A canonical snapshot can omit memory after the producer marks its Proxmox
facet unavailable. Retaining the previous display metric hides withdrawal
and leaves a stale percentage visible. Clear that explicit transition in
full and fast merges and emit the corresponding store operation, preserving
ordinary partial omission and trusted canonical metrics including zero.
Pin withdrawal and recovery with adapter tests and desktop/narrow Chromium
acceptance. Workload details remain canonical-only; do not invent raw totals
or Usage UI. Record inspected screenshots and matching subsystem contracts.
Change-source: pulse-maintainer
The real monitoring lifecycle dispatcher reproduces a closed incident reopening when its next occurrence fires: canonical projection selected all later events for the same alert. Bound retained-shell projections to their exact start and the next retained start, keeping subsecond recurrence and historical acknowledgement separate. Add in-memory callback coverage with both projections attached; twenty race repetitions pass along with focused incident tests. No retention migration, canonical-only fallback rewrite, notification-delivery claim or aggregate write-byte claim.
Change-source: pulse-maintainer
Issue #1966 reports distinct incident IDs for one occurrence. Deterministic lifecycle replay creates eleven shells for one resolved start, including after JSON restart; open-only matching also lets an old resolution close a newer occurrence. Match exact lifecycle starts and retain closed identity on replay, without changing legacy zero-start matching or retention. Add recurrence, restart and canonical-shell regression coverage; focused incident race tests pass for twenty repetitions. This does not establish total write savings or migrate existing duplicates.
Change-source: pulse-maintainer
Backfill could save a stale List snapshot after manual discovery repaired a service, restoring unknown identity and dropping its URL and engine version. Derive and persist missing suggestions from the current record under the store lock instead, without holding it across monitor reads.
Add a deterministic SetReadState/manual-refresh interleaving and encrypted restart assertions, plus coverage for current identity, dismissed proposals, deletion and persistence failure. The discovery package passes twenty race-enabled repetitions.
Change-source: pulse-maintainer
Repeated alert lifecycle evaluations retain one occurrence but still replace the whole incident file. Compare bounded existing bytes before replacement, preserving changed-state saves and retry after failure or file loss.
Focused regression reproduced 21 replacements for one initial save plus 20 unchanged evaluations before the fix. Repeated race-enabled incident tests cover unchanged checkpoints, metadata, restart, resolution, recurrence and failed-write retry. This does not establish the cause of all writes or duplicate incidents reported in #1966.
Change-source: pulse-maintainer
Exercise canonical REST and socket snapshots through the Proxmox table and guest drawer for issue #1962. Preserve platform fallback and measured-zero presentation without substituting nested agent memory; backend polling remains separately qualified.
Change-source: pulse-maintainer
Apply the repository formatter to the two alert recovery test files rejected by the protected frontend check. This is an additive formatting-only correction; reviewed commit identities and behavior remain unchanged.
Change-source: pulse-maintainer
Issue #1962 describes automatic correlation into a hybrid VM, while the retained-link regression only exercises a manual merge. Exercise the hostname link selector through source snapshot reconstruction and next-poll memory resolution, preserving standalone host identity, cross-instance VMID isolation and ambiguous-name refusal. This narrows the acceptance boundary without changing matching behaviour or claiming installed recovery.
Change-source: pulse-maintainer
Incorporate the protected release-snapshot workflow landing while preserving every reviewed maintenance commit and the additive governance correction in local history.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/deployment-installability.md
A reviewed notification correction and its required contracts and API proof were accepted as separate immutable commits, leaving the protected per-commit governance check unable to pass without rewriting reviewed history. Add a fail-closed exact-pair validator that reconstructs the completion commit in a detached worktree and runs the normal guard over the combined file set; all unregistered commits continue through the unchanged per-commit path.
Change-source: pulse-maintainer
Keep stale/offline/unavailable controls, diagnostic and alert agreement, and verify isolation with a simultaneous duplicate VMID in another instance. Test-only follow-through for issue #1962.
Change-source: pulse-maintainer
Apply the repository Prettier policy to the newly integrated issue #1962 reactive-boundary fixture. The exact reviewed candidate remains preserved as a merge parent, and the focused test behavior is unchanged.
