Commit graph

1711 commits

Author SHA1 Message Date
pulse-triage[bot]
f9569426f5 fix(release): publish qualified tags after optional skipped checks
Use an explicit status guard while requiring successful preparation and qualification. Model the beta skipped-ancestor path and adverse direct prerequisites; retain immutable identity and all release gates.

Change-source: pulse-maintainer
2026-09-13 13:03:02 +01:00
rcourtman
c7c503994b
Merge pull request #2063 from rcourtman/fix/disposable-release-qualification
Some checks failed
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Has been cancelled
Unified Agent Native Verification / Linux x64 (push) Has been cancelled
Unified Agent Native Verification / Windows x64 (push) Has been cancelled
Unified Agent Native Verification / macOS ARM64 (push) Has been cancelled
Unified Agent Native Verification / macOS Intel (push) Has been cancelled
Unified Agent Native Verification / FreeBSD cross-build contract (push) Has been cancelled
Isolate release preparation and qualification on hosted VMs
2026-09-12 18:33:17 +01:00
rcourtman
9e87fae07b Align backend partition proof with hosted release isolation
The native installer suite still required the retired persistent runner
label. Require the fresh hosted runner while preserving the canonical
partition command, capacity checks, watchdogs and cache constraints.
2026-09-12 16:00:04 +01:00
rcourtman
051ce81a72 Isolate release preparation and qualification on hosted VMs
Persistent prerelease runners can retain state from earlier source execution
and influence later admission, build output or qualification. Use the
existing hosted stable-release path for every channel while preserving
exact-source checks, resource planning, watchdogs and release gates.
2026-09-12 15:44:11 +01:00
pulse-triage[bot]
34ba9a5ed9 Merge candidate 20260911T204017Z-core-runtime
Change-source: pulse-maintainer
2026-09-11 21:47:11 +01:00
pulse-triage[bot]
097422837b fix(release): preserve quarantined version identity
Reject historical draft reuse before PATCH when its retained target is not the exact checkout SHA, including missing targets and moving refs. Preserve same-source recovery and activation guards.

Depends on PR2056 qualification-first workflow and immutable tag checks. Executable absent-tag fixtures fail before repair and pass on PR head 9e5e18f0 plus this patch; 53 policy, 6 immutability and 42 trust tests pass. Update the deployment contract in the same commit.

Change-source: pulse-maintainer
2026-09-11 21:43:11 +01:00
rcourtman
9e5e18f008 fix(release): qualify candidates before public version writes
A draft GitHub release does not hide its public Git tag or registry
images. Publishing those before qualification consumed a beta identity
when the candidate later failed.

Stage drafts without Git refs, join exact-source checks before public
tag, Docker and Helm publication, and preserve exposed tag identities.
Keep final digest verification before release activation.
2026-09-11 21:04:46 +01:00
pulse-triage[bot]
45f76ed7a9 fix(release): map 6.4.5 reliability checkpoints to release line
The following notification reliability patch needs an explicit branch binding before selection. Keep 6.4.4 frozen and preserve historical and unlisted patch mappings while testing beta, RC and stable workflow resolution.

Change-source: pulse-maintainer
2026-09-11 00:23:11 +01:00
pulse-triage[bot]
3da2356dda fix(ci): archive durable root-pair candidate
The reviewed diagnostic named an ephemeral proposal commit that is no longer fetchable after its branch was retired, so a hosted checkout could not archive the fixed candidate. Use the merged main commit with the identical reviewed tree, retain the original evidence identity in metadata, and require an exactly balanced AB/BA contract.

Change-source: pulse-maintainer
2026-09-10 19:13:29 +01:00
pulse-triage[bot]
9902c204d0 ci: collect fixed hosted root-route pair evidence
The completed local study did not explain the adverse hosted root comparison. Add an exact-source root-only collector with matched builds, ten alternating samples and retained layout and host evidence, rather than repeat full qualification or relax its threshold. Eight focused mocked collector tests pass; hosted execution remains after independent review and protected landing.

