Name the landed notification-confidentiality and discovery repairs, add their
focused tester checks, and disclose the fresh installed persistence-write and
discoverability evidence. Keep the existing 6.4.4-beta.1 mapping and stable
rollback target unchanged.
Contract-Neutral: Align release notes, changelog, and the zero-capture rationale with already-reviewed source and fresh user evidence without changing runtime behavior, release gates, or publication authority
Change-source: pulse-maintainer
Backfill could save a stale List snapshot after manual discovery repaired a service, restoring unknown identity and dropping its URL and engine version. Derive and persist missing suggestions from the current record under the store lock instead, without holding it across monitor reads.
Add a deterministic SetReadState/manual-refresh interleaving and encrypted restart assertions, plus coverage for current identity, dismissed proposals, deletion and persistence failure. The discovery package passes twenty race-enabled repetitions.
Change-source: pulse-maintainer
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
(cherry picked from commit b64709e7b7)
Change-source: pulse-maintainer
Literal-only query matching and the separate resolved ntfy transport caller leaked recognised URL credentials. Decode each query name once and project ntfy transport errors before logging or returning them, without changing destinations or error causes. Add synthetic sink-matrix and HTTP projection regressions plus the bounded notification contract in this commit.
Change-source: pulse-maintainer
(cherry picked from commit 21ed7a8927)
The reviewed v6.4 userinfo backport made the existing delivery-log caller fail closed on a complete error sentence, which preserves secrecy but discards useful status context and fails the release-line regression. Redact embedded webhook URLs separately while retaining malformed-URL fail-closed behaviour.
Change-source: pulse-maintainer
Backport 77a8e4ee35 for candidate credential confidentiality. Preserve transport causes and destinations; cover Slack/GovSlack, encoded and legacy paths, and rate-limit diagnostics.
Change-source: pulse-maintainer
Security backport of db0c72c367. Release base reproduces credential disclosure in transport diagnostics and rate-limit logs. Preserve exact helper/tests; relocate the confidentiality contract without importing unrelated SMTP work.
Validation: three focused notification tests fail before repair and pass with -race -count=20 on Go 1.26.7. Protected PR review and exact-candidate qualification remain required.
Change-source: pulse-maintainer
A workflow dispatch by branch can resolve after that branch moves, allowing an unreviewed tip to enter the release pipeline. Require every publishing dispatch to name its expected source SHA and make the workflow reject a different source or workflow commit before checkout.
Change-source: pulse-maintainer
(cherry picked from commit a461fc9c0a)
(cherry picked from commit f503b13442)
Advance the protected v6.4 release line to the bounded alert-reliability beta, align install and chart metadata, and add the user-facing packet. Extend same-commit package and installer proof so alpha, beta, and RC preparation is governed without weakening the completion guard. Disclose the fresh stable Retry/Dismiss 503 report without claiming this candidate repairs that installed failure.
Change-source: pulse-maintainer
Backport PR1948 for the candidate preflight EACCES regression. Resolve main-only context by preserving release/v6.4 fixed smoke ports and omitting its unavailable PULSE_E2E_BASE_URL variable. No runtime changes, ACL widening, CLI download fallback or gate waiver. Supersedes the proposed ae1ac6ae95 and 0d0b105352 stack; normal reviewed source landing and exact qualification remain required.
(cherry picked from commit 8b73085e82)
Change-source: pulse-maintainer
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.
Change-source: pulse-maintainer
(cherry picked from commit 64dba483d0)
Backport runtime and regression tests from 495562ef66. Reproduced both failures on exact release-line parent 101bae339; patched 38 focused tests, TypeScript and three-width Chromium pass. Retain local qualification and exact runtime browser receipt. No recipient receipt or release HOLD clearance claimed.
Change-source: pulse-maintainer
PR #1933 failed paired normalization benchmarks despite unchanged hot-path source. Preserve actual checkout identities, selected toolchains and sample order so investigation does not confuse PR head metadata with measured source. Keep thresholds and sample collection unchanged.
