Commit Graph

1624 Commits

Author SHA1 Message Date
pulse-triage[bot] 7c373a5162 fix(release): reject draft Helm chart publication retries
Reproduce draft and unknown publication states reaching the Pages index boundary. Require an explicitly non-draft existing release before uploading, editing or advertising its chart, without implicitly publishing operator drafts.

Exercise the actual publication shell with a fake GitHub CLI and wire its seven retry tests into canonical governance. Existing digest and maturity behaviour remains covered.

Change-source: pulse-maintainer
2026-09-05 20:55:01 +01:00
pulse-triage[bot] ef6e784c2e docs(release): clarify combined continuity incident recovery
Fresh stable readback still shows mutable v6.4.1 alongside orphan v6.4.2. Explain forward supersession without deleting historical tags or treating frontier success as release admission. Cover that distinction with a focused recovery regression; publication authority and all existing gates remain unchanged.

Change-source: pulse-maintainer
2026-09-05 20:12:48 +01:00
pulse-triage[bot] 829be07d3c Merge remote-tracking branch 'origin/main'
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
2026-09-05 20:06:58 +01:00
pulse-triage[bot] b6c8bf6bef test(governance): anchor organisation references to contract content
Reproduce PR #1909 governance failures on the combined lane source. Derive reference positions from named content while retaining explicit section, ownership and verification assertions, so unrelated documentation insertions do not break CI.

Validation: all 163 subsystem lookup tests pass via pulse-heavy-run; both affected tests also pass with two documentation lines inserted in memory. No runtime or release-policy change.
Change-source: pulse-maintainer
2026-09-05 19:39:37 +01:00
rcourtman d223ba0262 Start scoped explanations from Patrol and alert actions
Explain actions previously opened a blank conversation and discarded richer
finding context. Dispatch the selected explanation through shared chat
handling, retain evidence and drafts, and cancel pending work on tenant
switches. Keep unrelated workflow starters out of scoped conversations.

Record the remaining real-model and customer-outcome qualification gap
without treating scripted browser responses as proof of product value.
2026-09-05 19:13:11 +01:00
pulse-triage[bot] 0833e8dc80 test(web): qualify superseded admission and diagnose narrow table access
Close the missing third-organisation and real shell SIGTERM evidence without expanding product scope. Retain measured narrow-table clipping and accessible-name evidence so follow-up repairs preserve Android vertical gesture ownership rather than assuming horizontal scroll access.

Validation: eight Chromium admission cases, two local-backend narrow socket/access runs, real Compose/Playwright SIGTERM cleanup, twelve focused shell tests, and diff checks passed. No installed release or physical-device qualification.
Change-source: pulse-maintainer
2026-09-05 17:57:42 +01:00
pulse-triage[bot] 5617e5bed5 Merge commit '9fdf8059e08a89f82e426330d8131802be3f0298'
Change-source: pulse-maintainer
2026-09-05 17:39:49 +01:00
pulse-triage[bot] 9fdf8059e0 test(web): qualify admission races and reconnect at phone height
Close the unfinished browser evidence gap without extending UI scope. Exercise admission races and subsequent current-organisation reconnect requests, and use 390x844 for populated socket recovery so retained screenshots expose the remaining table clipping rather than implying mobile layout acceptance.

Change-source: pulse-maintainer
2026-09-05 17:35:14 +01:00
pulse-triage[bot] 6998908d2a fix(release): limit asset validation readiness claims
Downstream release-note syndication repeats the asset check banner even when installed health or release convergence is not qualified. Report asset checks only and state the remaining evidence boundaries for both draft and post-publication banners.

Change-source: pulse-maintainer
2026-09-05 17:30:49 +01:00
pulse-triage[bot] a41e35f296 test(release): reject signatures outside the configured trust boundary
Exercise real SSH signatures from an untrusted key and the trusted key under an unrelated namespace, for both manifest and installer. Keep checksum content valid so these regressions specifically protect signature trust selection.

Change-source: pulse-maintainer
2026-09-05 17:17:54 +01:00
pulse-triage[bot] 4f61c581b9 fix(release): expose reconciliation decisions in run summaries
The successful scheduled reconciliation at run 33972475922 retained a credential-containment hold and dispatched no retry. Put safe decision messages in the Actions summary so a green reconciler is not mistaken for delivered releases. Narrow empty-discovery wording because mutable channels and missing runs are not qualified. Preserve containment, retry budgets and dispatch behaviour; cover summary output and empty discovery with focused tests.

