason for the longer name.
The API-connected next step and combined-source option still implied that installing a Proxmox agent always supplies temperature and SMART readings. Describe them as host-local telemetry only where available in English, German and Spanish, cover both states in tests, and bind twelve rendered locale/viewport states.
Contract-Neutral: Copy-only clarification of conditional sensor coverage; installer behaviour, sensor support and credential scopes are unchanged.
Change-source: pulse-maintainer
Make the setup-completion guidance explain that users run the host installer
and that sensor and workload coverage varies by platform. Align English,
German and Spanish copy, update coverage tests, and bind a rendered desktop
and narrow-browser receipt.
Contract-Neutral: Correct misleading first-source copy only; installer behaviour, sensor support and credential scopes are unchanged.
Change-source: pulse-maintainer
The first rewrite told users that Proxmox, TrueNAS and VMware need
nothing installed, which reads as "do not put the agent on them". On
Proxmox that is wrong: the API does not report node temperatures or SMART
disk health, and the agent on each node does. TrueNAS already reports
both through its API, and ESXi hosts take no agent, so the copy now says
to start with the API and add the agent on Proxmox nodes.
Contract-Neutral: copy-only: correct first-source copy about the agent on Proxmox nodes; no runtime, API or primitive change
After security setup, the screen asked new users to choose "how the first
system should enter the unified infrastructure model: platform API
inventory, Pulse Agent telemetry, or both", under a "Choose the first
source strategy" heading. Someone who only wants their Proxmox server on
screen knows none of those terms, and this is where most never-activated
installs stop: in the week to 2026-09-28, 280 of 596 persistent installs
that never monitored anything had finished security setup and then never
configured a connection.
The screen keeps its structure and routing. The copy now says what to
do and what each path shows: connect Proxmox, TrueNAS or VMware by API
with nothing to install, add the agent for temperatures, disk health and
Docker, or both. German and Spanish follow, and the agent-lifecycle
contract records the plain-words rule.
Contract-Neutral: copy-only: plain-language first-source setup copy; owning agent-lifecycle clause updated; no runtime, API or primitive change
The unlock screen told Docker users to run `docker exec` from the host,
which does not fit the Unraid, Portainer and TrueNAS app UIs, where the
console already runs inside the container. Those `container_other`
installs are the largest group stalling before first setup: in the week
to 2026-09-28, 158 of 3114 persistent Docker installs never got past
first start, against 94 of 5462 binary and systemd installs.
The startup log also suggested revealing the token "by reading the token
file path". That file holds ciphertext, as the security-privacy contract
requires, so anyone following the hint pasted JSON the unlock screen
rejects. The log now names the command, including the console form, and
the install docs and the contract gain the same guidance.
Contract-Neutral: copy-only: new unlock-screen command row and corrected startup log text; no API payload, lifecycle, storage or primitive change; owning security-privacy clause updated
Combine the protected schema-v18 sender with the exact-archive updater. Require installable archives in positive fixtures, classify missing archives and unavailable Pro checks without claiming an offer, and avoid caching an unactivated Pro result. Record the contract and exact combined-source browser receipt.
Change-source: pulse-maintainer
A failed update check never reaches the update history, because nothing
was applied, so telemetry could not tell an install whose check is broken
from one that was offered an update and ignored it. The 6.4.3-rc.1 installs
looked healthy while their check failed on every call (#2282).
The update manager now records a closed outcome for every check on the
install's effective channel (up_to_date, available, no_release,
rate_limited, network_error, metadata_error, skipped, error), tagging
lookup failures without changing their error text, and ignores previews of
another channel from Settings. Telemetry schema v18 exports update_channel,
update_check_outcome and update_available. No version, URL or error text
leaves the install. The Settings preview type, privacy disclosure, adoption
report and subsystem contracts are updated to match; the Pulse Pro receiver
change lands separately and the parity check passes against it.
Keep linked guest physical-disk summaries in the initial Workloads bundle while loading SMART cards and history only when a disk opens. Show a loading status, preserve keyboard and pointer behaviour, and cover desktop and narrow browser states with a same-commit verification receipt.