Change-source: pulse-maintainer
2026-09-10 19:03:01 +01:00
rcourtman
bd37ae186a Preserve live agent state over saved enrollment history
Saved enrollment records can correlate with a live Proxmox host after a
reinstall. The continuity overlay then replaced its current agent payload
with an older offline identity, hiding metrics and marking the node offline.

Use canonical matching to add only absent continuity resources. Preserve
current identity, telemetry and provider links without deleting history or
changing token admission. Cover repeated reads and identity collisions.

Refs #1913
2026-09-10 16:00:36 +01:00
rcourtman
837a5b8843 Fix manual update freshness and unknown release dates
Manual checks previously bypassed only the browser cache, so a newly
published preview could remain hidden behind a fresh-looking server result.
Carry explicit freshness to the provider, retain prior evidence on failure,
and omit unknown dates instead of rendering year one.
2026-09-10 15:33:53 +01:00
rcourtman
bd678cfde6
Merge pull request #2026 from rcourtman/docs/release-reliability-priority
Prioritize dependable release delivery
2026-09-10 09:49:23 +01:00
rcourtman
5d862dfce8 Prioritize dependable release delivery
Record clean, consistent releases as the highest current objective.
Keep release consistency explicitly unconfirmed until actual release
and recovery evidence establishes dependable delivery.
2026-09-10 09:05:46 +01:00
pulse-triage[bot]
07ad2a8ea3 fix(alerts): discard pending history reads after clearing
A history request started before a successful clear can return deleted rows afterwards and repopulate the view. Invalidate those reads and settle loading only after the clear succeeds, preserving history on failure and allowing later refreshes.

Change-source: pulse-maintainer
2026-09-10 06:44:37 +01:00
pulse-triage[bot]
ad1cfd33c3 fix(ci): qualify grouped release action pin consumers
The grouped action upgrade leaves signing, network and publication consumer assertions on superseded pins. Align those contracts and check every consumer against reviewed immutable upstream manifests, retaining exact dispatch and release trust boundaries without claiming hosted execution.

Change-source: pulse-maintainer
2026-09-10 00:35:47 +01:00
pulse-triage[bot]
37d1874904 docs(msp): verify published evaluation bundle guidance
Replace obsolete v6.2.1 guidance using retained signed v6.4.1 delivery and payload evidence. Limit privacy claims to the evaluated licence request, synchronize the shipped guide, and adapt the registered deployment regression and contract without claiming installed onboarding acceptance.

Change-source: pulse-maintainer
2026-09-09 20:23:20 +01:00
pulse-triage[bot]
c418ee01c6 Merge setup-node v7 consumer qualification
Integrate the independently reviewed setup-node workflow and contract update alongside the Kubernetes dependency repair.

Change-source: pulse-maintainer
2026-09-09 19:47:11 +01:00
pulse-triage[bot]
e9a1310528 fix(deps): split Kubernetes update with discovery-compatible tests
client-go 0.37 extends the Discovery return interface, which broke the metrics test double in grouped dependency PR #1977. Use the real discovery client over an in-memory HTTP transport so the fixture follows the selected client API without losing metrics and error assertions.

Upgrade only the coordinated Kubernetes modules and their selected transitive dependencies. Leave the unrelated grouped updates unchanged and check cohort alignment in local runtime orchestration, including mixed and incomplete negative cases.

Change-source: pulse-maintainer
2026-09-09 19:30:02 +01:00
pulse-triage[bot]
9a6a5811a7 ci: qualify setup-node v7 consumer contracts
The standalone setup-node proposal lacked lifecycle and deployment evidence. Preserve Node 24, explicit cache controls and native Windows proof steps while upgrading the immutable action revision; add consumer regression coverage for the removed dummy auth-token assumption. Keep grouped signing and deployment action upgrades separate.

