The report matcher already filters host-local interfaces, but registry inference could lend a trusted agent identity to an unrelated provider using shared loopback, link-local or Docker bridge addresses. Apply the same bounded identity policy to strong and one-way provider corroboration, preserving reciprocal links, private management networks and explicit report-IP hints.
Four cross-provider cases and a one-way mismatched-hostname case fail before the repair. Focused race tests pass after it, including presentation separation and management compatibility. This is a synthetic defect reproduction, not proof of the cause or resolution of issue #1930.
Change-source: pulse-maintainer
A running custom sensor updated its canonical incident from warning to critical without dispatching the new severity (#1801). Enable upward transitions in the shared health adapter while keeping unchanged observations and downgrades quiet. Use the existing hourly budget and dispatch suppression rather than bypassing policy.
Pin CheckHost callback delivery, acknowledgement, snooze, inactive and flapping suppression, and shared ZFS rate exhaustion with focused regressions.
Change-source: pulse-maintainer
Activate the offline default context before mobile organization audits. Preserve visible session controls without page overflow, with real-backend Chromium and WebKit proof.
Change-source: pulse-maintainer
Carry the operator include override in disk reports so server filtering does not discard selected tmpfs mounts again. Keep automatic filtering for unmarked reports and agent exclusion precedence. Cover both ingest paths, collection, forwarding and wire compatibility for #1875.
Change-source: pulse-maintainer
Keep a loopback ephemeral issuer alive for source-built managed browser runs and activate each organisation through the authenticated API. Verify installation bindings without billing-state injection or signature bypass, and retain a narrow CI provisioning proof separately from quarantine acceptance.
Change-source: pulse-maintainer
Keep a loopback ephemeral issuer alive for source-built managed browser runs and activate each organisation through the authenticated API. Verify installation bindings without billing-state injection or signature bypass, and retain a narrow CI provisioning proof separately from quarantine acceptance.
Change-source: pulse-maintainer
Diagnostic query masking recognised only lowercase credential names, leaving mixed-case and encoded variants visible in URL and transport-error diagnostics. Match decoded names without case while preserving query spelling, unrelated parameters and the original request URL. Add seven regression cases covering diagnostics and wrapped error identity.
Change-source: pulse-maintainer
The failed exact rehearsal buffered the store-history latency assertion, preventing resource telemetry from locating its actual test interval. Extend the existing exact API lifecycle allowlist and cover both targets with synthetic pass/fail fixtures without rerunning product qualification or changing thresholds. This is prospective observability, not clearance of the retained latency or crash evidence.
Change-source: pulse-maintainer
Use patched Vitest/coverage 4.1.11 and js-yaml 4.3.2. Adapt constructor mocks, callable mock types and explicit call-history cleanup for Vitest 4 without weakening assertions or audit gates.
Change-source: pulse-maintainer
Manually entered Pushover aliases were normalised on save but not on test, so the test could exercise a different payload. Apply the same normalisation and retain a failing-before parity regression; 56 focused webhook tests pass.
Change-source: pulse-maintainer
Buffered package logs cannot map the API stress-test failure to resource telemetry. Stream Go events and retain a bounded target lifecycle with distinct event, receipt and resource collection times, while preserving readable output and pipeline failure status. Synthetic decoder and worker tests cover pass, skip, failure and unavailable telemetry; this does not clear historical qualification or authorise a replay.
Change-source: pulse-maintainer
Persistent authenticated WebSockets sent nothing between polls, allowing idle-timeout appliances to discard them before the next refresh. Send bounded control pings for each authenticated session and stop the sender on disposal without treating pongs as fresh inventory.
Successful refreshes also added a full interval after completion. Target start-to-start cadence while preserving up to five seconds of minimum idle time, unchanged failure backoff and honest completion timestamps. Authenticated idle-timeout and cadence regressions failed before the repairs; focused transport and poller race tests pass. Addresses the reproduced paths in #1893, not native appliance or reporter confirmation.
Change-source: pulse-maintainer
The queue and health API expose server_error, but the delivery UI treated it as unclassified. Preserve that diagnosis and direct operators to service availability and server logs before retrying retained deliveries. Add focused label and health guidance regression coverage.
