The test-only assertion update preserves the browser-tested runtime bytes. Bind the retained content-matching receipt to the completed source-proof candidate.
Change-source: pulse-maintainer
Update the existing extra-argument ordering assertion to the repaired single-line grammar. The exact-source run passed the new paste and execution regressions but exposed this obsolete multiline formatting expectation.
Change-source: pulse-maintainer
Resolve issue #2076 mixed PVE/agent aliases only within the same parent and unique compatible device topology. Reject conflicting populated identities and controller-member fallback; preserve usable serials and WWNs over placeholders. Include snapshot and JSON regression coverage in the canonical registry verification artifact.
Change-source: pulse-maintainer
Prevent simultaneous recoveries from bypassing the configured grouping window. Preserve destination receipts and pending restart recovery, and keep PagerDuty incident keys separate. Include the notification contract and regression coverage with the runtime change.
Change-source: pulse-maintainer
The integration merge preserves the exact browser-tested frontend bytes. Rebind the content-bound receipt to that merge so the canonical range passes the parent-identity guard.
Change-source: pulse-maintainer
Render complete wrapping paths above usage using an opt-in shared detail-row layout. Preserve compact rows and unknown-usage semantics. Include the typed regression fixture, registered primitive and Workloads guardrails, substantive owning contracts and the content-bound five-layout browser receipt in the same candidate commit. Recompose the rejected unshared candidate without changing its browser-tested runtime bytes. Addresses #2121.
Change-source: pulse-maintainer
Exercise in-memory snapshot replacement, cached lookup and unified reseeding for PBS-only, agent and side-by-side PVE hosts. Verify label, order and freshness changes do not replace history coordinates, while actual agent removal or replacement does not pin stale targets.
Change-source: pulse-maintainer
Extend the PBS History regression to PBS-only and bare-metal PVE/PBS host shapes, stable and reordered snapshots, and desktop/mobile widths. Retain guest coverage and assert drawer identity, tab selection and history targets. This does not claim the separate reported tab reset is reproduced or resolved.
Change-source: pulse-maintainer
Detach each rendered datastore from the nested PBS snapshot so independent row reconciliation cannot overwrite another datastore's identity. Cover switching and refreshed History in the component regression and real-browser fixture for #1723.
Contract-Neutral: Restore existing PBS datastore row identity during snapshot reconciliation; no API or canonical ownership change.
Change-source: pulse-maintainer
Prettier wraps the added byAgentKey assertion, which failed the Frontend format:check on the candidate integration pull request. Re-point the browser receipt base at this commit's parent; the cumulative guard compares the receipt at the tip against the tip parent, and the two user-visible frontend sources are unchanged.
Change-source: pulse-maintainer
The cumulative browser guard matches the receipt at the integration tip against the tip parent. Re-point base_sha from the candidate tip parent e9a426aeeb to the integration merge a3ad75e78b so the content-addressed receipt for the two frontend sources is accepted.
Change-source: pulse-maintainer
Integrates the web-product candidate: #2119 alert-card footer alignment (41fa79d52b) and #1723 PBS host-history correlation across guest and agent rows (e9a426aeeb), with the cumulative browser receipt at 98cab1a8bd. Preflight passed; base efeac6cb72.
Change-source: pulse-maintainer
The cumulative candidate browser guard compares the receipt at the tip against every user-visible frontend source changed since the candidate base. This candidate carries two: the #2119 alert-card footer class and the #1723 PBS host-history correlation. Record both content-addressed sources, the union of the two offline proof matrices, and re-point base_sha at the tip parent so the guard can match the candidate.
Change-source: pulse-maintainer
A standalone source=pbs host row and the PVE guest carrying the same agent are one machine. Collapse correlation candidates that share an agent identity and prefer the guest metrics target, whose persisted host series the Backups drawer renders; the PBS service target names the service key and has no host history. Distinct agent identities, or rows without a provable identity, still decline to choose so the drawer cannot substitute an unrelated host. Re-compose the reviewed runtime change with its three subsystem contracts, offline browser fixture, check script and a content-addressed browser receipt in one governed commit.
Change-source: pulse-maintainer
Register 8b56fc72e4 with its contract-completion commit so canonical governance evaluates the reviewed Proxmox LXC linked-agent memory runtime change and its monitoring and unified-resources contract sections as one historical unit.
Change-source: pulse-maintainer
Complete the #2148 runtime change with the monitoring and unified-resources contract sections its canonical subsystem paths require, so the combined change satisfies the canonical completion guard without rewriting reviewed history.
Change-source: pulse-maintainer
A PBS host/config backup (backup-type host) is keyed by the node name, not a guest VMID, so CheckBackupsWithInventory raised a guest backup-age alert under a node-named subject (for example 'nas backup via proxmox-pbs') that never advanced while the node's guests were backed up, notifying repeatedly. Skip backup-age alerts for PBS subjects with no guest VMID: they are host/config backups, not guest workloads, and the Backups overview already keeps them out of guest coverage. PVE host backups already produce no subject and no alert, restoring consistency. Genuine orphaned PBS guest backups (numeric VMID) and PMG node backups still alert. The recovery point and rollup are retained, so inventory and artifact display are unchanged; only the spurious alert is cleared. Includes the alerts subsystem contract record and the regression tests.