Change-source: pulse-maintainer
2026-09-09 19:29:17 +01:00
pulse-triage[bot]
f293d6fe33 fix(release): mark store-history SLO measurement windows
The failed exact rehearsal buffered the store-history latency assertion, preventing resource telemetry from locating its actual test interval. Extend the existing exact API lifecycle allowlist and cover both targets with synthetic pass/fail fixtures without rerunning product qualification or changing thresholds. This is prospective observability, not clearance of the retained latency or crash evidence.

Change-source: pulse-maintainer
2026-09-09 01:34:22 +01:00
pulse-triage[bot]
7de1195416 fix(web): align webhook test custom fields with saved configuration
Manually entered Pushover aliases were normalised on save but not on test, so the test could exercise a different payload. Apply the same normalisation and retain a failing-before parity regression; 56 focused webhook tests pass.

Change-source: pulse-maintainer
2026-09-08 23:29:31 +01:00
pulse-triage[bot]
6edaa56f4f fix(web): avoid prescribing permissions from update access failures
The update evidence reason represents generic permission errors and HTTP 403, not a verified missing Sys.Audit privilege. Report access denial without prescribing a role change, as illustrated by the new #1802 retest. Preserve unavailable and stale evidence semantics. Both focused presentation and drawer suites pass (6 tests).

Change-source: pulse-maintainer
2026-09-08 21:59:40 +01:00
pulse-triage[bot]
4462e43288 fix(release): retain streamed stress-test timing evidence
Buffered package logs cannot map the API stress-test failure to resource telemetry. Stream Go events and retain a bounded target lifecycle with distinct event, receipt and resource collection times, while preserving readable output and pipeline failure status. Synthetic decoder and worker tests cover pass, skip, failure and unavailable telemetry; this does not clear historical qualification or authorise a replay.

Change-source: pulse-maintainer
2026-09-08 20:45:07 +01:00
pulse-triage[bot]
a6f90ec181 fix(release): bound transient convergence API read retries
Scheduled reconciliation run 34264958741 aborted while listing releases after GitHub returned HTTP 504. Allow JSON API reads three attempts with bounded backoff so a transient gateway error need not strand this reconciliation until the next schedule. Discard partial pagination on failure and preserve terminal failure after exhaustion.

Only read helpers opt in; mutations, downloads, log reads and access failures retain their single-attempt behaviour. Focused reconciliation suite passes 42 tests, including new transient-read regressions that failed before the change.

Change-source: pulse-maintainer
2026-09-08 20:02:08 +01:00
pulse-triage[bot]
6988e486f2 fix(web): identify notification destination server failures
The queue and health API expose server_error, but the delivery UI treated it as unclassified. Preserve that diagnosis and direct operators to service availability and server logs before retrying retained deliveries. Add focused label and health guidance regression coverage.

Change-source: pulse-maintainer
2026-09-08 12:54:21 +01:00
pulse-triage[bot]
ef4116bc38 test(alerts): distinguish staged recovery edits from saved intent
The real-backend persistence check covered only the saved path. Assert that reload discards an unsaved recovery edit before saving it, so browser-only state cannot be mistaken for persisted operator intent. Retain reload and real startup checks after Save.

Change-source: pulse-maintainer
2026-09-08 10:32:49 +01:00
pulse-triage[bot]
6a66de4556 test(alerts): verify saved recovery intent across backend restart
Exercise the production Schedule control and real configuration API on an owned local backend without alert endpoint mocks. Keep persistence evidence distinct from installed notification delivery.

Change-source: pulse-maintainer
2026-09-08 10:06:21 +01:00
pulse-triage[bot]
953cda829a docs(test): clarify mocked alert activation in browser proof
The application journey stubs configuration and active alerts as well as incident data. State those boundaries explicitly so UI refresh evidence is not mistaken for saved-intent persistence or real activation acceptance.

