Backport PR1948 for the candidate preflight EACCES regression. Resolve main-only context by preserving release/v6.4 fixed smoke ports and omitting its unavailable PULSE_E2E_BASE_URL variable. No runtime changes, ACL widening, CLI download fallback or gate waiver. Supersedes the proposed ae1ac6ae95 and 0d0b105352 stack; normal reviewed source landing and exact qualification remain required.
(cherry picked from commit 8b73085e82)
Change-source: pulse-maintainer
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.
Change-source: pulse-maintainer
(cherry picked from commit 64dba483d0)
Backport runtime and regression tests from 495562ef66. Reproduced both failures on exact release-line parent 101bae339; patched 38 focused tests, TypeScript and three-width Chromium pass. Retain local qualification and exact runtime browser receipt. No recipient receipt or release HOLD clearance claimed.
Change-source: pulse-maintainer
PR #1933 failed paired normalization benchmarks despite unchanged hot-path source. Preserve actual checkout identities, selected toolchains and sample order so investigation does not confuse PR head metadata with measured source. Keep thresholds and sample collection unchanged.
Change-source: pulse-maintainer
(cherry picked from commit cbfe0d8eac)
Backport production correction from d04f368f6f. Candidate regression introduced by 4d2b312457 after v6.4.1. Two baseline recovery cases fail; 32 focused final tests and four synthetic Chromium cases pass. Existing delivery-log ordering defect remains main-only, not established as a candidate regression.
Change-source: pulse-maintainer
Release v6.4 reproduces lost concurrent invocation IDs and duplicate approval cards. Backport the four runtime/test files from reviewed main fix 33b852f66b and portable synthetic browser fixture 2d36bb7d4d, without private replay attestations or unrelated main state.
All 167 affected units and three browser widths pass; independent release-parent runtime substitutions fail. Record fresh scoped browser evidence and contract obligations; this does not qualify providers or release promotion.
Change-source: pulse-maintainer
Backport main 386fc0415e and its custom bridge correction 2ed9965968. Fix the provider-interface association regression introduced by afaf128950, present in v6.4.1 and this release candidate. Seven negative matcher cases and NAS ingestion fail before the repair; focused matcher, filtering, ingestion and manual link race tests pass three times afterwards. Preserve management bridges and explicit unicast report hints. No legacy link cleanup or manual-intent persistence change; reporter issue #1930 remains unconfirmed.
Change-source: pulse-maintainer
Backport test coverage from 4d87bd37c5 and 7425089632, as merged in 9b4fa52d84, for candidate regression repair 7a5b535a43. No production changes. Focused monitoring receipt race test passes three repetitions. Loopback and manager restart evidence does not qualify installed provider delivery.
Change-source: pulse-maintainer
Reproduce false recovery on candidate f71542ec21, then backport storage-only changes from 2e661e075a and 9a8ee6a5a7. Preserve known inactive/disabled behavior and normalized offline capacity suppression. Focused storage race tests pass three repetitions; installed qualification and a new exact-candidate soak remain required.
Change-source: pulse-maintainer
Retain storage policy aliases in durable metric and forecast metadata and use them during active-alert re-evaluation. Recover exact legacy PBS aliases from the recorded instance and datastore identity. Prevent a configuration reload from fabricating recovery against global defaults after restart.
Change-source: pulse-maintainer
(cherry picked from commit da5be2db15)
Backport 9d1b726 onto release/v6.4 parent 89c8e614 with before-failing and after-passing hook and Chromium controls. CI train admission is already merged; retain its independent contract evidence without duplicating changes.
Change-source: pulse-maintainer
Release-line proposals were receiving documentation and boundary checks while Build and Test and Core E2E excluded release/v* targets. Apply the reviewed branch-admission contract to the active train before publishing further alert regression coverage, without changing existing path or job gates.
Change-source: pulse-maintainer
Distinguish policy skips from provider success so suppressed jobs do not create false sent rows or successful audit entries. Reconcile cancelled queue health after releasing alert gates, preserve real attempt history, and cover all three providers for firing/recovery and global/destination disablement.
Change-source: pulse-maintainer
(cherry picked from commit 229d8668af)
Reproduced on candidate 80a5c50e13: failed and DLQ retry replay resolved firing entries after queue reopen, and per-item retry accepts cancelled or delivered rows. Backport fe273fc949 without unrelated main failure-classification changes; preserve grouped active members, recovery jobs and audit history. Focused notification regression tests pass ten times under the race detector.
