Commit Graph

766 Commits

Author SHA1 Message Date
rcourtman 8b73085e82 Fix release smoke workspace identity on rootless Docker
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.

Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
2026-09-07 08:29:42 +01:00
rcourtman 3853124a39 Keep Patrol action history consistent with recorded outcomes
Refresh durable investigation lifecycle from authoritative actions while
preserving completed evidence. Keep resolved history reviewable and label
recorded plan facts separately from action outcomes. Follow all resource
pages during qualification and record live approval, rejection and storage
semantic-review results. Integrate current main and preserve its alert
ordering correction.
2026-09-06 21:23:01 +01:00
rcourtman 57ead19484 Preserve Patrol evidence and surface action submission failures
Live funded qualification found hidden tool results and misleading action
submission outcomes. Share the result-bearing transcript across stored chat
and product history, render the retained evidence, and distinguish captured
proposals from broker acceptance. Keep review usable while Patrol is paused.

Record Gemini route pricing and exact qualification limits. Integrate current
main and repeat browser proof for the incoming login flow. Approved/rejected
recovery remains unqualified without the development command agent.
2026-09-06 20:09:54 +01:00
pulse-triage[bot] 64dba483d0 fix(release): bind forward 6.4.4 checkpoint to release train
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.

Change-source: pulse-maintainer
2026-09-06 16:48:17 +01:00
rcourtman 919331d5b3 Join Docker alert events with canonical resource history
Keep alert and inventory evidence together after container removal and
restart without rewriting retained events or transferring approval and
operator authority. Resolve exact source identities in the shared store
and preserve event replay idempotency across old and current records.

Verify actual retained homelab events, registered tool reads, lifecycle
callbacks, tenant isolation, race behaviour and responsive evidence views.
2026-09-06 16:23:30 +01:00
rcourtman 6e18777d30 Preserve tmpfs mount evidence through collection and queries
Docker can report tmpfs mounts only in HostConfig.Tmpfs. Preserve those
entries in shared inventory and retain type, options and canonical write
access in diagnostic queries. Configured size is not measured free space.

Record the failed ordinary storage diagnosis and independently verified
recovery without claiming autonomous or installed-collector qualification.
2026-09-06 14:50:11 +01:00
rcourtman f48c806718 Preserve observed Docker storage evidence
Missing block I/O and container image sizes could become false evidence
for diagnosis. Preserve per-direction counter presence and measured zero
through collection, resource conversion and browser rendering. Separate
new observed history from ambiguous retained disk series without deleting
old rows or changing public metric names.

Keep partial host rates distinct and persist a newly enabled Disk I/O
column across the first preference reload.
2026-09-06 12:45:40 +01:00
rcourtman f779bf064a Merge current main and verify diagnostic workflows
Integrate the latest alert, delivery and action-result changes with the
Patrol evidence conversation. Replace the conflicted browser receipt
with current source-bound qualification and fix shared warning-card
wrapping exposed by the intermediate-width check.

Real diagnostic and autonomous action outcome qualification stays open.
2026-09-06 04:22:09 +01:00
rcourtman 668af3fe6b fix(ai): preserve uncertain investigation conclusions
Tool-call totals do not establish diagnostic sufficiency. Preserve seed-only
and failed-read conclusions, remove count-based completion instructions from
evidence, and retain configured limits and authority checks.

Keep findings grouped under alerts selectable in the shared review panel so
their investigations and access limits remain available to Assistant.
2026-09-06 02:47:55 +01:00
pulse-triage[bot] b5784df4b7 fix(delivery): verify public Helm package against qualified bytes
Readable chart metadata does not prove that the public index serves the OCI-qualified package. Pull through the consumer repository and compare exact bytes before reporting convergence, with offline regression coverage for mismatched, missing and unavailable downloads. Activation and publication authority remain unchanged.

Change-source: pulse-maintainer
2026-09-05 22:24:18 +01:00
pulse-triage[bot] 9c70c2e1ec fix(release): report skipped mutable channel convergence debt
The scheduled reconciler can select a preview retry while silently excluding the mutable stable head. Report that concrete continuity debt in the existing log and job summary, without changing retry eligibility, credential containment or publication authority.