Change-source: pulse-maintainer
2026-09-08 09:50:56 +01:00
pulse-triage[bot]
a39b08e55d test(web): verify native return through owning CDP session
The application preflight stayed visible because Playwright enabled focus emulation on another CDP session. Disable that override in an opt-in loopback transport without fabricating visibility or weakening assertions. Preserve the ordinary fixtures and prior adverse evidence.

Change-source: pulse-maintainer
2026-09-08 09:24:03 +01:00
pulse-triage[bot]
7443465c28 test(web): retain application incident foreground preflight
Exercise the real history row before native background and explicit refresh. Keep the opt-in headed check and its observed visibility failure distinct from passing component coverage and installed acceptance.

Change-source: pulse-maintainer
2026-09-08 09:20:43 +01:00
pulse-triage[bot]
c5dca69702 test(web): cover production incident refresh after tab suspension
Existing suspension coverage forces overlapping requests through a fixture-only control. Add a separate cached-read scenario using the enabled production Refresh button after native foreground return, so that ownership evidence is not mistaken for user refresh integration. Document the synthetic component and full-application boundary.

Change-source: pulse-maintainer
2026-09-08 08:42:45 +01:00
pulse-triage[bot]
64c63e7435 Merge candidate 20260908T072509Z-delivery-trust
Change-source: pulse-maintainer
2026-09-08 08:35:43 +01:00
pulse-triage[bot]
ded338657d fix(ci): select governed source for scheduled release rehearsals
The default-branch schedule rejected main before any product checks. Resolve the governed branch to one commit, check its VERSION against policy and retain exact event-source checks for manual dispatches. Report workflow and tested source separately and exercise selection against local Git fixtures in governance CI.

Change-source: pulse-maintainer
2026-09-08 08:30:38 +01:00
pulse-triage[bot]
daa471edf3 test(web): verify incident convergence after native tab suspension
The verified headed-tab control previously stopped at blank-page lifecycle evidence. Apply the same single-session mechanism to the production incident hook and panel with bounded synthetic HTTP responses, preserving the failed same-URL fixture attempt and separating this result from installed release qualification.

Change-source: pulse-maintainer
2026-09-08 08:23:44 +01:00
pulse-triage[bot]
15b3deff9f test(web): establish native tab lifecycle positive control
Bare Xvfb window bounds requests never established native backgrounding. Use an owned second tab and verify background/foreground states before suspension so future convergence checks do not mistake protocol acknowledgement for visibility evidence. Preserve earlier adverse controls and separate this passing diagnostic from application and installed-release acceptance.

Change-source: pulse-maintainer
2026-09-08 08:01:53 +01:00
pulse-triage[bot]
ad8f7af6c1 test(web): record headed lifecycle activation control
Add an opt-in owned-X-display diagnostic with window restoration and bounded foreground observations. Preserve the failed bare-Xvfb result: resumed timers do not establish restored visibility or Pulse convergence.

Change-source: pulse-maintainer
2026-09-08 07:52:15 +01:00
pulse-triage[bot]
73fd4da42f test(web): retain failed foreground activation control
A successful lifecycle resume leaves the diagnostic target hidden. Add an opt-in tab activation observation with explicit visibility and focus assertions so it cannot be mistaken for foreground convergence. Preserve both failed runs and the short timer-sampling limitation; no application or release qualification is claimed.

Change-source: pulse-maintainer
2026-09-08 07:41:45 +01:00
pulse-triage[bot]
90ff4e0b17 test(web): establish single-session browser freeze control
Compare forced focus with an independent unforced target using one CDP owner. Retain observed timer suspension and prior adverse evidence without claiming installed incident recovery.

Change-source: pulse-maintainer
2026-09-08 07:12:46 +01:00
pulse-triage[bot]
4caca9c12e test(web): retain failing browser suspension control diagnostic
The previous fresh-session focus intervention did not suspend timers. Preserve a bounded true-to-false comparison and its adverse result so acknowledged CDP commands cannot be mistaken for lifecycle or Pulse recovery proof. This diagnostic is deliberately outside CI and release qualification.