Change-source: pulse-maintainer
Backport 6375d09a8b. Candidate f64fbb8b7 reproduced six false independent confirmations before repair; focused Docker result/executor and receipt reconciliation tests pass afterwards. Preserve stopped updates and execution history. This does not resolve issue #1891 or qualify an installed artifact.
Change-source: pulse-maintainer
Backport production fixes 57cb1a83bf and 49b998a251, with restart coverage from 49928385ba. Adapt PBS webhook assertions to the release-line nonzero recovery fixture.
On candidate 6558b2d106, reproduced confirmed-empty storage retaining its incident; applying only the storage guard then reproduced stale recovery content. Both fixes pass focused alert checks and three race-enabled repetitions across alerts and monitoring. Local synthetic receiver and orderly restart evidence only; no installed qualification.
Change-source: pulse-maintainer
Backport of 31f1f1933a, adapted to release/v6.4 client tests. Reproduced absent envelopes returning zero metrics and the null-status poller availability failure on candidate base 239ee0f9da before applying the production fix. Focused client and lifecycle race checks pass three repetitions. No installed qualification claimed.
Change-source: pulse-maintainer
Backport 2b78867cae with the PBS HTTP fixture and connectivity characterisation from a01efeed6b. Exclude unrelated main-line security-status documentation.
Release-line reproduction on 369e7f339e: node-status denial falsely resolves active memory utilisation. Retain active metric alerts until a valid sample arrives; connectivity and policy suppression remain independent.
Validation: go test -race ./internal/alerts ./internal/models ./internal/monitoring -run 'Test.*PBS' -count=3 passes. Installed destination delivery and restart persistence remain unqualified.
Change-source: pulse-maintainer
Reproduced on release base 11539a8059: HTTP 502 quoting API error 403 and HTTP 503 quoting API error 404 discarded cached backups. Both now preserve inventory; genuine 401/403/404 remain terminal.
Backport of c3b28f4557, including substantive monitoring contract and verification documentation. Adapt client test rename to the three existing callers; no unrelated mainline tests imported.
Validation: focused monitoring and PBS client tests passed with -race -count=3. No installed candidate, notification delivery or soak claim.
Change-source: pulse-maintainer
Reproduced on release candidate 7f44ccd047: WARNING to EMERGENCY retained severity but dispatched only once instead of twice. Backport the existing delivery repair and acknowledgement/rate-budget lifecycle regression coverage; no new product scope.
Backport-of: 4752d5b4b7 (code and tests), b116d05592
Validation: five focused race repetitions passed; pre-fix active transition failed. Appliance/provider receipt and restarted candidate soak remain outstanding.
Change-source: pulse-maintainer
Backport runtime mapping and regression tests from 65a024b3d3. Candidate v6.4.3-rc.1 and stable v6.4.1 omit the documented EMERGENCY severity. Include release-line monitoring and unified-resource contracts for the repaired projection and recovery boundary.
Reproduced omitted projection, zero notification callbacks and false recovery before the fix. Affected package suites and focused race tests passed in the initial turn. Appliance and external-provider receipt remain unqualified.
Change-source: pulse-maintainer
Correct the INFO backport so native TrueNAS NOTICE remains actionable while retaining informational canonical severity. Preserve the provider level as optional evidence and pin projection, JSON compatibility, alert activation, and confirmed recovery boundaries.
Adapted from ff1d010dd9 for release/v6.4.
Change-source: pulse-maintainer
Issue #1892 reports successful replication information requiring acknowledgement. Preserve provider information on resources while excluding TrueNAS INFO-level conditions from active alert synchronisation. Warning conditions still activate and clear when downgraded to information.
Resource-incident timeline events contain numeric placeholders, not threshold evidence. Avoid displaying these as a fictitious 0 >= 0 trigger while retaining numeric metric formatting. Focused regressions reproduce both failures and pass with these changes.
Change-source: pulse-maintainer
(cherry picked from commit 7726539f83)
TrueNAS emits FINISHED for successful replication, but the recovery mapper treated it as unknown. Recognise that provider state while preserving error precedence and the missing-run guard; add regression coverage reproducing the reported outcome.
Change-source: pulse-maintainer
(cherry picked from commit 62c6e07477)
Issue #1895 reports parity alerts when mdNumDisks=0 on a pool-only Unraid system. Array service state alone does not establish that a parity array exists.
