Use an explicit status guard while requiring successful preparation and qualification. Model the beta skipped-ancestor path and adverse direct prerequisites; retain immutable identity and all release gates.
Change-source: pulse-maintainer
The native installer suite still required the retired persistent runner
label. Require the fresh hosted runner while preserving the canonical
partition command, capacity checks, watchdogs and cache constraints.
Persistent prerelease runners can retain state from earlier source execution
and influence later admission, build output or qualification. Use the
existing hosted stable-release path for every channel while preserving
exact-source checks, resource planning, watchdogs and release gates.
Reject historical draft reuse before PATCH when its retained target is not the exact checkout SHA, including missing targets and moving refs. Preserve same-source recovery and activation guards.
Depends on PR2056 qualification-first workflow and immutable tag checks. Executable absent-tag fixtures fail before repair and pass on PR head 9e5e18f0 plus this patch; 53 policy, 6 immutability and 42 trust tests pass. Update the deployment contract in the same commit.
Change-source: pulse-maintainer
A draft GitHub release does not hide its public Git tag or registry
images. Publishing those before qualification consumed a beta identity
when the candidate later failed.
Stage drafts without Git refs, join exact-source checks before public
tag, Docker and Helm publication, and preserve exposed tag identities.
Keep final digest verification before release activation.
The following notification reliability patch needs an explicit branch binding before selection. Keep 6.4.4 frozen and preserve historical and unlisted patch mappings while testing beta, RC and stable workflow resolution.
Change-source: pulse-maintainer
The reviewed diagnostic named an ephemeral proposal commit that is no longer fetchable after its branch was retired, so a hosted checkout could not archive the fixed candidate. Use the merged main commit with the identical reviewed tree, retain the original evidence identity in metadata, and require an exactly balanced AB/BA contract.
Change-source: pulse-maintainer
The completed local study did not explain the adverse hosted root comparison. Add an exact-source root-only collector with matched builds, ten alternating samples and retained layout and host evidence, rather than repeat full qualification or relax its threshold. Eight focused mocked collector tests pass; hosted execution remains after independent review and protected landing.
Change-source: pulse-maintainer
Saved enrollment records can correlate with a live Proxmox host after a
reinstall. The continuity overlay then replaced its current agent payload
with an older offline identity, hiding metrics and marking the node offline.
Use canonical matching to add only absent continuity resources. Preserve
current identity, telemetry and provider links without deleting history or
changing token admission. Cover repeated reads and identity collisions.
Refs #1913
Manual checks previously bypassed only the browser cache, so a newly
published preview could remain hidden behind a fresh-looking server result.
Carry explicit freshness to the provider, retain prior evidence on failure,
and omit unknown dates instead of rendering year one.
Record clean, consistent releases as the highest current objective.
Keep release consistency explicitly unconfirmed until actual release
and recovery evidence establishes dependable delivery.
A history request started before a successful clear can return deleted rows afterwards and repopulate the view. Invalidate those reads and settle loading only after the clear succeeds, preserving history on failure and allowing later refreshes.
Change-source: pulse-maintainer
The grouped action upgrade leaves signing, network and publication consumer assertions on superseded pins. Align those contracts and check every consumer against reviewed immutable upstream manifests, retaining exact dispatch and release trust boundaries without claiming hosted execution.
Change-source: pulse-maintainer
Replace obsolete v6.2.1 guidance using retained signed v6.4.1 delivery and payload evidence. Limit privacy claims to the evaluated licence request, synchronize the shipped guide, and adapt the registered deployment regression and contract without claiming installed onboarding acceptance.
Change-source: pulse-maintainer
client-go 0.37 extends the Discovery return interface, which broke the metrics test double in grouped dependency PR #1977. Use the real discovery client over an in-memory HTTP transport so the fixture follows the selected client API without losing metrics and error assertions.
Upgrade only the coordinated Kubernetes modules and their selected transitive dependencies. Leave the unrelated grouped updates unchanged and check cohort alignment in local runtime orchestration, including mixed and incomplete negative cases.
Change-source: pulse-maintainer
The failed exact rehearsal buffered the store-history latency assertion, preventing resource telemetry from locating its actual test interval. Extend the existing exact API lifecycle allowlist and cover both targets with synthetic pass/fail fixtures without rerunning product qualification or changing thresholds. This is prospective observability, not clearance of the retained latency or crash evidence.
Change-source: pulse-maintainer
Manually entered Pushover aliases were normalised on save but not on test, so the test could exercise a different payload. Apply the same normalisation and retain a failing-before parity regression; 56 focused webhook tests pass.
Change-source: pulse-maintainer
The update evidence reason represents generic permission errors and HTTP 403, not a verified missing Sys.Audit privilege. Report access denial without prescribing a role change, as illustrated by the new #1802 retest. Preserve unavailable and stale evidence semantics. Both focused presentation and drawer suites pass (6 tests).
Change-source: pulse-maintainer
Buffered package logs cannot map the API stress-test failure to resource telemetry. Stream Go events and retain a bounded target lifecycle with distinct event, receipt and resource collection times, while preserving readable output and pipeline failure status. Synthetic decoder and worker tests cover pass, skip, failure and unavailable telemetry; this does not clear historical qualification or authorise a replay.
Change-source: pulse-maintainer
Scheduled reconciliation run 34264958741 aborted while listing releases after GitHub returned HTTP 504. Allow JSON API reads three attempts with bounded backoff so a transient gateway error need not strand this reconciliation until the next schedule. Discard partial pagination on failure and preserve terminal failure after exhaustion.
Only read helpers opt in; mutations, downloads, log reads and access failures retain their single-attempt behaviour. Focused reconciliation suite passes 42 tests, including new transient-read regressions that failed before the change.