Change-source: pulse-maintainer
2026-09-05 16:23:47 +01:00
pulse-triage[bot] bf6121e41d fix(release): reject ambiguous activation asset inventories
Count all activation marker names before validating their metadata so a malformed duplicate cannot pass the immutable packet boundary. Reproduced acceptance with a valid uploaded marker plus a zero-size pending duplicate; both valid and malformed duplicates now fail before attestation or download.

Validation: 13 focused integrity tests and 46 promotion policy tests pass; bash syntax and git diff checks pass. No publication or deployment performed.
Change-source: pulse-maintainer
2026-09-05 15:43:23 +01:00
pulse-triage[bot] 280e73e1f2 test(delivery): bind recovery receipts to successful submissions
Exercise all three reconciliation recovery paths through the mocked transport for accepted and rejected POSTs. Assert rejected submissions raise without emitting a success receipt.

Validation: 30 reconciliation tests and 46 release promotion policy tests pass. No remote mutations performed.

Change-source: pulse-maintainer
2026-09-05 15:12:05 +01:00
pulse-triage[bot] 2d979682fd fix(delivery): preserve convergence receipt policy checks
The dry-run receipt repair made submitted messages dynamic, hiding the literal
pre-commit renewal contract from canonical governance. Keep submitted and
non-mutating output distinct while spelling each receipt explicitly so the
existing release-policy guard continues to verify the recovery handoff.

Validation: 29 reconciliation tests and 46 release promotion policy tests
pass, including the check that failed on pull request 1904.

Change-source: pulse-maintainer
2026-09-05 15:08:14 +01:00
pulse-triage[bot] 9a837b8b40 fix(web): discard superseded organisation admission responses
An outgoing admission refresh could restore platform navigation after an organisation switch. Accept only the latest request response, including when a newer request fails or is still pending. Preserve authoritative successful empty admission and subsequent navigation recovery.

Reproduced at 390px and 1440px; six repaired synthetic full-app browser cases and 59 focused tests pass. Typecheck passes. This does not qualify backend isolation, a released artifact or external alert delivery.

Change-source: pulse-maintainer
Contract-Neutral: Restore existing latest-organisation admission semantics only; no API, entitlement, navigation surface or subsystem contract changes. Focused ordering regressions and desktop/narrow browser proof cover the repair.
2026-09-05 10:33:40 +01:00
pulse-triage[bot] 6ecee4b4c4 fix(delivery): distinguish dry-run proposals from submitted retries
A read-only reconciliation of current release debt printed Dispatched despite suppressing the POST. Return submission status from the transport and qualify all three mutation receipts. Preserve retry and containment policy unchanged.

Verified 29 reconciliation and 41 workflow-trust tests; new dry-run regression rejects all three baseline paths. Live --latest --dry-run now reports Would dispatch without mutation.

Change-source: pulse-maintainer
2026-09-05 10:20:38 +01:00
pulse-triage[bot] 5add9bfc36 fix(ci): permit audited caller-only permission inheritance
The stable-install smoke body is intentionally workflow_call-only so its read-only continuity caller and draft-capable release caller can supply different explicit token budgets. Treat that exact no-override shape as an auditable permission boundary while continuing to reject independent triggers and job permission overrides.

Validation: 41 workflow-trust tests, repository workflow audit, focused install-smoke contract tests, Python compilation and diff checks pass.

Change-source: pulse-maintainer
2026-09-05 09:06:17 +01:00
pulse-triage[bot] ec462ad964 fix(release): inspect convergence logs through safe Actions reader
Scheduled reconciliation fails when gh api refuses ANSI-bearing Actions logs. Use the dedicated sanitising log reader without disabling terminal protection, preserving private authentication and fail-closed evidence handling. Focused reconciliation and policy tests pass; a read-only live job probe retains failure evidence without ESC bytes.

Change-source: pulse-maintainer
2026-09-05 04:32:38 +01:00
pulse-triage[bot] fb9e4335e1 fix(ci): keep stable install smoke within caller permissions
Stable continuity run 33592377446 was rejected before any job ran: its read-only caller invoked a reusable job requesting contents:write. Extract the unchanged smoke execution into a body that inherits the caller budget, keeping the existing draft-capable entry point and its write-level draft GET access. Continuity now calls the shared body directly without broadening its token. Pin the permission boundary in regression coverage; do not relax immutable-release admission.

