Commit Graph

1645 Commits

Author SHA1 Message Date
pulse-triage[bot] 92c3297049 ci: add fixed UUID layout diagnostic without release gate waiver
The exact release tree retains a failed paired UUID benchmark check, while push CI cannot repeat that comparison. Provide a reviewed-source route to collect the requested four-condition hosted layout evidence instead of repeating local samples or changing product order.

Fix source/tree/toolchain identities, isolate diagnostic controls, alternate ten rounds, and retain partial receipts without publishing binaries. Execution still needs separate operator authority; collection success does not dispose of the failed gate. Nine focused harness tests and existing benchmark contract tests pass.

Change-source: pulse-maintainer
2026-09-06 22:11:03 +01:00
pulse-triage[bot] 495562ef66 fix(alerts): ignore superseded delivery diagnosis responses
Overlapping bulk diagnosis refreshes could resolve out of order and replace a current notifications-disabled warning with older dispatch evidence. Version each request, including empty alert sets, so only the newest response updates card diagnoses.

Pin overlap and empty-set invalidation with component and registered hook regressions. All 47 focused tests and TypeScript pass. Isolated Chromium verifies rendered ordering at three widths; update both subsystem contracts and bind browser proof to the runtime bytes. No backend delivery or recipient receipt is claimed.

Change-source: pulse-maintainer
2026-09-06 17:17:36 +01:00
pulse-triage[bot] 64dba483d0 fix(release): bind forward 6.4.4 checkpoint to release train
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.

Change-source: pulse-maintainer
2026-09-06 16:48:17 +01:00
pulse-triage[bot] 9ddee2f8f9 fix(alerts): distinguish dispatch from notification receipt
LastNotified is recorded before delivery callbacks, so the active card cannot use it as evidence of destination success. Name dispatch and cooldown eligibility explicitly while preserving policy and timestamp fallbacks.

Pin the evidence boundary in presentation and Overview regressions, subsystem contracts and an isolated real-browser qualification. Scripted diagnoses verify labels and wrapping, not installed delivery or recipient receipt.

Change-source: pulse-maintainer
2026-09-06 15:12:07 +01:00
pulse-triage[bot] 7475fbf5f4 fix(ci): bind benchmark samples to executed binary hashes
Record executable SHA-256 before measured Go test invocations without logging paths or arguments. Preserve sample ordering and failure status; document instrumentation limits rather than dismissing historical regressions.

Change-source: pulse-maintainer
2026-09-06 13:32:05 +01:00
pulse-triage[bot] 2d36bb7d4d test(assistant): add portable identity browser regression
Release-line could reproduce tool identity and shared evidence regressions but could not replay browser evidence tied to private capture paths. Supply a synthetic standalone real reducer/transcript journey with blocked backend and external requests, desktop and narrow assertions, and content-hashed receipts. This verifies renderer behaviour without claiming provider, production or release admission qualification.

Change-source: pulse-maintainer
2026-09-06 12:29:50 +01:00
pulse-triage[bot] cbfe0d8eac ci: retain exact benchmark collection provenance
PR #1933 failed paired normalization benchmarks despite unchanged hot-path source. Preserve actual checkout identities, selected toolchains and sample order so investigation does not confuse PR head metadata with measured source. Keep thresholds and sample collection unchanged.

Change-source: pulse-maintainer
2026-09-06 11:12:42 +01:00
pulse-triage[bot] c27c8abc77 fix(web): retain current delivery evidence across overlapping reads
Mount and Retry reads can finish out of order, erasing current attempts and held-event evidence or hiding an unavailable result. Assign refresh ownership and ignore abandoned completions after disposal. Ordinary regression tests and six scripted Chromium cases protect ordering and loading state; this does not qualify installed notification delivery.

Change-source: pulse-maintainer
2026-09-06 10:19:46 +01:00
rcourtman f779bf064a Merge current main and verify diagnostic workflows
Integrate the latest alert, delivery and action-result changes with the
Patrol evidence conversation. Replace the conflicted browser receipt
with current source-bound qualification and fix shared warning-card
wrapping exposed by the intermediate-width check.

