Commit Graph

4975 Commits

Author SHA1 Message Date
pulse-triage[bot] d9f2637ee2 Merge current upstream source main into reviewed maintenance
Incorporate the protected release-snapshot workflow landing while preserving every reviewed maintenance commit and the additive governance correction in local history.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/deployment-installability.md
2026-09-07 21:02:31 +01:00
pulse-triage[bot] a4d5130ec6 Restore VM-correlated agent memory fallback
Read agent-owned memory and source freshness from VM views when correlation removes the standalone host row. Preserve preferred guest memory sources and reject stale, offline or unavailable agent evidence. Reproduce issue #1962 through registry merge, next-poll diagnostics, card projection and memory alerts.

Change-source: pulse-maintainer
2026-09-07 19:43:48 +01:00
pulse-triage[bot] d63aa56729 Merge candidate 20260907T175505Z-core-runtime
Integrate the reviewed bounded webhook diagnostic confidentiality repair and its exact candidate ancestry.

Change-source: pulse-maintainer
2026-09-07 19:32:10 +01:00
rcourtman b64709e7b7 Publish reviewed release snapshots independently of branch tips
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.

Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
2026-09-07 19:30:27 +01:00
pulse-triage[bot] dd8945e942 Merge latest upstream qualification record into reviewed alert recovery
Incorporate the landed Patrol qualification record while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.

Change-source: pulse-maintainer
2026-09-07 19:28:42 +01:00
pulse-triage[bot] 1f965e85b0 Merge current upstream main into reviewed alert recovery
Incorporate the landed Patrol planning work while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/agent-lifecycle.md
#	docs/release-control/v6/internal/subsystems/api-contracts.md
#	docs/release-control/v6/internal/subsystems/storage-recovery.md
#	frontend-modern/browser-verification.json
2026-09-07 19:16:44 +01:00
rcourtman 7d1fb7285e Record verified Patrol and Assistant qualification delivery
Reconcile the executable plan with the merged implementation and exact
qualification evidence. Keep the independent-environment rollout gate open
and preserve failed attempts, measurement limits and provider refusal.

Preserve the requested reservation for independent release snapshot work.

Refs #1782
2026-09-07 19:14:49 +01:00
pulse-triage[bot] 21ed7a8927 fix(notifications): contain encoded query and resolved ntfy diagnostics
Literal-only query matching and the separate resolved ntfy transport caller leaked recognised URL credentials. Decode each query name once and project ntfy transport errors before logging or returning them, without changing destinations or error causes. Add synthetic sink-matrix and HTTP projection regressions plus the bounded notification contract in this commit.

Change-source: pulse-maintainer
2026-09-07 19:07:52 +01:00
pulse-triage[bot] 5f99f5c13f test(notifications): prove delivery diagnostic API contract
Pin useful diagnostic context and credential masking at the HTTP boundary, and document the API, agent and retained-history boundaries omitted from a2dbb27. This supplement must be packaged with that source commit for per-commit governance; it does not clear the historical hosted failure.

Change-source: pulse-maintainer
2026-09-07 18:33:06 +01:00
pulse-triage[bot] e62f591ecb Merge candidate 20260907T170018Z-core-runtime
Change-source: pulse-maintainer
2026-09-07 18:24:35 +01:00
rcourtman 17aa972f35 Make investigation wiring checks ignore field alignment
Normalize whitespace in required wiring snippets so gofmt alignment changes
do not fail the model-only handoff contract. Preserve the same required
identifiers and forbidden adapter checks.

Refs #1782
2026-09-07 18:10:32 +01:00
pulse-triage[bot] a2dbb27a68 fix(notifications): retain context around redacted delivery URLs
PR #1959 exposed that the URL-only redactor was called with a complete delivery error, causing safe but unhelpful replacement of the whole diagnostic. Redact embedded webhook URLs separately so credentials stay masked and non-secret failure context remains available; malformed URLs continue to fail closed.

Change-source: pulse-maintainer
2026-09-07 18:07:09 +01:00
pulse-triage[bot] 192a72e05c fix(notifications): redact Telegram credentials from decoded paths
Raw URL matching missed encoded bot prefixes and mistook bot hostnames and query URLs for credential paths. Use the decoded path and clear RawPath so diagnostic errors and rate-limit logs cannot retain these synthetic bot tokens, while preserving local API server support and original destinations.