Preserve the optional disk count from collection through canonical runtime conversion and suppress only the no-parity warning for an explicit zero. Missing or malformed counts retain legacy behaviour, and disk failure reasons remain active.
Validated focused Unraid tests in hostagent, storagehealth, monitoring, unifiedresources and alerts, including JSON zero preservation and canonical round trip. The new pool-only regression fails against the previous warning condition. Both agent and server need this change; no release or reporter retest is claimed.
Change-source: pulse-maintainer
(cherry picked from commit 3334cccfd9)
Near-synchronous host and Docker reports consumed a shared CPU baseline, measuring collection bursts rather than each module's reporting interval. Retain a collector per host collector and a separate Docker module collector while preserving the package-level convenience API and disk filters.
Add an interleaved-counter regression covering both collection entry points. It fails when routed through the shared baseline and passes with isolated state. All hostmetrics, hostagent and dockeragent tests pass, as do the focused CPU regression tests under the race detector.
Change-source: pulse-maintainer
(cherry picked from commit 0f972f42f2)
Issue #1890 reports macOS agent updates stopping because the root group does not exist. Use numeric superuser ownership in the two shared lifecycle writes without relaxing failure handling or the least-privilege group boundary. Add a regression fixture that rejects named root ownership and checks that chown failures still prevent replacement.
Change-source: pulse-maintainer
(cherry picked from commit 19c2b6a925)
Backport of the main-branch guard. pkg/server tests boot the real server
through Run() with the version literal "test-version", which normalizes to
0.0.0-test-version, and each test runs against its own t.TempDir(), so
every run mints a fresh install ID. The service-health failure reporter
sends synchronously from a deferred handler as soon as Run() returns an
error, so any test exercising a startup failure posts one ping.
This line still emitted after main was fixed: release-line lane work runs
pkg/server tests on this branch, and those pings arrive with the old
version classifier too, so they land mislabelled as ordinary prereleases
and re-contaminate install-population reads that were just corrected.
send() now refuses the production endpoint whenever testing.Testing()
reports true. The check compares against productionPingEndpoint, so
telemetry's own tests keep asserting on ping content through a redirected
endpoint. Verified on this branch: three runs of the failing-startup
tests, zero pings received.
The browser compatibility coalescer could undo the server's provider-scoped split after websocket reconciliation. Honour machine and provider identity before merging same-hostname rows.
(cherry picked from commit 724a8a4960)
A cluster name is an operator-selected display label, not global machine identity. Two independently configured estates using the same label could share one linked agent and then collapse into one presentation row after delayed cluster detection. Require node identity, exact endpoint, or host corroboration across provider instances instead.
Refs #1753
Change-source: pulse-maintainer
(cherry picked from commit 384dc53608)
The stable-row focus fallback ran after the shared dialog cleanup and could scroll a lower Manage trigger into view. Preserve the existing focus return without changing the operator's viewport, and cover the real desktop and narrow browser path.
Contract-Neutral: frontend focus-restoration bugfix; no API or persisted-data change.
Change-source: pulse-maintainer
(cherry picked from commit da9800ff2f)
Shared subtabs used scrollIntoView for horizontal visibility, allowing remounted or programmatically changed drawers to scroll the whole application shell. Reuse the horizontal rail controller instead, and restore disclosure focus without scrolling when a detail row closes.
Record the shared primitive contract and its registry-approved guardrails, with desktop and narrow Backups browser coverage for visible Overview and Manage states, off-screen tab changes, and non-scrolling focus return.
Change-source: pulse-maintainer
(cherry picked from commit 59e9f5ea2b)
The v6.4.3-rc.1 dispatch from main (run 33579042375) failed inside the
compiler dispatch: main advanced one minute after the release pipeline
pinned its source SHA, so the exact-SHA identity check on the compiler run
correctly refused the moved head. With the maintainer landing pull requests
every few minutes, a candidate dispatched from main cannot hold its SHA for
the minutes between prepare and compile.
Declare release/v6.4 for the 6.4.3 version prefix, created from main at the
exact-SHA-qualified commit 56e51e622e, so the workflow refuses a v6.4.3
dispatch from any other branch and the compiler binding stays exact. This is
the delivery contract's branch-per-train rule applied to the patch line that
predates the first train; earlier 6.4.x versions keep their historical main
mapping, and the 6.5 train mapping is unchanged.
Stable promotions built whatever the dispatch branch was at that second.