Validated with 37 reconciler and 47 release policy tests. New debt assertions fail against the original code; read-only live discovery reports v6.4.1 debt and preserves preview candidate 33674637446.

Change-source: pulse-maintainer
2026-09-05 21:44:23 +01:00
pulse-triage[bot] 2de83c0e27 Merge Helm publication version binding
Change-source: pulse-maintainer
2026-09-05 21:25:59 +01:00
pulse-triage[bot] 12a3b87529 fix(governance): recognize proven frontend-only reformats
The open publication proposal exposed an earlier additive formatting correction that lacked a Contract-Neutral trailer and therefore could not pass per-commit governance without rewriting reviewed history. Infer neutrality only for immutable commits whose every governed runtime path is byte-for-byte the locked Prettier output of its parent; mixed, unreadable, added, deleted, or non-frontend changes continue to fail closed.

Change-source: pulse-maintainer
2026-09-05 21:21:04 +01:00
pulse-triage[bot] 96bc6f084f fix(release): bind Helm application version to chart release
Reject mismatched image defaults before packaging; preserve equal and default versions. Reproduced four accepted mismatches before the fix. All 58 focused tests pass; no publication performed.

Change-source: pulse-maintainer
2026-09-05 21:13:23 +01:00
pulse-triage[bot] 7c373a5162 fix(release): reject draft Helm chart publication retries
Reproduce draft and unknown publication states reaching the Pages index boundary. Require an explicitly non-draft existing release before uploading, editing or advertising its chart, without implicitly publishing operator drafts.

Exercise the actual publication shell with a fake GitHub CLI and wire its seven retry tests into canonical governance. Existing digest and maturity behaviour remains covered.

Change-source: pulse-maintainer
2026-09-05 20:55:01 +01:00
pulse-triage[bot] ef6e784c2e docs(release): clarify combined continuity incident recovery
Fresh stable readback still shows mutable v6.4.1 alongside orphan v6.4.2. Explain forward supersession without deleting historical tags or treating frontier success as release admission. Cover that distinction with a focused recovery regression; publication authority and all existing gates remain unchanged.

Change-source: pulse-maintainer
2026-09-05 20:12:48 +01:00
pulse-triage[bot] b6c8bf6bef test(governance): anchor organisation references to contract content
Reproduce PR #1909 governance failures on the combined lane source. Derive reference positions from named content while retaining explicit section, ownership and verification assertions, so unrelated documentation insertions do not break CI.

Validation: all 163 subsystem lookup tests pass via pulse-heavy-run; both affected tests also pass with two documentation lines inserted in memory. No runtime or release-policy change.
Change-source: pulse-maintainer
2026-09-05 19:39:37 +01:00
pulse-triage[bot] 6998908d2a fix(release): limit asset validation readiness claims
Downstream release-note syndication repeats the asset check banner even when installed health or release convergence is not qualified. Report asset checks only and state the remaining evidence boundaries for both draft and post-publication banners.

Change-source: pulse-maintainer
2026-09-05 17:30:49 +01:00
pulse-triage[bot] 4f61c581b9 fix(release): expose reconciliation decisions in run summaries
The successful scheduled reconciliation at run 33972475922 retained a credential-containment hold and dispatched no retry. Put safe decision messages in the Actions summary so a green reconciler is not mistaken for delivered releases. Narrow empty-discovery wording because mutable channels and missing runs are not qualified. Preserve containment, retry budgets and dispatch behaviour; cover summary output and empty discovery with focused tests.

Change-source: pulse-maintainer
2026-09-05 16:23:47 +01:00
pulse-triage[bot] bf6121e41d fix(release): reject ambiguous activation asset inventories
Count all activation marker names before validating their metadata so a malformed duplicate cannot pass the immutable packet boundary. Reproduced acceptance with a valid uploaded marker plus a zero-size pending duplicate; both valid and malformed duplicates now fail before attestation or download.

