37 Commits

Author SHA1 Message Date
pulse-triage[bot] ad9877e28d test: match lifecycle receipts at published webhook precision
Preserve nanosecond API timestamps for incident queries, compare recipient alert identity and RFC3339-second starts, and reject ambiguous same-second recurrences. Require a recipient receipt for terminal retry as well as its original notification audit.

Change-source: pulse-maintainer
2026-09-10 16:22:51 +01:00
pulse-triage[bot] eb88aa7be2 test: retry live terminal alerts before resolving acceptance fixture
Installed beta.2 correctly cancels obsolete terminal firing rows on resolution. Exercise operator retry while the occurrence is live, then verify distinct recurrence delivery, and retain failed retry responses.

Change-source: pulse-maintainer
2026-09-10 16:21:31 +01:00
pulse-triage[bot] 73a7e477ab test: correct installed alert fixture scope contract
The first immutable beta.2 fixture stopped with 403 before alert stimulus because the documented token omitted monitoring:write. Include the required scope and verify both corrected admission and the original denial through the production scope guard. Preserve rejected attempts and require reviewed fresh fixtures; no product authorization checks are changed.

Change-source: pulse-maintainer
2026-09-10 15:58:12 +01:00
pulse-triage[bot] 0f87aad59f test(alerts): add external installed lifecycle acceptance driver
Published notification recovery still lacks installed ordinary-recipient lifecycle evidence. Add a synthetic-only HTTP driver with bounded faults, occurrence-aware receipts, preserved-state restart attestations and explicit incomplete-acceptance reporting so qualification can gather that evidence without changing the frozen product.

Validate the harness failure/observation guards and its report/template contracts separately from installed acceptance. No production code or release gate changes.

Change-source: pulse-maintainer
2026-09-10 15:38:49 +01:00
pulse-triage[bot] 37d1874904 docs(msp): verify published evaluation bundle guidance
Replace obsolete v6.2.1 guidance using retained signed v6.4.1 delivery and payload evidence. Limit privacy claims to the evaluated licence request, synchronize the shipped guide, and adapt the registered deployment regression and contract without claiming installed onboarding acceptance.

Change-source: pulse-maintainer
2026-09-09 20:23:20 +01:00
rcourtman 618700db5e test(patrol): qualify bounded service storage failures
Add a disposable service-storage fault with an independent filesystem
oracle, bounded tmpfs writes, identity checks and verified recovery.
Exercise overwrite and symlink refusal without contacting a model.

Align the published schema with supported summary-term groups and validate
the complete catalogue in CI. Record the exact proof and remaining model
and missing-access qualification limits in the customer-journey plan.
2026-09-06 06:04:56 +01:00
rcourtman ab9e0e4d3d fix(patrol): align qualification schema with action scenarios
The runtime and three restart scenarios use health_process_stop, but the
published schema rejected it. Accept that implemented injector and check
actual catalogue fault types against the schema to prevent recurrence.

Record the remaining missing-access and storage qualification gaps.
2026-09-06 04:33:20 +01:00
pulse-triage[bot] b3395d9116 docs(web): retain admission-clean recovery qualification receipts
Preserve original failed-run JUnit bytes in deterministic gzip archives while normalising trailing CDATA whitespace in reviewable XML. Bind the passing source-build results, invocation flags and table-access attachments without changing tests or implying installed delivery qualification.

Change-source: pulse-maintainer
2026-09-05 22:47:25 +01:00
pulse-triage[bot] 7ddd910cb6 docs: clarify conditional navigation qualification evidence
The retained JUnit cannot establish that opt-in table assertions ran, and the repeat command omitted their flag. Make the repeat complete and distinguish navigation recovery from changed-data recovery so this receipt is not over-weighted in release decisions.

Change-source: pulse-maintainer
2026-09-05 22:04:45 +01:00
pulse-triage[bot] e0f93d03e9 test: record integrated navigation recovery qualification
The combined mainline recovery and narrow-screen repairs need independent integrated evidence after recent merges. Retain eight passing isolated Chromium results and representative screenshots, with explicit limits so source-only navigation success is not mistaken for candidate or notification-delivery qualification.

Change-source: pulse-maintainer
2026-09-05 21:46:59 +01:00
pulse-triage[bot] 370a81e04a docs(test): record 320px integration qualification
Record the successful eight-case Chromium rerun and bounded visual inspection
performed on the exact merged test tree. Preserve the known narrow-layout
limitations and avoid upgrading the formal browser or release claims.

