Commit graph

4922 commits

Author SHA1 Message Date
pulse-triage[bot]
b281ee80e1 Reconcile initial main frontier with reviewed local maintenance
Change-source: pulse-maintainer
2026-10-01 12:15:01 +01:00
rcourtman
4eeb297ca6
Watch main and every active release line for new frontend advisories daily (#2366)
Some checks are pending
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-2) (push) Blocked by required conditions
Build and Test / Backend tests (api-3) (push) Blocked by required conditions
Build and Test / Backend tests (api-4) (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
On 30 Sep and 1 Oct two new advisories (brace-expansion
GHSA-q2hr-2g5m-vwhr, DOMPurify GHSA-p98j-92pf-mc4p) failed the required
frontend audit on every PR across main, release/v6.4 and release/v6.5,
holding the v6.5 RC for days and blocking the v6.4.6 preparation. The
existing scheduled npm-audit is informational and only sees main. This
adds a daily workflow that runs the same complete frontend audit as
Build and Test on main and every active release line, fails on any
finding, and names the branch, advisories and fix. The maintainer's
release-path health check raises it to Delivery immediately.
2026-10-01 12:01:43 +01:00
courtmanr@gmail.com
64d8dbc7fc Watch main and active release lines daily for new npm advisories
On 30 Sep-1 Oct 2026 GHSA-q2hr-2g5m-vwhr (brace-expansion) and
GHSA-p98j-92pf-mc4p (DOMPurify) failed the required "Audit complete
frontend dependency graph" step on every pull request to main,
release/v6.4 and release/v6.5. That held the v6.4.6 preparation PR and
the v6.5 RC for days with no owner. The scheduled audit in
security-scan.yml only informs and runs on the default branch, so
release lines were never checked.

dependency-advisory-watch.yml runs daily and on dispatch. It lists main
plus every release/v<major>.<minor> line at or newer than the latest
stable's line (all lines if that lookup fails), then audits each in a
fail-fast-free matrix. Each job fetches only that line's
frontend-modern/package.json and package-lock.json with git and runs
scripts/npm-audit-retry.sh all on them under the same Node.js pin that
build-and-test requires. npm audit reads the lockfile, so nothing is
installed. The job never checks out or runs the audited branch's code,
because a scheduled run holds the default branch's cache scope and
CodeQL flagged running npm ci there as cache poisoning.

A job fails when the audit fails, and its step summary and annotation
name the branch, the GHSA ids and the fix (npm audit fix
--package-lock-only plus raised floors in dependencySecurity.test.ts).
Read-only, hosted-only, no secrets, no uploads.
2026-10-01 11:46:12 +01:00
pulse-triage[bot]
fee838d4e4 Integrate reviewed credential-safe container diagnostics
Preserve both exact Core candidate commits; keep private terminal entry and monitoring trust boundaries intact.

Change-source: pulse-maintainer
2026-10-01 11:13:35 +01:00
pulse-triage[bot]
f047d7b5db Reconcile published lifecycle rehearsal with reviewed maintenance
Preserve the complete reviewed maintenance tip and published upstream source unchanged. Combine their installability contract and subsystem registry entries without changing runtime behaviour.

Change-source: pulse-maintainer
2026-10-01 10:10:22 +01:00
pulse-triage[bot]
166f6d8aae Keep container diagnostics bootstrap credentials out of copied commands
Reuse the complete-download and preflight private-token entry boundary for both monitoring modes. Keep issued credentials separate and no-store, use the installer-owned token path in the diagnostic service reference, and reject structural unit injection before minting. Add executable root/sudo, history, transport, failure cleanup and systemd grammar regressions alongside the subsystem contracts.

Change-source: pulse-maintainer
2026-10-01 09:22:15 +01:00
courtmanr@gmail.com
8f302e4520 Add shadow release lifecycle rehearsal workflow
Install a published release (latest stable by default) with its signed
install.sh, seed auth, a webhook and a PVE node through the API, upgrade with
the installed /bin/update --version helper, then roll back with the documented
/bin/update --version command. Each step checks /api/version and the binary
version, /api/health, unit state, the seeded settings against fixed
expectations and the pre-upgrade read-back, and data-dir survival, then
reports a phase table in the step summary.

