Do not turn absent used capacity into an empty pool or invented free space.
Preserve independently observed bytes and explicit percentages, with guarded
derivation only from known inputs. Cover live drawer transitions and
desktop/phone browser states.
Contract-Neutral: Correct presentation of existing nullable capacity fields; no shared primitive API, layout, collector schema or recovery authority changes.
Change-source: pulse-maintainer
First step of the release simplification plan. create-release.yml loses
candidate_qualification and release_readiness, which only restated other
jobs' results. Their exact predicates move into publish_release_tag,
publish_docker, publish_helm_chart, activate_release and
release_commit_verdict, with cancellation unchanged.
recover-release-activation accepts both run shapes, so v6.4.6 and older
runs recover exactly as before. Failure-only diagnostics and the chart
artifact nobody downloads keep 3 days instead of 14 or 90. Only lines
cut from main after this land use it (release/v6.6 from 7 Oct). Reviewed
with gpt-6.1-sol, SAFE TO MERGE; predicate equivalence sampled over
2,784 cases.
The first snapshot control also stalled the unrelated app-stat stream. Model its valid empty reply and the proper stream field shapes in the two-connection poller fixture without weakening timeout, session, inventory or recovery assertions. Clarify that initial transport negotiation is bounded separately from each serialized RPC operation; runtime timeout policy is unchanged.
Contract-Neutral: Correct synthetic fixture responses and clarify the existing budget description; no runtime or wire behaviour changes.
Change-source: pulse-maintainer
Apply the configured timeout to serialized JSON-RPC operations, subscriptions and permitted read retries. Let cancelled waiters leave without dispatching or poisoning the active session. Preserve modern transport selection and action no-replay; distinguish caller deadlines from successful bounded log tails.
A required-method timeout must preserve cached host identity and previous success while allowing the next connection and recovery poll to proceed. Optional telemetry remains unavailable without blocking usable inventory. This repairs reproduced source paths, not a verified diagnosis or native resolution of issue #2382.
Change-source: pulse-maintainer
Preserve every accepted commit while incorporating the published setup-node advisory-cache repair. Upstream changes a separate workflow; retain the proved runtime and documentation candidate bytes.
Change-source: pulse-maintainer
The scheduled watch reads each release line's lockfile in the default
branch's cache scope, so it deliberately writes no dependency cache.
It sets no cache input, but the pinned setup-node enables npm caching
on its own once package.json names npm as its packageManager. Nothing
declares that today; adding it later would silently reopen a
default-branch cache write here. Set package-manager-cache: false, as
five release workflows already do, assert it in the workflow test, and
say how the contract's no-dependency-cache promise is kept.
The keyed platform renderer preserves row owners, but the disk table captured mount-time presentation. Derive current health, readings, placement and target bindings reactively without discarding focus or expanded detail. Cover snapshot replacement, in-place updates, missing evidence and attention-filter recovery; record desktop and phone browser acceptance.
Change-source: pulse-maintainer
Suppress raw CLI targets/output, HTTP response bodies and credential-bearing endpoint paths across firing, recovery, tests, queue audits and settings logs. Preserve exact delivery inputs, typed causes and retry classification; retain structured status, counts and safe validation reasons.
Contract-Neutral: Shared agent-lifecycle and storage-recovery references are unchanged; this diagnostic repair alters no agent or storage behaviour, API schema, destination admission or delivery policy.
Change-source: pulse-maintainer
Chain signed installer downloads, verification and execution in the English, German and Spanish landing pages so a failed trust step cannot run stale or unverified bytes. Keep the pinned signer, namespace and release URLs, preserve real installer exits, and correct the existing plan and paired-app retirement guidance. Exercise the copyable Bash gate with offline command stubs and run those documentation regressions in Public docs CI.
Contract-Neutral: Public documentation and its secret-free CI validation only; no runtime, entitlement, release-selection or subsystem contract delta.
Change-source: pulse-maintainer
Finish the connected #2077 outcome: persist an observed TrueNAS host temperature through the existing canonical writer, so local chart coverage cannot suppress the Thermals panel. Extend the pinned REST-to-chart control to cover the write, persistent readback and full local-window fast path; preserve source and absence gates.
Change-source: pulse-maintainer
Contract-Neutral: Restores existing TrueNAS Thermals history through its canonical writer; no agent lifecycle, schema, route, resource identity or alert-policy delta.
Complete the native CORE #2077 repair after its whole-suite adverse result: retain ARC without inventing free RAM, enforce live-window freshness even with coarse RRD steps, and assert bounded graph splitting including CPU temperature. Keep empty/zero, aligned ARC and transport boundaries intact.
Change-source: pulse-maintainer
Exercise the unique-device selection ceiling separately from deduplication, and keep the graph-isolation account aligned with catalogue-selected requests. No runtime logic or public contract shape is changed.
