Commit graph

4887 commits

Author SHA1 Message Date
pulse-triage[bot]
a291579190 Keep timeout fixtures specific to the stalled RPC surface
The first snapshot control also stalled the unrelated app-stat stream. Model its valid empty reply and the proper stream field shapes in the two-connection poller fixture without weakening timeout, session, inventory or recovery assertions. Clarify that initial transport negotiation is bounded separately from each serialized RPC operation; runtime timeout policy is unchanged.

Contract-Neutral: Correct synthetic fixture responses and clarify the existing budget description; no runtime or wire behaviour changes.
Change-source: pulse-maintainer
2026-10-02 12:37:03 +01:00
pulse-triage[bot]
7e369d418f Bound TrueNAS RPC operations and keep polling after silent peers
Apply the configured timeout to serialized JSON-RPC operations, subscriptions and permitted read retries. Let cancelled waiters leave without dispatching or poisoning the active session. Preserve modern transport selection and action no-replay; distinguish caller deadlines from successful bounded log tails.

A required-method timeout must preserve cached host identity and previous success while allowing the next connection and recovery poll to proceed. Optional telemetry remains unavailable without blocking usable inventory. This repairs reproduced source paths, not a verified diagnosis or native resolution of issue #2382.

Change-source: pulse-maintainer
2026-10-02 12:27:35 +01:00
pulse-triage[bot]
2e331d594d Correct Apprise confidentiality queue and API fixtures
Handle nullable retry-row diagnostics while checking the actual attempt audit and DLQ error; verify omitted stored API keys through the established redacted response type and preserve authorised endpoint/target round-trips. Retain the original diagnostic repair and its adverse proof.

Change-source: pulse-maintainer
2026-10-02 10:17:49 +01:00
pulse-triage[bot]
1ce98f2693 Keep Apprise credentials and private payloads out of diagnostics
Suppress raw CLI targets/output, HTTP response bodies and credential-bearing endpoint paths across firing, recovery, tests, queue audits and settings logs. Preserve exact delivery inputs, typed causes and retry classification; retain structured status, counts and safe validation reasons.

Contract-Neutral: Shared agent-lifecycle and storage-recovery references are unchanged; this diagnostic repair alters no agent or storage behaviour, API schema, destination admission or delivery policy.
Change-source: pulse-maintainer
2026-10-02 03:34:36 +01:00
pulse-triage[bot]
45eec9a20e Keep native TrueNAS Thermals in local and persisted host History
Finish the connected #2077 outcome: persist an observed TrueNAS host temperature through the existing canonical writer, so local chart coverage cannot suppress the Thermals panel. Extend the pinned REST-to-chart control to cover the write, persistent readback and full local-window fast path; preserve source and absence gates.

Change-source: pulse-maintainer
Contract-Neutral: Restores existing TrueNAS Thermals history through its canonical writer; no agent lifecycle, schema, route, resource identity or alert-policy delta.
2026-10-02 02:09:48 +01:00
pulse-triage[bot]
579eee2907 Preserve independent ARC and stop cancelled CORE reporting before I/O
Complete the native CORE #2077 repair after its whole-suite adverse result: retain ARC without inventing free RAM, enforce live-window freshness even with coarse RRD steps, and assert bounded graph splitting including CPU temperature. Keep empty/zero, aligned ARC and transport boundaries intact.

Change-source: pulse-maintainer
2026-10-02 01:49:25 +01:00
pulse-triage[bot]
bab5cf77d6 Prove native CORE catalogue overflow fails without partial totals
Exercise the unique-device selection ceiling separately from deduplication, and keep the graph-isolation account aligned with catalogue-selected requests. No runtime logic or public contract shape is changed.

Change-source: pulse-maintainer
2026-10-02 00:48:46 +01:00
pulse-triage[bot]
b50313c599 Decode native CORE reporting rows across live metrics and History
Use external RRD timing, native legends, scoped device graphs and measured CPU temperature for issue #2077. Keep absent, empty and zero buckets distinct, normalize CORE CPU states and preserve ARC alignment, safe transport failures and canonical projection. Add native-shape and end-to-end monitoring controls without changing release selection.