Validation: 13 focused integrity tests and 46 promotion policy tests pass; bash syntax and git diff checks pass. No publication or deployment performed.
Change-source: pulse-maintainer
2026-09-05 15:43:23 +01:00
pulse-triage[bot] 280e73e1f2 test(delivery): bind recovery receipts to successful submissions
Exercise all three reconciliation recovery paths through the mocked transport for accepted and rejected POSTs. Assert rejected submissions raise without emitting a success receipt.

Validation: 30 reconciliation tests and 46 release promotion policy tests pass. No remote mutations performed.

Change-source: pulse-maintainer
2026-09-05 15:12:05 +01:00
pulse-triage[bot] 2d979682fd fix(delivery): preserve convergence receipt policy checks
The dry-run receipt repair made submitted messages dynamic, hiding the literal
pre-commit renewal contract from canonical governance. Keep submitted and
non-mutating output distinct while spelling each receipt explicitly so the
existing release-policy guard continues to verify the recovery handoff.

Validation: 29 reconciliation tests and 46 release promotion policy tests
pass, including the check that failed on pull request 1904.

Change-source: pulse-maintainer
2026-09-05 15:08:14 +01:00
pulse-triage[bot] 6ecee4b4c4 fix(delivery): distinguish dry-run proposals from submitted retries
A read-only reconciliation of current release debt printed Dispatched despite suppressing the POST. Return submission status from the transport and qualify all three mutation receipts. Preserve retry and containment policy unchanged.

Verified 29 reconciliation and 41 workflow-trust tests; new dry-run regression rejects all three baseline paths. Live --latest --dry-run now reports Would dispatch without mutation.

Change-source: pulse-maintainer
2026-09-05 10:20:38 +01:00
pulse-triage[bot] ec462ad964 fix(release): inspect convergence logs through safe Actions reader
Scheduled reconciliation fails when gh api refuses ANSI-bearing Actions logs. Use the dedicated sanitising log reader without disabling terminal protection, preserving private authentication and fail-closed evidence handling. Focused reconciliation and policy tests pass; a read-only live job probe retains failure evidence without ESC bytes.

Change-source: pulse-maintainer
2026-09-05 04:32:38 +01:00
pulse-triage[bot] 7db3192a3f fix(release): measure candidate soak from release publication
Git tag creation can precede candidate publication, allowing stable promotion before the required observation period. Read the exact published prerelease and fail closed when publication evidence is unavailable. Cover repaired-candidate minor and patch boundaries.

Change-source: pulse-maintainer
2026-09-05 01:47:12 +01:00
pulse-triage[bot] 09da37881f Check release inventory independently of Git refs
A published release packet is a customer-visible surface in its own right. Deriving newer published versions only from matching Git refs lets that surface escape continuity validation when the corresponding ref is absent. Evaluate every stable-shaped release record independently and pin the detached-ref case with a regression test.

Change-source: pulse-maintainer
2026-09-04 15:01:51 +01:00
pulse-triage[bot] d7356ef76e Detect orphaned stable delivery versions
A failed v6.4.2 release left newer stable-shaped source and public container tags behind after its GitHub Release packet was removed. Extend the scheduled continuity audit across the stable tag and public registry frontier so this partial publication cannot remain hidden behind an older latest release.

Change-source: pulse-maintainer
2026-09-04 13:58:07 +01:00
pulse-triage[bot] afa66ec69b Quiesce exhausted convergence retries
An unchanged control revision cannot repair release-convergence debt after its
bounded retry budget is spent. Continuing to raise from the scheduled
reconciler only creates a recurring controller failure while the original
failed run already preserves the actionable debt signal.

Treat that exhausted current revision as a stable no-op, but let a newer
control revision dispatch again so repaired controls are not stranded behind
stale attempts.

Contract-Neutral: release-control automation only; no runtime or public API contract changed
Change-source: pulse-maintainer
2026-09-04 07:09:48 +01:00
pulse-triage[bot] 4daa41c3ae Keep unrelated release debt retriable
Credential-containment suppression could otherwise hide failed, cancelled, or incomplete public release jobs and strand recoverable convergence debt without an unattended retry. Require complete job evidence and limit suppression to the paid-runtime failure plus its aggregate verdict.
2026-09-04 02:54:05 +01:00
pulse-triage[bot] 5e30bbb346 Recover Helm Pages from attested OCI charts
Keep convergence recoverable after short-lived Actions artifacts expire by preserving the exact digest-bound package already verified from GHCR.

