The stable-install smoke body is intentionally workflow_call-only so its read-only continuity caller and draft-capable release caller can supply different explicit token budgets. Treat that exact no-override shape as an auditable permission boundary while continuing to reject independent triggers and job permission overrides.
Validation: 41 workflow-trust tests, repository workflow audit, focused install-smoke contract tests, Python compilation and diff checks pass.
Change-source: pulse-maintainer
Issue #1894 exposed CPU sampling interference between host and Docker reporting loops. Existing tests cover independent collectors and host routing but do not exercise Docker's production dependency entry points.
Interleave the real host, Docker and package-level collectors over synthetic procfs counters. Alternate Docker's include and no-include paths and require each loop to retain a full-interval 5 percent baseline. Production behaviour is unchanged.
Validation: focused test passed; reverting either Docker route to the package-level collector made it fail. After restoration, three focused CPU tests passed with -race -count=3 across dockeragent, hostagent and hostmetrics. git diff --check passed.
Change-source: pulse-maintainer
Preserve the exact reviewed core-runtime candidate and add its storage-history regression test to the integrated mainline tree.
Change-source: pulse-maintainer
A reproduced admission HTTP 503 after socket recovery removed platform destinations despite populated inventory. Retain the last valid facet on request failure, keep tenant resets and successful empty responses authoritative, and cover desktop/mobile interruption and recovery.
Change-source: pulse-maintainer
Format the reviewed regression tests and use the canonical online resource status so the combined unpublished batch passes formatting and TypeScript validation.
Change-source: pulse-maintainer
Issue #1882 reports repeated PBS history observations. The existing regression test does not actually rebuild the registry or verify persistence after closing the store, leaving the repaired observation-time behaviour exposed to regressions.
Exercise repeated registry rebuilds across three source observations and SQLite close/reopen, checking canonical identity and all four storage metrics. Retain later equal-valued observations rather than deduplicating by value. Production behaviour is unchanged.
Validation: focused normal and race tests passed in the original execution, including ten race repetitions; a source-time mutation made the new test fail. This amendment changes only commit metadata.
Change-source: pulse-maintainer
Keep resource snapshot receipt separate from alert hydration and tenant-scoped across reconnect. Include matching subsystem contracts, architecture coverage and fresh browser receipt.
Validation: 87 focused tests and three real-backend Chromium checks pass at 1440, 1100 and 390px. Exact release-candidate qualification remains outstanding.
Change-source: pulse-maintainer
Scheduled reconciliation fails when gh api refuses ANSI-bearing Actions logs. Use the dedicated sanitising log reader without disabling terminal protection, preserving private authentication and fail-closed evidence handling. Focused reconciliation and policy tests pass; a read-only live job probe retains failure evidence without ESC bytes.
Change-source: pulse-maintainer
The powered-off recovery integration test previously discarded the firing payload, so it could pass even when the initial delivery named the wrong incident. Assert the grouped firing envelope contains exactly the active alert before checking recovery identity through the real loopback HTTP receiver.
Change-source: pulse-maintainer
Issue #1899 reports navigation disappearing when backend health changes to sync reconnecting on v6.4.1. Protect the isolated shell transition with stable link, label, icon and focus assertions rather than assuming the badge unit test covers navigation. This does not reproduce the reporter's browser or socket environment and makes no production fix claim.
Validation: AppLayout, useAppRuntimeState and ConnectionStatusBadge focused suites pass 46 tests. Temporarily hiding desktop navigation during sync reconnecting makes the new test fail; the mutation was restored and the suites rerun successfully.
Change-source: pulse-maintainer
Stable continuity run 33592377446 was rejected before any job ran: its read-only caller invoked a reusable job requesting contents:write. Extract the unchanged smoke execution into a body that inherits the caller budget, keeping the existing draft-capable entry point and its write-level draft GET access. Continuity now calls the shared body directly without broadening its token. Pin the permission boundary in regression coverage; do not relax immutable-release admission.
Change-source: pulse-maintainer
The integrated removed-row focus repair had only jsdom coverage. Exercise populated Timeline and Resource dialogs with production styles in two browser engines so focus trapping, dismissal and fallback regressions are observable without live credentials or customer data. This is synthetic component qualification, not backend delivery evidence.
Change-source: pulse-maintainer
History refreshes or filter changes can remove the card that opened an investigation. Cover the existing list-focus fallback so closing the dialog does not strand keyboard focus on the document body. Removing that fallback fails only the new test; all four tests pass after restoration.
Change-source: pulse-maintainer
An already-cancelled collector could still admit a filesystem syscall which ignores cancellation and blocks indefinitely. Reject expired contexts before registering work while retaining shared in-flight probes. The new regression test reproduces one unwanted probe before this fix; focused collector and guarded-probe tests pass ten repeats under the race detector.
Change-source: pulse-maintainer
Integrate the reviewed allocation reduction while preserving shared stuck-mount protection and its focused concurrency coverage.
Change-source: pulse-maintainer
Shared probes prevent overlapping collectors from stacking blocked statfs calls, but their short-lived sync.Map entries added measured collection overhead. Use a mutex-protected typed map and allocate only for the owning caller, retaining deadlines, result publication and one in-flight syscall per mount.