Change-source: pulse-maintainer
(cherry picked from commit cbfe0d8eac)
Backport production correction from d04f368f6f. Candidate regression introduced by 4d2b312457 after v6.4.1. Two baseline recovery cases fail; 32 focused final tests and four synthetic Chromium cases pass. Existing delivery-log ordering defect remains main-only, not established as a candidate regression.
Change-source: pulse-maintainer
Release v6.4 reproduces lost concurrent invocation IDs and duplicate approval cards. Backport the four runtime/test files from reviewed main fix 33b852f66b and portable synthetic browser fixture 2d36bb7d4d, without private replay attestations or unrelated main state.
All 167 affected units and three browser widths pass; independent release-parent runtime substitutions fail. Record fresh scoped browser evidence and contract obligations; this does not qualify providers or release promotion.
Change-source: pulse-maintainer
Backport main 386fc0415e and its custom bridge correction 2ed9965968. Fix the provider-interface association regression introduced by afaf128950, present in v6.4.1 and this release candidate. Seven negative matcher cases and NAS ingestion fail before the repair; focused matcher, filtering, ingestion and manual link race tests pass three times afterwards. Preserve management bridges and explicit unicast report hints. No legacy link cleanup or manual-intent persistence change; reporter issue #1930 remains unconfirmed.
Change-source: pulse-maintainer
Backport test coverage from 4d87bd37c5 and 7425089632, as merged in 9b4fa52d84, for candidate regression repair 7a5b535a43. No production changes. Focused monitoring receipt race test passes three repetitions. Loopback and manager restart evidence does not qualify installed provider delivery.
Change-source: pulse-maintainer
Reproduce false recovery on candidate f71542ec21, then backport storage-only changes from 2e661e075a and 9a8ee6a5a7. Preserve known inactive/disabled behavior and normalized offline capacity suppression. Focused storage race tests pass three repetitions; installed qualification and a new exact-candidate soak remain required.
Change-source: pulse-maintainer
Retain storage policy aliases in durable metric and forecast metadata and use them during active-alert re-evaluation. Recover exact legacy PBS aliases from the recorded instance and datastore identity. Prevent a configuration reload from fabricating recovery against global defaults after restart.
Change-source: pulse-maintainer
(cherry picked from commit da5be2db15)
Backport 9d1b726 onto release/v6.4 parent 89c8e614 with before-failing and after-passing hook and Chromium controls. CI train admission is already merged; retain its independent contract evidence without duplicating changes.
Change-source: pulse-maintainer
Release-line proposals were receiving documentation and boundary checks while Build and Test and Core E2E excluded release/v* targets. Apply the reviewed branch-admission contract to the active train before publishing further alert regression coverage, without changing existing path or job gates.
Change-source: pulse-maintainer
Distinguish policy skips from provider success so suppressed jobs do not create false sent rows or successful audit entries. Reconcile cancelled queue health after releasing alert gates, preserve real attempt history, and cover all three providers for firing/recovery and global/destination disablement.
Change-source: pulse-maintainer
(cherry picked from commit 229d8668af)
Reproduced on candidate 80a5c50e13: failed and DLQ retry replay resolved firing entries after queue reopen, and per-item retry accepts cancelled or delivered rows. Backport fe273fc949 without unrelated main failure-classification changes; preserve grouped active members, recovery jobs and audit history. Focused notification regression tests pass ten times under the race detector.
Change-source: pulse-maintainer
Backport 6375d09a8b. Candidate f64fbb8b7 reproduced six false independent confirmations before repair; focused Docker result/executor and receipt reconciliation tests pass afterwards. Preserve stopped updates and execution history. This does not resolve issue #1891 or qualify an installed artifact.
Change-source: pulse-maintainer
Backport production fixes 57cb1a83bf and 49b998a251, with restart coverage from 49928385ba. Adapt PBS webhook assertions to the release-line nonzero recovery fixture.
On candidate 6558b2d106, reproduced confirmed-empty storage retaining its incident; applying only the storage guard then reproduced stale recovery content. Both fixes pass focused alert checks and three race-enabled repetitions across alerts and monitoring. Local synthetic receiver and orderly restart evidence only; no installed qualification.