Change-source: pulse-maintainer
2026-09-04 01:04:30 +01:00
pulse-triage[bot] 6f3c436121 Stop retrying unchanged credential blocks
A committed release with an unchanged operator-owned containment failure cannot converge through unattended retries. Classify that evidence without weakening the block, and rearm only when the relevant private inputs or public controls change.

Change-source: pulse-maintainer
2026-09-04 00:14:40 +01:00
pulse-triage[bot] f74de141b4 Reconcile convergence with current controls
GitHub reruns preserve the failed workflow SHA, so a repaired convergence control cannot resolve an already committed release. A missed workflow_run event can also leave mutable aliases stranded without another attempt.

Change-source: pulse-maintainer
2026-09-02 13:11:04 +01:00
rcourtman 5476288a4e Merge pull request #1840 from rcourtman/claude/helm-publish-checkout-order
Fix the release preflight worker and Helm publish, and map v6.4.3 to release/v6.4
2026-09-02 10:10:19 +01:00
rcourtman 22b9abf231 Fix the release preflight worker and Helm publish, and map v6.4.3 to release/v6.4
Three defects that the v6.4.3-rc.1 cut exposed, each with its contract note
and proof:

1. scripts/release-preflight-worker.sh published the smoke stack on host port
   7655 and probed it directly. pulse-dev also hosts the maintainer's dogfood
   Pulse instance on 127.0.0.1:7655 and a second instance on 17655, so the
   release smoke failed to start after every other stage had passed on the
   qualified head. The worker now honours PULSE_RELEASE_PREFLIGHT_E2E_PORT,
   otherwise takes the first candidate host port pair it verifies free and
   fails fast when none is, probes health and update status on that port, and
   hands Playwright the same base URL.

2. .github/workflows/publish-helm-chart.yml resolved the chart version before
   checking out the repository, but de41ea1883 made that step call
   scripts/write_github_output.py, so every chart publish since failed with
   "can't open file". Run 33580123246 hit it after all other staging passed;
   the checkout now precedes the resolver.

3. docs/release-control/control_plane.json maps the 6.4.3 version prefix to
   release/v6.4. Run 33579042375, dispatched from main, failed inside the
   compiler dispatch because main advanced one minute after the pipeline
   pinned its source SHA; with pull requests landing every few minutes a
   candidate cannot hold its SHA between prepare and compile. release/v6.4
   was created from main at the exact-SHA-qualified commit 56e51e622e and
   carries these same fixes; v6.4.3-rc.1 published from it.

The deployment-installability contract records the worker port and toolchain
rules and the Helm checkout order; release_preflight_test.py and
build_release_assets_test.go pin them.
2026-09-02 09:32:40 +01:00
pulse-triage[bot] 9edc8bcea3 Merge captured Pulse upstream
Incorporate the batch-start upstream rootful qualification fixes without re-parenting canonical maintainer commits.

Change-source: pulse-maintainer
2026-09-02 03:48:55 +01:00
pulse-triage[bot] 44e274e5b3 Merge captured Pulse upstream
Change-source: pulse-maintainer
2026-09-02 02:52:13 +01:00
rcourtman e836dfda13 Fix rootful qualification readiness
The disposable host reached multi-user.target in a degraded state because distro Podman housekeeping used overlay storage inside the outer container. Mask unused units, force VFS for explicit daemons, and fail closed on systemd unit failures so retained rootful evidence remains trustworthy.
2026-09-02 02:43:30 +01:00
rcourtman 6d0b33fee6 Merge pull request #1834 from rcourtman/pulse/fix-rootful-attestation-import
Fix isolated rootful attester loading
2026-09-02 02:31:37 +01:00
pulse-triage[bot] 5017c599f0 Bind rootful attestation to recovery test
The pre-batch upstream rootful source-closure manifest was created before the local Unix recovery test. Include that compiled installer input so merged qualification evidence remains bound to the complete harness.