Change-source: pulse-maintainer
Contract-Neutral: Restores existing canonical metrics and temperature behaviour for CORE input formats; no public schema, route, resource identity or alert-policy delta.
2026-10-02 00:32:32 +01:00
pulse-triage[bot]
5213b794b2 Revalidate queued alert delivery against current quiet hours
Keep continuous and late replay held without spending a provider attempt. Split mixed batches atomically so eligible alerts retain admitted destinations, occurrence links and retry budgets, and bind saved monitor policy before activating persisted work. Add local receipt, cancellation, rollback, reconstruction and race regression coverage with the owning contracts and verification routes.

Change-source: pulse-maintainer
2026-10-01 23:05:07 +01:00
pulse-triage[bot]
89a0896959 Match quiet-hours diagnosis regression to its category reason
Keep the new clock/dispatch proof aligned with the unchanged quiet_hours:non-critical diagnosis contract; no production or schedule policy changes.

Change-source: pulse-maintainer
2026-10-01 21:14:07 +01:00
pulse-triage[bot]
cecbd5418b Respect local clocks through alert quiet-hours changes
Compare scheduled civil minutes on each selected day so repeated or missing DST minutes cannot shift suppression. Calculate non-full-day replay from real clock boundaries and keep location fallback read-only for concurrent policy consumers. Retain category controls and the existing full-day replay boundary; pin the civil-time contract and dedicated regression proof.

Change-source: pulse-maintainer
2026-10-01 21:11:11 +01:00
pulse-triage[bot]
14d3dc3b6c Fix MD RAID spare counts without hiding member failures
Retain configured RAID members separately from source-native totals through collection, reports and canonical read views. Correct the healthy legacy mdadm tuple from #2369 without subtracting spares from mdstat requirements or suppressing real deficits, failures and recovery warnings. Preserve observed zero-active counts through fallback, and verify collector, wire, ingestion, health and canonical activation/resolution boundaries.

Change-source: pulse-maintainer
2026-10-01 19:56:47 +01:00
pulse-triage[bot]
1f4f3a0957 Establish initial delivery in restart lifecycle proof
Register the initial real dispatch callback before creating the occurrence, so retained LastNotified is an observed delivery identity rather than an unset fixture field.

Contract-Neutral: Test fixture correction only; establishes the initial delivery callback without changing runtime behaviour or the alert contract.
Change-source: pulse-maintainer
2026-10-01 17:04:22 +01:00
pulse-triage[bot]
ed8415ea6a Keep active Docker update age through restart
A restored image-update incident must not wait another whole delay before positive reports refresh it. Recover pending age from the same resource's active occurrence, retaining acknowledgement and delivery identity while preserving explicit recovery and a new update's normal delay. Exercise both checkpoint authorities, both cleanup paths, cached and unknown evidence, 24/48-hour delays and isolated hosts through the public checker.

Change-source: pulse-maintainer
2026-10-01 16:58:21 +01:00
pulse-triage[bot]
33345f2981 Preserve telemetry sender transitions and bound-socket health
Adapt PR2351 to current main without losing bounded probe deadlines, retries, explicit binds or confidentiality. Inspect IPv6 wildcard socket mode so unrelated servers sharing the port cannot determine Pulse health. Apply the telemetry callback only after a persisted explicit boolean transition, including stale-disk and null-input boundaries.

Retain real HTTP/HTTPS wildcard and same-port isolation regressions, callback persistence-order tests, and the owning subsystem contracts. No dependency manifests, frontend source or telemetry payload schema change. Exact runtime proof remains dependent on the unavailable root graph; it is not represented as passed.

Change-source: pulse-maintainer
Original-source: https://github.com/rcourtman/Pulse/pull/2351
Original-commit: f50c4d6e3b
Co-authored-by: rcourtman <8825017+rcourtman@users.noreply.github.com>
2026-10-01 13:28:21 +01:00
pulse-triage[bot]
c0525852f8 Avoid discarded identity candidates in live broadcast projections
The residual whole-broadcast profile attributes about 80 percent of synthetic allocation to connected-infrastructure grouping. Request only its unchanged 0.90 identity floor, and discard equal or worse-priority fallback peers before allocating and sorting them. Keep general matching and all group identity, ambiguity, explanation and review semantics against independent pre-repair oracles. Update the obsolete broadcast-wrapper source assertion to the prepared single-pass path.