Real diagnostic and autonomous action outcome qualification stays open.
2026-09-06 04:22:09 +01:00
rcourtman 668af3fe6b fix(ai): preserve uncertain investigation conclusions
Tool-call totals do not establish diagnostic sufficiency. Preserve seed-only
and failed-read conclusions, remove count-based completion instructions from
evidence, and retain configured limits and authority checks.

Keep findings grouped under alerts selectable in the shared review panel so
their investigations and access limits remain available to Assistant.
2026-09-06 02:47:55 +01:00
pulse-triage[bot] d04f368f6f fix(alerts): allow overview health refresh after recovery outage
Retry or Dismiss can succeed while the subsequent health request fails. Offer the existing refresh action when overview health is unavailable so users can verify recovery in place. Two regression cases fail without the fix; 24 focused tests pass with it. API mocks do not qualify installed notification delivery.

Change-source: pulse-maintainer
2026-09-06 01:55:06 +01:00
pulse-triage[bot] 4a68f98602 Merge commit '3413b37940add4305f7b8f16369d37320799073f'
Change-source: pulse-maintainer
2026-09-06 01:01:28 +01:00
pulse-triage[bot] 4051b7d32a Merge commit '9d1b726da9a08797c6adb6330a1d1bac6d763ac7'
Change-source: pulse-maintainer
2026-09-06 01:01:28 +01:00
pulse-triage[bot] 3413b37940 fix(ci): include release trains in build and E2E triggers
PR #1921 targets release/v6.4 but receives only docs and boundary checks because build and E2E triggers still name the historical release branch. Include versioned release trains for push and pull request events without changing job gates or path filters. A focused regression fails all four event/workflow combinations before repair and passes after it.

Change-source: pulse-maintainer
2026-09-06 00:58:57 +01:00
pulse-triage[bot] 9d1b726da9 Fix stale notification health ownership with browser regression proof
Keep overlapping success, failure and loading completion owned by the latest started read. Retain caller and queue-action controls, subsystem contracts and exact-source scripted Chromium evidence. Installed delivery and release qualification remain separate.

Change-source: pulse-maintainer
2026-09-06 00:57:10 +01:00
pulse-triage[bot] aed8b8923a test(release): require exact public Helm package receipt
The exact-byte public package check superseded metadata-only chart inspection, but the broader deployment contract still required the removed command and failed deterministically. Require the consumer-path pull and byte comparison so the contract matches the stronger workflow guarantee.

Change-source: pulse-maintainer
2026-09-06 00:17:44 +01:00
pulse-triage[bot] b5784df4b7 fix(delivery): verify public Helm package against qualified bytes
Readable chart metadata does not prove that the public index serves the OCI-qualified package. Pull through the consumer repository and compare exact bytes before reporting convergence, with offline regression coverage for mismatched, missing and unavailable downloads. Activation and publication authority remain unchanged.

Change-source: pulse-maintainer
2026-09-05 22:24:18 +01:00
pulse-triage[bot] 9c70c2e1ec fix(release): report skipped mutable channel convergence debt
The scheduled reconciler can select a preview retry while silently excluding the mutable stable head. Report that concrete continuity debt in the existing log and job summary, without changing retry eligibility, credential containment or publication authority.

Validated with 37 reconciler and 47 release policy tests. New debt assertions fail against the original code; read-only live discovery reports v6.4.1 debt and preserves preview candidate 33674637446.

Change-source: pulse-maintainer
2026-09-05 21:44:23 +01:00
pulse-triage[bot] 2de83c0e27 Merge Helm publication version binding
Change-source: pulse-maintainer
2026-09-05 21:25:59 +01:00
pulse-triage[bot] 12a3b87529 fix(governance): recognize proven frontend-only reformats
The open publication proposal exposed an earlier additive formatting correction that lacked a Contract-Neutral trailer and therefore could not pass per-commit governance without rewriting reviewed history. Infer neutrality only for immutable commits whose every governed runtime path is byte-for-byte the locked Prettier output of its parent; mixed, unreadable, added, deleted, or non-frontend changes continue to fail closed.

Change-source: pulse-maintainer
2026-09-05 21:21:04 +01:00
pulse-triage[bot] 96bc6f084f fix(release): bind Helm application version to chart release
Reject mismatched image defaults before packaging; preserve equal and default versions. Reproduced four accepted mismatches before the fix. All 58 focused tests pass; no publication performed.

