Commit graph

11438 commits

Author SHA1 Message Date
pulse-triage[bot]
c6546fce74 build(deps): qualify the go-minor-patch dependency group
Advance the managed go-minor-patch group with its required transitives:
golang.org/x/crypto 0.56.0->0.57.0, golang.org/x/term 0.45.0->0.46.0 and
modernc.org/sqlite 1.53.0->1.59.0 (libc 1.75.7, memory 1.12.1, x/text 0.42.0).
All other direct versions are unchanged.

Raise the dev-runtime dependency-manifest floors to the qualified releases and
add the storage-driver integrity floor so a silent downgrade fails. Record the
change in the deployment-installability contract.

The batch is routine managed dependency maintenance, independent of the excluded
6 September SQLite SIGSEGV investigation. The NormalizeSegment benchmark delta is
a code-layout measurement artifact (pure function; caller benchmarks do not
corroborate) and the failed advisory result is preserved.

Change-source: pulse-maintainer
2026-09-23 06:49:52 +01:00
pulse-triage[bot]
c050a0bda9 Merge upstream main e18a2c48b8 before publishing the KnowledgeStore serialization and portal esbuild batch (additive, no content change)
Change-source: pulse-maintainer
2026-09-23 06:24:35 +01:00
pulse-triage[bot]
316b660e2f Merge reviewed candidate 20260923T050007Z-web-product (pulse 92f2619509)
Change-source: pulse-maintainer
2026-09-23 06:20:10 +01:00
pulse-triage[bot]
e18a2c48b8
Merge pull request #2182 from rcourtman/maintainer/20260923T043540Z
Refresh governed container base-image digests
2026-09-23 05:14:20 +00:00
pulse-triage[bot]
92f2619509 build(deps): bump portal frontend esbuild to 0.28.2
Apply Dependabot #2142 (esbuild 0.28.1 -> 0.28.2) and regenerate the committed portal build manifest so the source_hash covers the changed package.json. The lockfile and package.json reproduce the Dependabot blobs exactly; the manifest hash is e65ea72f, matching the value the failing backend check computed.

Change-source: pulse-maintainer
Contract-Neutral: Dev-only portal bundler patch bump (esbuild 0.28.1 -> 0.28.2); no public contract or runtime behavior changed.
2026-09-23 06:14:00 +01:00
pulse-triage[bot]
47cadcc188 fix(ai): serialize KnowledgeStore disk saves and track in-flight writes
SaveNote launched an untracked goroutine per note. Concurrent saves shared the fixed knowledge_store.json.tmp path, so the atomic temp+fsync+rename write could be defeated by an interleaved truncate/rename, and a still-running writer could recreate files in the data directory after a caller removed it (the flaky t.TempDir cleanup observed in TestKnowledgeStore_SaveLoad during release qualification).

Guard disk writes with a dedicated save mutex so only one save touches the temp path at a time, track in-flight saves with a WaitGroup, and add an unexported flush() the test uses to join them before cleanup. Add a concurrent SaveNote reload regression covering all entries, and record the persistence boundary in the ai-runtime subsystem contract.

Change-source: pulse-maintainer
2026-09-23 06:01:17 +01:00
pulse-triage[bot]
bb3951cbb8 build(deps): refresh governed container image digests
Refresh the pinned digests for the governed node:24-alpine, golang:1.26.8-alpine
and alpine:3.24 tags used by the release, control-plane and mock-github-server
images. Tag versions are unchanged; this picks up the current rebuilt base
layers, matching the docker dependabot policy that refreshes immutable digests
automatically while keeping tag upgrades in explicit work.

Supersedes Dependabot #2104 (node), #2137 (golang) and #2150 (alpine).

Contract-Neutral: digest-only refresh of unchanged governed image tags; no public-contract delta
Change-source: pulse-maintainer
2026-09-23 05:23:41 +01:00
pulse-triage[bot]
9ac6480350
Merge pull request #2180 from rcourtman/maintainer/20260923T012852Z
Some checks are pending
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
Capture agent logs on FreeBSD/pfSense and fix the installer log hint
2026-09-23 02:09:40 +00:00
pulse-triage[bot]
db531929ee Merge upstream main 08175af524 before publishing the #2123 FreeBSD/pfSense agent log-capture fix (additive, no content change)
Change-source: pulse-maintainer
2026-09-23 02:31:55 +01:00
pulse-triage[bot]
08175af524
Merge pull request #2178 from rcourtman/maintainer/20260923T002652Z
Keep the resource drawer's selected tab across data refreshes
2026-09-23 01:14:30 +00:00
pulse-triage[bot]
ad141a6396 Merge reviewed candidate 20260923T004045Z-core-runtime (pulse 922626418c)
Integrate the exact reviewed FreeBSD/pfSense agent log-capture repair for #2123. The rc.d service now receives the agent's installer-owned rotating --log-file on both the pfSense/OPNsense/vanilla-FreeBSD and TrueNAS CORE branches, and the completion hints name that file instead of the absent /var/log/messages. Includes the installtests coverage and the agent-lifecycle and deployment-installability contract updates.

