The ingestion worker closed writeCh when it observed stopCh. A concurrent WriteWithTier that passed its stopping check, or a WriteBatchSync/WriteBatchBounded caller (which never checks stopping), could then send on the closed channel and panic the process during shutdown. Reproduced deterministically: enqueueWrite after Close panics with send on closed channel, and 8 concurrent monitoring writers racing Close panic in boundedEnqueueAndWait (store.go:1034).
Never close writeCh. Drain already-queued requests non-blockingly, then process them. Late writes land in the buffered channel and are discarded with the store rather than crashing it. Record the invariant in the performance-and-scalability contract and pin it in the accepted store proof file.
Change-source: pulse-maintainer
A removed host agent could re-enroll under a derived base-hex identity because identity resolution forked the machine before the removal block was consulted. The block is keyed on the base machine identity, so the forked ID bypassed it and the machine was silently re-admitted (#2113). ApplyHostReport now consults the base-identity removal block when the presenting token had no prior binding, so a fresh install token clears the block and heals to the base identity while an established distinct forked host (#1753) is left alone.
Record the behaviour in the monitoring and agent-lifecycle contracts and add the focused regression to the accepted monitor.go proof file. Change-source: pulse-maintainer
Change-source: pulse-maintainer
Docker update check compared a single RepoDigest against the registry tag digest, so a current image that carries two RepoDigests (postgres:16.15-alpine3.24) reported update-available. Compare the whole local RepoDigest set in CheckImageUpdate and in the typed update preflight; the primary digest is still reported for display.
Record the behaviour in the monitoring and agent-lifecycle contracts and add focused regression tests in the accepted docker proof files. Proof: go test ./internal/dockeragent/ passes including TestRegistryChecker_MultipleLocalRepoDigestsSuppressFalseUpdate and TestAgent_getImageRepoDigests_MultipleDigestsForOneImage.
Change-source: pulse-maintainer
Read-side registry rebuilds re-run the unified metric sync as often as every two seconds, so one poll observation was re-written many times between polls. The metrics store upserts on (resource, metric, tier, timestamp), so each replay UPDATEs the same row and commits a fresh transaction for no new data, churning the SQLite WAL and driving the disk-write amplification reported in #1966.
Track the last sample handed to the store per series and skip exact timestamp+value repeats before the batch is enqueued. A corrected value at the same observation time is still written, so the guard cannot mask a real change. Record the behaviour in the monitoring and agent-lifecycle contracts and move the focused regression into the accepted monitor.go proof file.
Change-source: pulse-maintainer
release_preflight_test still asserted the retired PVE runner labels after 051ce81a72 moved every release channel to GitHub-hosted runners. Assert runs-on: ubuntu-24.04 and the absence of self-hosted/pulse-pve so the test matches the governing workflow contract.
Change-source: pulse-maintainer
Initialize the persistent CSRF store for middleware tests that construct session-cookie requests, and restore the package test store afterward. This keeps exact release preflight runs from panicking before they can report qualification results.
Update the Pulse Account portal Vitest dependency to 4.1.11, clearing Dependabot security alerts 154 and 155 for Vitest and @vitest/mocker.
Contract-Neutral: Dev-only Vitest security dependency update; no product contract or runtime behavior changed.
Reloading configuration replaced the monitor's config pointer while API and
authentication handlers retained the original object. Tokens created afterwards
could authenticate successfully while Agent Doctor reported an unlisted token.
Refresh the canonical runtime configuration in place before constructing the
replacement manager. Cover repeated reloads, live token creation and revocation.
Use an exact runtime-file policy before the general API fallback, so setup preservation evidence cannot substitute for unrelated API changes. Assert both setup routing and unchanged organization/RBAC verification requirements. Retain the original failed broader-registry test evidence.
Change-source: pulse-maintainer
Sort the dedicated regression path into the existing exact-file list as required by the registry audit. Accepted proofs and enforcement remain identical.
Change-source: pulse-maintainer
The per-commit API guard needs the actual dedicated preservation test declared in its verification registry. Restore that tested artifact and add its exact path to the existing backend API proof list. Retain all existing requirements and reviewed commit identities; no history rewrite, contract-neutral override, or unrelated proof substitution is used.
Change-source: pulse-maintainer
Represent the retained L1 maintenance residual with the required kind and id fields so the status audit resolves its owned follow-up.
Change-source: pulse-maintainer
Link the L1 residual to an explicit owned follow-up when claiming the independent settings repair. Source admission, failed checks, installed recovery and exact-candidate observation remain unfinished rather than disappearing with the claim change.
