Advance the managed go-minor-patch group with its required transitives:
golang.org/x/crypto 0.56.0->0.57.0, golang.org/x/term 0.45.0->0.46.0 and
modernc.org/sqlite 1.53.0->1.59.0 (libc 1.75.7, memory 1.12.1, x/text 0.42.0).
All other direct versions are unchanged.
Raise the dev-runtime dependency-manifest floors to the qualified releases and
add the storage-driver integrity floor so a silent downgrade fails. Record the
change in the deployment-installability contract.
The batch is routine managed dependency maintenance, independent of the excluded
6 September SQLite SIGSEGV investigation. The NormalizeSegment benchmark delta is
a code-layout measurement artifact (pure function; caller benchmarks do not
corroborate) and the failed advisory result is preserved.
Change-source: pulse-maintainer
Apply Dependabot #2142 (esbuild 0.28.1 -> 0.28.2) and regenerate the committed portal build manifest so the source_hash covers the changed package.json. The lockfile and package.json reproduce the Dependabot blobs exactly; the manifest hash is e65ea72f, matching the value the failing backend check computed.
Change-source: pulse-maintainer
Contract-Neutral: Dev-only portal bundler patch bump (esbuild 0.28.1 -> 0.28.2); no public contract or runtime behavior changed.
SaveNote launched an untracked goroutine per note. Concurrent saves shared the fixed knowledge_store.json.tmp path, so the atomic temp+fsync+rename write could be defeated by an interleaved truncate/rename, and a still-running writer could recreate files in the data directory after a caller removed it (the flaky t.TempDir cleanup observed in TestKnowledgeStore_SaveLoad during release qualification).
Guard disk writes with a dedicated save mutex so only one save touches the temp path at a time, track in-flight saves with a WaitGroup, and add an unexported flush() the test uses to join them before cleanup. Add a concurrent SaveNote reload regression covering all entries, and record the persistence boundary in the ai-runtime subsystem contract.
Change-source: pulse-maintainer
Refresh the pinned digests for the governed node:24-alpine, golang:1.26.8-alpine
and alpine:3.24 tags used by the release, control-plane and mock-github-server
images. Tag versions are unchanged; this picks up the current rebuilt base
layers, matching the docker dependabot policy that refreshes immutable digests
automatically while keeping tag upgrades in explicit work.
Supersedes Dependabot #2104 (node), #2137 (golang) and #2150 (alpine).
Contract-Neutral: digest-only refresh of unchanged governed image tags; no public-contract delta
Change-source: pulse-maintainer
Integrate the exact reviewed FreeBSD/pfSense agent log-capture repair for #2123. The rc.d service now receives the agent's installer-owned rotating --log-file on both the pfSense/OPNsense/vanilla-FreeBSD and TrueNAS CORE branches, and the completion hints name that file instead of the absent /var/log/messages. Includes the installtests coverage and the agent-lifecycle and deployment-installability contract updates.
Change-source: pulse-maintainer
The FreeBSD rc.d branch printed a log hint pointing at the system log,
but pfSense has no /var/log/messages (its system log is
/var/log/system.log). More importantly, daemon(8) does not capture the
child's stdout and rc.d has no journal, so the agent's zerolog output was
never written to any file: correcting the path alone would still point
users at a log with no agent entries.
Give the agent its own rotating log via --log-file on FreeBSD (both the
TrueNAS CORE and pfSense/OPNsense/vanilla FreeBSD branches) and point the
completion hint at it, matching the Unraid/QNAP/TrueNAS-Linux convention.
The shell installer is a canonical path shared by agent-lifecycle and
deployment-installability, so record the FreeBSD log-capture obligation in
both subsystem contracts.
Refs #2123.
Change-source: pulse-maintainer
A live resource snapshot can briefly omit a field that gates a drawer tab, for example a merged metrics target during a refresh. The tab guard reset the active tab to Overview whenever the selected tab was missing, so the reported Proxmox -> Backups History tab silently jumped back to Summary on data refresh. Reset only when the drawer starts showing a different resource; each tab body already renders an availability notice while its tab is transiently unavailable. Adds a regression test covering a snapshot that drops and restores the metrics target, a source guard in ResourceDetailDrawer.history.test.tsx, the unified-resources contract update, and a fresh frontend browser-verification receipt from scripts/check-drawer-tab-retention.cjs (the same check times out on the pre-fix source).
Change-source: pulse-maintainer
Integrate the exact reviewed notification startup-ordering repair: install the queue processor without waking the worker during manager construction, so an already-due persisted delivery is not terminally cancelled before saved webhook/email/Apprise configuration is applied. Includes the grouping contract-test wait correction, the TestRestartKeepsDueDeliveryPendingUntilConfigured regression test, and the notifications subsystem contract update. Retained offline race proof covers the exact candidate source; the release/v6.4 RC.2 backport remains with the release line.
Change-source: pulse-maintainer
Incorporate the remote main merge that existed when this coordination batch began while preserving the already reviewed local candidate identities.