Change-source: pulse-maintainer
2026-09-23 02:04:57 +01:00
pulse-triage[bot]
922626418c fix(installer): capture agent logs on FreeBSD/pfSense
The FreeBSD rc.d branch printed a log hint pointing at the system log,
but pfSense has no /var/log/messages (its system log is
/var/log/system.log). More importantly, daemon(8) does not capture the
child's stdout and rc.d has no journal, so the agent's zerolog output was
never written to any file: correcting the path alone would still point
users at a log with no agent entries.

Give the agent its own rotating log via --log-file on FreeBSD (both the
TrueNAS CORE and pfSense/OPNsense/vanilla FreeBSD branches) and point the
completion hint at it, matching the Unraid/QNAP/TrueNAS-Linux convention.

The shell installer is a canonical path shared by agent-lifecycle and
deployment-installability, so record the FreeBSD log-capture obligation in
both subsystem contracts.

Refs #2123.

Change-source: pulse-maintainer
2026-09-23 01:57:51 +01:00
pulse-triage[bot]
189ef2c506 Merge origin/main before publishing the #1723 drawer-tab retention fix
Change-source: pulse-maintainer
2026-09-23 01:29:01 +01:00
pulse-triage[bot]
d2ec62b4f8
Merge pull request #2175 from rcourtman/maintainer/20260922T232553Z
Deliver persisted alert notifications that are due at startup
2026-09-23 00:13:59 +00:00
pulse-triage[bot]
2c3a6b306a fix(web): keep the drawer tab across transient snapshot changes (#1723)
A live resource snapshot can briefly omit a field that gates a drawer tab, for example a merged metrics target during a refresh. The tab guard reset the active tab to Overview whenever the selected tab was missing, so the reported Proxmox -> Backups History tab silently jumped back to Summary on data refresh. Reset only when the drawer starts showing a different resource; each tab body already renders an availability notice while its tab is transiently unavailable. Adds a regression test covering a snapshot that drops and restores the metrics target, a source guard in ResourceDetailDrawer.history.test.tsx, the unified-resources contract update, and a fresh frontend browser-verification receipt from scripts/check-drawer-tab-retention.cjs (the same check times out on the pre-fix source).

Change-source: pulse-maintainer
2026-09-23 00:55:58 +01:00
pulse-triage[bot]
79cf2d0058 Merge reviewed candidate 20260922T224013Z-core-runtime (pulse f235fc37f2)
Integrate the exact reviewed notification startup-ordering repair: install the queue processor without waking the worker during manager construction, so an already-due persisted delivery is not terminally cancelled before saved webhook/email/Apprise configuration is applied. Includes the grouping contract-test wait correction, the TestRestartKeepsDueDeliveryPendingUntilConfigured regression test, and the notifications subsystem contract update. Retained offline race proof covers the exact candidate source; the release/v6.4 RC.2 backport remains with the release line.

Change-source: pulse-maintainer
2026-09-23 00:24:30 +01:00
pulse-triage[bot]
cf1ee005ff Merge upstream main before candidate review
Incorporate the remote main merge that existed when this coordination batch began while preserving the already reviewed local candidate identities.

Change-source: pulse-maintainer
2026-09-23 00:24:24 +01:00
pulse-triage[bot]
2d2d272cb4
Merge pull request #2172 from rcourtman/maintainer/20260922T223953Z
Fix TrueNAS CORE CPU and memory telemetry over legacy REST
2026-09-22 23:18:05 +00:00
pulse-triage[bot]
f235fc37f2 fix(notifications): start queue processing after destination config
A persisted notification that was already due at startup could be terminally cancelled as 'delivery disabled'. NewNotificationManagerWithDataDir woke the queue worker during construction, before the owner had applied saved webhook/email/Apprise configuration, so the still-empty destination list looked like a removed destination.

Install the queue processor without waking it. The worker ticker and later enqueues start delivery once configuration is present. This removes the order/state-dependent failure in TestResolvedGroupingOrdinaryRestart and drops a persisted grouped recovery in production.

Also wait past the queue poll interval in the grouping contract test, add a regression test for the startup ordering, and update the notifications subsystem contract's processor-attachment semantics.

Change-source: pulse-maintainer
2026-09-23 00:01:56 +01:00
pulse-triage[bot]
2545fb8cba test(web): guard PBS identity rows across snapshot refresh (#1723)
The Backups drawer renders Discovery and Metrics Target from the merged host resource, so a snapshot-driven correlation change would silently flip those labels. Add discoveryTarget to the retained real-browser fixture and assert both identity rows stay present and byte-identical across reordered, timer-driven snapshots and datastore switching. The guard passes on the current source; it does not reproduce the reporter's live target-spelling flicker.

