Commit Graph

10821 Commits

Author SHA1 Message Date
pulse-triage[bot] 088f597907 Merge current upstream main after PR #1929
Preserve the reviewed alert and TrueNAS work while incorporating the canonical API metrics optimization and patrol qualification record.

Change-source: pulse-maintainer
2026-09-06 09:12:03 +01:00
rcourtman cf98358c0e Merge pull request #1929 from rcourtman/fix/retained-history-coverage
perf(api): avoid rune decoding in route label checks
2026-09-06 09:08:50 +01:00
pulse-triage[bot] 49f305467b test(proxmox): preserve NAS inventory membership boundary
Issue #1930 shows a NAS with a PVE cluster label but supplies no resource payload. Verify that shared identity labels do not promote a generic host into the PVE model, while a genuine node with no version remains visible. This synthetic boundary test does not reproduce or resolve the reported incident.

Contract-Neutral: Tests only; preserves existing platform membership semantics.
Change-source: pulse-maintainer
2026-09-06 09:06:08 +01:00
pulse-triage[bot] 9a8ee6a5a7 fix(alerts): keep normalized offline capacity suppressed
Use the normalized connectivity status consistently when deciding whether storage capacity is actionable, preserving the existing offline suppression rule for case and whitespace variants.

Change-source: pulse-maintainer
2026-09-06 08:45:39 +01:00
pulse-triage[bot] 2e661e075a fix(alerts): preserve storage incidents when connectivity is unknown
Do not count empty or unknown storage status as recovery evidence. Normalise status spelling for connectivity checks while leaving capacity evaluation independent and preserving existing inactive/disabled storage behaviour.

Change-source: pulse-maintainer
2026-09-06 08:40:29 +01:00
pulse-triage[bot] cbbe42ff7f Merge web TrueNAS setup regression coverage
Change-source: pulse-maintainer
2026-09-06 08:31:58 +01:00
rcourtman a2f0ef8817 perf(api): avoid rune decoding in route label checks
Route labels classify ASCII digits and hexadecimal UUID bytes. Scan those
bytes directly while preserving numeric precedence, Unicode names and
invalid UTF-8 handling. This reduces the shared normaliser overhead exposed
by paired landing benchmarks without changing the benchmark gate.

Refs #1928

Contract-Neutral: ASCII route-label optimization preserves label values, identifier precedence, Unicode and invalid UTF-8 behavior, and agent lifecycle authority.
2026-09-06 08:31:26 +01:00
pulse-triage[bot] 6b40a52add test(truenas): supply API key owner in setup journeys
The setup fixtures omitted the owner identity required by supported API-key authentication, so they stopped at local validation rather than exercising test, preview, save and capacity denial. Supply the owner and assert it reaches test and create payloads; retain a browser assertion that a missing owner sends no test request.

Validation: reproduced both original Chromium failures and inspected the missing-owner screenshot; corrected spec passes 3/3 with no retries using pulse-heavy-run. Focused TrueNAS state tests pass 36/36 and E2E tier selection passes. No runtime or tier changes.
Change-source: pulse-maintainer
2026-09-06 08:26:14 +01:00
pulse-triage[bot] 7425089632 test(alerts): verify PBS webhook receipts across manager restart
Existing HTTP receipt coverage exercised uninterrupted operation while restart coverage ended at internal callbacks. Recreate both disk-backed managers during a missing-observation incident and after recovery to verify local transport delivery, incident identity, retained history and recurrence together. This does not qualify an installed binary or external provider.

Change-source: pulse-maintainer
2026-09-06 08:23:10 +01:00
rcourtman 6d2d188867 Merge pull request #1928 from rcourtman/fix/retained-history-coverage
fix(patrol): preserve evidence across history and access failures
2026-09-06 08:18:16 +01:00
rcourtman ba69933da3 docs(patrol): record current diagnostic qualification failure
Preserve the real Assistant result separately from passing access routing
and disposable fault oracles. Correct tool evidence still produced
unsupported temporal claims, so customer outcome readiness remains open.

Refs #1928
2026-09-06 08:06:58 +01:00
rcourtman 173d74a8e4 test(patrol): exercise dependency and restart fault oracles
Validate the checked-in dependency and three service restart fault contracts
against disposable Docker resources before using them to assess model output.
Verify baseline, injected fault, refused duplicate injection, explicit fixture
recovery, and two-pass cleanup with unchanged pre-existing inventory.