Change-source: pulse-maintainer
Give users a public account of beta, RC and stable expectations so they can
choose an update channel and understand how releases earn promotion.
Document fixed candidates, observation periods and rollback guidance, with
links from the main documentation entry points and matching shipped docs.
Webhook transport already retries HTTP 421, 423 and 425, but shared classification marked them terminal and discarded the remaining queue retry budget. Align these exceptions with retryable connectivity or receiver failure classes. A synthetic 400-599 transport matrix reproduces the three mismatches and verifies permanent rejections remain terminal without starting storage workers.
Change-source: pulse-maintainer
A truncated diagnostic body currently erases a received HTTP rejection, causing terminal failures such as 403 to consume extra delivery attempts and report a connectivity class. Preserve the HTTP verdict and wrapped read error so existing retry rules still apply. Transport-only regressions reproduce the extra attempt, verify transient recovery and retain successful-response read-error behaviour.
Change-source: pulse-maintainer
The reload watcher exits with the parent context, so unconditional request and reply waits could strand callers during shutdown. Select on that same context at both waits and reject calls before Start; retain buffered completion for an in-flight reload.
Channel-only regression fixtures reproduce the old hang and verify cancellation, late completion and unchanged result propagation without starting monitors or storage. Update the monitoring contract with the bounded lifecycle guarantee and its limits.
Change-source: pulse-maintainer
Recovery handlers retained the startup monitor after router reload, unlike normal notification handlers. Stopping that monitor cleared its queue and left Retry/Dismiss returning 503 even when the replacement notifier was available. Refresh the stable handler in both replacement paths and synchronise its owner reads. Add stopped-owner regression, concurrent replacement and scope proofs; keep queue persistence semantics unchanged.
Change-source: pulse-maintainer
The JSON mirror fast path avoided file replacement but still dirtied directory metadata on every save through chmod. Check the current permissions before repairing them, retaining correction of unsafe modes. A Linux regression reproduces the ctime change and verifies unchanged metadata and permission repair. This is a narrow contributor to #1966, not a claim that aggregate write amplification is resolved.
Change-source: pulse-maintainer
Verify saved email and HTTP Apprise receiver configuration through the real constructor alongside routing intent, without transport calls or reapplying setters.
Change-source: pulse-maintainer
Exercise the production monitor constructor twice from persisted routing, resolve, activation and webhook filtering choices without reapplying notification setters. Document that constructor restoration does not establish browser saving, process restart or destination delivery.
Change-source: pulse-maintainer
HTTP 503 can advertise a recovery delay through Retry-After, but the transport previously ignored it and retried after the default second. Use the existing bounded parser for 503 as well as 429 without changing retry budgets or terminal-error classification. Add request-spacing coverage for valid and malformed 503 hints and both zero-hint status sequences. The valid 503 test fails before the repair (1.0005s versus 2s); focused race tests pass three times. This longstanding interoperability repair is main-only, not a release-candidate regression backport.
Change-source: pulse-maintainer
Align the public transparency page and shipped copy with the standing
publication and issue-reply grant. Keep ownership, qualification and
verification responsibilities explicit.
The default-branch schedule rejected main before any product checks. Resolve the governed branch to one commit, check its VERSION against policy and retain exact event-source checks for manual dispatches. Report workflow and tested source separately and exercise selection against local Git fixtures in governance CI.
Change-source: pulse-maintainer
The renewed #1126 report shows seven-day alerts beside 33/34-day globals. Cover absent, sparse and preexisting divergent overrides through JSON decoding and evaluation so a global screenshot is not mistaken for effective guest configuration. Clarify that differing persisted values do not prove user intent; preserving them avoids silently deleting deliberate overrides. This reproduces a possible configuration path, not the reporter environment.
Change-source: pulse-maintainer
Incoming webhook destinations can repeatedly return 429. Cover exhaustion for explicit and default retry budgets so response hints cannot reset the attempt ceiling or misreport failed delivery history. Verify each attempt preserves payload and event identity. Correct the transport comment's off-by-one ceiling and remove its delivery guarantee; runtime behaviour is unchanged.
Change-source: pulse-maintainer
Validate the decoded URL path so encoded fail/start/log suffixes cannot pass the existing success-endpoint guard. Cover encoded separators, valid base URLs, and runtime rejection without transport or token disclosure.
