Commit Graph

10828 Commits

Author SHA1 Message Date
rcourtman ab562c82aa Encode the release source branch through the shared output helper
The branch is validated by the snapshot guard, but its transfer between
workflow steps must also use the canonical GitHub command-file encoder.
Keep the source binding unchanged and satisfy the workflow trust audit.

Validation: all 41 workflow trust tests and five snapshot tests pass.
Contract-Neutral: Encode the already-validated release branch with the shared GitHub command-file helper without changing source identity or release authority
2026-09-07 19:38:48 +01:00
rcourtman b64709e7b7 Publish reviewed release snapshots independently of branch tips
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.

Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
2026-09-07 19:30:27 +01:00
rcourtman 3300649c12 Merge pull request #1963 from rcourtman/docs/patrol-qualification-delivery
Record verified Patrol and Assistant qualification delivery
2026-09-07 19:20:55 +01:00
rcourtman 7d1fb7285e Record verified Patrol and Assistant qualification delivery
Reconcile the executable plan with the merged implementation and exact
qualification evidence. Keep the independent-environment rollout gate open
and preserve failed attempts, measurement limits and provider refusal.

Preserve the requested reservation for independent release snapshot work.

Refs #1782
2026-09-07 19:14:49 +01:00
rcourtman a42e3800d9 Merge pull request #1960 from rcourtman/fix/patrol-planning-outcomes
Preserve canonical Patrol planning and outcome continuity
2026-09-07 19:09:23 +01:00
rcourtman 17aa972f35 Make investigation wiring checks ignore field alignment
Normalize whitespace in required wiring snippets so gofmt alignment changes
do not fail the model-only handoff contract. Preserve the same required
identifiers and forbidden adapter checks.

Refs #1782
2026-09-07 18:10:32 +01:00
rcourtman c501376843 Preserve canonical Patrol planning and outcome continuity
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.

Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.

Refs #1782
2026-09-07 17:24:25 +01:00
pulse-triage[bot] 7e34b00d4f Merge pull request #1958 from rcourtman/maintainer/20260907T131524Z
Protect alert settings navigation and threshold edits from regressions
2026-09-07 15:54:14 +01:00
rcourtman a66b8e11d7 Merge pull request #1957 from rcourtman/fix/assistant-continuation-evidence
Remove inferred Assistant continuation gates
2026-09-07 15:24:04 +01:00
pulse-triage[bot] 1dcaee8ae8 test(web): preserve threshold edits across controlled disclosure toggles
Threshold table tests replace the disclosure with a mock, so they cannot protect the controlled collapse/reopen behaviour used by snapshot controls. Exercise the real disclosure with reactive parent state and verify accessibility attributes and retained input identity/value without claiming browser focus or installed-release recovery evidence.

Change-source: pulse-maintainer
2026-09-07 14:59:02 +01:00
pulse-triage[bot] e2f15d22df Merge candidate 20260907T130503Z-web-product
Integrate the reviewed settings-shell assertion corrections after confirming the canonical parent reconciliation is tree-identical to the verified candidate base. Preserve exact commit 096480a4e3 and its 33-test Chromium/mobile browser evidence.

Change-source: pulse-maintainer
2026-09-07 14:37:15 +01:00
rcourtman 43514faded Update Assistant adapter contract after gate retirement
Keep the shared tool classification contract while removing assertions that
require the retired session state machine and inferred recovery behavior.

Refs #1782
2026-09-07 14:24:57 +01:00
pulse-triage[bot] 096480a4e3 test(web): verify compact settings headings and canonical routes
Fresh multi-tenant browser runs reproduced desktop-title expectations on mobile organization panels. Match the compact navigation labels, update the server-updates title, and assert canonical URLs including the legacy AI route redirect. All 33 settings-shell checks pass across Chromium, mobile Chrome and mobile Safari; production presentation policy is unchanged.

Change-source: pulse-maintainer
2026-09-07 14:24:22 +01:00
pulse-triage[bot] 8b165130f6 Merge current upstream main into reviewed E2E fixture repair
Incorporate the landed recovery-feedback history without rewriting accepted commit 82ad139f0a. The upstream and local patches have no path overlap.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-07 14:19:37 +01:00
pulse-triage[bot] 25e60532bf Merge pull request #1953 from rcourtman/maintainer/20260907T102346Z
Keep Retry and Dismiss outcomes visible after toasts expire
2026-09-07 14:14:50 +01:00
rcourtman e37353f937 Remove inferred Assistant continuation gates
Let the configured model choose investigation steps within explicit budgets.
Keep canonical planning, permissions and independent verification authoritative,
and preserve streamed conclusions in conversation history.

Expose recorded action outcomes so cached inventory cannot stand in for an
approval or execution receipt. Retain full plan context and make the exact
action review reachable from Assistant, including on narrow screens.