Change-source: pulse-maintainer
2026-09-05 21:13:23 +01:00
pulse-triage[bot] 7c373a5162 fix(release): reject draft Helm chart publication retries
Reproduce draft and unknown publication states reaching the Pages index boundary. Require an explicitly non-draft existing release before uploading, editing or advertising its chart, without implicitly publishing operator drafts.

Exercise the actual publication shell with a fake GitHub CLI and wire its seven retry tests into canonical governance. Existing digest and maturity behaviour remains covered.

Change-source: pulse-maintainer
2026-09-05 20:55:01 +01:00
pulse-triage[bot] ef6e784c2e docs(release): clarify combined continuity incident recovery
Fresh stable readback still shows mutable v6.4.1 alongside orphan v6.4.2. Explain forward supersession without deleting historical tags or treating frontier success as release admission. Cover that distinction with a focused recovery regression; publication authority and all existing gates remain unchanged.

Change-source: pulse-maintainer
2026-09-05 20:12:48 +01:00
pulse-triage[bot] 829be07d3c Merge remote-tracking branch 'origin/main'
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
2026-09-05 20:06:58 +01:00
pulse-triage[bot] b6c8bf6bef test(governance): anchor organisation references to contract content
Reproduce PR #1909 governance failures on the combined lane source. Derive reference positions from named content while retaining explicit section, ownership and verification assertions, so unrelated documentation insertions do not break CI.

Validation: all 163 subsystem lookup tests pass via pulse-heavy-run; both affected tests also pass with two documentation lines inserted in memory. No runtime or release-policy change.
Change-source: pulse-maintainer
2026-09-05 19:39:37 +01:00
rcourtman d223ba0262 Start scoped explanations from Patrol and alert actions
Explain actions previously opened a blank conversation and discarded richer
finding context. Dispatch the selected explanation through shared chat
handling, retain evidence and drafts, and cancel pending work on tenant
switches. Keep unrelated workflow starters out of scoped conversations.

Record the remaining real-model and customer-outcome qualification gap
without treating scripted browser responses as proof of product value.
2026-09-05 19:13:11 +01:00
pulse-triage[bot] 0833e8dc80 test(web): qualify superseded admission and diagnose narrow table access
Close the missing third-organisation and real shell SIGTERM evidence without expanding product scope. Retain measured narrow-table clipping and accessible-name evidence so follow-up repairs preserve Android vertical gesture ownership rather than assuming horizontal scroll access.

Validation: eight Chromium admission cases, two local-backend narrow socket/access runs, real Compose/Playwright SIGTERM cleanup, twelve focused shell tests, and diff checks passed. No installed release or physical-device qualification.
Change-source: pulse-maintainer
2026-09-05 17:57:42 +01:00
pulse-triage[bot] 5617e5bed5 Merge commit '9fdf8059e08a89f82e426330d8131802be3f0298'
Change-source: pulse-maintainer
2026-09-05 17:39:49 +01:00
pulse-triage[bot] 9fdf8059e0 test(web): qualify admission races and reconnect at phone height
Close the unfinished browser evidence gap without extending UI scope. Exercise admission races and subsequent current-organisation reconnect requests, and use 390x844 for populated socket recovery so retained screenshots expose the remaining table clipping rather than implying mobile layout acceptance.

Change-source: pulse-maintainer
2026-09-05 17:35:14 +01:00
pulse-triage[bot] 6998908d2a fix(release): limit asset validation readiness claims
Downstream release-note syndication repeats the asset check banner even when installed health or release convergence is not qualified. Report asset checks only and state the remaining evidence boundaries for both draft and post-publication banners.

Change-source: pulse-maintainer
2026-09-05 17:30:49 +01:00
pulse-triage[bot] a41e35f296 test(release): reject signatures outside the configured trust boundary
Exercise real SSH signatures from an untrusted key and the trusted key under an unrelated namespace, for both manifest and installer. Keep checksum content valid so these regressions specifically protect signature trust selection.