Change-source: pulse-maintainer
Bind the anonymised JSON regression input to the existing TrueNAS runtime proof policy. The repair restores existing canonical behavior and has no public contract shape change; its source, tests and substantive monitoring account remain in the preceding commit.
Change-source: pulse-maintainer
Use external RRD timing, native legends, scoped device graphs and measured CPU temperature for issue #2077. Keep absent, empty and zero buckets distinct, normalize CORE CPU states and preserve ARC alignment, safe transport failures and canonical projection. Add native-shape and end-to-end monitoring controls without changing release selection.
Change-source: pulse-maintainer
Contract-Neutral: Restores existing canonical metrics and temperature behaviour for CORE input formats; no public schema, route, resource identity or alert-policy delta.
Use the existing delivery activity and failure classes before collecting raw logs. Keep both Docker streams and log-reader exits visible, warn about provider echoes and duplicate retries, and distinguish test success from real alert delivery. Exercise the copied bounded recipes and their unsafe predecessor with synthetic readers.
Change-source: pulse-maintainer
Preserve the exact product-intelligence candidate and clarify execution scope versus live channel admission without changing runtime behaviour.
Change-source: pulse-maintainer
The LXC discovery report reached command-capable credentials but could not distinguish them from live command-channel admission. Explain the blocked state, keep successful guest checks, and provide a bounded local journal check without credential resets, broader permissions or full-log disclosure. Bind the guidance and command syntax to the existing service events.
Change-source: pulse-maintainer
Move the quiet-hours startup regression beside the other monitor proof files without changing any runtime, test or contract content. This corrects the registry audit's lexical ordering error.
Change-source: pulse-maintainer
Keep continuous and late replay held without spending a provider attempt. Split mixed batches atomically so eligible alerts retain admitted destinations, occurrence links and retry budgets, and bind saved monitor policy before activating persisted work. Add local receipt, cancellation, rollback, reconstruction and race regression coverage with the owning contracts and verification routes.
Change-source: pulse-maintainer
Repair the deterministic registry audit rejection by moving the dedicated quiet-hours test into its lexicographic position and matching the existing indentation. Preserve all verification entries, path policies and runtime bytes.
Change-source: pulse-maintainer
candidate_qualification and release_readiness only restated other jobs'
results. publish_release_tag, publish_docker, publish_helm_chart and
activate_release now each carry the exact candidate predicate in their own
needs and if, guarded by !cancelled() with the same allowed integration
skip, and activation joins the tag and both registry publications directly.
The commit verdict restates every candidate result in place of the
readiness join.
recover-release-activation.yml accepts both shapes. A source run that has
release_readiness still has to prove only that join, as before. A run
without it has to prove publish_release_tag and at least one, and only
successful, jobs under the publish_docker and publish_helm_chart caller IDs.
Failure diagnostics and the inspection-only Helm chart artifact, which
nothing downloads, are kept for three days instead of 14 and 90.
The CORE reporter could find requests but not the matching replies. Clarify Firefox message filtering, per-request IDs, CPU versus temperature and bounded response sharing in the canonical and shipped guide; keep secrets and full captures out of diagnostics. Add guidance regression coverage while preserving the existing authenticated connection recipes.
Change-source: pulse-maintainer
Compare scheduled civil minutes on each selected day so repeated or missing DST minutes cannot shift suppression. Calculate non-full-day replay from real clock boundaries and keep location fallback read-only for concurrent policy consumers. Retain category controls and the existing full-day replay boundary; pin the civil-time contract and dedicated regression proof.
Change-source: pulse-maintainer
Preserve the exact reviewed specialist commit and its documentation and signer controls alongside the current canonical frontier.
Change-source: pulse-maintainer
Preserve exact Core candidate identity for issue #2369, its required-member provenance and genuine-deficit controls. Retain source proof limitations and the owned compatible patch route; no frontend content changes.
Change-source: pulse-maintainer
Distinguish failed verification from a tampering diagnosis, unsigned history, query errors and runtime gates. Remove live-key replacement and regeneration advice, correct default store paths, and preserve matching keys and history for isolated recovery. Bind the shipped guides to regression checks and exercise recovery distinctions with the real signer and encryption manager on synthetic temporary data.
Contract-Neutral: Audit documentation and synthetic regression controls only; no signing, storage, entitlement, API or frontend runtime behaviour changes.
Change-source: pulse-maintainer
Retain configured RAID members separately from source-native totals through collection, reports and canonical read views. Correct the healthy legacy mdadm tuple from #2369 without subtracting spares from mdstat requirements or suppressing real deficits, failures and recovery warnings. Preserve observed zero-active counts through fallback, and verify collector, wire, ingestion, health and canonical activation/resolution boundaries.