The workflow is read-only, hosted-only, uploads nothing and no release job
depends on it.
2026-10-01 09:11:15 +01:00
pulse-triage[bot]
0832be112f Integrate reviewed credential-safe Proxmox bootstrap and demo sampler reuse
Merge Core candidate cf12c37e63 unchanged onto 22380a3546. Resolve only the shared browser receipt to the candidate receipt; changed frontend source exactly matches its non-merge proof-bearing commit. Preserve newer safe API recipes and sparse History source.

Retained focused configapi, hostagent, mock, monitoring and installtests race suites, affected API cases, frontend suite and type-check, builds and PVE/PBS desktop and phone-emulated browser checks cover the changed behaviour. Broad API timeout and output-limit attempts remain unresolved, not passes. No installed recovery, release qualification, publication or deployment is claimed.

Change-source: pulse-maintainer
2026-10-01 09:06:11 +01:00
pulse-triage[bot]
22380a3546 Integrate reviewed release-note qualification compatibility repair
Preserve exact Delivery candidate 90c80acb49, including bounded grouped notes, operator safety checks and complete qualification source closure. No product or published release changes.

Change-source: pulse-maintainer
2026-10-01 08:45:26 +01:00
pulse-triage[bot]
0aaf639b5a Bind qualification to the complete current filesystem source
Exact-source validation found two unbound compiled packages after composing the retained notes repair with current main. Include both in the source manifest and report the whole dependency closure without weakening the check.

Change-source: pulse-maintainer
2026-10-01 07:33:49 +01:00
pulse-triage[bot]
d012113e92 Restore retained release-note qualification repair
Compose the exact earlier source repair on the current reviewed base for final validation. No published release or source routing is changed.

Change-source: pulse-maintainer
2026-10-01 07:13:38 +01:00
pulse-triage[bot]
ec37284554 Show sparse drawer History without inventing a trend
Render lone stored observations at their actual time instead of blank collecting panels. Label live legend fallbacks as current and describe empty windows without claiming collection is active. Preserve source/range isolation and failed-refresh recovery.

Add sparse-observation regressions and scoped browser evidence, and align both canonical contracts with the shared renderer's verification boundary.

Change-source: pulse-maintainer
2026-10-01 06:22:45 +01:00
pulse-triage[bot]
4efa529215 Close release-note qualification input and fixture gaps
Bind the new compiled notes helper and authored fixture in the rootful source manifest. Repair the visual rollback fixture's missing version and align the internal control-plane page with the active release-reliability target, without changing source routing or published packets.

Change-source: pulse-maintainer
2026-10-01 05:51:28 +01:00
pulse-triage[bot]
022b55083d Keep authored release notes compatible with safety checks
Bind stable notes to version and operator disclosures rather than obsolete prose. Support bounded grouped customer sections for v6.4.6 and later, align generation and rendering, and preserve published history and all qualification gates.

Change-source: pulse-maintainer
2026-10-01 05:28:54 +01:00
pulse-triage[bot]
2fd114b3ac Keep Proxmox bootstrap credentials out of copied commands
Separate PVE/PBS setup and telemetry credentials from shell source and download URLs. Use silent root/sudo input, private-file handoff, complete downloads and the agent preflight; preserve scope, TLS defaults, single-line paste and coherent rolling-upgrade metadata. Reveal tokens through the existing dialog and discard late issuance after close. Pin executable shell, history, TLS/registration and browser contracts without using real credentials.

Change-source: pulse-maintainer
2026-10-01 05:23:08 +01:00
pulse-triage[bot]
36418af66b Integrate reviewed shared-table touch activation repair
Preserve the exact Web candidate, parent-bound browser receipt and lint correction. Restore first-touch disclosure while retaining delegated nested controls and keyboard behaviour.

Change-source: pulse-maintainer
2026-10-01 05:21:00 +01:00
pulse-triage[bot]
88f52387af Restore touch activation on shared table rows
Mark clickable table rows as native WebKit touch targets without moving their actions out of Solid's delegated event ordering. Preserve keyboard disclosure, embedded controls, dynamic action removal and explicit native handlers; cover the shared table and data grid, and record production PBS drawer browser proof.

Change-source: pulse-maintainer
2026-10-01 04:24:25 +01:00
pulse-triage[bot]
6b23876ec8 Integrate reviewed truthful TrueNAS telemetry
Preserve exact Core candidate commits and per-metric missing-versus-zero semantics. Appliance recovery and release qualification remain separate outcomes.