Change-source: pulse-maintainer
A persisted notification that was already due at startup could be terminally cancelled as 'delivery disabled'. NewNotificationManagerWithDataDir woke the queue worker during construction, before the owner had applied saved webhook/email/Apprise configuration, so the still-empty destination list looked like a removed destination.
Install the queue processor without waking it. The worker ticker and later enqueues start delivery once configuration is present. This removes the order/state-dependent failure in TestResolvedGroupingOrdinaryRestart and drops a persisted grouped recovery in production.
Also wait past the queue poll interval in the grouping contract test, add a regression test for the startup ordering, and update the notifications subsystem contract's processor-attachment semantics.
Change-source: pulse-maintainer
The Backups drawer renders Discovery and Metrics Target from the merged host resource, so a snapshot-driven correlation change would silently flip those labels. Add discoveryTarget to the retained real-browser fixture and assert both identity rows stay present and byte-identical across reordered, timer-driven snapshots and datastore switching. The guard passes on the current source; it does not reproduce the reporter's live target-spelling flicker.
Change-source: pulse-maintainer
Omit the identifier key for device-independent legacy REST reporting graphs instead of sending an explicit null, matching the TrueNAS 13 middleware requests the reporter supplied for issue #2077. The null identifier is not the native contract and is a plausible whole-batch rejection that discards CPU and memory telemetry. Keep the existing per-graph failure isolation and add a request-validating synthetic regression that rejects any graph carrying an identifier key. Native CORE response schema and appliance acceptance remain unproved.
Change-source: pulse-maintainer
Treat higher delivered severity as new information for the same occurrence without bypassing manager admission, grouping or destination routing. Keep the highest delivered level across late lower-severity completions. Include the contract and observation-to-HTTP/history regressions in this commit.
Change-source: pulse-maintainer
Compose the previously committed focused investigation with assigned source for exact-source validation. This does not establish native pfSense acceptance.
Change-source: pulse-maintainer
Cover real installer and local HTTP handlers with an explicit uname shim. Distinguish bundled artifacts from missing binaries or signature sidecars without claiming native pfSense installation acceptance.
Change-source: pulse-maintainer
Incorporate the remote main merge that existed when this coordination batch began while preserving the already reviewed local candidate identities.
Change-source: pulse-maintainer
Keep usable system telemetry when an optional reporting graph fails, with bounded per-graph fallback that preserves terminal errors. Stop treating FreeBSD active pages as total used memory so free/ARC history agrees with live projection.
Request-validating synthetic regressions cover repeated snapshots, history and adverse responses. Native CORE schema and appliance acceptance remain unproved for issue #2077.
Change-source: pulse-maintainer
The exact candidate merges do not alter the browser-tested production utility. Rebind its content-matching receipt to the final combined parent so canonical cumulative governance verifies the retained proof without re-parenting either reviewed candidate.
Change-source: pulse-maintainer
The test-only assertion update preserves the browser-tested runtime bytes. Bind the retained content-matching receipt to the completed source-proof candidate.
Change-source: pulse-maintainer
Update the existing extra-argument ordering assertion to the repaired single-line grammar. The exact-source run passed the new paste and execution regressions but exposed this obsolete multiline formatting expectation.
Change-source: pulse-maintainer
Resolve issue #2076 mixed PVE/agent aliases only within the same parent and unique compatible device topology. Reject conflicting populated identities and controller-member fallback; preserve usable serials and WWNs over placeholders. Include snapshot and JSON regression coverage in the canonical registry verification artifact.
Change-source: pulse-maintainer
Prevent simultaneous recoveries from bypassing the configured grouping window. Preserve destination receipts and pending restart recovery, and keep PagerDuty incident keys separate. Include the notification contract and regression coverage with the runtime change.
Change-source: pulse-maintainer
The integration merge preserves the exact browser-tested frontend bytes. Rebind the content-bound receipt to that merge so the canonical range passes the parent-identity guard.
Change-source: pulse-maintainer
Render complete wrapping paths above usage using an opt-in shared detail-row layout. Preserve compact rows and unknown-usage semantics. Include the typed regression fixture, registered primitive and Workloads guardrails, substantive owning contracts and the content-bound five-layout browser receipt in the same candidate commit. Recompose the rejected unshared candidate without changing its browser-tested runtime bytes. Addresses #2121.
Change-source: pulse-maintainer
Exercise in-memory snapshot replacement, cached lookup and unified reseeding for PBS-only, agent and side-by-side PVE hosts. Verify label, order and freshness changes do not replace history coordinates, while actual agent removal or replacement does not pin stale targets.
Change-source: pulse-maintainer
Extend the PBS History regression to PBS-only and bare-metal PVE/PBS host shapes, stable and reordered snapshots, and desktop/mobile widths. Retain guest coverage and assert drawer identity, tab selection and history targets. This does not claim the separate reported tab reset is reproduced or resolved.
Change-source: pulse-maintainer