Pulse/pkg
rcourtman a1ba51630d Commit B (pulse): typed lifecycle is the only Patrol route; delete the command side doors
OrchestratorChatService is replaced, not extended: it exposes only
ExecuteInvestigationStream (returning a structured
OrchestratorInvestigationResult) and ListInvestigationTools. The generic
ExecuteStream, SetAutonomousMode, ListAvailableTools, and the
AutonomousMode request field are gone, along with
OrchestratorCommandExecutor, OrchestratorApprovalStore, and the
autonomy/fix-verifier/license dependency interfaces. OrchestratorDeps
now carries a REQUIRED ActionBroker and no command/autonomy deps.

The pulse investigation adapter is rewritten to drive
ExecuteInvestigationStream, injecting proposal/finding/investigation
identity from trusted context and feeding a per-org proposal catalog
resolved from the tenant-bound action lifecycle (so acceptance and
planning validate identically). The retired command-execution,
autonomy, and command-shaped approval adapters are deleted; the router
wires the broker and catalog factories onto the AI settings handler.

The sixth side door is removed: PatrolService.generateRemediation-
PlanFromInvestigation and its call, which copied Fix.Commands into an
executable enterprise remediation plan, are deleted, pinned closed by a
source-audit test.

ActionCapabilityParamInfo gains Pattern (mapped by the broker), so the
canonical planner's pattern validation survives the cross-repo
boundary.

L20 readiness assertion RA35 asserts every Patrol-initiated
infrastructure mutation originates as a typed proposal and reaches
execution only through the canonical action lifecycle, with unsupported
proposals failing closed. Contract prose updated across ai-runtime,
api-contracts, agent-lifecycle, performance-and-scalability,
security-privacy, and storage-recovery.

Lands together with the pulse-enterprise orchestrator migration (the
replace directive means both heads move as one window).
2026-07-10 18:05:25 +01:00
..
agents Modernize Unified Agent lifecycle and platform support 2026-07-09 23:20:35 +01:00
aicontracts Commit B (pulse): typed lifecycle is the only Patrol route; delete the command side doors 2026-07-10 18:05:25 +01:00
audit Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
auth Remove unreachable exported functions from pkg/ 2026-07-10 00:27:35 +01:00
cloudauth fix(hosted): preserve direct handoff membership continuity 2026-03-26 23:40:02 +00:00
db feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
discovery Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
edition Block in-app self-update on the Pro binary to prevent silent downgrade 2026-07-08 10:02:04 +01:00
extensions Allow clearing SSO provider restriction fields from Settings 2026-07-07 22:04:46 +01:00
fsfilters Improve Machines disk summaries 2026-06-03 11:09:58 +01:00
licensing Remove unreachable exported functions from pkg/ 2026-07-10 00:27:35 +01:00
metrics Stabilize metrics rollup chunk proof 2026-07-03 21:57:14 +01:00
pbs Fix PBS job task history filters 2026-05-13 17:09:45 +01:00
pmg Harden outbound URLs and file-backed storage 2026-03-29 12:47:55 +01:00
proxmox Use checked int parsing for Proxmox conversions 2026-07-09 17:47:23 +01:00
pulsecli Remove unreachable exported functions from pkg/ 2026-07-10 00:27:35 +01:00
reporting reporting: fit and wrap operator-controlled cover title and brand lines 2026-07-10 00:42:06 +01:00
securityutil Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
server Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
tlsutil Remove unreachable exported functions from pkg/ 2026-07-10 00:27:35 +01:00