Change-source: pulse-maintainer
2026-09-05 19:20:45 +01:00
pulse-triage[bot] 8be4e41e8c test(web): extend phone reflow qualification to 320px
Existing phone receipts cover 390px, whereas reflow guidance includes 320px cell content. Extend the opt-in navigation and text-bound checks without changing product behaviour. Preserve the stronger single-line label requirement at 390px while allowing wrapping at 320px. Record the initial one-pass/one-failure diagnostic and the cancelled queued final rerun explicitly; final test revision remains browser-unqualified.

Change-source: pulse-maintainer
2026-09-05 19:06:45 +01:00
pulse-triage[bot] 537c7ae9a5 fix(web): keep Docker phone update labels and detail names readable
Chromium receipts showed that the phone table clipped update badges without any horizontal path to recover the text. Wrap existing labels within reduced cell padding and allow expanded drawer names to wrap, preserving Android page-owned scrolling and existing action semantics. Add real text-bound and heading assertions and retain six passing reconnect cases plus inspected synthetic screenshots.

Change-source: pulse-maintainer
2026-09-05 18:28:23 +01:00
pulse-triage[bot] 0833e8dc80 test(web): qualify superseded admission and diagnose narrow table access
Close the missing third-organisation and real shell SIGTERM evidence without expanding product scope. Retain measured narrow-table clipping and accessible-name evidence so follow-up repairs preserve Android vertical gesture ownership rather than assuming horizontal scroll access.

Validation: eight Chromium admission cases, two local-backend narrow socket/access runs, real Compose/Playwright SIGTERM cleanup, twelve focused shell tests, and diff checks passed. No installed release or physical-device qualification.
Change-source: pulse-maintainer
2026-09-05 17:57:42 +01:00
pulse-triage[bot] 9fdf8059e0 test(web): qualify admission races and reconnect at phone height
Close the unfinished browser evidence gap without extending UI scope. Exercise admission races and subsequent current-organisation reconnect requests, and use 390x844 for populated socket recovery so retained screenshots expose the remaining table clipping rather than implying mobile layout acceptance.

Change-source: pulse-maintainer
2026-09-05 17:35:14 +01:00
pulse-triage[bot] 38f0960d4b test: qualify owned cleanup with real Chromium writers
Process fixtures did not prove that browser-generated artefacts finish before supervisor cleanup. Exercise real Chromium late cookie, screenshot, trace and video writers for all three catchable signals, while keeping full-stack qualification limits explicit.

Change-source: pulse-maintainer
2026-09-05 17:13:24 +01:00
pulse-triage[bot] 57beb6010f test: reap isolated browser writers before credential cleanup
Shell-only signal traps could leave browser descendants writing sensitive state after cleanup, and simultaneous runs shared the same cookie cache. Give the Linux qualification runner an invocation-owned cookie root and a child-subreaper supervisor so catchable interruption waits for writers before removing owned artifacts. Preserve normal reports for inspection and fail closed if writers cannot be reaped. Focused fixtures cover all three signals, late detached writers, concurrent isolation and forced termination; no real-browser cleanup or release readiness is claimed.

Change-source: pulse-maintainer
2026-09-05 16:31:12 +01:00
pulse-triage[bot] 857e25f6b1 fix(web): preserve scoped local principal for organisation management
Scoped local sessions correctly lose privileged security-status fields, but Settings relied on the configured admin username and hid owner controls. Expose the validated current principal without broadening capabilities, and use it for organisation identity.

Include the API and dependent subsystem contracts, recognised payload and settings-shell tests, and a source-bound desktop/narrow browser receipt in this commit. Fresh matrices each pass six scenarios with one expected disabled-feature skip. Admission/reconnect and interruption cleanup remain separate unfinished qualification.

Change-source: pulse-maintainer
2026-09-05 16:04:12 +01:00
pulse-triage[bot] 296a131c0a test(e2e): use session identity for cross-org sharing diagnostic
Reproduced the restricted primary token being refused after organisation reload. Keep token isolation intact and exercise the sharing flow with a cookie session, with explicit authentication preconditions.

The diagnostic still fails on missing acceptance controls; retain that failure, quarantine and exact runtime receipts. Record process-group TERM cleanup limits rather than claiming complete artifact cleanup.