Change-source: pulse-maintainer
2026-10-01 12:18:28 +01:00
pulse-triage[bot]
36200e07db Use canonical resource fields in broadcast regression fixtures
The first exact candidate proof compiled and passed frontend snapshot tests, but rejected two monitoring fixture fields that only exist on frontend projections. Use the canonical resource name and tags to test the same sort/freshness boundaries. Preserve that failed aggregate result; no production code or expectation is relaxed.

Change-source: pulse-maintainer
2026-10-01 11:50:43 +01:00
pulse-triage[bot]
4b01e25cdf Remove redundant connected-dashboard projection and snapshot copies
List the continuity-aware registry once, decorate one owned host projection, and sort final frontend rows rather than a second estate-sized conversion array. Encode concrete frontend resources directly into immutable snapshot buffers, decoding every authoritative ID from those bytes; leave generic marshalers and all other fields on the existing path. Keep live freshness, alert and lifecycle semantics without a cache.

Change-source: pulse-maintainer
2026-10-01 11:32:30 +01:00
pulse-triage[bot]
db9e089691 Measure the complete connected-dashboard broadcast path
Pin a reproducible 1000-resource completed-ingest fixture with zero, one and four viewers before changing projection or encoding. Measure real monitor registry reads, projection, snapshot, per-client delta and queues, excluding persistence, timers and network transport.

Change-source: pulse-maintainer
2026-10-01 11:25:13 +01:00
pulse-triage[bot]
fee838d4e4 Integrate reviewed credential-safe container diagnostics
Preserve both exact Core candidate commits; keep private terminal entry and monitoring trust boundaries intact.

Change-source: pulse-maintainer
2026-10-01 11:13:35 +01:00
pulse-triage[bot]
ac34b6f461 Integrate reviewed PBS safety fixture repairs
Merge exact candidate 0955ddf9e0. Keep canonical API-only least-privilege, failure-stop and unsafe token/pipe assertions alongside the broader shell-fence checks and explicit TLS fixture floor.

Contract-Neutral: Test-only conflict resolution preserves existing PBS API and agent installation contracts.
Change-source: pulse-maintainer
2026-10-01 10:31:47 +01:00
pulse-triage[bot]
413d5ae7ea Bound private token input without terminal truncation
The executable overflow regression and a bounded Bash PTY probe show canonical terminals truncate long input before the size check. Read a bounded character count with echo held off, drain an invalid line before returning to the calling shell, and restore its modes on every exit. Pin maximum-size preservation, overflow history safety and terminal restoration.

Contract-Neutral: Repair bounded private terminal entry, overflow draining and mode restoration; no issuance, scope, install transport or response-shape delta.
Change-source: pulse-maintainer
2026-10-01 10:04:11 +01:00
pulse-triage[bot]
0955ddf9e0 Check PBS shell examples without rejecting TLS safety warnings
The exact-source validation found that the safety warning names the forbidden curl option. Scope the negative checks to fenced shell examples, while retaining certificate, private-token and canonical-installer assertions.

Contract-Neutral: Documentation regression assertions only; no installer, API or runtime contract change.
Change-source: pulse-maintainer
2026-10-01 10:02:52 +01:00
pulse-triage[bot]
7d5c6eb004 Integrate reviewed credential-safe administration guides
Change-source: pulse-maintainer
2026-10-01 09:36:28 +01:00
pulse-triage[bot]
2a81340358 Bind PBS bootstrap checks to the credential-safe guide
PR2361 run 36829483740 requires the retired inline-token HTTP pipe, rejecting the already reviewed guide. Require private directories/token files, inspected HTTPS downloads, the agent profile and TLS checks instead; explicitly forbid inline setup tokens and insecure transport. Existing API bootstrap contract checks remain intact.

Contract-Neutral: Documentation regression assertions only; no installer, API or runtime contract change.
Change-source: pulse-maintainer
2026-10-01 09:35:38 +01:00
pulse-triage[bot]
166f6d8aae Keep container diagnostics bootstrap credentials out of copied commands
Reuse the complete-download and preflight private-token entry boundary for both monitoring modes. Keep issued credentials separate and no-store, use the installer-owned token path in the diagnostic service reference, and reject structural unit injection before minting. Add executable root/sudo, history, transport, failure cleanup and systemd grammar regressions alongside the subsystem contracts.