Change-source: pulse-maintainer
(cherry picked from commit f5ad4e343e)
2026-09-02 02:28:15 +01:00
pulse-triage[bot] f503b13442 Bind release dispatches to the admitted commit
A workflow dispatch by branch can resolve after that branch moves, allowing an unreviewed tip to enter the release pipeline. Require every publishing dispatch to name its expected source SHA and make the workflow reject a different source or workflow commit before checkout.

Change-source: pulse-maintainer
(cherry picked from commit a461fc9c0a)
2026-09-02 02:28:14 +01:00
rcourtman 56e51e622e Merge pull request #1825 from rcourtman/topic/release-train
Adopt the release train: promote the soaked candidate, not the branch tip
2026-09-02 02:08:32 +01:00
rcourtman 0e6d99af65 Fix isolated rootful attester loading 2026-09-02 01:53:48 +01:00
rcourtman df7ad9be43 Adopt the release train: promote the soaked candidate, not the branch tip
Stable promotions built whatever the dispatch branch was at that second.
The resolver checked that HEAD descends from the promoted release
candidate but never that its content matches, so v6.4.0 shipped 64
changed files, including product code, that v6.4.0-rc.12 had not
soaked. Every v6 version was mapped to main, which now moves every few
minutes under the autonomous maintainer, so each fix to a candidate
brought everything landed since and stable was never an exact soaked
commit. Five of six stable minor releases shipped under version-bound
owner exceptions that waived the soak.

From v6.5.0 the release train applies (RELEASE_PROMOTION_POLICY.md,
"Release Train"): a two-week train sized to measured velocity, a
release/v6.N branch per train declared in the control plane so the
workflow refuses a dispatch from anywhere else, a stable promotion that
may differ from its candidate only in release metadata unless
hotfix_exception names active customer harm, and a seven day soak for
minor releases. The 6.4.x line stays on main so the v6.4.3-rc.1
candidate already prepared there is unaffected. The gap is registered
as coverage gap release-train-exact-candidate-promotion.
2026-09-02 01:17:38 +01:00
rcourtman 73b3d8eff3 Complete rootful artifact source closure 2026-09-02 00:07:39 +01:00
rcourtman 500cc1bf17 Harden rootful qualification evidence boundary 2026-09-01 23:53:36 +01:00
rcourtman 584cef81a1 Add rootful runtime qualification packet 2026-09-01 22:40:50 +01:00
pulse-triage[bot] 5fb7177b8a Require compiler dispatch run details
Change-source: pulse-maintainer
2026-09-01 22:26:46 +01:00
rcourtman 62bfdbca7e Prepare v6.4.3-rc.1 release
Open the v6.4.3 candidate line from main. The v6.4.2 tag was staged on
2026-08-31 but never activated: its release run was cancelled after the
private Pro build failed the compiler memory gate, so the latest published
stable is still v6.4.1. This candidate carries the complete v6.4.2 change
set plus the corrections landed since that tag, including the stale PBS
Backup Running state (#1815), the Windows Unified Agent auto-update 404
(#1820), and shared-token same-hostname agent identity collapse (#1753).

Packet: VERSION, compose and install-docker defaults, Helm chart metadata,
release notes with a declined visual plan, changelog, pointer docs and
the shipped docs mirror, and the deployment-installability cutoff note.
Rollback target is v6.4.1 and the mobile decision is no-mobile-impact.

Tests: the packet tests now describe the 6.4.3 train, v6.4.2 is recorded
as an unpublished stable so it is never derived as the previous stable or
rollback target, and the Python v6.4.2 notes expectation matches the
phrase the notes actually use.
2026-09-01 21:37:41 +01:00
rcourtman 60041ad9e6 Validate each rootless socket identity 2026-09-01 21:26:49 +01:00
pulse-triage[bot] b658a8361f Align release policy with safe workflow outputs
Change-source: pulse-maintainer
2026-09-01 18:32:39 +01:00