Change-source: pulse-maintainer
Extract the Windows-independent Docs repair from candidate 136d039de4a1f8f7debfb1f82d4fffd8bf610083. Add trusted scope after sanitization without expanding document-controlled attributes. Preserve table-local scrolling and verify the current eight-header plans table in desktop Chromium and phone WebKit; native Windows work remains separate.
Change-source: pulse-maintainer
Search the literal response request ID across JSON and console output, limit log collection, retain reader failures and distinguish missing logs from HTTP success. Explain safe browser evidence and default-level coverage without asking users to repeat a state-changing request. Execute the copied journal and Docker commands against bounded synthetic readers, including stderr, failures, no match and a console-only negative control.
Contract-Neutral: Documentation and executable recipe checks for existing request logging only; no API, authentication, runtime, schema or frontend behaviour changes.
Change-source: pulse-maintainer
Failed setup now yields local-only, topology-free diagnostics. Require recognised Running state and successful tailnet ping before TCP, retain probe exits without raw private output or fallback probes, and exercise twenty synthetic readiness/privacy cases. Parent controls expose false success and private output on both channels. Keep workflow identities, secrets, action pins, mutation gates and release scope unchanged.
Change-source: pulse-maintainer
Replace the login-user Docker-group shortcut with actual service-account and collector-profile guidance. Add a one-shot LXC socket/daemon diagnostic that keeps failures visible without collecting container identity or credentials, with executable bounded fixtures.
Contract-Neutral: Existing documentation and diagnostic tests only; collector access, runtime commands, opt-in gates and entitlements are unchanged.
Change-source: pulse-maintainer
A restored image-update incident must not wait another whole delay before positive reports refresh it. Recover pending age from the same resource's active occurrence, retaining acknowledgement and delivery identity while preserving explicit recovery and a new update's normal delay. Exercise both checkpoint authorities, both cleanup paths, cached and unknown evidence, 24/48-hour delays and isolated hosts through the public checker.
Change-source: pulse-maintainer
Resolve overlapping copy assertions by retaining main’s stronger retirement and license-boundary checks plus the candidate’s continuing paired-access and FAQ/plan coverage. User-visible documentation is unchanged from the reviewed candidate; no runtime frontend source changed.
Change-source: pulse-maintainer
The existing FAQ and linked entitlement guide still advertise Relay purchases and remote web access after the reviewed retirement change. Explain continuing app access, subscriber Pro continuity, current plans and phone-alert alternatives; distinguish old Relay payloads without changing their runtime gates. Preserve shipped mirrors and enforce the accepted security guidance's continuing-access boundary.
Contract-Neutral: Documentation and copy assertions reflect existing retirement policy; runtime entitlements, routes and access controls are unchanged.
Change-source: pulse-maintainer
Merge the exact reviewed Web tip and retain its stronger retirement copy assertions where concurrent test-only maintenance overlaps. Runtime frontend content remains exactly browser-verified; existing credential issuance, identity and transport policy are preserved.
Change-source: pulse-maintainer
Replace literal credential bootstraps with the exercised bounded Core private-entry pattern, preserve a checked local private-file route for non-terminal FreeBSD command fields, and consolidate Unix repair, upgrade and removal transport without changing token issuance, TLS choice or host identity. Removal does not depend on a new binary preflight. Windows credential transport remains the next rework step. Add executable PTY/file/lifecycle proofs and the missing DOMPurify after-attributes detached-subtree regression, with parent-bound browser evidence.
Change-source: pulse-maintainer
Adapt PR2351 to current main without losing bounded probe deadlines, retries, explicit binds or confidentiality. Inspect IPv6 wildcard socket mode so unrelated servers sharing the port cannot determine Pulse health. Apply the telemetry callback only after a persisted explicit boolean transition, including stale-disk and null-input boundaries.
Retain real HTTP/HTTPS wildcard and same-port isolation regressions, callback persistence-order tests, and the owning subsystem contracts. No dependency manifests, frontend source or telemetry payload schema change. Exact runtime proof remains dependent on the unavailable root graph; it is not represented as passed.
Change-source: pulse-maintainer
Original-source: https://github.com/rcourtman/Pulse/pull/2351
Original-commit: f50c4d6e3b
Co-authored-by: rcourtman <8825017+rcourtman@users.noreply.github.com>
Replace token arguments, an ignored API_TOKENS bootstrap and plaintext DaemonSet credentials with scoped UI-created tokens, private files and a pre-created Secret. Route hosted installation to the existing private-file flow and retain HTTP errors and encoded resource identities in metrics queries. Exercise copied recipes, failure stops and actual curl requests with synthetic credentials.
Contract-Neutral: Documentation-only private-file setup and metrics access guidance; no runtime, API, entitlement or deployment contract delta.
Change-source: pulse-maintainer