Change-source: pulse-maintainer
2026-10-01 09:22:15 +01:00
pulse-triage[bot]
5116c2a2d9 Align guards with accepted PBS safety and release direction
The exact source proof exposed a guard incorrectly rejecting prose that forbids insecure TLS flags and a stale control-plane target assertion after the reviewed release-reliability documentation update. Check executable shell fences for unsafe forms, and require the current target in its documentation. Disposable proof lacks sibling repository evidence for two full-suite status checks; that context is retained, not treated as a pass.

Contract-Neutral: Regression-test reconciliation only; accepted product and governance source remains unchanged.
Change-source: pulse-maintainer
2026-10-01 09:20:46 +01:00
pulse-triage[bot]
0fd47f7ebf Keep PBS guidance checks credential-safe and TLS-bounded
Completed PR 2362 CI still required the retired credential-bearing PBS bootstrap command, and CodeQL reported an implicit TLS protocol floor in its local fixture. Assert the accepted read-only and private-file guidance instead, forbid the unsafe forms, and explicitly require TLS 1.2 or later in the fixture. No product or permission changes.

Contract-Neutral: Documentation regression assertions and local TLS test fixture only; runtime and public contracts unchanged.
Change-source: pulse-maintainer
2026-10-01 09:16:32 +01:00
pulse-triage[bot]
0c3cd4fb3a Isolate administration guide session-revocation proof
Initialise the real persistent auth stores for the guide lifecycle and prove user removal revokes its session and CSRF token. Clarify that an empty role list clears built-in assignments too; no runtime authority changes.

Contract-Neutral: Documentation and test-fixture correction only; session revocation, role assignment and authorization runtime contracts are unchanged.
Change-source: pulse-maintainer
2026-10-01 08:55:56 +01:00
pulse-triage[bot]
2c98baabea Align administration guide details with current handlers
Use the accepted organisation ID alphabet and canonical resource types, and expect the documented role assignments to return 204. Keep the guide lifecycle checks at the existing API contract.

Contract-Neutral: Documentation and test expectations only; API methods, validation, authentication and tenant isolation are unchanged.
Change-source: pulse-maintainer
2026-10-01 08:44:10 +01:00
pulse-triage[bot]
0e06f2b38b Make administration guides safe and executable
Keep RBAC, audit and organisation tokens out of process arguments. Use signed-in organisation mutations, actual schemas and acceptance rules, a custom role ID, and private audit exports. Exercise copied commands and handler lifecycles without changing runtime authority.

Contract-Neutral: Documentation and documentation tests only; authentication, RBAC, tenant isolation, licensing and API runtime contracts are unchanged.
Change-source: pulse-maintainer
2026-10-01 08:23:23 +01:00
pulse-triage[bot]
cf12c37e63 Reuse graph-bound metric samplers for demo chart series
The full API race run timed out while cloning the entire mock estate and rebuilding every persona for each chart series. Cache one immutable sampler against the canonical graph data version under its publication lock. Preserve values, current revisions, disabled-mode fallback and isolation from private/global persona updates. Pin zero-allocation warm acquisition, reference equivalence and concurrent snapshot binding; compare both paths with the same thousand-VM sample.

Contract-Neutral: Avoid repeated canonical graph cloning and persona reconstruction without changing metric formulas, identity, graph freshness, retention, endpoints or permissions.
Change-source: pulse-maintainer
2026-10-01 07:33:33 +01:00
pulse-triage[bot]
3fb4b0456a Correct private-bootstrap renderer and URL assertions
Require the exact shared artifact command, stdin PVE authorization and correctly delimited normalized URL instead of legacy pipe/header forms or an over-broad path substring. These corrections retain installer, ACL and transport assertions; no runtime change.

Change-source: pulse-maintainer
2026-10-01 07:33:32 +01:00
pulse-triage[bot]
4af4f9119d Keep credentials outside hosted setup downloads in contract tests
Retain configured-origin and proxy-spoofing coverage while requiring separate credentials, identical tokenless script URLs and private-input renderers. This aligns remaining routed setup assertions with the credential-safe response; no runtime change.