Change-source: pulse-maintainer
2026-09-05 15:02:06 +01:00
pulse-triage[bot] a6a02847ef test: isolate shell runner browser artifacts and multi-tenant auth
Concurrent qualification runs could overwrite shared browser artifacts and authentication state, while an inherited PLAYWRIGHT_BASE_URL could send browser traffic outside the shell-owned stack. Scope outputs and fixture credentials to each invocation and clear that endpoint override so isolation evidence refers to the intended stack.

Focused runner checks cover inherited overrides and cleanup. Recorded concurrent Docker diagnostics reached healthy stacks but browser execution remained blocked by the existing multi-tenant quarantine; this test-only repair does not claim browser or release qualification and changes no user-visible application surface.

Change-source: pulse-maintainer
2026-09-05 13:13:28 +01:00
pulse-triage[bot] 9a837b8b40 fix(web): discard superseded organisation admission responses
An outgoing admission refresh could restore platform navigation after an organisation switch. Accept only the latest request response, including when a newer request fails or is still pending. Preserve authoritative successful empty admission and subsequent navigation recovery.

Reproduced at 390px and 1440px; six repaired synthetic full-app browser cases and 59 focused tests pass. Typecheck passes. This does not qualify backend isolation, a released artifact or external alert delivery.

Change-source: pulse-maintainer
Contract-Neutral: Restore existing latest-organisation admission semantics only; no API, entitlement, navigation surface or subsystem contract changes. Focused ordering regressions and desktop/narrow browser proof cover the repair.
2026-09-05 10:33:40 +01:00
pulse-triage[bot] 6570e95bdb fix(web): retain platform admission when reconnect refresh fails
A reproduced admission HTTP 503 after socket recovery removed platform destinations despite populated inventory. Retain the last valid facet on request failure, keep tenant resets and successful empty responses authoritative, and cover desktop/mobile interruption and recovery.

Change-source: pulse-maintainer
2026-09-05 05:12:58 +01:00
pulse-triage[bot] 672a497076 fix(web): preserve platform admission through cold reconnect
Keep resource snapshot receipt separate from alert hydration and tenant-scoped across reconnect. Include matching subsystem contracts, architecture coverage and fresh browser receipt.

Validation: 87 focused tests and three real-backend Chromium checks pass at 1440, 1100 and 390px. Exact release-candidate qualification remains outstanding.

Change-source: pulse-maintainer
2026-09-05 04:43:43 +01:00
pulse-triage[bot] d60da624c8 test(web): qualify mobile alert focus return in Chromium and WebKit
The integrated removed-row focus repair had only jsdom coverage. Exercise populated Timeline and Resource dialogs with production styles in two browser engines so focus trapping, dismissal and fallback regressions are observable without live credentials or customer data. This is synthetic component qualification, not backend delivery evidence.

Change-source: pulse-maintainer
2026-09-05 03:44:17 +01:00
rcourtman f0478c769b Accept tool-free Patrol all-clears 2026-08-14 22:42:08 +01:00
rcourtman 48fac73ff0 Rework Patrol around outcome-driven autonomous operations 2026-08-14 12:52:51 +01:00
rcourtman 4d80e53588 Align restart-loop qualification with Patrol threshold 2026-07-16 20:53:02 +01:00
rcourtman 676117bf27 Separate Patrol evidence and model-turn budgets 2026-07-16 17:50:08 +01:00
rcourtman b6e5f4d512 Align remediation qualification with Patrol policy 2026-07-16 17:01:37 +01:00
rcourtman d162110233 Make remediation fixtures model-neutral 2026-07-16 15:44:19 +01:00
rcourtman a39150ba4c Make qualification profiles statistically passable 2026-07-15 17:34:57 +01:00
rcourtman 87699dfff3 Align remediation qualification with advertised actions 2026-07-15 11:31:56 +01:00
rcourtman 03ae7d2b58 Score investigation facts without magic words 2026-07-15 10:56:12 +01:00
rcourtman a95edafcf1 Qualify model-led Patrol investigations 2026-07-15 10:32:16 +01:00
rcourtman 3b1bc65b43 Separate Watch symptoms from injected fault targets 2026-07-14 19:02:32 +01:00
rcourtman 2b271e3e20 Repair disposable dependency qualification fixtures 2026-07-14 18:49:25 +01:00
rcourtman 3f45953866 Complete Patrol autonomous qualification loop 2026-07-14 15:35:48 +01:00