Change-source: pulse-maintainer
2026-09-05 04:02:24 +01:00
pulse-triage[bot] 8433ea426c Merge web application refresh qualification
Change-source: pulse-maintainer
2026-09-05 02:13:05 +01:00
pulse-triage[bot] abff834d80 test(web): qualify backup refresh through application boundaries
The isolated Coverage fixture cannot establish whether resource-provider and WebSocket replacement preserves application interaction in issue #1869. Exercise the actual shell, scoped paginated resources, windowed Coverage and By date, and the real PBS History drawer with synthetic snapshots. Retain desktop and narrow evidence without claiming a deployed-release or Brave fix.

Change-source: pulse-maintainer
2026-09-05 01:55:54 +01:00
pulse-triage[bot] 7db3192a3f fix(release): measure candidate soak from release publication
Git tag creation can precede candidate publication, allowing stable promotion before the required observation period. Read the exact published prerelease and fail closed when publication evidence is unavailable. Cover repaired-candidate minor and patch boundaries.

Change-source: pulse-maintainer
2026-09-05 01:47:12 +01:00
pulse-triage[bot] ac8172c42c Preserve backup coverage row focus across polling snapshots
Reconcile coverage rows by logical keys before windowing. Isolated Chromium checks at desktop and narrow widths preserve keyboard focus, expanded evidence, route and scroll across replacement HTTP snapshots. Include subsystem completion obligations and a content-bound browser receipt.

Does not qualify the full application scroll-jump report in #1869 or reporter resolution.

Change-source: pulse-maintainer
2026-09-05 01:33:47 +01:00
pulse-triage[bot] 19c2b6a925 Fix portable root ownership for installer lifecycle state
Issue #1890 reports macOS agent updates stopping because the root group does not exist. Use numeric superuser ownership in the two shared lifecycle writes without relaxing failure handling or the least-privilege group boundary. Add a regression fixture that rejects named root ownership and checks that chown failures still prevent replacement.

Change-source: pulse-maintainer
2026-09-04 22:33:08 +01:00
pulse-triage[bot] 26309d71a0 Restore release contract assertions after merges
Reapply the reviewed Go 1.26.8, OCI Helm recovery, and non-login-shell test expectations that later upstream merges accidentally replaced while retaining the corresponding implementations.

Contract-Neutral: test-only reconciliation; no product or runtime behavior changed

Change-source: pulse-maintainer
2026-09-04 20:39:02 +01:00
pulse-triage[bot] 09da37881f Check release inventory independently of Git refs
A published release packet is a customer-visible surface in its own right. Deriving newer published versions only from matching Git refs lets that surface escape continuity validation when the corresponding ref is absent. Evaluate every stable-shaped release record independently and pin the detached-ref case with a regression test.

Change-source: pulse-maintainer
2026-09-04 15:01:51 +01:00
pulse-triage[bot] 485e19600f Align npm audit contracts after upstream merge
Update the retained canonical Python contract for the upstream wall-clock timeout mechanism and the single complete per-PR audit, while preserving the two-view scheduled audit expectations.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-04 14:31:31 +01:00
pulse-triage[bot] d170a23d22 Merge commit 'd7356ef76e26cd461278de18cd471d7cb2682043'
Change-source: pulse-maintainer
2026-09-04 14:29:39 +01:00
pulse-triage[bot] e46e897702 Merge remote-tracking branch 'origin/main'
# Conflicts:
#	.github/workflows/build-and-test.yml
#	docs/release-control/v6/internal/subsystems/deployment-installability.md
#	scripts/installtests/build_release_assets_test.go
#	scripts/npm-audit-retry.sh

Change-source: pulse-maintainer
2026-09-04 14:29:31 +01:00
pulse-triage[bot] d7356ef76e Detect orphaned stable delivery versions
A failed v6.4.2 release left newer stable-shaped source and public container tags behind after its GitHub Release packet was removed. Extend the scheduled continuity audit across the stable tag and public registry frontier so this partial publication cannot remain hidden behind an older latest release.

Change-source: pulse-maintainer
2026-09-04 13:58:07 +01:00
pulse-triage[bot] 4b7faa5a97 Align the scheduled audit contract test
The security workflow moved to the scoped npm audit retry runner, but its
dependency-policy test still asserted the retired direct invocation. Assert the
checked-in all and production modes so the script suite tests the active
scheduled scan.

Contract-Neutral: test expectation only; scheduled audit behaviour is unchanged

Change-source: pulse-maintainer
2026-09-04 13:13:04 +01:00
pulse-triage[bot] 9720f6726b Pair benchmark evidence on one runner
The benchmark gate compared five-sample PR results with a cache produced on
another hosted VM. Two unrelated changes failed today while the same main code
passed, and benchstat reports infinite 95% confidence intervals for that sample
size.