Refs #1782
2026-09-07 14:06:58 +01:00
pulse-triage[bot] 82ad139f0a test(e2e): keep shared multi-tenant fixture non-white-label
The multi-tenant bootstrap granted white_label, which security/status maps to commercial suppression. Settings shell tests then reached General instead of the expected billing pages. Keep the shared fixture non-white-label and assert that both general-purpose profiles exclude this presentation-changing entitlement. Dedicated commercial-boundary tests and production policy are unchanged.

Change-source: pulse-maintainer
2026-09-07 13:56:57 +01:00
pulse-triage[bot] b2b67ae0d5 Merge current upstream main into reviewed recovery feedback
Preserve reviewed recovery feedback commits while incorporating Pulse main through 62f6931c1f. Reconcile independent frontend contract additions and retain the latest upstream browser receipt; the recovery receipt remains preserved in commit 036d324460.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
2026-09-07 13:19:28 +01:00
rcourtman 62f6931c1f Merge pull request #1955 from rcourtman/fix/typed-proxmox-action-evidence
Use typed Proxmox runners and preserve cross-clock action evidence
2026-09-07 12:29:09 +01:00
pulse-triage[bot] 4f56ffdb73 style(web): format toast recovery regression
Apply the repository Prettier contract to the accepted toast accessibility test so the Frontend publication check can evaluate the complete recovery-feedback batch.

Change-source: pulse-maintainer
2026-09-07 12:12:53 +01:00
rcourtman 2a7019b0fa Use typed Proxmox runners and preserve cross-clock action evidence
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.

Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.

Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
2026-09-07 12:00:48 +01:00
pulse-triage[bot] 036d324460 fix(alerts): retain notification recovery failure feedback
Recovery failures otherwise disappear with their toast, leaving slower readers without the action outcome. Keep a view-local untimed equivalent on Overview and Notifications until clear or a newer confirmed action, independently of queue health.

Separate accepted queue mutations from optional activity-refresh failures. Cover ownership and cancellation in focused tests, and verify both real views with scripted APIs in Chromium at three widths and both themes. This implements the current main-only recovery feedback bet, not a backend delivery fix or release-line backport.

Change-source: pulse-maintainer
2026-09-07 11:44:50 +01:00
pulse-triage[bot] e949c15c3d test(alerts): distinguish recovery mutation feedback from health failure
Recovery feedback must distinguish accepted queue actions from failed health reads. Assert the success and error channels for both actions, including cancelled and rejected requests, before persistent feedback is implemented. This adds unit coverage only; it does not qualify browser behaviour or change the UI.

Change-source: pulse-maintainer
2026-09-07 11:02:18 +01:00
pulse-triage[bot] 4ba57faf8c Merge batch-start upstream main
Incorporate upstream commit 96db010415, which existed before this coordination batch began.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-07 10:58:23 +01:00
pulse-triage[bot] 96db010415 Merge pull request #1949 from rcourtman/maintainer/20260907T082759Z
Protect notification explanations through holds and outages
2026-09-07 10:52:25 +01:00
pulse-triage[bot] 5b56306491 Merge remote-tracking branch 'origin/main'
Change-source: pulse-maintainer
2026-09-07 10:40:34 +01:00
rcourtman 09ab5c2d0a Merge pull request #1951 from rcourtman/fix/patrol-filesystem-evidence
Preserve native filesystem evidence and Patrol action history
2026-09-07 10:24:57 +01:00
pulse-triage[bot] cdab4e1c0c test(web): preserve toast announcement and focus semantics
Recovery feedback must remain available without stealing keyboard focus. Cover existing error/warning and success/info live-region distinctions, atomic contextual text and retained focus through the public toast entry point. This protects accessibility behaviour without adding product scope; DOM assertions do not establish screen-reader acceptance.

Change-source: pulse-maintainer
2026-09-07 10:02:25 +01:00
rcourtman 3a4a3fd62b Preserve native filesystem evidence and Patrol action history
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.

Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.

Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
2026-09-07 09:45:31 +01:00
pulse-triage[bot] b18c08af4c Merge candidate 20260907T082519Z-web-product
Change-source: pulse-maintainer
2026-09-07 09:37:16 +01:00
pulse-triage[bot] 7a261e4830 test(alerts): cover held delivery rows across log outages
Existing outage coverage exercises attempted deliveries only. Protect held-only histories from appearing readable during an outage, and verify recovery uses the current held state rather than stale rows or a misleading empty result.

Change-source: pulse-maintainer
2026-09-07 09:26:35 +01:00
pulse-triage[bot] 0af1fee10b Merge batch-start upstream main
Change-source: pulse-maintainer
2026-09-07 09:25:35 +01:00
pulse-triage[bot] de09f27d29 fix(release): reconcile runner with published daemon identity repair
Replace the superseded local ACL alternative with the exact three files reviewed and merged in PR #1948 (03848a932f). Preserve locked CLI execution, private workspace permissions and failure gates. Rootless daemon identity selects container 0:0; rootful uses the host UID/GID. Probe runtime before expensive qualification. This is main-line reconciliation, not a release-line backport or release qualification.