Change-source: pulse-maintainer
2026-10-01 04:16:35 +01:00
pulse-triage[bot]
920aa2f27c Integrate reviewed post-publication watchdog observation
Change-source: pulse-maintainer
2026-10-01 03:39:51 +01:00
pulse-triage[bot]
8a0937a0f3 Integrate reviewed dated drawer History window
Change-source: pulse-maintainer
2026-10-01 03:39:50 +01:00
pulse-triage[bot]
22ca07ba71 Keep missing TrueNAS samples distinct from observed zero
Carry per-metric presence through REST and realtime snapshots, canonical host rows and shared History writes. Do not interpret arbitrary numeric object fields as reporting values. Preserve bounded telemetry failure diagnostics without blocking inventory or exposing provider text.

Change-source: pulse-maintainer
2026-10-01 03:25:28 +01:00
pulse-triage[bot]
4101c37db5 Keep watchdog source observations separate from promotion gates
The exact no-mutation watchdog failed at published 6.4.5 because the release line has pending repairs but still declares its stable VERSION. Observe that governed source and its preceding stable reference without inventing a new promotion, while keeping candidate resolver gates unchanged and watchdog artifacts out of promotion-readiness records.

Change-source: pulse-maintainer
2026-10-01 02:56:58 +01:00
pulse-triage[bot]
1c8f51bf1f Integrate reviewed active alert acknowledgement retention
Change-source: pulse-maintainer
2026-10-01 02:49:11 +01:00
pulse-triage[bot]
5e886b04d6 Keep drawer History on one dated time window
Use the fulfilled API window and a common observed envelope across metric groups so sparse samples cannot look like a full selected range. Show dated endpoints, retain them with matching failed-refresh data, and clear them on range replacement. Preserve edge observations and reject non-date geometry.

Pin mounted/model regressions, update both affected contracts, and retain production PBS drawer browser proof with its installed-acceptance limits.

Change-source: pulse-maintainer
2026-10-01 02:45:12 +01:00
pulse-triage[bot]
e256e9fc50 Retain active alert acknowledgements through tracking cleanup
The hourly sweep pruned canonical acknowledgement records after 24 hours even while their incidents remained active. Preserve active tracking identities as the ordinary cleanup already does, so a short recovery and recurrence retain the operator decision. Keep inactive expiry, legacy timestamp fallback and explicit unacknowledgement unchanged. Validate manual and automatic acknowledgements through provider-native pool incident reconciliation, JSON and durable checkpoint restart, dispatch counters and retention bounds; update the alert contract in the same commit.

Change-source: pulse-maintainer
2026-10-01 02:14:32 +01:00
pulse-triage[bot]
00f82e2afc Integrate reviewed common-time History pointer inspection
Preserve the exact reviewed Web candidate and its browser receipts. Existing PBS History pointer readings now share one stored timestamp; absent sibling observations remain unavailable.

Change-source: pulse-maintainer
2026-10-01 02:01:05 +01:00
pulse-triage[bot]
02090fe351 Keep drawer History pointer values at one observed time
Resolve pointer inspection against the group's actual stored timestamps. Missing series stay unavailable instead of borrowing neighbours or live readings, while keyboard focus, single samples and scoped refresh recovery remain intact. Add mounted regressions, the shared contract and exact-content browser receipts.

Change-source: pulse-maintainer
2026-10-01 01:38:17 +01:00
pulse-triage[bot]
7cbde2e3bf Keep observed unacknowledged alerts through retention cleanup
Age-based housekeeping deleted continuing conditions when automatic acknowledgement was disabled. Require last-observation inactivity as well as occurrence age, retain legacy timestamp fallback and inactive cleanup, and document the unchanged acknowledgement/recovery boundaries. Regression exercises cached, absent and failed Docker registry reports, callback/history identity and actual checkpoint restart.

Change-source: pulse-maintainer
2026-10-01 01:26:14 +01:00
pulse-triage[bot]
0dc858cb36 Integrate reviewed keyboard and touch History inspection
Preserve exact reviewed candidate d38e2ec61a and retain both History and update-progress browser evidence. Only the shared receipt file needed resolution; frontend runtime content matches the candidate receipt.