Change-source: pulse-maintainer
2026-09-07 18:02:25 +01:00
pulse-triage[bot] 3c77ecb338 fix(notifications): mask Discord webhook credentials in diagnostics
Discord webhook paths include tokens authorising webhook operations. Mask the credential suffix on exact Discord hosts without changing destinations or error causes, and cover helper output, transport errors and rate-limit logs with synthetic regressions.

Change-source: pulse-maintainer
2026-09-07 17:50:14 +01:00
rcourtman c501376843 Preserve canonical Patrol planning and outcome continuity
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.

Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.

Refs #1782
2026-09-07 17:24:25 +01:00
pulse-triage[bot] 77a8e4ee35 fix(notifications): mask Slack webhook paths in diagnostics
Slack incoming webhook paths contain credentials, but existing diagnostic redaction retained them. Mask standard and legacy Slack/GovSlack paths while preserving host and error-cause diagnostics; cover encoded paths and actual rate-limit logs.

Change-source: pulse-maintainer
2026-09-07 17:08:03 +01:00
pulse-triage[bot] c6dfbdbf02 Merge candidate 20260907T154236Z-delivery-trust
Change-source: pulse-maintainer
2026-09-07 16:53:02 +01:00
pulse-triage[bot] b116f2defc chore(release): retain bounded backend resource evidence
The held latency failure lacks contemporaneous resource context, and isolated passing samples do not explain it. Retain allowlisted backend boundary counters including cgroup ancestors in the existing durable log, preserving backend failures and unchanged qualification thresholds. Focused tests cover failure exits, unavailable telemetry, ancestor collection and environment filtering.

Change-source: pulse-maintainer
2026-09-07 16:47:55 +01:00
pulse-triage[bot] 55e945f957 Merge candidate 20260907T152524Z-web-product
Change-source: pulse-maintainer
2026-09-07 16:46:43 +01:00
pulse-triage[bot] fc3ebefd86 test(web): verify recovery preserves real settings-parent edits
The previous recovery browser fixture owned the edited URL in a synthetic parent, leaving the production configuration-state integration untested. Mount the real Alerts settings surface and assert edits and dirty state survive recovery without reload or implicit save, then reach the explicit save boundary intact.

Two serialized Chromium runs passed 12 cases each, including six real settings-parent cases. Record the exact script hash and final result; retain earlier harness failures and distinguish mocked API evidence from persistence, installed recovery and recipient receipt.

Change-source: pulse-maintainer
2026-09-07 16:39:11 +01:00
pulse-triage[bot] db0c72c367 fix(notifications): redact webhook URL userinfo from diagnostics
Mask username and password credentials before existing path and query redaction, and fail closed when the URL cannot be parsed. Reproduce the leak through rate-limit logs and transport errors, preserving error unwrapping and destination configuration.

Change-source: pulse-maintainer
2026-09-07 16:36:37 +01:00
pulse-triage[bot] aab925d675 Merge candidate 20260907T145014Z-core-runtime
Change-source: pulse-maintainer
2026-09-07 15:58:10 +01:00
pulse-triage[bot] 056e98fd81 Merge candidate 20260907T144528Z-web-product
Change-source: pulse-maintainer
2026-09-07 15:58:10 +01:00
pulse-triage[bot] 8970c3b1b4 fix(notifications): clamp retry seconds before duration conversion
A large Retry-After integer can overflow time.Duration during multiplication and become zero, defeating the existing 30-second cap. Clamp seconds before conversion and parse at a consistent 64-bit width. Preserve existing negative-value and HTTP-date handling.

Validation: new parser cases fail before the repair; focused parser, HTTP error classification and synthetic terminal-rejection tests pass with -race -count=20. No persistent queue tests or release qualification performed.
Change-source: pulse-maintainer
2026-09-07 15:54:08 +01:00
pulse-triage[bot] 504d9a0c6e test(web): verify unsaved edits survive recovery actions
The recovery browser fixture used no-op configuration setters, so prior passes could not demonstrate unsaved-value retention. Exercise a reactive synthetic ping URL and dirty flag through rejection, cancellation, refresh failure and message clearing without expanding the product surface. All 12 serialized Chromium cases pass, including six edited-value cases; installed and assistive-technology acceptance remain separate.

Change-source: pulse-maintainer
2026-09-07 15:52:21 +01:00
rcourtman a66b8e11d7 Merge pull request #1957 from rcourtman/fix/assistant-continuation-evidence
Remove inferred Assistant continuation gates
2026-09-07 15:24:04 +01:00
rcourtman e37353f937 Remove inferred Assistant continuation gates
Let the configured model choose investigation steps within explicit budgets.
Keep canonical planning, permissions and independent verification authoritative,
and preserve streamed conclusions in conversation history.

