Incorporate the protected release-snapshot workflow landing while preserving every reviewed maintenance commit and the additive governance correction in local history.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/deployment-installability.md
Read agent-owned memory and source freshness from VM views when correlation removes the standalone host row. Preserve preferred guest memory sources and reject stale, offline or unavailable agent evidence. Reproduce issue #1962 through registry merge, next-poll diagnostics, card projection and memory alerts.
Change-source: pulse-maintainer
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
Incorporate the landed Patrol qualification record while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.
Change-source: pulse-maintainer
Incorporate the landed Patrol planning work while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/agent-lifecycle.md
# docs/release-control/v6/internal/subsystems/api-contracts.md
# docs/release-control/v6/internal/subsystems/storage-recovery.md
# frontend-modern/browser-verification.json
Reconcile the executable plan with the merged implementation and exact
qualification evidence. Keep the independent-environment rollout gate open
and preserve failed attempts, measurement limits and provider refusal.
Preserve the requested reservation for independent release snapshot work.
Refs #1782
Literal-only query matching and the separate resolved ntfy transport caller leaked recognised URL credentials. Decode each query name once and project ntfy transport errors before logging or returning them, without changing destinations or error causes. Add synthetic sink-matrix and HTTP projection regressions plus the bounded notification contract in this commit.
Change-source: pulse-maintainer
Pin useful diagnostic context and credential masking at the HTTP boundary, and document the API, agent and retained-history boundaries omitted from a2dbb27. This supplement must be packaged with that source commit for per-commit governance; it does not clear the historical hosted failure.
Change-source: pulse-maintainer
Normalize whitespace in required wiring snippets so gofmt alignment changes
do not fail the model-only handoff contract. Preserve the same required
identifiers and forbidden adapter checks.
Refs #1782
PR #1959 exposed that the URL-only redactor was called with a complete delivery error, causing safe but unhelpful replacement of the whole diagnostic. Redact embedded webhook URLs separately so credentials stay masked and non-secret failure context remains available; malformed URLs continue to fail closed.
Change-source: pulse-maintainer
Raw URL matching missed encoded bot prefixes and mistook bot hostnames and query URLs for credential paths. Use the decoded path and clear RawPath so diagnostic errors and rate-limit logs cannot retain these synthetic bot tokens, while preserving local API server support and original destinations.
Change-source: pulse-maintainer
Discord webhook paths include tokens authorising webhook operations. Mask the credential suffix on exact Discord hosts without changing destinations or error causes, and cover helper output, transport errors and rate-limit logs with synthetic regressions.
Change-source: pulse-maintainer
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.
Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.
Refs #1782
Slack incoming webhook paths contain credentials, but existing diagnostic redaction retained them. Mask standard and legacy Slack/GovSlack paths while preserving host and error-cause diagnostics; cover encoded paths and actual rate-limit logs.
Change-source: pulse-maintainer
The held latency failure lacks contemporaneous resource context, and isolated passing samples do not explain it. Retain allowlisted backend boundary counters including cgroup ancestors in the existing durable log, preserving backend failures and unchanged qualification thresholds. Focused tests cover failure exits, unavailable telemetry, ancestor collection and environment filtering.
Change-source: pulse-maintainer
The previous recovery browser fixture owned the edited URL in a synthetic parent, leaving the production configuration-state integration untested. Mount the real Alerts settings surface and assert edits and dirty state survive recovery without reload or implicit save, then reach the explicit save boundary intact.
Two serialized Chromium runs passed 12 cases each, including six real settings-parent cases. Record the exact script hash and final result; retain earlier harness failures and distinguish mocked API evidence from persistence, installed recovery and recipient receipt.
Change-source: pulse-maintainer
Mask username and password credentials before existing path and query redaction, and fail closed when the URL cannot be parsed. Reproduce the leak through rate-limit logs and transport errors, preserving error unwrapping and destination configuration.
Change-source: pulse-maintainer
A large Retry-After integer can overflow time.Duration during multiplication and become zero, defeating the existing 30-second cap. Clamp seconds before conversion and parse at a consistent 64-bit width. Preserve existing negative-value and HTTP-date handling.
Validation: new parser cases fail before the repair; focused parser, HTTP error classification and synthetic terminal-rejection tests pass with -race -count=20. No persistent queue tests or release qualification performed.
Change-source: pulse-maintainer
The recovery browser fixture used no-op configuration setters, so prior passes could not demonstrate unsaved-value retention. Exercise a reactive synthetic ping URL and dirty flag through rejection, cancellation, refresh failure and message clearing without expanding the product surface. All 12 serialized Chromium cases pass, including six edited-value cases; installed and assistive-technology acceptance remain separate.
Change-source: pulse-maintainer
Let the configured model choose investigation steps within explicit budgets.
Keep canonical planning, permissions and independent verification authoritative,
and preserve streamed conclusions in conversation history.