Change-source: pulse-maintainer
2026-10-01 01:13:28 +01:00
pulse-triage[bot]
4824d1067e Integrate reviewed bounded alert checkpoint worker
Change-source: pulse-maintainer
2026-10-01 00:51:00 +01:00
pulse-triage[bot]
5dea312f2b Bound asynchronous alert checkpoints during bursts
Coalesce full active-alert snapshots into one worker and one requested follow-up instead of queueing a goroutine per mutation. Preserve immediate lifecycle durability, fresh snapshots, failure recovery and the final shutdown save; reproduce the old burst amplification and validate the new admission and persistence boundaries.

Change-source: pulse-maintainer
2026-10-01 00:28:53 +01:00
pulse-triage[bot]
9093cc881d Integrate reviewed exact-source release watchdog
Preserve the fixed no-publication envelope, component verdicts and reviewed Delivery commit identities.

Change-source: pulse-maintainer
2026-10-01 00:28:33 +01:00
pulse-triage[bot]
d38e2ec61a Make drawer History inspectable by keyboard and touch
Expose existing stored history through labelled native observation controls and dated accessible descriptions. Keep missing samples distinct from live or neighbouring readings, preserve the selected timestamp through refreshes and reset selection at resource/range boundaries. Cover input state and real native browser interaction without changing collection or licence gates.

Change-source: pulse-maintainer
2026-10-01 00:28:29 +01:00
pulse-triage[bot]
d80b49835c Incorporate newly landed update-progress repair
Preserve accepted History recovery and current upstream ancestry after the publication boundary detected an upstream advance. Resolve the browser receipt collision by retaining both original parent-bound records without claiming new browser execution.

Change-source: pulse-maintainer
2026-10-01 00:11:24 +01:00
courtmanr@gmail.com
119ac49d10 Keep the update progress modal moving when the update stream goes quiet
Updating to v6.4.5-rc.5 and then v6.4.5 left the progress modal on
"Downloading update... 10%" even though the update finished in the
background. The status stream could go silent behind a proxy (Tailscale
Serve, nginx buffering) and the modal only advanced on stream events.

Backend: the update SSE endpoint now sends the current status on connect,
writes events through one ordered writer with an explicit flush, sends a
15s heartbeat and sets X-Accel-Buffering: no.

Frontend: a silence watchdog falls back to status polling, the restart
phase is entered only on real restart evidence (restarting status, the
server going away, or a version change) rather than a single failed poll,
and the page never auto-reloads on unconfirmed completion without a
pre-update version baseline to compare against.
2026-09-30 23:39:35 +01:00
pulse-triage[bot]
0d3e5a801a Integrate reviewed History refresh recovery
Retain matching History through failed refreshes and settle superseding reads. Preserve the exact reviewed frontend commit and its browser receipts.

Change-source: pulse-maintainer
2026-09-30 23:28:59 +01:00
pulse-triage[bot]
40037f0035 Bind on-demand release watchdogs to reviewed main
Retain the scheduled governed-source selection and no-mutation demo verdict in a separate fixed dispatch mode. Check its control SHA and candidate-free envelope before checkout, preserve ordinary rehearsal rollback and exact event-source guards, and skip candidate builds.

Change-source: pulse-maintainer
2026-09-30 23:27:54 +01:00
pulse-triage[bot]
744160fa0e Keep drawer History usable through failed refreshes
Retain only matching stored observations with an explicit refresh-failure warning and a keyboard-safe scoped retry. Settle latest-read loading when polling overtakes a foreground refresh. Preserve target isolation, licence gates and diagnostic containment with regressions and exact-content browser receipts.

Change-source: pulse-maintainer
2026-09-30 23:02:05 +01:00
pulse-triage[bot]
66ec68c813 Incorporate batch-start upstream main
Change-source: pulse-maintainer
2026-09-30 22:32:19 +01:00
pulse-triage[bot]
4b2b469b68 Integrate reviewed bounded dual-stack service-health repair
Change-source: pulse-maintainer
2026-09-30 22:19:22 +01:00
pulse-triage[bot]
781cbfa98e Integrate reviewed drawer History source isolation
Change-source: pulse-maintainer
2026-09-30 21:42:48 +01:00
pulse-triage[bot]
fffaa64e57 fix(server): make local service-health probes dual-stack and bounded
Try both loopback families for IPv6 wildcard listeners without changing explicit or IPv4-only binds. Reserve each family a share of the API deadline, keep all later checks on the responding address, and retry a failed observation once with a fresh bounded budget in the telemetry background runner.