Change-source: pulse-maintainer
Issue #1962 exposes disagreement between canonical and nested agent memory. Protect the reactive workload boundary against UI-only substitution, same-VMID instance mixing and confusion between missing telemetry and measured zero. Synthetic snapshots do not qualify the outstanding poller repair.
Change-source: pulse-maintainer
Read agent-owned memory and source freshness from VM views when correlation removes the standalone host row. Preserve preferred guest memory sources and reject stale, offline or unavailable agent evidence. Reproduce issue #1962 through registry merge, next-poll diagnostics, card projection and memory alerts.
Change-source: pulse-maintainer
The branch is validated by the snapshot guard, but its transfer between
workflow steps must also use the canonical GitHub command-file encoder.
Keep the source binding unchanged and satisfy the workflow trust audit.
Validation: all 41 workflow trust tests and five snapshot tests pass.
Contract-Neutral: Encode the already-validated release branch with the shared GitHub command-file helper without changing source identity or release authority
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
Incorporate the landed Patrol qualification record while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.
Change-source: pulse-maintainer
Incorporate the landed Patrol planning work while preserving every reviewed alert recovery, credential-redaction and release-evidence commit and its ancestry.
Change-source: pulse-maintainer
# Conflicts:
# docs/release-control/v6/internal/subsystems/agent-lifecycle.md
# docs/release-control/v6/internal/subsystems/api-contracts.md
# docs/release-control/v6/internal/subsystems/storage-recovery.md
# frontend-modern/browser-verification.json
Reconcile the executable plan with the merged implementation and exact
qualification evidence. Keep the independent-environment rollout gate open
and preserve failed attempts, measurement limits and provider refusal.
Preserve the requested reservation for independent release snapshot work.
Refs #1782
Accepted queue actions and failed follow-up reads are different outcomes. Extend actual-tab regression coverage so unavailable health and history cannot erase SMTP edits or misrepresent the accepted action as rejected.
Change-source: pulse-maintainer
Literal-only query matching and the separate resolved ntfy transport caller leaked recognised URL credentials. Decode each query name once and project ntfy transport errors before logging or returning them, without changing destinations or error causes. Add synthetic sink-matrix and HTTP projection regressions plus the bounded notification contract in this commit.
Change-source: pulse-maintainer
Cancellation after a failed recovery must retain operator evidence and unfinished SMTP edits without triggering another API request. Cover this boundary in both actual destination-tab action scenarios.
Change-source: pulse-maintainer
Assert rejected and accepted retry/dismiss never clear the dirty flag after an SMTP edit; retained input value alone does not prove unsaved-state preservation.
Change-source: pulse-maintainer
Exercise the actual destinations tab, delivery hooks and SMTP editor across rejected and accepted Retry and Dismiss requests. Guard input identity, focus, dirty state, feedback and retained history rendering as health reconciles; standalone feedback tests did not cover this integration.
Change-source: pulse-maintainer
Pin useful diagnostic context and credential masking at the HTTP boundary, and document the API, agent and retained-history boundaries omitted from a2dbb27. This supplement must be packaged with that source commit for per-commit governance; it does not clear the historical hosted failure.
Change-source: pulse-maintainer
Normalize whitespace in required wiring snippets so gofmt alignment changes
do not fail the model-only handoff contract. Preserve the same required
identifiers and forbidden adapter checks.
Refs #1782
PR #1959 exposed that the URL-only redactor was called with a complete delivery error, causing safe but unhelpful replacement of the whole diagnostic. Redact embedded webhook URLs separately so credentials stay masked and non-secret failure context remains available; malformed URLs continue to fail closed.
Change-source: pulse-maintainer
Existing coverage checks focus after Clear but not when asynchronous failure feedback arrives. Guard input focus, unfinished text and mounted live-region identity without changing the interface or claiming screen-reader acceptance.
Change-source: pulse-maintainer
Raw URL matching missed encoded bot prefixes and mistook bot hostnames and query URLs for credential paths. Use the decoded path and clear RawPath so diagnostic errors and rate-limit logs cannot retain these synthetic bot tokens, while preserving local API server support and original destinations.
Change-source: pulse-maintainer
Discord webhook paths include tokens authorising webhook operations. Mask the credential suffix on exact Discord hosts without changing destinations or error causes, and cover helper output, transport errors and rate-limit logs with synthetic regressions.
Change-source: pulse-maintainer
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.
Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.
Refs #1782