Collect ten base and candidate samples on the PR runner in alternating order,
retain both inputs and the comparison, and reject under-sampled verdicts. Keep
non-PR benchmark evidence without the cross-run baseline cache.

Contract-Neutral: CI performance evidence collection only; no product or release contract changes
Change-source: pulse-maintainer
2026-09-04 13:13:04 +01:00
rcourtman 5434868bd0 Bound the npm audit retry budget by wall clock
The retry hardening added in #1885 bounded attempts but not time. npm's own
fetch-timeout defaults to five minutes and it retries internally, so three
"attempts" against a hanging advisory endpoint ran for 10m56s on job
100986651307, and a second audit step added 3m36s. The Frontend job was
cancelled 31s into type-check with all 1183 test files already passing, and a
cancelled job reports as a failed required check, so a green run blocked every
pull request. #1888 raised the job timeout to 40 minutes to unblock delivery;
this decides the policy instead.

Each attempt now runs under a hard wall-clock bound and the sequence stops at
a total deadline (60s and 240s by default). npm's internal retry loop is
disabled in favour of this one, since it was the hidden multiplier. The bound
is enforced by a watchdog subshell rather than timeout(1), which is not
present on every developer machine.

What happens when the endpoint stays unreachable is unchanged, because that
split was already right: the run fails when the change touches the dependency
graph and the answer is genuinely unknown, and warns without failing when it
does not, because the graph is then identical to a base commit that already
produced a passing answer. Any advisory at any severity still fails.

Also drops the production-only audit from the per-pull-request path. It audits
a subset of the same packages, so it reports a subset of the same advisories,
and because the complete audit fails the job on any finding, the production
step could only ever execute in the cases where it was already guaranteed
clean. The dev-versus-production split still runs for every npm workspace in
the scheduled security-scan job, where it informs rather than blocks delivery,
and Dependabot security updates remain the route for advisories published
against unchanged dependencies.

With the audit bounded to 4 minutes against an ~11 minute baseline, the job
timeout returns to 30: a stalled endpoint should surface as a warning, not be
absorbed by a budget large enough to hide it.
2026-09-04 12:13:31 +01:00
pulse-triage[bot] 6d8546b756 Keep Actions workflows on Node 24
Replace the remaining Node 20 action pins before GitHub removes that runtime, and make the reviewed Node 24 pins a workflow trust invariant.

Change-source: pulse-maintainer
2026-09-04 11:08:34 +01:00
pulse-triage[bot] b7e6a1e4e7 Merge privileged runner trust candidate for coordination
Change-source: pulse-maintainer
2026-09-04 09:39:27 +01:00
pulse-triage[bot] 0b72eca737 Keep privileged jobs on ephemeral hosted runners
Retire the unused self-hosted live qualification workflow and reject future secret- or write-capable jobs on persistent or dynamically selected runners. Keep live Patrol qualification as a disposable lab operation.

Change-source: pulse-maintainer
2026-09-04 09:30:11 +01:00
pulse-triage[bot] 9bd43732c2 Merge frozen Pulse upstream for coordination batch
# Conflicts:
#	.github/workflows/build-and-test.yml
#	scripts/installtests/build_release_assets_test.go
#	scripts/npm-audit-retry.sh

Change-source: pulse-maintainer
2026-09-04 09:01:28 +01:00
pulse-triage[bot] 38575bb5e6 Merge release workflow trust candidate for coordination
Retain the reviewed release-boundary cache and pull-request secret hardening alongside the current Go toolchain work.

Change-source: pulse-maintainer
2026-09-04 08:19:26 +01:00
rcourtman c01d152a35 Separate a real advisory from an unreachable npm audit endpoint
On 2026-09-03 registry.npmjs.org returned 503s and then timeouts from its
bulk advisory endpoint for over an hour. `npm audit` exits non-zero both
for a real advisory and for an endpoint it cannot reach, so the Frontend
job failed four times running and, because it is a required check, no
pull request could land at all - including Go-only ones that touch no
JavaScript. Every one of those failures was the outage. In two of the
runs the other audit call in the same job succeeded and reported zero
vulnerabilities.

The audits now run through scripts/npm-audit-retry.sh, which separates
the two cases and does nothing else. A conclusive result is acted on
immediately, and the gate stays exactly as strict as before: any
vulnerability at any severity still fails, and no severity threshold is
introduced. Only an unreachable endpoint is retried, with backoff.