Change-source: pulse-maintainer
2026-09-05 17:17:54 +01:00
pulse-triage[bot] 4f61c581b9 fix(release): expose reconciliation decisions in run summaries
The successful scheduled reconciliation at run 33972475922 retained a credential-containment hold and dispatched no retry. Put safe decision messages in the Actions summary so a green reconciler is not mistaken for delivered releases. Narrow empty-discovery wording because mutable channels and missing runs are not qualified. Preserve containment, retry budgets and dispatch behaviour; cover summary output and empty discovery with focused tests.

Change-source: pulse-maintainer
2026-09-05 16:23:47 +01:00
pulse-triage[bot] bf6121e41d fix(release): reject ambiguous activation asset inventories
Count all activation marker names before validating their metadata so a malformed duplicate cannot pass the immutable packet boundary. Reproduced acceptance with a valid uploaded marker plus a zero-size pending duplicate; both valid and malformed duplicates now fail before attestation or download.

Validation: 13 focused integrity tests and 46 promotion policy tests pass; bash syntax and git diff checks pass. No publication or deployment performed.
Change-source: pulse-maintainer
2026-09-05 15:43:23 +01:00
pulse-triage[bot] 280e73e1f2 test(delivery): bind recovery receipts to successful submissions
Exercise all three reconciliation recovery paths through the mocked transport for accepted and rejected POSTs. Assert rejected submissions raise without emitting a success receipt.

Validation: 30 reconciliation tests and 46 release promotion policy tests pass. No remote mutations performed.

Change-source: pulse-maintainer
2026-09-05 15:12:05 +01:00
pulse-triage[bot] 2d979682fd fix(delivery): preserve convergence receipt policy checks
The dry-run receipt repair made submitted messages dynamic, hiding the literal
pre-commit renewal contract from canonical governance. Keep submitted and
non-mutating output distinct while spelling each receipt explicitly so the
existing release-policy guard continues to verify the recovery handoff.

Validation: 29 reconciliation tests and 46 release promotion policy tests
pass, including the check that failed on pull request 1904.

Change-source: pulse-maintainer
2026-09-05 15:08:14 +01:00
pulse-triage[bot] 9a837b8b40 fix(web): discard superseded organisation admission responses
An outgoing admission refresh could restore platform navigation after an organisation switch. Accept only the latest request response, including when a newer request fails or is still pending. Preserve authoritative successful empty admission and subsequent navigation recovery.

Reproduced at 390px and 1440px; six repaired synthetic full-app browser cases and 59 focused tests pass. Typecheck passes. This does not qualify backend isolation, a released artifact or external alert delivery.

Change-source: pulse-maintainer
Contract-Neutral: Restore existing latest-organisation admission semantics only; no API, entitlement, navigation surface or subsystem contract changes. Focused ordering regressions and desktop/narrow browser proof cover the repair.
2026-09-05 10:33:40 +01:00
pulse-triage[bot] 6ecee4b4c4 fix(delivery): distinguish dry-run proposals from submitted retries
A read-only reconciliation of current release debt printed Dispatched despite suppressing the POST. Return submission status from the transport and qualify all three mutation receipts. Preserve retry and containment policy unchanged.

Verified 29 reconciliation and 41 workflow-trust tests; new dry-run regression rejects all three baseline paths. Live --latest --dry-run now reports Would dispatch without mutation.

Change-source: pulse-maintainer
2026-09-05 10:20:38 +01:00
pulse-triage[bot] 5add9bfc36 fix(ci): permit audited caller-only permission inheritance
The stable-install smoke body is intentionally workflow_call-only so its read-only continuity caller and draft-capable release caller can supply different explicit token budgets. Treat that exact no-override shape as an auditable permission boundary while continuing to reject independent triggers and job permission overrides.

Validation: 41 workflow-trust tests, repository workflow audit, focused install-smoke contract tests, Python compilation and diff checks pass.

Change-source: pulse-maintainer
2026-09-05 09:06:17 +01:00
pulse-triage[bot] ec462ad964 fix(release): inspect convergence logs through safe Actions reader
Scheduled reconciliation fails when gh api refuses ANSI-bearing Actions logs. Use the dedicated sanitising log reader without disabling terminal protection, preserving private authentication and fail-closed evidence handling. Focused reconciliation and policy tests pass; a read-only live job probe retains failure evidence without ESC bytes.