Expose recorded action outcomes so cached inventory cannot stand in for an
approval or execution receipt. Retain full plan context and make the exact
action review reachable from Assistant, including on narrow screens.
Refs #1782
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.
Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.
Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
Recovery failures otherwise disappear with their toast, leaving slower readers without the action outcome. Keep a view-local untimed equivalent on Overview and Notifications until clear or a newer confirmed action, independently of queue health.
Separate accepted queue mutations from optional activity-refresh failures. Cover ownership and cancellation in focused tests, and verify both real views with scripted APIs in Chromium at three widths and both themes. This implements the current main-only recovery feedback bet, not a backend delivery fix or release-line backport.
Change-source: pulse-maintainer
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.
Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.
Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.
Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
The exact release tree retains a failed paired UUID benchmark check, while push CI cannot repeat that comparison. Provide a reviewed-source route to collect the requested four-condition hosted layout evidence instead of repeating local samples or changing product order.
Fix source/tree/toolchain identities, isolate diagnostic controls, alternate ten rounds, and retain partial receipts without publishing binaries. Execution still needs separate operator authority; collection success does not dispose of the failed gate. Nine focused harness tests and existing benchmark contract tests pass.
Change-source: pulse-maintainer
A provider 403 response mentioning an authentication timeout was treated as a transient network failure and sent again with unchanged credentials. Classify explicit HTTP status before diagnostic text, retaining existing transient status and network fallback behaviour. Add a status/body matrix and a queue-free loopback regression that verifies one request and terminal delivery history.
Change-source: pulse-maintainer
Refresh durable investigation lifecycle from authoritative actions while
preserving completed evidence. Keep resolved history reviewable and label
recorded plan facts separately from action outcomes. Follow all resource
pages during qualification and record live approval, rejection and storage
semantic-review results. Integrate current main and preserve its alert
ordering correction.
Community outage reports expose the difference between local delivery health and a monitor surviving site failure. The existing External watchdog has no troubleshooting entry explaining that boundary. Document its current setup, period-plus-grace timing, secret handling and authorised receipt/recovery checks without adding runtime scope or claiming end-to-end qualification.
Change-source: pulse-maintainer
Live funded qualification found hidden tool results and misleading action
submission outcomes. Share the result-bearing transcript across stored chat
and product history, render the retained evidence, and distinguish captured
proposals from broker acceptance. Keep review usable while Patrol is paused.
Record Gemini route pricing and exact qualification limits. Integrate current
main and repeat browser proof for the incoming login flow. Approved/rejected
recovery remains unqualified without the development command agent.
Exercise the production collector through healthy, full and recovered
storage states using the existing bounded disposable lab. Preserve exact
mount configuration while keeping collector proof separate from model
diagnosis and installed-agent qualification.
The fleet sampler and coordinator had no production alert trigger and could
repeat cached values as fresh incident evidence. Preserve saved recordings
through explicit read-only lookups, propagate read failures and report the
former live incident count as unmeasured. Keep historical status and duration
units explicit without rewriting archived observations.
Integrate main's alert dispatch wording and startup replay qualification.
Canonical incident listing and real-model outcome qualification remain open.
Overlapping bulk diagnosis refreshes could resolve out of order and replace a current notifications-disabled warning with older dispatch evidence. Version each request, including empty alert sets, so only the newest response updates card diagnoses.
Pin overlap and empty-set invalidation with component and registered hook regressions. All 47 focused tests and TypeScript pass. Isolated Chromium verifies rendered ordering at three widths; update both subsystem contracts and bind browser proof to the runtime bytes. No backend delivery or recipient receipt is claimed.
Change-source: pulse-maintainer
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.
Change-source: pulse-maintainer
Preserve both monitoring contracts and combine the diagnostic history
correction with current host continuity and delivery evidence changes.
Verify the combined backend, frontend and browser behaviour before
landing the existing diagnostic work.
Keep alert and inventory evidence together after container removal and
restart without rewriting retained events or transferring approval and
operator authority. Resolve exact source identities in the shared store
and preserve event replay idempotency across old and current records.
Verify actual retained homelab events, registered tool reads, lifecycle
callbacks, tenant isolation, race behaviour and responsive evidence views.
Assistant incident reads used an unconnected cached-metric recorder while
resource history already retained operational events. Read the shared
organization-scoped timeline with original provenance, bounded results
and explicit coverage and failure semantics. Keep legacy archive reads
resource-bound.
Record the separately reproduced alert identity split at the shared
write boundary. This read-path correction does not qualify complete
incident diagnosis or recovery.
LastNotified is recorded before delivery callbacks, so the active card cannot use it as evidence of destination success. Name dispatch and cooldown eligibility explicitly while preserving policy and timestamp fallbacks.
Pin the evidence boundary in presentation and Overview regressions, subsystem contracts and an isolated real-browser qualification. Scripted diagnoses verify labels and wrapping, not installed delivery or recipient receipt.
Change-source: pulse-maintainer