Preserve the reviewed sensor synchronization backport while incorporating the protected beta.2 preparation merge now present upstream. This keeps the later test-only correction additive and outside the frozen candidate that already landed.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Sleeping fixture writers can expose only some updated domains to the second sample, producing false zero watts in CI. Run collection under synctest, wait for its sampling timer, update counters synchronously and join completion before assertions or cleanup.
Retain availability, routing and wraparound assertions, add exact delta checks, and apply the same ordering to AMD fallback and RAPL preference fixtures. Production collection and sampling semantics are unchanged.
Change-source: pulse-maintainer
(cherry picked from commit 2e3ff7494c)
Add the reviewed cold-tenant isolation repair to the beta.2 tester scope and replace the superseded route-normalization benchmark note with the retained metrics-handler advisory result. Keep the unresolved relationship and pre-RC disposition explicit.
Contract-Neutral: release-note evidence only; no runtime behavior, public API, qualification threshold or selected product checkpoint changes.
Change-source: pulse-maintainer
Shorten the retained-delivery outcome and split the reporter-specific risk so the repository release notes satisfy the customer-facing bullet limit without changing product scope or claims.
Contract-Neutral: release-note formatting only; version, runtime behavior, public APIs, and the selected product checkpoint are unchanged.
Change-source: pulse-maintainer
(cherry picked from commit 539eb2f7a9197427a9dc54e66c37e3c22d816b1c)
Freeze the protected notification recovery repair as the next beta checkpoint and align version pins, tester notes, rollback guidance, and the zero-capture visual plan.
Contract-Neutral: release preparation changes version and delivery metadata only; product runtime and public API behavior remain the reviewed release-line checkpoint.
Change-source: pulse-maintainer
(cherry picked from commit 9a1f44d7c8a3e7757f5f3f3a1f8016997f04fc72)
The failed exact rehearsal buffered the store-history latency assertion, preventing resource telemetry from locating its actual test interval. Extend the existing exact API lifecycle allowlist and cover both targets with synthetic pass/fail fixtures without rerunning product qualification or changing thresholds. This is prospective observability, not clearance of the retained latency or crash evidence.
Change-source: pulse-maintainer
(cherry picked from commit f293d6fe33)
The failed qualification and isolated API samples used the same setup but lacked comparable phase and per-worker request evidence. Retain UTC setup/load boundaries, execution context and first-attempt versus subsequent successful resource latency without altering workloads, aggregate reports or verdicts. These are observational partitions, not cold-tenant or historical-cause claims.
Focused instrumented API stress passed; JSON assertions verify ordered phases and partition totals. Historical exact-candidate failure remains unresolved.
Change-source: pulse-maintainer
(cherry picked from commit 98efe62d7c)
Buffered package logs cannot map the API stress-test failure to resource telemetry. Stream Go events and retain a bounded target lifecycle with distinct event, receipt and resource collection times, while preserving readable output and pipeline failure status. Synthetic decoder and worker tests cover pass, skip, failure and unavailable telemetry; this does not clear historical qualification or authorise a replay.
Change-source: pulse-maintainer
(cherry picked from commit 4462e43288)
The held latency failure lacks contemporaneous resource context, and isolated passing samples do not explain it. Retain allowlisted backend boundary counters including cgroup ancestors in the existing durable log, preserving backend failures and unchanged qualification thresholds. Focused tests cover failure exits, unavailable telemetry, ancestor collection and environment filtering.
Change-source: pulse-maintainer
(cherry picked from commit b116f2defc)
Cold resource store construction held the shared cache mutex and delayed unrelated tenants, including cache hits. A bounded API measurement found 480ms p95 cache-hit mutex wait, while a synthetic blocked constructor reproduced the coordination defect independently of storage internals.
Deduplicate construction per tenant outside the cache mutex, and coordinate eviction with in-flight opens. Add synthetic regressions for unrelated tenants, same-tenant deduplication, retry after failure and close ordering. The resource API race suite passes. This does not establish the cause of the historical release stress failure or qualify a release.
Change-source: pulse-maintainer
Contract-Neutral: Internal tenant-store lock scheduling repair only; routes, payloads, authorization, tenant keys, storage format and eviction semantics are unchanged. Existing race-tested API coordination regressions establish deduplication, retry and close ordering; no frontend surface changes.
(cherry picked from commit 3b91896371)
Diagnostic query masking recognised only lowercase credential names, leaving mixed-case and encoded variants visible in URL and transport-error diagnostics. Match decoded names without case while preserving query spelling, unrelated parameters and the original request URL. Add seven regression cases covering diagnostics and wrapped error identity.
Change-source: pulse-maintainer
(cherry picked from commit 0e61fa62c4)
Use patched Vitest/coverage 4.1.11 and js-yaml 4.3.2. Adapt constructor mocks, callable mock types and explicit call-history cleanup for Vitest 4 without weakening assertions or audit gates.