Change-source: pulse-maintainer
2026-09-08 07:00:33 +01:00
pulse-triage[bot]
f526f72c21 Merge candidate 20260908T021505Z-web-product
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/alerts.md
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
#	scripts/check-incident-request-ownership.mjs
2026-09-08 03:36:54 +01:00
pulse-triage[bot]
a222424c63 Merge current upstream incident history before publication
Incorporate protected PR #1973 while preserving every reviewed local alert and notification commit in history. Reconcile its failed-read state with per-request ownership and retain exact combined browser evidence.

Change-source: pulse-maintainer
2026-09-08 03:21:41 +01:00
pulse-triage[bot]
7a915017d4 fix(alerts): preserve request ownership in incident error state
PR #1973 introduced resource incident error state independently of the request lifecycle repair. Reconcile its state with this branch's ownership guards so superseded or disposed reads cannot report a false current failure. Reset clears errors and retry preserves cached history while clearing the failure indicator.

Extend lifecycle assertions for error ownership, retry and superseded success after a current failure. Focused incident hook and panel tests pass: 3 files, 17 tests. Full merged UI browser acceptance remains separate.

Change-source: pulse-maintainer
2026-09-08 03:19:57 +01:00
pulse-triage[bot]
e5ef265c77 fix(alerts): retain ownership of incident history requests
Invalidate pending reads on reset and disposal, and gate success, failure and loading writes per resource. Convert the four reproductions to ordinary tests and retain reset/reopen and stale-failure controls. Qualify the real hook and panel with 14 Chromium lifecycle cases; register that exact browser surface proof without broadening path policies. This does not qualify installed delivery or PR1973's absent error accessor.

Change-source: pulse-maintainer
2026-09-08 02:57:57 +01:00
rcourtman
e2b6fe3b16 Preserve canonical incident history and Assistant handoffs
Filter canonical history before selecting occurrences, preserve source evidence
and expose bounded reads and failures. Reconcile duplicate saved shells without
splitting one alert lifecycle, and keep note identity and canonical risk intact.

Carry attributed operator notes into Assistant. Preserve mobile investigations
across layout changes, transfer composer focus on handoff and keep long event
text readable. Record scoped qualification and its unresolved wider limits.

Refs #1782
2026-09-08 02:08:15 +01:00
pulse-triage[bot]
d9f2637ee2 Merge current upstream source main into reviewed maintenance
Incorporate the protected release-snapshot workflow landing while preserving every reviewed maintenance commit and the additive governance correction in local history.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/deployment-installability.md
2026-09-07 21:02:31 +01:00
pulse-triage[bot]
092405e33c fix(governance): validate reviewed split completions exactly
A reviewed notification correction and its required contracts and API proof were accepted as separate immutable commits, leaving the protected per-commit governance check unable to pass without rewriting reviewed history. Add a fail-closed exact-pair validator that reconstructs the completion commit in a detached worktree and runs the normal guard over the combined file set; all unregistered commits continue through the unchanged per-commit path.

Change-source: pulse-maintainer
2026-09-07 20:13:34 +01:00
rcourtman
b64709e7b7 Publish reviewed release snapshots independently of branch tips
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.

Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
2026-09-07 19:30:27 +01:00
pulse-triage[bot]
1f965e85b0 Merge current upstream main into reviewed alert recovery
Incorporate the landed Patrol planning work while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/agent-lifecycle.md
#	docs/release-control/v6/internal/subsystems/api-contracts.md
#	docs/release-control/v6/internal/subsystems/storage-recovery.md
#	frontend-modern/browser-verification.json
2026-09-07 19:16:44 +01:00
rcourtman
c501376843 Preserve canonical Patrol planning and outcome continuity
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.

Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.

Refs #1782
2026-09-07 17:24:25 +01:00