Change-source: pulse-maintainer
The queue and health API expose server_error, but the delivery UI treated it as unclassified. Preserve that diagnosis and direct operators to service availability and server logs before retrying retained deliveries. Add focused label and health guidance regression coverage.
Change-source: pulse-maintainer
The real-backend persistence check covered only the saved path. Assert that reload discards an unsaved recovery edit before saving it, so browser-only state cannot be mistaken for persisted operator intent. Retain reload and real startup checks after Save.
Change-source: pulse-maintainer
Exercise the production Schedule control and real configuration API on an owned local backend without alert endpoint mocks. Keep persistence evidence distinct from installed notification delivery.
Change-source: pulse-maintainer
The application journey stubs configuration and active alerts as well as incident data. State those boundaries explicitly so UI refresh evidence is not mistaken for saved-intent persistence or real activation acceptance.
Change-source: pulse-maintainer
The application preflight stayed visible because Playwright enabled focus emulation on another CDP session. Disable that override in an opt-in loopback transport without fabricating visibility or weakening assertions. Preserve the ordinary fixtures and prior adverse evidence.
Change-source: pulse-maintainer
Exercise the real history row before native background and explicit refresh. Keep the opt-in headed check and its observed visibility failure distinct from passing component coverage and installed acceptance.
Change-source: pulse-maintainer
Existing suspension coverage forces overlapping requests through a fixture-only control. Add a separate cached-read scenario using the enabled production Refresh button after native foreground return, so that ownership evidence is not mistaken for user refresh integration. Document the synthetic component and full-application boundary.
Change-source: pulse-maintainer
The default-branch schedule rejected main before any product checks. Resolve the governed branch to one commit, check its VERSION against policy and retain exact event-source checks for manual dispatches. Report workflow and tested source separately and exercise selection against local Git fixtures in governance CI.
Change-source: pulse-maintainer
The verified headed-tab control previously stopped at blank-page lifecycle evidence. Apply the same single-session mechanism to the production incident hook and panel with bounded synthetic HTTP responses, preserving the failed same-URL fixture attempt and separating this result from installed release qualification.
Change-source: pulse-maintainer
Bare Xvfb window bounds requests never established native backgrounding. Use an owned second tab and verify background/foreground states before suspension so future convergence checks do not mistake protocol acknowledgement for visibility evidence. Preserve earlier adverse controls and separate this passing diagnostic from application and installed-release acceptance.
Change-source: pulse-maintainer
Add an opt-in owned-X-display diagnostic with window restoration and bounded foreground observations. Preserve the failed bare-Xvfb result: resumed timers do not establish restored visibility or Pulse convergence.
Change-source: pulse-maintainer
A successful lifecycle resume leaves the diagnostic target hidden. Add an opt-in tab activation observation with explicit visibility and focus assertions so it cannot be mistaken for foreground convergence. Preserve both failed runs and the short timer-sampling limitation; no application or release qualification is claimed.
Change-source: pulse-maintainer
Compare forced focus with an independent unforced target using one CDP owner. Retain observed timer suspension and prior adverse evidence without claiming installed incident recovery.
Change-source: pulse-maintainer
The previous fresh-session focus intervention did not suspend timers. Preserve a bounded true-to-false comparison and its adverse result so acknowledged CDP commands cannot be mistaken for lifecycle or Pulse recovery proof. This diagnostic is deliberately outside CI and release qualification.
Change-source: pulse-maintainer
Incorporate protected PR #1973 while preserving every reviewed local alert and notification commit in history. Reconcile its failed-read state with per-request ownership and retain exact combined browser evidence.
Change-source: pulse-maintainer
PR #1973 introduced resource incident error state independently of the request lifecycle repair. Reconcile its state with this branch's ownership guards so superseded or disposed reads cannot report a false current failure. Reset clears errors and retry preserves cached history while clearing the failure indicator.
Extend lifecycle assertions for error ownership, retry and superseded success after a current failure. Focused incident hook and panel tests pass: 3 files, 17 tests. Full merged UI browser acceptance remains separate.
Change-source: pulse-maintainer
Invalidate pending reads on reset and disposal, and gate success, failure and loading writes per resource. Convert the four reproductions to ordinary tests and retain reset/reopen and stale-failure controls. Qualify the real hook and panel with 14 Chromium lifecycle cases; register that exact browser surface proof without broadening path policies. This does not qualify installed delivery or PR1973's absent error accessor.
Change-source: pulse-maintainer
Filter canonical history before selecting occurrences, preserve source evidence
and expose bounded reads and failures. Reconcile duplicate saved shells without
splitting one alert lifecycle, and keep note identity and canonical risk intact.
Carry attributed operator notes into Assistant. Preserve mobile investigations
across layout changes, transfer composer focus on handoff and keep long event
text readable. Record scoped qualification and its unresolved wider limits.
Refs #1782
Incorporate the protected release-snapshot workflow landing while preserving every reviewed maintenance commit and the additive governance correction in local history.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/deployment-installability.md
A reviewed notification correction and its required contracts and API proof were accepted as separate immutable commits, leaving the protected per-commit governance check unable to pass without rewriting reviewed history. Add a fail-closed exact-pair validator that reconstructs the completion commit in a detached worktree and runs the normal guard over the combined file set; all unregistered commits continue through the unchanged per-commit path.
Change-source: pulse-maintainer
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
Incorporate the landed Patrol planning work while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/agent-lifecycle.md
# docs/release-control/v6/internal/subsystems/api-contracts.md
# docs/release-control/v6/internal/subsystems/storage-recovery.md
# frontend-modern/browser-verification.json
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.
Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.
Refs #1782