These opt-in tests make no Pulse or model request. Fixture recovery is teardown
and does not count as an approval, rejection, execution or customer outcome.
Record exact live, owning-package and source-bound proof in the redesign plan.
2026-09-06 07:42:32 +01:00
rcourtman 58caeda69b fix(assistant): retain monitored targets without command access
Resolve monitored topology before checking command connections so unavailable
inspection retains the known resource and parent node. Prevent known targets
from falling through to a colliding agent ID, and preserve the single-agent
requirement when no target is supplied.

Use one failed tool envelope for diagnostic reads and file mutations. Missing
connections neither prove an installation problem nor count as successful
writes. Hypervisor lifecycle authority remains on its canonical action path.

Verify disconnected and unknown targets, collision isolation, all affected
tool handlers, token/WebSocket scope boundaries, and the linked Patrol and
Assistant failure journey at desktop and narrow widths.
2026-09-06 07:27:05 +01:00
rcourtman 1f41fa174d perf(metrics): avoid ordinal binding allocations
The 500-node dashboard query triggered repeated ordinal string conversions
in the SQLite driver while matching numbered parameters. Use alphabetic
named bindings to preserve current values and shared query branches without
that allocation cost.

Cover large cached scopes with changed resource families, identities,
metric filters and windows, including IDs that resemble SQL syntax.

Refs #1928
2026-09-06 06:54:40 +01:00
rcourtman b964eea767 fix(hostmetrics): retire disk probes before publishing results
A completed probe remained discoverable after its first caller returned,
allowing the next collection to reuse stale filesystem measurements.
Remove it and publish completion within one registry critical section.
Keep in-flight sharing, cancellation and timeout behaviour intact.

The controlled regression fails before this change. Twenty full package
runs and three race runs pass on the worker.

Refs #1928
2026-09-06 06:28:00 +01:00
rcourtman 618700db5e test(patrol): qualify bounded service storage failures
Add a disposable service-storage fault with an independent filesystem
oracle, bounded tmpfs writes, identity checks and verified recovery.
Exercise overwrite and symlink refusal without contacting a model.

Align the published schema with supported summary-term groups and validate
the complete catalogue in CI. Record the exact proof and remaining model
and missing-access qualification limits in the customer-journey plan.
2026-09-06 06:04:56 +01:00
pulse-triage[bot] dc2839a050 Merge pull request #1927 from rcourtman/maintainer/20260906T041917Z
Protect alert recovery receipts across gaps and crashes
2026-09-06 05:59:04 +01:00
rcourtman f26668aa6d perf(metrics): reuse retained query plans and output series
Canonical tier reconciliation rebuilt SQL and probed absent preferred tiers
for each fallback point, regressing batch reads and allocation costs. Reuse
bounded query shapes with current bindings and snapshot-scoped absence
checks, then append consecutive points directly to their output series.

Preserve coverage and ordering semantics and verify fresh bindings after
new preferred observations arrive. Integrate current main test additions.
2026-09-06 05:36:19 +01:00
rcourtman 3347f561ec Merge pull request #1920 from rcourtman/fix/retained-history-coverage
fix(ai): preserve canonical evidence through diagnostic workflows
2026-09-06 05:30:17 +01:00
pulse-triage[bot] f2f29ee360 Merge current upstream into alert receipt coverage
The published upstream merge has the same tree as the reviewed batch base; retain the accepted local tip and join the histories without rewriting it.

Change-source: pulse-maintainer
2026-09-06 05:22:01 +01:00
pulse-triage[bot] 6c000837e2 Merge pull request #1926 from rcourtman/maintainer/20260906T030106Z
Protect alert continuity and TrueNAS investigation coverage
2026-09-06 04:52:52 +01:00
pulse-triage[bot] 11e2bd907d test(notifications): verify post-crash webhook event receipts
Extend abrupt-exit resolution coverage through the real notification processor and local HTTP receiver. Assert surviving grouped members and the resolved event, retaining terminal cancellation and dispatch assertions. This does not establish installed provider receipt or exactly-once crash delivery.

Validation: restart/crash tests passed ten race-enabled repetitions; broader receipt/restart selection passed three. Negative control erasing the recovery event fails the HTTP event/member assertion.

Change-source: pulse-maintainer
2026-09-06 04:34:13 +01:00
rcourtman ab9e0e4d3d fix(patrol): align qualification schema with action scenarios
The runtime and three restart scenarios use health_process_stop, but the
published schema rejected it. Accept that implemented injector and check
actual catalogue fault types against the schema to prevent recurrence.

Record the remaining missing-access and storage qualification gaps.
2026-09-06 04:33:20 +01:00
rcourtman f779bf064a Merge current main and verify diagnostic workflows
Integrate the latest alert, delivery and action-result changes with the
Patrol evidence conversation. Replace the conflicted browser receipt
with current source-bound qualification and fix shared warning-card
wrapping exposed by the intermediate-width check.

