Add a disposable service-storage fault with an independent filesystem
oracle, bounded tmpfs writes, identity checks and verified recovery.
Exercise overwrite and symlink refusal without contacting a model.
Align the published schema with supported summary-term groups and validate
the complete catalogue in CI. Record the exact proof and remaining model
and missing-access qualification limits in the customer-journey plan.
The runtime and three restart scenarios use health_process_stop, but the
published schema rejected it. Accept that implemented injector and check
actual catalogue fault types against the schema to prevent recurrence.
Record the remaining missing-access and storage qualification gaps.
Preserve original failed-run JUnit bytes in deterministic gzip archives while normalising trailing CDATA whitespace in reviewable XML. Bind the passing source-build results, invocation flags and table-access attachments without changing tests or implying installed delivery qualification.
Change-source: pulse-maintainer
The retained JUnit cannot establish that opt-in table assertions ran, and the repeat command omitted their flag. Make the repeat complete and distinguish navigation recovery from changed-data recovery so this receipt is not over-weighted in release decisions.
Change-source: pulse-maintainer
The combined mainline recovery and narrow-screen repairs need independent integrated evidence after recent merges. Retain eight passing isolated Chromium results and representative screenshots, with explicit limits so source-only navigation success is not mistaken for candidate or notification-delivery qualification.
Change-source: pulse-maintainer
Record the successful eight-case Chromium rerun and bounded visual inspection
performed on the exact merged test tree. Preserve the known narrow-layout
limitations and avoid upgrading the formal browser or release claims.
Change-source: pulse-maintainer
Existing phone receipts cover 390px, whereas reflow guidance includes 320px cell content. Extend the opt-in navigation and text-bound checks without changing product behaviour. Preserve the stronger single-line label requirement at 390px while allowing wrapping at 320px. Record the initial one-pass/one-failure diagnostic and the cancelled queued final rerun explicitly; final test revision remains browser-unqualified.
Change-source: pulse-maintainer
Chromium receipts showed that the phone table clipped update badges without any horizontal path to recover the text. Wrap existing labels within reduced cell padding and allow expanded drawer names to wrap, preserving Android page-owned scrolling and existing action semantics. Add real text-bound and heading assertions and retain six passing reconnect cases plus inspected synthetic screenshots.
Change-source: pulse-maintainer
Close the missing third-organisation and real shell SIGTERM evidence without expanding product scope. Retain measured narrow-table clipping and accessible-name evidence so follow-up repairs preserve Android vertical gesture ownership rather than assuming horizontal scroll access.
Validation: eight Chromium admission cases, two local-backend narrow socket/access runs, real Compose/Playwright SIGTERM cleanup, twelve focused shell tests, and diff checks passed. No installed release or physical-device qualification.
Change-source: pulse-maintainer
Close the unfinished browser evidence gap without extending UI scope. Exercise admission races and subsequent current-organisation reconnect requests, and use 390x844 for populated socket recovery so retained screenshots expose the remaining table clipping rather than implying mobile layout acceptance.
Change-source: pulse-maintainer
Process fixtures did not prove that browser-generated artefacts finish before supervisor cleanup. Exercise real Chromium late cookie, screenshot, trace and video writers for all three catchable signals, while keeping full-stack qualification limits explicit.
Change-source: pulse-maintainer
Shell-only signal traps could leave browser descendants writing sensitive state after cleanup, and simultaneous runs shared the same cookie cache. Give the Linux qualification runner an invocation-owned cookie root and a child-subreaper supervisor so catchable interruption waits for writers before removing owned artifacts. Preserve normal reports for inspection and fail closed if writers cannot be reaped. Focused fixtures cover all three signals, late detached writers, concurrent isolation and forced termination; no real-browser cleanup or release readiness is claimed.
Change-source: pulse-maintainer
Scoped local sessions correctly lose privileged security-status fields, but Settings relied on the configured admin username and hid owner controls. Expose the validated current principal without broadening capabilities, and use it for organisation identity.
Include the API and dependent subsystem contracts, recognised payload and settings-shell tests, and a source-bound desktop/narrow browser receipt in this commit. Fresh matrices each pass six scenarios with one expected disabled-feature skip. Admission/reconnect and interruption cleanup remain separate unfinished qualification.
Change-source: pulse-maintainer
Reproduced the restricted primary token being refused after organisation reload. Keep token isolation intact and exercise the sharing flow with a cookie session, with explicit authentication preconditions.
The diagnostic still fails on missing acceptance controls; retain that failure, quarantine and exact runtime receipts. Record process-group TERM cleanup limits rather than claiming complete artifact cleanup.
Change-source: pulse-maintainer
Concurrent qualification runs could overwrite shared browser artifacts and authentication state, while an inherited PLAYWRIGHT_BASE_URL could send browser traffic outside the shell-owned stack. Scope outputs and fixture credentials to each invocation and clear that endpoint override so isolation evidence refers to the intended stack.
Focused runner checks cover inherited overrides and cleanup. Recorded concurrent Docker diagnostics reached healthy stacks but browser execution remained blocked by the existing multi-tenant quarantine; this test-only repair does not claim browser or release qualification and changes no user-visible application surface.
Change-source: pulse-maintainer
An outgoing admission refresh could restore platform navigation after an organisation switch. Accept only the latest request response, including when a newer request fails or is still pending. Preserve authoritative successful empty admission and subsequent navigation recovery.
Reproduced at 390px and 1440px; six repaired synthetic full-app browser cases and 59 focused tests pass. Typecheck passes. This does not qualify backend isolation, a released artifact or external alert delivery.
Change-source: pulse-maintainer
Contract-Neutral: Restore existing latest-organisation admission semantics only; no API, entitlement, navigation surface or subsystem contract changes. Focused ordering regressions and desktop/narrow browser proof cover the repair.
A reproduced admission HTTP 503 after socket recovery removed platform destinations despite populated inventory. Retain the last valid facet on request failure, keep tenant resets and successful empty responses authoritative, and cover desktop/mobile interruption and recovery.
Change-source: pulse-maintainer
Keep resource snapshot receipt separate from alert hydration and tenant-scoped across reconnect. Include matching subsystem contracts, architecture coverage and fresh browser receipt.
Validation: 87 focused tests and three real-backend Chromium checks pass at 1440, 1100 and 390px. Exact release-candidate qualification remains outstanding.
Change-source: pulse-maintainer
The integrated removed-row focus repair had only jsdom coverage. Exercise populated Timeline and Resource dialogs with production styles in two browser engines so focus trapping, dismissal and fallback regressions are observable without live credentials or customer data. This is synthetic component qualification, not backend delivery evidence.
Change-source: pulse-maintainer