Change-source: pulse-maintainer
2026-09-22 23:49:13 +01:00
pulse-triage[bot]
50dc7f3e17 fix(truenas): request legacy reporting graphs in native shape
Omit the identifier key for device-independent legacy REST reporting graphs instead of sending an explicit null, matching the TrueNAS 13 middleware requests the reporter supplied for issue #2077. The null identifier is not the native contract and is a plausible whole-batch rejection that discards CPU and memory telemetry. Keep the existing per-graph failure isolation and add a request-validating synthetic regression that rejects any graph carrying an identifier key. Native CORE response schema and appliance acceptance remain unproved.

Change-source: pulse-maintainer
2026-09-22 23:26:53 +01:00
pulse-triage[bot]
e17c33782a
Merge pull request #2170 from rcourtman/maintainer/20260922T194424Z
Deliver critical alert escalations after warning notifications
2026-09-22 20:19:18 +00:00
pulse-triage[bot]
ee8de91eac fix(notifications): deliver severity increases through cooldown
Treat higher delivered severity as new information for the same occurrence without bypassing manager admission, grouping or destination routing. Keep the highest delivered level across late lower-severity completions. Include the contract and observation-to-HTTP/history regressions in this commit.

Change-source: pulse-maintainer
2026-09-22 20:37:00 +01:00
pulse-triage[bot]
52f4c4a9df
Merge pull request #2168 from rcourtman/maintainer/20260922T184021Z
Keep TrueNAS telemetry available when optional graphs fail
2026-09-22 19:18:14 +00:00
pulse-triage[bot]
213e6c54f4 Merge reviewed candidate 20260922T182021Z-core-runtime
Change-source: pulse-maintainer
2026-09-22 19:39:05 +01:00
pulse-triage[bot]
777a421ce5 Merge upstream main before candidate review
Change-source: pulse-maintainer
2026-09-22 19:39:04 +01:00
pulse-triage[bot]
037e5d8695 test(agent): retain offline preflight investigation on current source
Compose the previously committed focused investigation with assigned source for exact-source validation. This does not establish native pfSense acceptance.

Change-source: pulse-maintainer
2026-09-22 19:29:12 +01:00
pulse-triage[bot]
8674a5269c
Merge pull request #2166 from rcourtman/maintainer/20260922T173907Z
Some checks are pending
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Keep copied installs usable and prevent duplicate disk rows
2026-09-22 18:19:42 +00:00
pulse-triage[bot]
037715dc8b Merge reviewed TrueNAS reporting isolation
Change-source: pulse-maintainer
2026-09-22 19:08:28 +01:00
pulse-triage[bot]
6e2841cc65 test(agent): exercise offline FreeBSD preflight through local downloads
Cover real installer and local HTTP handlers with an explicit uname shim. Distinguish bundled artifacts from missing binaries or signature sidecars without claiming native pfSense installation acceptance.

Change-source: pulse-maintainer
2026-09-22 18:42:51 +01:00
pulse-triage[bot]
00f9c3c243 Merge upstream main before candidate review
Incorporate the remote main merge that existed when this coordination batch began while preserving the already reviewed local candidate identities.

Change-source: pulse-maintainer
2026-09-22 18:36:16 +01:00
pulse-triage[bot]
873093134f fix(truenas): isolate legacy reporting graph failures
Keep usable system telemetry when an optional reporting graph fails, with bounded per-graph fallback that preserves terminal errors. Stop treating FreeBSD active pages as total used memory so free/ARC history agrees with live projection.

Request-validating synthetic regressions cover repeated snapshots, history and adverse responses. Native CORE schema and appliance acceptance remain unproved for issue #2077.

Change-source: pulse-maintainer
2026-09-22 18:26:17 +01:00
pulse-triage[bot]
49654c0bd9
Merge pull request #2164 from rcourtman/maintainer/20260922T164109Z
Group resolved alert notifications to prevent restart delivery bursts
2026-09-22 17:21:16 +00:00
pulse-triage[bot]
950c875b6f chore(frontend): bind install proof to integration
The exact candidate merges do not alter the browser-tested production utility. Rebind its content-matching receipt to the final combined parent so canonical cumulative governance verifies the retained proof without re-parenting either reviewed candidate.

Change-source: pulse-maintainer
2026-09-22 18:14:12 +01:00
pulse-triage[bot]
702278cd8c Merge reviewed candidate 20260922T162030Z-core-runtime
Integrate the exact reviewed #2076 mixed-source disk correlation repair and regression coverage.