Change-source: pulse-maintainer
(cherry picked from commit 15000f0a67)
Backport Core 439c1a6195 API repair for the candidate recovery-control regression. Preserve registered handlers while refreshing their synchronised owner in both monitor replacement paths. Include stopped-owner, concurrency and scope tests and matching release-line contracts; exclude unrelated main changes.
Change-source: pulse-maintainer
A zero response override erased the exponential schedule and exhausted later retries immediately. Backport the notification repair and regression test from PR #1976, reproducing both subsequent 503 and headerless 429 failures on the release candidate. Focused race-enabled retry/parser tests pass after repair; this does not replace the selected beta or approve publication.
Change-source: pulse-maintainer
Backport only the workflow hunk from 5f3b73955a. PR #1971 exposed the release-line job-level skip leaving required matrix check names absent. Expand shards and gate existing steps without changing test commands or security checks.
Contract-Neutral: CI reporting repair only; no product, policy, deployment or selected-candidate changes.
Change-source: pulse-maintainer
Incorporate protected release/v6.4 merge afef6eaae0 while preserving the exact reviewed projection-bounds backport and its ancestry.
Change-source: pulse-maintainer
Backport of a41c60597b. Named candidate regression: resolved incident reads reopen after recurrence. Both 2m and 500ms dispatcher baselines fail on 601d061; focused incident and dispatcher tests pass with race count=20 after repair. No persistence optimisation, duplicate migration or release-readiness claim.
Change-source: pulse-maintainer
Name the landed notification-confidentiality and discovery repairs, add their
focused tester checks, and disclose the fresh installed persistence-write and
discoverability evidence. Keep the existing 6.4.4-beta.1 mapping and stable
rollback target unchanged.
Contract-Neutral: Align release notes, changelog, and the zero-capture rationale with already-reviewed source and fresh user evidence without changing runtime behavior, release gates, or publication authority
Change-source: pulse-maintainer
Backfill could save a stale List snapshot after manual discovery repaired a service, restoring unknown identity and dropping its URL and engine version. Derive and persist missing suggestions from the current record under the store lock instead, without holding it across monitor reads.
Add a deterministic SetReadState/manual-refresh interleaving and encrypted restart assertions, plus coverage for current identity, dismissed proposals, deletion and persistence failure. The discovery package passes twenty race-enabled repetitions.
Change-source: pulse-maintainer
The branch is validated by the snapshot guard, but its transfer between
workflow steps must also use the canonical GitHub command-file encoder.
Keep the source binding unchanged and satisfy the workflow trust audit.
Validation: all 41 workflow trust tests and five snapshot tests pass.
Contract-Neutral: Encode the already-validated release branch with the shared GitHub command-file helper without changing source identity or release authority
(cherry picked from commit ab562c82aa)
Change-source: pulse-maintainer
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
(cherry picked from commit b64709e7b7)
Change-source: pulse-maintainer
Incorporate the protected landing of the preceding release-line batch while preserving the exact reviewed Discord and Telegram backport tips and their ancestry.
Change-source: pulse-maintainer
Literal-only query matching and the separate resolved ntfy transport caller leaked recognised URL credentials. Decode each query name once and project ntfy transport errors before logging or returning them, without changing destinations or error causes. Add synthetic sink-matrix and HTTP projection regressions plus the bounded notification contract in this commit.
Change-source: pulse-maintainer
(cherry picked from commit 21ed7a8927)
The reviewed v6.4 userinfo backport made the existing delivery-log caller fail closed on a complete error sentence, which preserves secrecy but discards useful status context and fails the release-line regression. Redact embedded webhook URLs separately while retaining malformed-URL fail-closed behaviour.
Change-source: pulse-maintainer
Backport 77a8e4ee35 for candidate credential confidentiality. Preserve transport causes and destinations; cover Slack/GovSlack, encoded and legacy paths, and rate-limit diagnostics.
Change-source: pulse-maintainer
Security backport of db0c72c367. Release base reproduces credential disclosure in transport diagnostics and rate-limit logs. Preserve exact helper/tests; relocate the confidentiality contract without importing unrelated SMTP work.
Validation: three focused notification tests fail before repair and pass with -race -count=20 on Go 1.26.7. Protected PR review and exact-candidate qualification remain required.
Change-source: pulse-maintainer
The candidate publisher rejected its admitted SHA input. Execute the backported workflow guard in focused tests so accepting the input cannot silently permit source or workflow drift before checkout.
Change-source: pulse-maintainer
A workflow dispatch by branch can resolve after that branch moves, allowing an unreviewed tip to enter the release pipeline. Require every publishing dispatch to name its expected source SHA and make the workflow reject a different source or workflow commit before checkout.
Change-source: pulse-maintainer
(cherry picked from commit a461fc9c0a)
(cherry picked from commit f503b13442)