Change-source: pulse-maintainer
2026-10-01 06:06:47 +01:00
pulse-triage[bot]
083c73103c Align routed and hosted Proxmox private-input contracts
Keep fresh token issuance, scope, persistence, normalized product and origin checks while requiring the minted credential outside copied shell text. Dynamic executable coverage already pins decoded quoted arguments. No runtime or frontend content changes.

Change-source: pulse-maintainer
2026-10-01 05:51:09 +01:00
pulse-triage[bot]
521acef97a Reject mixed bootstrap metadata and align credential-safe fixtures
The root parser's legacy no-token alias accepted a new private-file command beside a legacy download URL. Reject every mixed alias, as the existing coherent-transport contract requires. Preserve backup-permission URL bindings. Align older secret-in-command and shared type fixtures, and exercise the actual wrong server installer parser.

Contract-Neutral: Enforce the already-declared coherent bootstrap transports and correct verification fixtures; no API, scope or documented behaviour delta.
Change-source: pulse-maintainer
2026-10-01 05:42:34 +01:00
pulse-triage[bot]
2fd114b3ac Keep Proxmox bootstrap credentials out of copied commands
Separate PVE/PBS setup and telemetry credentials from shell source and download URLs. Use silent root/sudo input, private-file handoff, complete downloads and the agent preflight; preserve scope, TLS defaults, single-line paste and coherent rolling-upgrade metadata. Reveal tokens through the existing dialog and discard late issuance after close. Pin executable shell, history, TLS/registration and browser contracts without using real credentials.

Change-source: pulse-maintainer
2026-10-01 05:23:08 +01:00
pulse-triage[bot]
28cdde7299 Allow the autonomous queue to produce the restart receipt
The complete race run observed a successful PBS recovery webhook after the functional test watchdog expired. Match the existing notification recovery contract watchdog: two autonomous five-second polls plus callback scheduling, while still requiring the actual HTTP payload and incident identity. No production queue, delivery policy or performance assertion changes.

Contract-Neutral: Test-only functional receipt watchdog for the existing autonomous notification queue; production delivery and API unchanged.
Change-source: pulse-maintainer
2026-10-01 03:59:08 +01:00
pulse-triage[bot]
5c6e826cc4 Advance the partial-reporting fixture through due poll cycles
Drive each modeled response through a due deadline instead of zeroing it, which legitimately reconstructs the existing future cadence. The production scheduling policy is unchanged.

Contract-Neutral: Test-only due-deadline setup for the telemetry pipeline; production polling and API unchanged.
Change-source: pulse-maintainer
2026-10-01 03:43:28 +01:00
pulse-triage[bot]
00ed443d00 Use certificate-pin trust for the self-signed pipeline fixture
Match the client's existing self-signed pin contract while retaining VerifyConnection. The full TrueNAS suite includes the pin mismatch refusal control; production transport remains unchanged.

Contract-Neutral: Test-only trust configuration for a pinned synthetic TLS endpoint; production transport and API unchanged.
Change-source: pulse-maintainer
2026-10-01 03:38:56 +01:00
pulse-triage[bot]
dc6a66a62c Pin TLS in the TrueNAS telemetry pipeline fixture
Exercise the existing authenticated transport without a plaintext fixture or a verification bypass. Production telemetry and transport behavior are unchanged.

Contract-Neutral: Test-only pinned-TLS fixture for the existing telemetry contract; production transport and API unchanged.
Change-source: pulse-maintainer
2026-10-01 03:33:38 +01:00
pulse-triage[bot]
22ca07ba71 Keep missing TrueNAS samples distinct from observed zero
Carry per-metric presence through REST and realtime snapshots, canonical host rows and shared History writes. Do not interpret arbitrary numeric object fields as reporting values. Preserve bounded telemetry failure diagnostics without blocking inventory or exposing provider text.

Change-source: pulse-maintainer
2026-10-01 03:25:28 +01:00
pulse-triage[bot]
da685d6d12 Make periodic alert-history persistence proof deterministic
The complete alerts race suite failed the existing 750 ms filesystem-poll deadline. Use Go virtual time with the real periodic worker and configured interval instead of widening the deadline or rerunning unchanged source. Assert no pre-tick write, exact first- and second-tick history content before shutdown, and drain the worker for cleanup. Runtime saving and production intervals are unchanged.