Change-source: pulse-maintainer
The secure-runtime RC qualification workflow (commit 79d87a4a2c) resolves the branch the control plane maps the version to and passes it as --main-ref, but secure_runtime_attestation_v6.verify_canonical_main_identity still required origin/main and required the candidate to be an ancestor of origin/main. Every release-train candidate therefore failed the pre-authentication step before any check ran; v6.4.5-rc.1 failed at 'Pre-authenticate exact qualification packet' with 'committed-main classification requires canonical origin/main' (run 35680955017), and all three historical runs failed.
Accept exactly origin/main or the release train's origin/release/vX.Y, verify the ref against the canonical origin's live branch tip, and check candidate ancestry against that same ref. The release-candidate classification is unchanged. Update the deployment-installability contract and the v6 unit tests, including a mapped-release-branch acceptance case.
Change-source: pulse-maintainer
Extend the #1962 linked-agent memory fallback to Proxmox LXC containers (#2148). A correlated online Pulse agent running inside a container now supplies the container's memory metric instead of the cache-inclusive cluster/resources fallback, which can badly under-report shared-memory workloads. The agent sample is only trusted when its total matches the container's configured limit, so an agent without lxcfs cannot leak host memory into the guest row. Threads the previous-guest agent map through the efficient and node-by-node container builders and reads agent-owned memory from merged ContainerView resources.
Change-source: pulse-maintainer
Saved objectives could remain uncovered indefinitely after their in-memory
setup trigger was lost or rejected. Reconcile missing or invalidated
observers from retained intent and recheck its revision at run admission.
Persist attempt timing before provider work so restart and history pruning
cannot erase pacing. Keep coverage dependent on actual observer validation,
installation and health evidence.
Support case patrol-objective-recovery.
The Alerts overview alert-card footer is an items-center flex row whose first child, the Started timestamp, carried its own mt-1. Under items-center that margin shifted the Started run 2px below the adjacent delivery-status run, which is the small text misalignment the reporter underlined in #2119. Remove the child margin; the footer row already carries the top margin, so the two runs share a baseline.
Add a presentation regression test and an offline browser proof that measures the text rects of both runs at desktop and narrow widths.
Contract-Neutral: Behavioral footer-alignment fix; no public-contract or subsystem-shape delta.
Change-source: pulse-maintainer
Register the two #2140 runtime commits with their contract and proof completion commit so the canonical completion guard evaluates each runtime change together with the follow-up that records its contracts and verification artifacts, as one reviewed unit. Registry-only change; no runtime behaviour.
Change-source: pulse-maintainer
Record the #2140 node TLS-preference fix in the contracts its runtime commits touch: agent-lifecycle, api-contracts, security-privacy and the dependent storage-recovery contract, with the node API payload and persisted-field proofs in internal/api/contract_test.go and internal/config/config_load_test.go. The canonical completion history registers these contract and proof files as the completion of the auto-register and consolidation runtime commits.
Change-source: pulse-maintainer
ConsolidatePVEInstances promoted VerifySSL false->true whenever a merged duplicate or standalone had it enabled, silently re-enabling a disabled Verify SSL certificate setting on every save, load and monitor reconciliation (#2140). The add and update handlers now record an explicit operator choice in VerifySSLExplicit; a merge never overrides it, while the historical promotion is kept when neither side recorded a choice so an existing secure connection is not downgraded. A merged fingerprint still pins the peer.
Regression tests cover the standalone and duplicate-cluster merges and the reported PUT-save path through normalizePVEConfigState.
Change-source: pulse-maintainer
ConsolidatePVEInstances promoted VerifySSL false->true when folding a duplicate cluster or overlapping standalone into the canonical instance, silently re-enabling a disabled Verify SSL certificate setting on every save, load and monitor reconciliation (#2140). The canonical instance now owns the preference; a merged fingerprint still pins the peer, so verification is not downgraded.
Regression tests cover the standalone and duplicate-cluster merges and the reported PUT-save path through normalizePVEConfigState.
Change-source: pulse-maintainer
Record the canonical-shape completion for the auto-register VerifySSL preservation in the agent-lifecycle contract and its api-contracts and storage-recovery dependents, so the runtime change is documented in the same candidate.
Change-source: pulse-maintainer
Re-registration of an existing node overwrote the stored VerifySSL value with the fingerprint-capture result, silently re-enabling a disabled Verify SSL certificate setting on every agent health-check repair (#2140). Preserve the operator's choice and keep only the legacy heal where strict verification is on with no pin (#1303).
Change-source: pulse-maintainer
Dependabot's npm-minor-patch group (#2138) bumps frontend-modern and tests/integration but is blocked by Canonical Governance, which requires the deployment-installability contract update and the frontend dependency security proof in the same commit. The portal frontend in the same group is split out: it needs a portal bundle rebuild and is owned separately.
Carry the frontend-modern manifest/lock bump (dompurify 3.4.15, highlight.js 11.12.0, solid-js 1.9.15, @types/node 26.6.1, typescript-eslint 8.70.0, autoprefixer 10.6.1, eslint-plugin-solid 0.18.0, postcss 8.5.28, prettier 3.9.8, vite-plugin-solid 2.11.14, vite-plugin-sri-gen 1.7.4) and the tests/integration @types/node 26.6.1 bump with a Current State contract entry and dependencySecurity floor assertions. @playwright/test stays pinned at 1.56.1, so browser-test parity is unchanged.
Change-source: pulse-maintainer