Real diagnostic and autonomous action outcome qualification stays open.
2026-09-06 04:22:09 +01:00
pulse-triage[bot] 4d87bd37c5 test(monitoring): verify PBS observation-gap webhook receipts
Manager callback tests do not establish notification transport receipt. Exercise real monitor callbacks and the queued generic webhook path through firing, missing metrics, recovery and a distinct renewed breach, protecting against false recovery messages when PBS observations disappear.

Validation: ten focused race-enabled repetitions passed; three paired repetitions with the existing guest recovery transport test passed. Removing the PBS missing-metrics guard makes this test fail on a false recovery webhook. No runtime behaviour changes.
Change-source: pulse-maintainer
2026-09-06 04:11:18 +01:00
pulse-triage[bot] 4902a6271d Merge candidate 20260906T024756Z-core-runtime
Change-source: pulse-maintainer
2026-09-06 03:59:50 +01:00
pulse-triage[bot] df82a783fd Merge remote-tracking branch 'origin/main'
Change-source: pulse-maintainer
2026-09-06 03:59:50 +01:00
rcourtman 61607333cc fix(ai): keep Patrol decisions in one evidence conversation
Remove contextless evaluator and assessment passes, signal-count budgets,
and post-finding prompt replacement. Keep evidence tools available until
explicit run limits and retain incomplete assessments and provider errors
alongside accepted decisions. Failed file reads now preserve error status
through the model, telemetry and saved Assistant history.

Full chat, AI and tools packages, focused Patrol API and race tests pass.
Real read-only and scripted browser checks preserve failed reads and linked
uncertainty. Real-model and verified action outcome qualification remain open.
2026-09-06 03:59:37 +01:00
pulse-triage[bot] 3f74c0c273 Merge pull request #1924 from rcourtman/maintainer/20260906T021146Z
Keep persisted alerts from breaking threshold checks
2026-09-06 03:56:31 +01:00
pulse-triage[bot] 26d0af7a68 test(alerts): cover checkpoint recovery mirror write failures
SQLite remains authoritative when the JSON recovery mirror cannot be renamed. Exercise firing and resolved snapshots across restart so a failed mirror cannot silently lose or resurrect an incident. Close the event store before shutdown to prevent a second checkpoint from masking failure; also verify error reporting and temporary-file cleanup.

Change-source: pulse-maintainer
2026-09-06 03:51:04 +01:00
pulse-triage[bot] 2d63fbc25b test(web): scope TrueNAS incident count to active investigation surface
Run 34005581846 reports duplicate incident-count matches in the main page and mobile investigation sheet. Scope the existing count assertion to the active surface without selecting an arbitrary count match or changing product behaviour. Remove the unused panel locator. Browser requalification remains required; only diff whitespace validation was run locally.

Change-source: pulse-maintainer
2026-09-06 03:47:39 +01:00
pulse-triage[bot] e63704d890 test(alerts): verify PBS capacity callbacks across restart
Missing capacity and a measured empty datastore both report zero usage. Protect the existing distinction across durable manager restarts so missing observations cannot send a false recovery, while genuine recovery and subsequent high usage still dispatch callbacks. Assert incident identity and persisted lifecycle event counts as well as the callback boundary.

Change-source: pulse-maintainer
2026-09-06 03:18:43 +01:00
pulse-triage[bot] b96752a67a chore(integration): reconcile published main
Change-source: pulse-maintainer
2026-09-06 03:15:33 +01:00
pulse-triage[bot] a8ba97497f Merge pull request #1923 from rcourtman/maintainer/20260906T013333Z
Keep alert recovery visible and storage thresholds stable after outages
2026-09-06 03:05:45 +01:00
rcourtman f01db995ed perf(metrics): avoid redundant retained-read work
Execute plain retained reconciliation in one current SQLite snapshot and
reuse bounded compiled statements. Preserve per-series chronology without
a metric sort while keeping display aggregation ordering explicit.

Exact-base worker comparisons cover the prior PR benchmark failures. Full
metrics/database and focused concurrent race checks pass. Final CI and
real diagnostic outcome qualification remain open.
2026-09-06 03:02:59 +01:00
rcourtman 668af3fe6b fix(ai): preserve uncertain investigation conclusions
Tool-call totals do not establish diagnostic sufficiency. Preserve seed-only
and failed-read conclusions, remove count-based completion instructions from
evidence, and retain configured limits and authority checks.