Change-source: pulse-maintainer
2026-09-05 04:32:38 +01:00
pulse-triage[bot] fb9e4335e1 fix(ci): keep stable install smoke within caller permissions
Stable continuity run 33592377446 was rejected before any job ran: its read-only caller invoked a reusable job requesting contents:write. Extract the unchanged smoke execution into a body that inherits the caller budget, keeping the existing draft-capable entry point and its write-level draft GET access. Continuity now calls the shared body directly without broadening its token. Pin the permission boundary in regression coverage; do not relax immutable-release admission.

Change-source: pulse-maintainer
2026-09-05 04:02:24 +01:00
pulse-triage[bot] 8433ea426c Merge web application refresh qualification
Change-source: pulse-maintainer
2026-09-05 02:13:05 +01:00
pulse-triage[bot] abff834d80 test(web): qualify backup refresh through application boundaries
The isolated Coverage fixture cannot establish whether resource-provider and WebSocket replacement preserves application interaction in issue #1869. Exercise the actual shell, scoped paginated resources, windowed Coverage and By date, and the real PBS History drawer with synthetic snapshots. Retain desktop and narrow evidence without claiming a deployed-release or Brave fix.

Change-source: pulse-maintainer
2026-09-05 01:55:54 +01:00
pulse-triage[bot] 7db3192a3f fix(release): measure candidate soak from release publication
Git tag creation can precede candidate publication, allowing stable promotion before the required observation period. Read the exact published prerelease and fail closed when publication evidence is unavailable. Cover repaired-candidate minor and patch boundaries.

Change-source: pulse-maintainer
2026-09-05 01:47:12 +01:00
pulse-triage[bot] ac8172c42c Preserve backup coverage row focus across polling snapshots
Reconcile coverage rows by logical keys before windowing. Isolated Chromium checks at desktop and narrow widths preserve keyboard focus, expanded evidence, route and scroll across replacement HTTP snapshots. Include subsystem completion obligations and a content-bound browser receipt.

Does not qualify the full application scroll-jump report in #1869 or reporter resolution.

Change-source: pulse-maintainer
2026-09-05 01:33:47 +01:00
pulse-triage[bot] 19c2b6a925 Fix portable root ownership for installer lifecycle state
Issue #1890 reports macOS agent updates stopping because the root group does not exist. Use numeric superuser ownership in the two shared lifecycle writes without relaxing failure handling or the least-privilege group boundary. Add a regression fixture that rejects named root ownership and checks that chown failures still prevent replacement.

Change-source: pulse-maintainer
2026-09-04 22:33:08 +01:00
pulse-triage[bot] 26309d71a0 Restore release contract assertions after merges
Reapply the reviewed Go 1.26.8, OCI Helm recovery, and non-login-shell test expectations that later upstream merges accidentally replaced while retaining the corresponding implementations.

Contract-Neutral: test-only reconciliation; no product or runtime behavior changed

Change-source: pulse-maintainer
2026-09-04 20:39:02 +01:00
pulse-triage[bot] 09da37881f Check release inventory independently of Git refs
A published release packet is a customer-visible surface in its own right. Deriving newer published versions only from matching Git refs lets that surface escape continuity validation when the corresponding ref is absent. Evaluate every stable-shaped release record independently and pin the detached-ref case with a regression test.

Change-source: pulse-maintainer
2026-09-04 15:01:51 +01:00
pulse-triage[bot] 485e19600f Align npm audit contracts after upstream merge
Update the retained canonical Python contract for the upstream wall-clock timeout mechanism and the single complete per-PR audit, while preserving the two-view scheduled audit expectations.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-04 14:31:31 +01:00
pulse-triage[bot] d170a23d22 Merge commit 'd7356ef76e26cd461278de18cd471d7cb2682043'
Change-source: pulse-maintainer
2026-09-04 14:29:39 +01:00
pulse-triage[bot] e46e897702 Merge remote-tracking branch 'origin/main'
# Conflicts:
#	.github/workflows/build-and-test.yml
#	docs/release-control/v6/internal/subsystems/deployment-installability.md
#	scripts/installtests/build_release_assets_test.go
#	scripts/npm-audit-retry.sh

Change-source: pulse-maintainer
2026-09-04 14:29:31 +01:00