Keep genuine API, UI and asset failures visible and report only a closed timeout category, never transport details. Cover both real listener families, startup recovery, failure and privacy boundaries; synchronise the disclosure and subsystem contract.

Change-source: pulse-maintainer
2026-09-30 21:36:39 +01:00
pulse-triage[bot]
ac67b2375d Integrate reviewed scoped updater guidance validation
Preserve exact Delivery candidate identity and retain the current canonical TrueNAS repair.

Change-source: pulse-maintainer
2026-09-30 21:17:23 +01:00
pulse-triage[bot]
4ba830bfd3 Keep drawer History scoped to its current target and range
Use the existing non-suspending query's source-isolation option so an uncached target or range cannot display or cache former-host observations. Forward AbortSignal to the Charts API without changing matching-cache or same-source polling behaviour.

The assigned-base VM regression has six failures, including former-host cache contamination; the final mock-backed PBS browser check covers delayed reads, withdrawal, failure, late response and locked ranges at desktop and phone widths. Update the shared frontend contract with real renderer/cancellation regressions. Installed #1723 acceptance and the separate exact-graph security repair remain unresolved.

Change-source: pulse-maintainer
2026-09-30 21:12:44 +01:00
courtmanr@gmail.com
6ad6e18d53 Raise brace-expansion and DOMPurify past current advisories
GHSA-q2hr-2g5m-vwhr (brace-expansion quadratic {a},b} rewrite, below
1.1.21 and 4.0.0-5.0.11) fails the required frontend dependency audit on
every pull request. Move the locked copies to 1.1.21 and 5.0.12, and
DOMPurify from 3.4.15 to 3.4.16 for GHSA-p98j-92pf-mc4p (IN_PLACE
afterSanitize hook XSS). Lockfile only; the dependency security floors
move with it.
2026-09-30 20:45:07 +01:00
pulse-triage[bot]
9d77f09b4f Reject unscoped server updater commands in release bodies
Keep the existing signed installer fallback and require nearby Pulse helper ownership for every install and rollback example, including authored bullets. A distant community-scripts warning must not make an unsafe command publishable.

Change-source: pulse-maintainer
2026-09-30 20:28:17 +01:00
pulse-triage[bot]
21a35494ae fix(truenas): request supported reporting aggregations
Use TrueNAS default summaries for reporting queries so SCALE 25.04 can validate its History responses. Preserve raw samples, time windows, CORE live telemetry and existing error boundaries.

Refs #2346

Change-source: pulse-maintainer
2026-09-30 19:48:10 +01:00
pulse-triage[bot]
a919a84a26 Integrate reviewed allocation-bounded snapshot and metadata maintenance
Change-source: pulse-maintainer
2026-09-30 14:00:19 +01:00
pulse-triage[bot]
6ef79688a5 Keep positive npm advisory evidence fail-closed
A missing or zero total must not erase package or severity findings. Require a complete typed zero verdict, retain bounded outage handling for unknown reports, and keep raw metadata out of workflow annotations. Add executable regression coverage and update the installability contract.

Change-source: pulse-maintainer
2026-09-30 13:23:29 +01:00
pulse-triage[bot]
901274ee92 Reduce snapshot and clone allocations without trusting ID hints
Batch WebSocket identity decoding from the encoded arrays and retain decoder-owned entry buffers. Keep canonical metadata refresh on every resource clone while replacing membership maps with small scope slices and a single sensitivity-tag scan. Preserve delta identity, scope ordering, policy precedence and clone isolation with reference/fuzz and transition tests.

Adapt the remaining performance work proposed in Pulse PR #2342 for issue #2199. The contributor's first-ID check cannot verify a stale tail; this candidate uses standard JSON decoding for every encoded identity instead. Keep the imported contributor history and branch unchanged.

Co-authored-by: Andy Prosser <andy.prosser@icloud.com>
Based-on: https://github.com/rcourtman/Pulse/pull/2342
Original-Commit: 0cbfa43186c82675115ee40858764b534176d9a0
Change-source: pulse-maintainer
2026-09-30 13:21:56 +01:00