Expose recorded action outcomes so cached inventory cannot stand in for an
approval or execution receipt. Retain full plan context and make the exact
action review reachable from Assistant, including on narrow screens.

Refs #1782
2026-09-07 14:06:58 +01:00
pulse-triage[bot] b2b67ae0d5 Merge current upstream main into reviewed recovery feedback
Preserve reviewed recovery feedback commits while incorporating Pulse main through 62f6931c1f. Reconcile independent frontend contract additions and retain the latest upstream browser receipt; the recovery receipt remains preserved in commit 036d324460.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
2026-09-07 13:19:28 +01:00
rcourtman 2a7019b0fa Use typed Proxmox runners and preserve cross-clock action evidence
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.

Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.

Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
2026-09-07 12:00:48 +01:00
pulse-triage[bot] 036d324460 fix(alerts): retain notification recovery failure feedback
Recovery failures otherwise disappear with their toast, leaving slower readers without the action outcome. Keep a view-local untimed equivalent on Overview and Notifications until clear or a newer confirmed action, independently of queue health.

Separate accepted queue mutations from optional activity-refresh failures. Cover ownership and cancellation in focused tests, and verify both real views with scripted APIs in Chromium at three widths and both themes. This implements the current main-only recovery feedback bet, not a backend delivery fix or release-line backport.

Change-source: pulse-maintainer
2026-09-07 11:44:50 +01:00
rcourtman 09ab5c2d0a Merge pull request #1951 from rcourtman/fix/patrol-filesystem-evidence
Preserve native filesystem evidence and Patrol action history
2026-09-07 10:24:57 +01:00
rcourtman 3a4a3fd62b Preserve native filesystem evidence and Patrol action history
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.

Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.

Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
2026-09-07 09:45:31 +01:00
rcourtman 8b73085e82 Fix release smoke workspace identity on rootless Docker
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.

Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
2026-09-07 08:29:42 +01:00
pulse-triage[bot] edcd1dcc5e Merge batch-start upstream main
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/api-contracts.md
2026-09-06 22:31:11 +01:00
pulse-triage[bot] ad0a70bc75 test(notifications): cover SMTP transaction retry replies
Check permanent, transient and recovered sends at envelope and DATA boundaries without external delivery.

Change-source: pulse-maintainer
2026-09-06 22:26:55 +01:00
pulse-triage[bot] 13e5201f02 Merge candidate 20260906T210510Z-delivery-trust
Change-source: pulse-maintainer
2026-09-06 22:16:05 +01:00
pulse-triage[bot] 92c3297049 ci: add fixed UUID layout diagnostic without release gate waiver
The exact release tree retains a failed paired UUID benchmark check, while push CI cannot repeat that comparison. Provide a reviewed-source route to collect the requested four-condition hosted layout evidence instead of repeating local samples or changing product order.

Fix source/tree/toolchain identities, isolate diagnostic controls, alternate ten rounds, and retain partial receipts without publishing binaries. Execution still needs separate operator authority; collection success does not dispose of the failed gate. Nine focused harness tests and existing benchmark contract tests pass.

Change-source: pulse-maintainer
2026-09-06 22:11:03 +01:00
pulse-triage[bot] 79577981f9 fix(notifications): stop SMTP retries on permanent failures
Respect structured delivery classes in the inner email retry loop, retaining transient retry budgets and accurate attempt counts. Add queue-free SMTP failure regression coverage.

Change-source: pulse-maintainer
2026-09-06 22:10:04 +01:00
pulse-triage[bot] 4a981bc2ec fix(notifications): prioritise HTTP rejection over retry body hints
A provider 403 response mentioning an authentication timeout was treated as a transient network failure and sent again with unchanged credentials. Classify explicit HTTP status before diagnostic text, retaining existing transient status and network fallback behaviour. Add a status/body matrix and a queue-free loopback regression that verifies one request and terminal delivery history.

Change-source: pulse-maintainer
2026-09-06 21:54:18 +01:00
rcourtman 3853124a39 Keep Patrol action history consistent with recorded outcomes
Refresh durable investigation lifecycle from authoritative actions while
preserving completed evidence. Keep resolved history reviewable and label
recorded plan facts separately from action outcomes. Follow all resource
pages during qualification and record live approval, rejection and storage
semantic-review results. Integrate current main and preserve its alert
ordering correction.
2026-09-06 21:23:01 +01:00
pulse-triage[bot] 1b060ba48d docs(alerts): explain whole-site outage watchdog verification
Community outage reports expose the difference between local delivery health and a monitor surviving site failure. The existing External watchdog has no troubleshooting entry explaining that boundary. Document its current setup, period-plus-grace timing, secret handling and authorised receipt/recovery checks without adding runtime scope or claiming end-to-end qualification.