Contract-Neutral: Use virtual time to strengthen the periodic-history persistence test; no runtime or contract delta.
Change-source: pulse-maintainer
2026-10-01 02:30:43 +01:00
pulse-triage[bot]
e256e9fc50 Retain active alert acknowledgements through tracking cleanup
The hourly sweep pruned canonical acknowledgement records after 24 hours even while their incidents remained active. Preserve active tracking identities as the ordinary cleanup already does, so a short recovery and recurrence retain the operator decision. Keep inactive expiry, legacy timestamp fallback and explicit unacknowledgement unchanged. Validate manual and automatic acknowledgements through provider-native pool incident reconciliation, JSON and durable checkpoint restart, dispatch counters and retention bounds; update the alert contract in the same commit.

Change-source: pulse-maintainer
2026-10-01 02:14:32 +01:00
pulse-triage[bot]
7cbde2e3bf Keep observed unacknowledged alerts through retention cleanup
Age-based housekeeping deleted continuing conditions when automatic acknowledgement was disabled. Require last-observation inactivity as well as occurrence age, retain legacy timestamp fallback and inactive cleanup, and document the unchanged acknowledgement/recovery boundaries. Regression exercises cached, absent and failed Docker registry reports, callback/history identity and actual checkpoint restart.

Change-source: pulse-maintainer
2026-10-01 01:26:14 +01:00
pulse-triage[bot]
5dea312f2b Bound asynchronous alert checkpoints during bursts
Coalesce full active-alert snapshots into one worker and one requested follow-up instead of queueing a goroutine per mutation. Preserve immediate lifecycle durability, fresh snapshots, failure recovery and the final shutdown save; reproduce the old burst amplification and validate the new admission and persistence boundaries.

Change-source: pulse-maintainer
2026-10-01 00:28:53 +01:00
courtmanr@gmail.com
119ac49d10 Keep the update progress modal moving when the update stream goes quiet
Updating to v6.4.5-rc.5 and then v6.4.5 left the progress modal on
"Downloading update... 10%" even though the update finished in the
background. The status stream could go silent behind a proxy (Tailscale
Serve, nginx buffering) and the modal only advanced on stream events.

Backend: the update SSE endpoint now sends the current status on connect,
writes events through one ordered writer with an explicit flush, sends a
15s heartbeat and sets X-Accel-Buffering: no.

Frontend: a silence watchdog falls back to status polling, the restart
phase is entered only on real restart evidence (restarting status, the
server going away, or a version change) rather than a single failed poll,
and the page never auto-reloads on unconfirmed completion without a
pre-update version baseline to compare against.
2026-09-30 23:39:35 +01:00
pulse-triage[bot]
b0a4d2f392 test(telemetry): run background health checks with a test delay
Retain the two-minute production constant and extract the same background runner with an explicit test-only delay argument. Correct the startup non-blocking regression after exact-source proof found its invalid constant assignment.

Contract-Neutral: Extract the unchanged telemetry background runner for deterministic testing; production scheduling, payload and privacy contracts are unchanged.
Change-source: pulse-maintainer
2026-09-30 21:46:58 +01:00
pulse-triage[bot]
fffaa64e57 fix(server): make local service-health probes dual-stack and bounded
Try both loopback families for IPv6 wildcard listeners without changing explicit or IPv4-only binds. Reserve each family a share of the API deadline, keep all later checks on the responding address, and retry a failed observation once with a fresh bounded budget in the telemetry background runner.

Keep genuine API, UI and asset failures visible and report only a closed timeout category, never transport details. Cover both real listener families, startup recovery, failure and privacy boundaries; synchronise the disclosure and subsystem contract.

Change-source: pulse-maintainer
2026-09-30 21:36:39 +01:00
pulse-triage[bot]
21a35494ae fix(truenas): request supported reporting aggregations
Use TrueNAS default summaries for reporting queries so SCALE 25.04 can validate its History responses. Preserve raw samples, time windows, CORE live telemetry and existing error boundaries.

Refs #2346

Change-source: pulse-maintainer
2026-09-30 19:48:10 +01:00