Change-source: pulse-maintainer
2026-09-22 18:14:11 +01:00
pulse-triage[bot]
ddf87b5672 Merge reviewed candidate 20260922T162021Z-web-product
Integrate the exact reviewed #2123 single-line bootstrap repair and its retained browser/source proof.

Change-source: pulse-maintainer
2026-09-22 18:14:10 +01:00
pulse-triage[bot]
994ffd16fe Merge upstream main before publication
Change-source: pulse-maintainer
2026-09-22 17:40:19 +01:00
pulse-triage[bot]
a0861d5f66 chore(frontend): bind install paste proof to tested candidate
The test-only assertion update preserves the browser-tested runtime bytes. Bind the retained content-matching receipt to the completed source-proof candidate.

Change-source: pulse-maintainer
2026-09-22 17:32:16 +01:00
pulse-triage[bot]
4f3734630f test(agents): expect single-line installer option separators
Update the existing extra-argument ordering assertion to the repaired single-line grammar. The exact-source run passed the new paste and execution regressions but exposed this obsolete multiline formatting expectation.

Change-source: pulse-maintainer
2026-09-22 17:29:32 +01:00
pulse-triage[bot]
064b28367a fix(resources): correlate linked disks with missing hardware IDs
Resolve issue #2076 mixed PVE/agent aliases only within the same parent and unique compatible device topology. Reject conflicting populated identities and controller-member fallback; preserve usable serials and WWNs over placeholders. Include snapshot and JSON regression coverage in the canonical registry verification artifact.

Change-source: pulse-maintainer
2026-09-22 17:27:50 +01:00
pulse-triage[bot]
097e3386e0 fix(agents): keep copied Unix install commands single-line safe
Use explicit shell separators instead of newline-dependent grammar for command fields. Preserve quoted values, private token files, TLS options and preflight ordering; cover paste normalization and execution failures in the owning regression suite. Refs #2123.

Change-source: pulse-maintainer
2026-09-22 17:27:29 +01:00
pulse-triage[bot]
65c5630eb5
Merge pull request #2162 from rcourtman/maintainer/20260922T153254Z
Make guest filesystem mount paths readable
2026-09-22 16:20:54 +00:00
pulse-triage[bot]
9fbc4e7b3a fix(notifications): persist and group resolved alert deliveries
Prevent simultaneous recoveries from bypassing the configured grouping window. Preserve destination receipts and pending restart recovery, and keep PagerDuty incident keys separate. Include the notification contract and regression coverage with the runtime change.

Change-source: pulse-maintainer
2026-09-22 16:52:29 +01:00
pulse-triage[bot]
e8383ed63f chore(frontend): bind browser proof to integrated candidate
The integration merge preserves the exact browser-tested frontend bytes. Rebind the content-bound receipt to that merge so the canonical range passes the parent-identity guard.

Change-source: pulse-maintainer
2026-09-22 16:15:05 +01:00
pulse-triage[bot]
4b1fb511d1 Merge reviewed candidate 20260922T131605Z-web-product (pulse da19341fcd)
Change-source: pulse-maintainer
2026-09-22 16:14:24 +01:00
pulse-triage[bot]
a4efb83c1e Merge upstream main before candidate integration
Change-source: pulse-maintainer
2026-09-22 16:14:23 +01:00
pulse-triage[bot]
da19341fcd fix(web): keep guest filesystem mount paths readable
Render complete wrapping paths above usage using an opt-in shared detail-row layout. Preserve compact rows and unknown-usage semantics. Include the typed regression fixture, registered primitive and Workloads guardrails, substantive owning contracts and the content-bound five-layout browser receipt in the same candidate commit. Recompose the rejected unshared candidate without changing its browser-tested runtime bytes. Addresses #2121.

Change-source: pulse-maintainer
2026-09-22 14:42:22 +01:00
pulse-triage[bot]
c40aa70f04
Merge pull request #2159 from rcourtman/maintainer/20260922T124446Z
Expand PBS History refresh coverage across reported host layouts
2026-09-22 13:25:27 +00:00
pulse-triage[bot]
cc1dca44d0 test(resources): cover PBS metrics target continuity across refreshes
Exercise in-memory snapshot replacement, cached lookup and unified reseeding for PBS-only, agent and side-by-side PVE hosts. Verify label, order and freshness changes do not replace history coordinates, while actual agent removal or replacement does not pin stale targets.

Change-source: pulse-maintainer
2026-09-22 14:04:18 +01:00
pulse-triage[bot]
da1dddc1af test(web): cover PBS host topologies across automatic refresh
Extend the PBS History regression to PBS-only and bare-metal PVE/PBS host shapes, stable and reordered snapshots, and desktop/mobile widths. Retain guest coverage and assert drawer identity, tab selection and history targets. This does not claim the separate reported tab reset is reproduced or resolved.

Change-source: pulse-maintainer
2026-09-22 13:07:13 +01:00