Change-source: pulse-maintainer
Incorporate protected PR #1973 while preserving every reviewed local alert and notification commit in history. Reconcile its failed-read state with per-request ownership and retain exact combined browser evidence.
Change-source: pulse-maintainer
Record the landed implementation, passing final CI and exact local proof.
Retain the original benchmark failure and API timeouts, and keep model
reliability and independent-environment readiness limits explicit.
Refs #1782
PR #1973 introduced resource incident error state independently of the request lifecycle repair. Reconcile its state with this branch's ownership guards so superseded or disposed reads cannot report a false current failure. Reset clears errors and retry preserves cached history while clearing the failure indicator.
Extend lifecycle assertions for error ownership, retry and superseded success after a current failure. Focused incident hook and panel tests pass: 3 files, 17 tests. Full merged UI browser acceptance remains separate.
Change-source: pulse-maintainer
A zero Retry-After on a rate-limited response reset the exponential schedule to zero, causing subsequent transient failures to consume retries immediately. Apply the response delay only to its own wait and retain the normal schedule for later failures. Local HTTP regressions cover both a subsequent 503 and a headerless 429; focused retry tests pass with the race detector over three repetitions.
Change-source: pulse-maintainer
Invalidate pending reads on reset and disposal, and gate success, failure and loading writes per resource. Convert the four reproductions to ordinary tests and retain reset/reopen and stale-failure controls. Qualify the real hook and panel with 14 Chromium lifecycle cases; register that exact browser surface proof without broadening path policies. This does not qualify installed delivery or PR1973's absent error accessor.
Change-source: pulse-maintainer
Filter canonical history before selecting occurrences, preserve source evidence
and expose bounded reads and failures. Reconcile duplicate saved shells without
splitting one alert lifecycle, and keep note identity and canonical risk intact.
Carry attributed operator notes into Assistant. Preserve mobile investigations
across layout changes, transfer composer focus on handoff and keep long event
text readable. Record scoped qualification and its unresolved wider limits.
Refs #1782
Issue #1966 reports excessive idle writes. Canonicalise complete alert records and compare bounded existing bytes before replacing a secure regular recovery mirror. Preserve changed-state writes, missing/corrupt-file repair, failed-write retries and the directory durability barrier.
JSON-only regression failed before the repair and passes with repeated race coverage; existing load/save identity and permission tests pass. This is not a total disk-write measurement or a request to widen the selected beta.
Change-source: pulse-maintainer
Retain unordered and subsecond recurrence boundaries through incident-store reconstruction; assert unchanged projected identity and zero checkpoint replacements after replay. Canonical events remain in memory, with no durable event-store or installed write-rate claim.
Change-source: pulse-maintainer
A canonical snapshot can omit memory after the producer marks its Proxmox
facet unavailable. Retaining the previous display metric hides withdrawal
and leaves a stale percentage visible. Clear that explicit transition in
full and fast merges and emit the corresponding store operation, preserving
ordinary partial omission and trusted canonical metrics including zero.
Pin withdrawal and recovery with adapter tests and desktop/narrow Chromium
acceptance. Workload details remain canonical-only; do not invent raw totals
or Usage UI. Record inspected screenshots and matching subsystem contracts.
Change-source: pulse-maintainer
The real monitoring lifecycle dispatcher reproduces a closed incident reopening when its next occurrence fires: canonical projection selected all later events for the same alert. Bound retained-shell projections to their exact start and the next retained start, keeping subsecond recurrence and historical acknowledgement separate. Add in-memory callback coverage with both projections attached; twenty race repetitions pass along with focused incident tests. No retention migration, canonical-only fallback rewrite, notification-delivery claim or aggregate write-byte claim.
Change-source: pulse-maintainer
Issue #1966 reports distinct incident IDs for one occurrence. Deterministic lifecycle replay creates eleven shells for one resolved start, including after JSON restart; open-only matching also lets an old resolution close a newer occurrence. Match exact lifecycle starts and retain closed identity on replay, without changing legacy zero-start matching or retention. Add recurrence, restart and canonical-shell regression coverage; focused incident race tests pass for twenty repetitions. This does not establish total write savings or migrate existing duplicates.
Change-source: pulse-maintainer