The resolver checked that HEAD descends from the promoted release
candidate but never that its content matches, so v6.4.0 shipped 64
changed files, including product code, that v6.4.0-rc.12 had not
soaked. Every v6 version was mapped to main, which now moves every few
minutes under the autonomous maintainer, so each fix to a candidate
brought everything landed since and stable was never an exact soaked
commit. Five of six stable minor releases shipped under version-bound
owner exceptions that waived the soak.
From v6.5.0 the release train applies (RELEASE_PROMOTION_POLICY.md,
"Release Train"): a two-week train sized to measured velocity, a
release/v6.N branch per train declared in the control plane so the
workflow refuses a dispatch from anywhere else, a stable promotion that
may differ from its candidate only in release metadata unless
hotfix_exception names active customer harm, and a seven day soak for
minor releases. The 6.4.x line stays on main so the v6.4.3-rc.1
candidate already prepared there is unaffected. The gap is registered
as coverage gap release-train-exact-candidate-promotion.
A paying operator asked the Assistant to reboot five Proxmox VMs matching
a name pattern (GitHub #1782, support mail 2026-08-26 and 2026-08-29). The
model resolved the VMs and then ended with a report that invented a
prerequisite: a QEMU guest agent on 6.3.2, a "discovery binding" on stable
6.4.0. It never planned the action. Three defects made the governed path
fail whenever the model did try it, and nothing refused the prose ending
when it did not:
- pulse_control handed the session-scoped id (vm:<node>:<vmid>) to the
action lifecycle, whose registry keys on canonical unified ids, so a
Proxmox guest plan could never resolve.
- pulse_control gated the action on the legacy per-executor action list,
which never carried the canonical "reboot" capability Proxmox guests
advertise, so "reboot" was refused as not permitted before planning.
- A reference absent from the session context was refused with "resource
discovery is required" even when the unified inventory resolved it.
pulse_control now binds its target to the canonical unified resource
(session alias first, then a unique inventory match, refusing ambiguity
with candidate ids and naming the pulse_query recovery on a miss), passes
the canonical id to the planner, and answers "not available" only from
the resource's current advertised capabilities. The FSM ordering block
and the shared operating instructions state that a recoverable block is
not a limitation to report, and the instructions require the governed
action tool for advertised capabilities. The agentic loop adds a bounded
advertised-action gate: when the operator asked for a lifecycle action,
pulse_control was offered but never submitted, and a session-resolved
resource advertises the action, a tool-free final answer is refused once
with the exact per-target calls.
Covered by tools and loop unit tests (the #1782 transcript against a
scripted provider fails on the previous code with the two exact errors
above), a prompt-contract test, and the live eval scenario
ProxmoxBulkLifecycleActionScenario.
Since 60d0651a88 every typed request registers a per-connection cancellable
slot that its handler goroutine releases in a deferred cleanup after sending
its result. The server replays a request id when it wants the durable receipt
again, and that replay can reach the reader before the previous handler's
deferred release runs. launchCancellableRequest treated that as a duplicate
and dropped it, so the server waited out the operation's full timeout for a
result the agent already held. The Linux x64 native-verification leg failed
this way on 12 of the last 25 main runs, always on a "replay 1" dispatch of
host update, storage cleanup, or Docker lifecycle.
Give each slot a done channel that closes on release. A replay whose id is
still registered on the same connection now waits for that release and then
runs, answering from the durable receipt. Invalid ids and over-capacity
requests are still dropped. A unit test pins the wait-then-run behaviour and
the agent-lifecycle contract records the replay rule.
Open the v6.4.3 candidate line from main. The v6.4.2 tag was staged on
2026-08-31 but never activated: its release run was cancelled after the
private Pro build failed the compiler memory gate, so the latest published
stable is still v6.4.1. This candidate carries the complete v6.4.2 change
set plus the corrections landed since that tag, including the stale PBS
Backup Running state (#1815), the Windows Unified Agent auto-update 404
(#1820), and shared-token same-hostname agent identity collapse (#1753).
Packet: VERSION, compose and install-docker defaults, Helm chart metadata,
release notes with a declined visual plan, changelog, pointer docs and
the shipped docs mirror, and the deployment-installability cutoff note.
Rollback target is v6.4.1 and the mobile decision is no-mobile-impact.
Tests: the packet tests now describe the 6.4.3 train, v6.4.2 is recorded
as an unpublished stable so it is never derived as the previous stable or
rollback target, and the Python v6.4.2 notes expectation matches the
phrase the notes actually use.