Change-source: pulse-maintainer
2026-09-06 21:22:44 +01:00
rcourtman 57ead19484 Preserve Patrol evidence and surface action submission failures
Live funded qualification found hidden tool results and misleading action
submission outcomes. Share the result-bearing transcript across stored chat
and product history, render the retained evidence, and distinguish captured
proposals from broker acceptance. Keep review usable while Patrol is paused.

Record Gemini route pricing and exact qualification limits. Integrate current
main and repeat browser proof for the incoming login flow. Approved/rejected
recovery remains unqualified without the development command agent.
2026-09-06 20:09:54 +01:00
rcourtman b0b39f00dc Qualify Docker storage collection against a live fault
Exercise the production collector through healthy, full and recovered
storage states using the existing bounded disposable lab. Preserve exact
mount configuration while keeping collector proof separate from model
diagnosis and installed-agent qualification.
2026-09-06 18:00:24 +01:00
rcourtman 186ce504c8 Retire disconnected incident recording and preserve archives
The fleet sampler and coordinator had no production alert trigger and could
repeat cached values as fresh incident evidence. Preserve saved recordings
through explicit read-only lookups, propagate read failures and report the
former live incident count as unmeasured. Keep historical status and duration
units explicit without rewriting archived observations.

Integrate main's alert dispatch wording and startup replay qualification.
Canonical incident listing and real-model outcome qualification remain open.
2026-09-06 17:42:24 +01:00
pulse-triage[bot] 495562ef66 fix(alerts): ignore superseded delivery diagnosis responses
Overlapping bulk diagnosis refreshes could resolve out of order and replace a current notifications-disabled warning with older dispatch evidence. Version each request, including empty alert sets, so only the newest response updates card diagnoses.

Pin overlap and empty-set invalidation with component and registered hook regressions. All 47 focused tests and TypeScript pass. Isolated Chromium verifies rendered ordering at three widths; update both subsystem contracts and bind browser proof to the runtime bytes. No backend delivery or recipient receipt is claimed.

Change-source: pulse-maintainer
2026-09-06 17:17:36 +01:00
pulse-triage[bot] 64dba483d0 fix(release): bind forward 6.4.4 checkpoint to release train
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.

Change-source: pulse-maintainer
2026-09-06 16:48:17 +01:00
rcourtman ab6d214000 Merge main into diagnostic evidence improvements
Preserve both monitoring contracts and combine the diagnostic history
correction with current host continuity and delivery evidence changes.
Verify the combined backend, frontend and browser behaviour before
landing the existing diagnostic work.
2026-09-06 16:45:28 +01:00
rcourtman 919331d5b3 Join Docker alert events with canonical resource history
Keep alert and inventory evidence together after container removal and
restart without rewriting retained events or transferring approval and
operator authority. Resolve exact source identities in the shared store
and preserve event replay idempotency across old and current records.

Verify actual retained homelab events, registered tool reads, lifecycle
callbacks, tenant isolation, race behaviour and responsive evidence views.
2026-09-06 16:23:30 +01:00
rcourtman 580a246981 Read incident evidence from canonical resource history
Assistant incident reads used an unconnected cached-metric recorder while
resource history already retained operational events. Read the shared
organization-scoped timeline with original provenance, bounded results
and explicit coverage and failure semantics. Keep legacy archive reads
resource-bound.

Record the separately reproduced alert identity split at the shared
write boundary. This read-path correction does not qualify complete
incident diagnosis or recovery.
2026-09-06 15:33:44 +01:00
pulse-triage[bot] 9ddee2f8f9 fix(alerts): distinguish dispatch from notification receipt
LastNotified is recorded before delivery callbacks, so the active card cannot use it as evidence of destination success. Name dispatch and cooldown eligibility explicitly while preserving policy and timestamp fallbacks.

Pin the evidence boundary in presentation and Overview regressions, subsystem contracts and an isolated real-browser qualification. Scripted diagnoses verify labels and wrapping, not installed delivery or recipient receipt.

Change-source: pulse-maintainer
2026-09-06 15:12:07 +01:00