When retries are exhausted the outcome depends on whether the answer is
actually unknown. A change that touches frontend-modern/package.json,
frontend-modern/package-lock.json, or the runner itself fails, because
the dependency graph moved and no result means no answer. A change that
touches none of them warns and continues, because the graph is then
identical to the base commit that already produced a passing answer.
Advisories published later against unchanged dependencies are what
Dependabot security updates are for, not a per-pull-request audit.

Deliberately not done: relaxing the severity threshold. That was my first
instinct, but the evidence does not support it. None of the four failures
was an advisory, the lockfile reports zero vulnerabilities at every
severity, and a threshold would have weakened the gate without fixing
anything. The contract's rule that audit suppression is not a valid
closure stands.

The pinning test now requires the runner's invocation and the dependency
detection wiring, and additionally asserts the runner carries no
--audit-level flag, so the strictness cannot be quietly traded away
later.
2026-09-04 08:06:35 +01:00
pulse-triage[bot] 457aa90458 Keep release workflows free of implicit trust inputs
Remove the pull-request secret exception, drop inert E2E secret references, and disable setup-node caches at release trust boundaries. Document the exact metadata-only privileged trigger exception.

Change-source: pulse-maintainer
2026-09-04 07:30:35 +01:00
pulse-triage[bot] ffb5323868 Merge Go 1.26.8 release toolchain candidate
Change-source: pulse-maintainer
2026-09-04 07:27:08 +01:00
pulse-triage[bot] 35d4cb0e97 Advance release builds to Go 1.26.8
Go 1.26.8 supersedes the prior patch release, so every release builder and local toolchain guard must move together to prevent candidate artifacts from retaining an older compiler and runtime.

Contract-Neutral: toolchain-only patch update; no product or runtime contract changed
Change-source: pulse-maintainer
2026-09-04 07:20:28 +01:00
pulse-triage[bot] afa66ec69b Quiesce exhausted convergence retries
An unchanged control revision cannot repair release-convergence debt after its
bounded retry budget is spent. Continuing to raise from the scheduled
reconciler only creates a recurring controller failure while the original
failed run already preserves the actionable debt signal.

Treat that exhausted current revision as a stable no-op, but let a newer
control revision dispatch again so repaired controls are not stranded behind
stale attempts.

Contract-Neutral: release-control automation only; no runtime or public API contract changed
Change-source: pulse-maintainer
2026-09-04 07:09:48 +01:00
pulse-triage[bot] f891c49bc0 Raise Go crypto security floor
Move x/crypto to v0.56.0 after the upstream SSH connection deadlock advisories, and keep the local dependency-floor check from accepting a downgrade.

Contract-Neutral: dependency-only security floor update; no runtime contract changed
Change-source: pulse-maintainer
2026-09-04 06:46:07 +01:00
pulse-triage[bot] 627e29bb39 Keep advisory findings ahead of audit retries
Change-source: pulse-maintainer
2026-09-04 04:27:31 +01:00
pulse-triage[bot] 44ca02d3d4 Keep npm audit outages from erasing CI evidence
Retry only explicit registry failures with bounded one-minute attempts while preserving immediate advisory failures. Defer the aggregate audit verdict so frontend tests and builds still report during npm service incidents.
2026-09-04 03:53:58 +01:00
pulse-triage[bot] 4daa41c3ae Keep unrelated release debt retriable
Credential-containment suppression could otherwise hide failed, cancelled, or incomplete public release jobs and strand recoverable convergence debt without an unattended retry. Require complete job evidence and limit suppression to the paid-runtime failure plus its aggregate verdict.
2026-09-04 02:54:05 +01:00
pulse-triage[bot] 5e30bbb346 Recover Helm Pages from attested OCI charts
Keep convergence recoverable after short-lived Actions artifacts expire by preserving the exact digest-bound package already verified from GHCR.

Change-source: pulse-maintainer
2026-09-04 01:04:30 +01:00
pulse-triage[bot] 6f3c436121 Stop retrying unchanged credential blocks
A committed release with an unchanged operator-owned containment failure cannot converge through unattended retries. Classify that evidence without weakening the block, and rearm only when the relevant private inputs or public controls change.

Change-source: pulse-maintainer
2026-09-04 00:14:40 +01:00
pulse-triage[bot] f74de141b4 Reconcile convergence with current controls
GitHub reruns preserve the failed workflow SHA, so a repaired convergence control cannot resolve an already committed release. A missed workflow_run event can also leave mutable aliases stranded without another attempt.

Change-source: pulse-maintainer
2026-09-02 13:11:04 +01:00