Change-source: pulse-maintainer
Backport of 31f1f1933a, adapted to release/v6.4 client tests. Reproduced absent envelopes returning zero metrics and the null-status poller availability failure on candidate base 239ee0f9da before applying the production fix. Focused client and lifecycle race checks pass three repetitions. No installed qualification claimed.
Change-source: pulse-maintainer
Backport 2b78867cae with the PBS HTTP fixture and connectivity characterisation from a01efeed6b. Exclude unrelated main-line security-status documentation.
Release-line reproduction on 369e7f339e: node-status denial falsely resolves active memory utilisation. Retain active metric alerts until a valid sample arrives; connectivity and policy suppression remain independent.
Validation: go test -race ./internal/alerts ./internal/models ./internal/monitoring -run 'Test.*PBS' -count=3 passes. Installed destination delivery and restart persistence remain unqualified.
Change-source: pulse-maintainer
Reproduced on release base 11539a8059: HTTP 502 quoting API error 403 and HTTP 503 quoting API error 404 discarded cached backups. Both now preserve inventory; genuine 401/403/404 remain terminal.
Backport of c3b28f4557, including substantive monitoring contract and verification documentation. Adapt client test rename to the three existing callers; no unrelated mainline tests imported.
Validation: focused monitoring and PBS client tests passed with -race -count=3. No installed candidate, notification delivery or soak claim.
Change-source: pulse-maintainer
Reproduced on release candidate 7f44ccd047: WARNING to EMERGENCY retained severity but dispatched only once instead of twice. Backport the existing delivery repair and acknowledgement/rate-budget lifecycle regression coverage; no new product scope.
Backport-of: 4752d5b4b7 (code and tests), b116d05592
Validation: five focused race repetitions passed; pre-fix active transition failed. Appliance/provider receipt and restarted candidate soak remain outstanding.
Change-source: pulse-maintainer
Backport runtime mapping and regression tests from 65a024b3d3. Candidate v6.4.3-rc.1 and stable v6.4.1 omit the documented EMERGENCY severity. Include release-line monitoring and unified-resource contracts for the repaired projection and recovery boundary.
Reproduced omitted projection, zero notification callbacks and false recovery before the fix. Affected package suites and focused race tests passed in the initial turn. Appliance and external-provider receipt remain unqualified.
Change-source: pulse-maintainer
Correct the INFO backport so native TrueNAS NOTICE remains actionable while retaining informational canonical severity. Preserve the provider level as optional evidence and pin projection, JSON compatibility, alert activation, and confirmed recovery boundaries.
Adapted from ff1d010dd9 for release/v6.4.
Change-source: pulse-maintainer
Issue #1892 reports successful replication information requiring acknowledgement. Preserve provider information on resources while excluding TrueNAS INFO-level conditions from active alert synchronisation. Warning conditions still activate and clear when downgraded to information.
Resource-incident timeline events contain numeric placeholders, not threshold evidence. Avoid displaying these as a fictitious 0 >= 0 trigger while retaining numeric metric formatting. Focused regressions reproduce both failures and pass with these changes.
Change-source: pulse-maintainer
(cherry picked from commit 7726539f83)
TrueNAS emits FINISHED for successful replication, but the recovery mapper treated it as unknown. Recognise that provider state while preserving error precedence and the missing-run guard; add regression coverage reproducing the reported outcome.
Change-source: pulse-maintainer
(cherry picked from commit 62c6e07477)
Issue #1895 reports parity alerts when mdNumDisks=0 on a pool-only Unraid system. Array service state alone does not establish that a parity array exists.
Preserve the optional disk count from collection through canonical runtime conversion and suppress only the no-parity warning for an explicit zero. Missing or malformed counts retain legacy behaviour, and disk failure reasons remain active.
Validated focused Unraid tests in hostagent, storagehealth, monitoring, unifiedresources and alerts, including JSON zero preservation and canonical round trip. The new pool-only regression fails against the previous warning condition. Both agent and server need this change; no release or reporter retest is claimed.