Change-source: pulse-maintainer
The SSO mapping and Patrol changes were verified together in Chromium at desktop and phone widths. Bind the receipt to all three final frontend source blobs so candidate-wide preflight checks the actual composed source.
Change-source: pulse-maintainer
Retain the focused Patrol setup task while mounting the independent attention inbox when Patrol is off or model readiness is blocked. Reconcile the existing page test and cover responsive list, decision detail, return and remount states.
Refs #2257
Change-source: pulse-maintainer
Parse group-to-role entries by comma or newline, retaining spaces in IdP group names while leaving scopes and allowed-list parsing unchanged. Cover provider edit/save/reload in model, panel, architecture and desktop/narrow browser checks.
Refs #2266
Change-source: pulse-maintainer
Scope physical-disk reads to the opened guest, preserve agent RAID in the drawer, and prove the desktop and narrow interaction states with the performance contract updated in this same commit.
Change-source: pulse-maintainer
Carry changed resource IDs into the Workloads projection so periodic deltas
reuse unchanged rows. Index canonical aliases after ingest and resolve
identity-only links without cloning resources. Remove repeated group payloads
from windowed Storage rows, and keep fleet notices and Agent Doctor usable at
narrow widths.
Record the browser proof and remaining payload and benchmark observations in
the owning subsystem contracts.
Refs #2199
Rejected active-alert writes still reached history, firing events and
notification dispatch. Make admission explicit across detector and restore
paths so repeated suppressed observations cannot create those side effects.
Reconcile restored alerts when persisted resource policy attaches at startup,
reconcile again after native aliases become canonical, and refresh shared
state before those alerts reach clients.
Preserve occurrence identity when retained alerts re-fire, including durable
history reconstruction and delayed lifecycle replay.
Keep retained table and card components mounted when scrolling shifts the
visible window, so policy editors do not lose unsaved state. Show actual
future maintenance times and the paused-attention effect.
Keep synthetic host machine identities stable across restarts so saved
operator policy remains attached during verification.
Qualify server update and rollback instructions by helper ownership, and
stop signed installer recipes before execution if a download or signature
check fails.
Refs #2237
With no custom logo, Settings > General > Application branding previewed
the header with a hand-drawn stand-in: a blue circle holding a "●" text
character, which does not look like the Pulse logo. The header itself
falls back to PulseBrandMark (blue disc, white ring, white centre dot),
so the preview misrepresented what the header shows. Render the same
PulseBrandMark at the header's size; it follows the app theme in light
and dark.
The reviewed core-runtime commit is merged exactly, and the two browser-verified frontend source files remain byte-identical to its receipt. Rebind only the receipt base to the integration merge so cumulative governance checks retain exact parent identity.
Change-source: pulse-maintainer
The PBS API reports the node hostname about itself, but host-agent correlation only consulted the configured connection label and endpoint. When a connection is configured by IP or a DNS alias the agent never reports, the host agent could not be linked to its PBS connection, so the Backups drawer lost its persisted host history target between snapshots and fell back to the PBS service key, which has no host series (#1723).
Use the reported node name in pbsInstanceCorroboratesHost and expose it on the PBS resource (pbs.nodeName). The Proxmox Backups identity correlation now includes it so the host row stays correlated when the configured endpoint is not a machine-identity token.
Rebuilt on the current canonical pulse tip e994c41c20, which already carries the web-product retention change (5d831b8765). The offline browser fixture now combines both failure modes: the connection is configured by 10.0.0.5 and linked only by the reported pbs.nodeName, and a live refresh can transiently omit the correlated host row. The check passes 12/12 across pbs-only, side-by-side and guest topologies, stable and reordered snapshots, at 1280x900 and 390x844, and never requests the PBS service target.
Contract-Neutral: Behavioral machine-identity correlation fix plus an additive optional pbs.nodeName field; no breaking contract, public API removal, or canonical-ownership change.
Change-source: pulse-maintainer