Change-source: pulse-maintainer
2026-09-07 09:20:29 +01:00
rcourtman 03848a932f Merge pull request #1948 from rcourtman/fix/release-rootless-smoke
Fix release smoke workspace identity on rootless Docker
2026-09-07 09:06:49 +01:00
pulse-triage[bot] b85444c7c2 Merge candidate 20260907T071010Z-delivery-trust
Change-source: pulse-maintainer
2026-09-07 09:02:13 +01:00
rcourtman 8b73085e82 Fix release smoke workspace identity on rootless Docker
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.

Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
2026-09-07 08:29:42 +01:00
pulse-triage[bot] 0d0b105352 fix(release): map non-root browser mount access
Rootless Docker maps the unchanged browser UID to a subordinate host UID, so the host-owned 0770 integration tree is inaccessible. Grant that mapped identity POSIX ACL access only within the disposable integration mount, without following symlinks or granting world access. Inherit host access for generated evidence and fail closed on mapping or ACL errors. Preserve container UID/GID, image selection, direct installed CLI, browser gates and failure propagation. Focused fixtures cover identity mapping, subordinate mapping and preparation failures; exact release qualification remains separate.

Change-source: pulse-maintainer
2026-09-07 08:19:30 +01:00
pulse-triage[bot] 0529b32c57 test(web): preserve current notification hold evidence
The current notification diagnostic demand records confusion between failed delivery and intentional silence. Pin precedence of current holds over historic dispatch, known event reason labels and unknown-reason fallback so future UI changes do not erase that distinction. This adds regression coverage only; it does not establish recipient delivery.

Change-source: pulse-maintainer
2026-09-07 08:16:38 +01:00
pulse-triage[bot] ae1ac6ae95 fix(release): prevent Playwright runner download fallback
Exact admission attempted to fetch playwright@1.63.0 when the mounted runner was unavailable. Invoke the npm-ci-installed CLI directly so missing or inaccessible dependencies fail closed without substituting a registry package. Preserve the existing container identity and gates; this does not claim to resolve the observed EACCES. Exercise shell arguments and failure propagation with a mocked Docker command.

Change-source: pulse-maintainer
2026-09-07 00:24:10 +01:00
pulse-triage[bot] a5cbbaf1d4 Merge pull request #1946 from rcourtman/maintainer/20260906T201829Z
Stop permanent alert retries and keep delivery and backup evidence truthful
2026-09-07 00:03:21 +01:00
pulse-triage[bot] de5b49678e test(web): preserve mixed guest backup coverage evidence
Operator feedback distinguishes successful job completion from protection of every guest. Lock down the existing model boundary with mixed protected, unprotected, failed and unevaluated guests so aggregate success cannot silently erase missing coverage. Task success must not substitute for canonical posture evidence.

Change-source: pulse-maintainer
2026-09-06 22:57:17 +01:00
pulse-triage[bot] 9dd4750536 docs: sync watchdog guidance to shipped mirror
Copy the reviewed troubleshooting guidance into the shipped frontend mirror so public docs and repository docs remain identical.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-06 22:36:42 +01:00
pulse-triage[bot] edcd1dcc5e Merge batch-start upstream main
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/api-contracts.md
2026-09-06 22:31:11 +01:00
pulse-triage[bot] ad0a70bc75 test(notifications): cover SMTP transaction retry replies
Check permanent, transient and recovered sends at envelope and DATA boundaries without external delivery.

Change-source: pulse-maintainer
2026-09-06 22:26:55 +01:00
rcourtman 560dbf314c Merge pull request #1935 from rcourtman/fix/docker-observation-evidence
Preserve diagnostic evidence and Patrol outcome truth
2026-09-06 22:21:42 +01:00
pulse-triage[bot] 8490038699 style(frontend): format delivery refresh regression
Apply the repository formatter to the accepted stale-delivery evidence regression test. This changes layout only and preserves the reviewed assertions.

Change-source: pulse-maintainer
2026-09-06 22:17:09 +01:00
pulse-triage[bot] 13e5201f02 Merge candidate 20260906T210510Z-delivery-trust
Change-source: pulse-maintainer
2026-09-06 22:16:05 +01:00
pulse-triage[bot] e9904249c9 Merge candidate 20260906T210504Z-core-runtime
Change-source: pulse-maintainer
2026-09-06 22:16:04 +01:00
pulse-triage[bot] 8b295385cd Merge candidate 20260906T205512Z-web-product
Change-source: pulse-maintainer
2026-09-06 22:16:04 +01:00
pulse-triage[bot] 92c3297049 ci: add fixed UUID layout diagnostic without release gate waiver
The exact release tree retains a failed paired UUID benchmark check, while push CI cannot repeat that comparison. Provide a reviewed-source route to collect the requested four-condition hosted layout evidence instead of repeating local samples or changing product order.

Fix source/tree/toolchain identities, isolate diagnostic controls, alternate ten rounds, and retain partial receipts without publishing binaries. Execution still needs separate operator authority; collection success does not dispose of the failed gate. Nine focused harness tests and existing benchmark contract tests pass.

Change-source: pulse-maintainer
2026-09-06 22:11:03 +01:00