The paired filtering benchmark drops from 244 to 206 allocations and 21345 to 20129 bytes per operation. Five hostmetrics package repeats pass under the race detector, including new concurrent healthy-mount coverage. This is local mocked-collection evidence, not release or real-mount qualification.
Change-source: pulse-maintainer
The existing recovery test empties the whole table, which can mask stale expanded detail while monitoring continues. Keep a second disk incident active and verify recovery removes only the old detail and the remaining incident opens with its own resource identity.
Change-source: pulse-maintainer
The newly integrated critical-transition dispatch must retain the canonical incident notification budget. Exercise an exhausted budget through TrueNAS fixture ingestion while checking severity, identity and recovery; removing the rate-limit gate makes this case fail. Twenty focused repeats and five race repeats passed.
Change-source: pulse-maintainer
Critical-transition backend repairs need a UI regression check: an already-open incident must show the new severity without losing resource identity, then clear on recovery. Add reactive component coverage without changing product behaviour.
Change-source: pulse-maintainer
A TrueNAS WARNING progressing to EMERGENCY updated the live severity but never dispatched the critical transition. Bring provider incidents into line with metric critical re-notification using the existing rate-limit and delivery policy gates, without replacing lifecycle identity.
Add fixture-to-manager coverage for escalation, unchanged observations, downgrade, acknowledgement suppression and confirmed recovery. The new active transition case failed before the fix (one callback instead of two). TrueNAS tests passed 20 repeats and five race repeats; alerts and truenas package suites passed. External appliance and transport receipt remain unverified.
Change-source: pulse-maintainer
Green aggregate checks do not prove the standalone backup runners executed, and the related integration spec is non-gating probation coverage. Document the evidence boundary so release review does not mistake existing checks or retained samples for exact-revision refresh qualification.
Change-source: pulse-maintainer
TrueNAS documents EMERGENCY above ALERT, but native projection rejected it as an unknown level. Reproduced zero incidents and zero notification callbacks for this severity while the other six documented levels passed. Map it to critical so the most severe native condition is not silently omitted or mistaken for recovery.\n\nCover all seven native severity mappings, synchronous dispatch and confirmed recovery callbacks, and retention across repeated EMERGENCY observations. The two affected package suites and focused race checks pass; appliance and real notification-provider receipt remain unqualified.
Change-source: pulse-maintainer
The isolated Coverage fixture cannot establish whether resource-provider and WebSocket replacement preserves application interaction in issue #1869. Exercise the actual shell, scoped paginated resources, windowed Coverage and By date, and the real PBS History drawer with synthetic snapshots. Retain desktop and narrow evidence without claiming a deployed-release or Brave fix.
Change-source: pulse-maintainer
The INFO and NOTICE repairs need lifecycle coverage beyond isolated severity transitions. Verify that escalation retains identity and that renewed actionable evidence interrupts recovery, preventing a later single INFO observation from clearing the incident.
Change-source: pulse-maintainer
Git tag creation can precede candidate publication, allowing stable promotion before the required observation period. Read the exact published prerelease and fail closed when publication evidence is unavailable. Cover repaired-candidate minor and patch boundaries.
Change-source: pulse-maintainer
The INFO noise repair also suppressed NOTICE because both native levels map to monitor risk. TrueNAS documents NOTICE as notification-worthy. Retain native severity so NOTICE stays actionable without inflating its canonical severity; INFO suppression and confirmed recovery remain intact.
A native-projection regression fails with the blanket filter and passes with the correction. Affected TrueNAS, unified resources, alerts and incident-memory package tests pass.
Change-source: pulse-maintainer
Reconcile coverage rows by logical keys before windowing. Isolated Chromium checks at desktop and narrow widths preserve keyboard focus, expanded evidence, route and scroll across replacement HTTP snapshots. Include subsystem completion obligations and a content-bound browser receipt.
Does not qualify the full application scroll-jump report in #1869 or reporter resolution.
Change-source: pulse-maintainer
Issue #1892 reports successful replication information requiring acknowledgement. Preserve provider information on resources while excluding TrueNAS INFO-level conditions from active alert synchronisation. Warning conditions still activate and clear when downgraded to information.
Resource-incident timeline events contain numeric placeholders, not threshold evidence. Avoid displaying these as a fictitious 0 >= 0 trigger while retaining numeric metric formatting. Focused regressions reproduce both failures and pass with these changes.
Change-source: pulse-maintainer
TrueNAS emits FINISHED for successful replication, but the recovery mapper treated it as unknown. Recognise that provider state while preserving error precedence and the missing-run guard; add regression coverage reproducing the reported outcome.
Change-source: pulse-maintainer
Issue #1869 reports views resetting during refresh. Exercise the mounted backup coverage view through three replacement workload snapshots so losing expanded restore evidence is caught before release. Confirm each refreshed workload name renders to exclude stale-state false positives.
Contract-Neutral: regression coverage only; no runtime or API changes.
Change-source: pulse-maintainer
Exercise the mounted credential slot through repeated snapshots and a different edit target. A mutation that stops marking strategy selections dirty fails the new regression test.
Contract-Neutral: regression coverage only; no runtime or API changes
Change-source: pulse-maintainer