Change-source: pulse-maintainer
(cherry picked from commit 3334cccfd9)
Near-synchronous host and Docker reports consumed a shared CPU baseline, measuring collection bursts rather than each module's reporting interval. Retain a collector per host collector and a separate Docker module collector while preserving the package-level convenience API and disk filters.
Add an interleaved-counter regression covering both collection entry points. It fails when routed through the shared baseline and passes with isolated state. All hostmetrics, hostagent and dockeragent tests pass, as do the focused CPU regression tests under the race detector.
Change-source: pulse-maintainer
(cherry picked from commit 0f972f42f2)
Issue #1890 reports macOS agent updates stopping because the root group does not exist. Use numeric superuser ownership in the two shared lifecycle writes without relaxing failure handling or the least-privilege group boundary. Add a regression fixture that rejects named root ownership and checks that chown failures still prevent replacement.
Change-source: pulse-maintainer
(cherry picked from commit 19c2b6a925)
Backport of the main-branch guard. pkg/server tests boot the real server
through Run() with the version literal "test-version", which normalizes to
0.0.0-test-version, and each test runs against its own t.TempDir(), so
every run mints a fresh install ID. The service-health failure reporter
sends synchronously from a deferred handler as soon as Run() returns an
error, so any test exercising a startup failure posts one ping.
This line still emitted after main was fixed: release-line lane work runs
pkg/server tests on this branch, and those pings arrive with the old
version classifier too, so they land mislabelled as ordinary prereleases
and re-contaminate install-population reads that were just corrected.
send() now refuses the production endpoint whenever testing.Testing()
reports true. The check compares against productionPingEndpoint, so
telemetry's own tests keep asserting on ping content through a redirected
endpoint. Verified on this branch: three runs of the failing-startup
tests, zero pings received.
The browser compatibility coalescer could undo the server's provider-scoped split after websocket reconciliation. Honour machine and provider identity before merging same-hostname rows.
(cherry picked from commit 724a8a4960)
A cluster name is an operator-selected display label, not global machine identity. Two independently configured estates using the same label could share one linked agent and then collapse into one presentation row after delayed cluster detection. Require node identity, exact endpoint, or host corroboration across provider instances instead.
Refs #1753
Change-source: pulse-maintainer
(cherry picked from commit 384dc53608)
The stable-row focus fallback ran after the shared dialog cleanup and could scroll a lower Manage trigger into view. Preserve the existing focus return without changing the operator's viewport, and cover the real desktop and narrow browser path.
Contract-Neutral: frontend focus-restoration bugfix; no API or persisted-data change.
Change-source: pulse-maintainer
(cherry picked from commit da9800ff2f)
Shared subtabs used scrollIntoView for horizontal visibility, allowing remounted or programmatically changed drawers to scroll the whole application shell. Reuse the horizontal rail controller instead, and restore disclosure focus without scrolling when a detail row closes.
Record the shared primitive contract and its registry-approved guardrails, with desktop and narrow Backups browser coverage for visible Overview and Manage states, off-screen tab changes, and non-scrolling focus return.
Change-source: pulse-maintainer
(cherry picked from commit 59e9f5ea2b)
The v6.4.3-rc.1 dispatch from main (run 33579042375) failed inside the
compiler dispatch: main advanced one minute after the release pipeline
pinned its source SHA, so the exact-SHA identity check on the compiler run
correctly refused the moved head. With the maintainer landing pull requests
every few minutes, a candidate dispatched from main cannot hold its SHA for
the minutes between prepare and compile.
Declare release/v6.4 for the 6.4.3 version prefix, created from main at the
exact-SHA-qualified commit 56e51e622e, so the workflow refuses a v6.4.3
dispatch from any other branch and the compiler binding stays exact. This is
the delivery contract's branch-per-train rule applied to the patch line that
predates the first train; earlier 6.4.x versions keep their historical main
mapping, and the 6.5 train mapping is unchanged.