Change-source: pulse-maintainer
Place the authenticated settings-preservation regression in the established API contract proof surface so the owning contract guard consumes its actual assertions, without waiving verification or changing runtime behavior.
Change-source: pulse-maintainer
Quick security setup previously replaced system.json with defaults even for authenticated force reconfiguration. Initialize only absent settings under the persistence save mutex, preserving existing bytes and read failures. Cover credential rotation, custom and malformed settings, missing settings, and read errors without changing authorization or token scopes.
Change-source: pulse-maintainer
Apply existing candidate content-drift validation to every future stable promotion, including v6.4 patches. Preserve patch and minor soak durations and the explicit hotfix reason path. Extend regression cases to maintenance releases and give historical unit fixtures explicit source paths rather than reading the live checkout.
Change-source: pulse-maintainer
Replacement PR checks were queued behind obsolete runs even after the
previous revision failed. Cancel prior validation only for pull_request
events, preserving completed verdicts for branch pushes and manual runs.
Contract-Neutral: Only PR concurrency changes. Semantic YAML comparison confirms all jobs and triggers, including frontend dependency security checks, are unchanged. No security verification change is warranted. The scheduling contract is updated.
Resolve the PR2087 frontend formatting gate without changing severity behavior or rewriting the reviewed source. Re-run the production-component browser matrix and refresh its content hashes; whole-tree formatting and local TypeScript checking pass.
Change-source: pulse-maintainer
Retain warning severity through email API save/reload and webhook editing instead of coercing it to all. Add adapter round-trip and webhook edit/save regressions for issue #2069 with alerts, API and notifications contracts. Browser verification covers production components at desktop and narrow widths using synthetic settings; backend filtering is unchanged.
Change-source: pulse-maintainer
Canonical Governance for PR2082 failed because the host-agent lifecycle lookup expectation omitted the registered physical-disk round-trip regression. Include that exact proof file while preserving strict list equality and the existing runtime implementation and registry.
Change-source: pulse-maintainer
Keep the canonical completion guard unit fixtures synchronized with the registered physical-disk runtime proof so governance validates the actual contract inventory.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Preserve snapshot refresh and formatted alerts when legacy args are scalar, array or null. Restrict SMART metadata to typed object fields and cover repeated snapshot collection plus error boundaries for #2077.
Change-source: pulse-maintainer
Register the focused skipped-poll regression under monitoring runtime verification as well as the shared lifecycle and read-state edges.
Change-source: pulse-maintainer
Skipped disk polls must write the Proxmox source key back into inventory rather than hashing the canonical resource ID again. Add repeated-cycle runtime and JSON projection coverage for serial-less disks, distinct node/controller scopes and removal.
Change-source: pulse-maintainer
Use an explicit status guard while requiring successful preparation and qualification. Model the beta skipped-ancestor path and adverse direct prerequisites; retain immutable identity and all release gates.
Change-source: pulse-maintainer
Include the canonical 8.0.3.0 release in the API handler fixtures and expected negotiation sequence. This repairs the exact hosted API-suite failure on the reviewed VMware candidate without changing runtime behavior.
Change-source: pulse-maintainer
Probe 8.0.3.0 before the legacy spelling and older API schemas. Issue #2070 demonstrates method routing on the canonical version while Pulse reports 8.0.2.0. Retain legacy fallback and hard authentication/permission failures.
Add canonical negotiation, legacy/older fallback and auth/permission regression controls; update the runtime contract. Five reduced-function race probes fail before and pass after. Full package validation is unavailable with the installed offline dependency cache. This repairs negotiation, not the unresolved metrics/events/folder enrichment report.
Change-source: pulse-maintainer
Selecting a node filters its guests and reveals an off-screen guest
heading without moving results that are already visible. Repeating the selection
clears only the node filter. Keep node details on the
chevron and preserve other guest filters when changing or clearing nodes.
Build node filter options from inventory as well as guests so empty nodes
retain their names and selection after reload. Do not present unrelated
inventory failures as the cause of an empty filtered result.
Refs lane L8. Update the owning interaction and identity contracts.
The native installer suite still required the retired persistent runner
label. Require the fresh hosted runner while preserving the canonical
partition command, capacity checks, watchdogs and cache constraints.
Persistent prerelease runners can retain state from earlier source execution
and influence later admission, build output or qualification. Use the
existing hosted stable-release path for every channel while preserving
exact-source checks, resource planning, watchdogs and release gates.