Keep findings grouped under alerts selectable in the shared review panel so
their investigations and access limits remain available to Assistant.
2026-09-06 02:47:55 +01:00
pulse-triage[bot] bb1d177d87 test(alerts): isolate pending threshold fixtures from persisted state
Main CI job 101407611069 failed when the pending-start test restored unrelated active alerts from the shared data directory. A synthetic persisted alert reproduces the same failure locally. Give all three legacy threshold fixtures their own temporary directory and stop their workers during cleanup, retaining every threshold and pending-start assertion.

Validation: seeded-directory focused race tests pass 30 repetitions after failing before the repair. No production alert behaviour changes.
Change-source: pulse-maintainer
2026-09-06 02:46:05 +01:00
pulse-triage[bot] 2614a371ac Merge current upstream main before alert reliability publication
Change-source: pulse-maintainer
2026-09-06 02:36:34 +01:00
pulse-triage[bot] 65c7a7dbc1 Merge pull request #1918 from rcourtman/maintainer/20260905T212144Z
Keep alert delivery and release checks trustworthy
2026-09-06 02:26:53 +01:00
pulse-triage[bot] 32a0d40d2d Merge candidate 20260906T004518Z-web-product
Change-source: pulse-maintainer
2026-09-06 02:03:03 +01:00
pulse-triage[bot] 4270803e8f Merge candidate 20260906T004007Z-core-runtime
Change-source: pulse-maintainer
2026-09-06 01:58:36 +01:00
pulse-triage[bot] d04f368f6f fix(alerts): allow overview health refresh after recovery outage
Retry or Dismiss can succeed while the subsequent health request fails. Offer the existing refresh action when overview health is unavailable so users can verify recovery in place. Two regression cases fail without the fix; 24 focused tests pass with it. API mocks do not qualify installed notification delivery.

Change-source: pulse-maintainer
2026-09-06 01:55:06 +01:00
rcourtman c5d2f56dda fix(ai): preserve diagnostic evidence and proposal boundaries
Keep canonical disk risk, source freshness and retained history intact when
Assistant and Patrol gather evidence. Proposal acceptance validates an action
contract and must not rewrite uncertain conclusions as established root cause.

Preserve complete subscription tool batches without exposing routing envelopes
as answers. Keep wide answer tables readable and keyboard-scrollable on mobile.
Optimize retained tier reconciliation without discarding gaps or newer samples.

Record failed real-model diagnoses and outstanding autonomous qualification
separately from passing data-path and interface checks.
2026-09-06 01:54:28 +01:00
pulse-triage[bot] da5be2db15 fix(alerts): preserve storage override identity during config reload
Retain storage policy aliases in durable metric and forecast metadata and use them during active-alert re-evaluation. Recover exact legacy PBS aliases from the recorded instance and datastore identity. Prevent a configuration reload from fabricating recovery against global defaults after restart.

Change-source: pulse-maintainer
2026-09-06 01:47:11 +01:00
pulse-triage[bot] 4cc53d1095 Merge candidate 20260906T003510Z-web-product
Change-source: pulse-maintainer
2026-09-06 01:42:07 +01:00
pulse-triage[bot] 0641034be5 test(alerts): exercise overview delivery recovery actions
The overview only asserted that recovery buttons were present. Exercise cancellation, failure and deferred action/health completion so regressions cannot silently clear attention or allow conflicting actions while recovery is pending. APIs remain mocked; this does not qualify installed delivery.

Change-source: pulse-maintainer
2026-09-06 01:37:08 +01:00
pulse-triage[bot] 6252023fab test(notifications): preserve recovery receipts through provider outage
Successful ntfy transitions alone do not prove a rejected recovery can be retried after restart. Exercise real HTTP 503/202 responses and SQLite reopen, retaining the firing receipt on failure and clearing it only after recovery succeeds. Assert failed and successful audits remain truthful without replaying the firing notification.

Change-source: pulse-maintainer
2026-09-06 01:31:27 +01:00
pulse-triage[bot] 66de2220ee Merge candidate 20260906T000001Z-core-runtime
Change-source: pulse-maintainer
2026-09-06 01:21:23 +01:00
pulse-triage[bot] 806990af2b test(notifications): verify queued ntfy lifecycle HTTP receipts
Exercise the real queue processor alongside direct delivery for warning, critical, recovery and same-identity refiring. Require HTTP payload/header receipt and committed sent state, using an isolated temporary queue.

Change-source: pulse-maintainer
2026-09-06 01:02:48 +01:00
pulse-triage[bot] 4a68f98602 Merge commit '3413b37940add4305f7b8f16369d37320799073f'
Change-source: pulse-maintainer
2026-09-06 01:01:28 +01:00