Retry or Dismiss can succeed while the subsequent health request fails. Offer the existing refresh action when overview health is unavailable so users can verify recovery in place. Two regression cases fail without the fix; 24 focused tests pass with it. API mocks do not qualify installed notification delivery.
Change-source: pulse-maintainer
PR #1921 targets release/v6.4 but receives only docs and boundary checks because build and E2E triggers still name the historical release branch. Include versioned release trains for push and pull request events without changing job gates or path filters. A focused regression fails all four event/workflow combinations before repair and passes after it.
Change-source: pulse-maintainer
Keep overlapping success, failure and loading completion owned by the latest started read. Retain caller and queue-action controls, subsystem contracts and exact-source scripted Chromium evidence. Installed delivery and release qualification remain separate.
Change-source: pulse-maintainer
Distinguish policy skips from provider success so suppressed jobs do not create false sent rows or successful audit entries. Reconcile cancelled queue health after releasing alert gates, preserve real attempt history, and cover all three providers for firing/recovery and global/destination disablement.
Change-source: pulse-maintainer
Preserve the reviewed notification retry finality fix and its exact ancestry after incorporating the batch-start upstream main.
Change-source: pulse-maintainer
Resolution only cancelled pending/sending rows, so retained failures could resurrect healthy incidents after operator retry and restart. Suppress terminal firing entries too, preserve unrelated grouped alerts and recovery jobs, and reconcile queue health after releasing locks. Reject stale per-item retries of cancelled or delivered rows. Regression tests reproduce both bypasses and retain failed-attempt history; focused race tests pass.
Change-source: pulse-maintainer
Incorporate the landed Patrol evidence-trust repair while preserving reviewed publication tip 6d6a776ef5 unchanged in ancestry.
Change-source: pulse-maintainer
A provider policy refusal was classified as a connection failure, while
summary tools mixed high-utilisation heuristics with unchecked health claims.
Preserve explicit refusals before tool recovery and provide retained metrics
with source scope, observation timestamps and bucket extrema for diagnosis.
Record the live qualification limits and the shared temporal tier-query gap.
Replacement identity alone could confirm an unhealthy or restarting container when no independent observer was available. Check agent-reported running state and health, retaining inconclusive truth for unknown health and preserving intentionally stopped updates. Seven regression cases cover these distinctions; the four unsafe cases failed before the repair. Execution and compensation history are unchanged.
Change-source: pulse-maintainer
Readable chart metadata does not prove that the public index serves the OCI-qualified package. Pull through the consumer repository and compare exact bytes before reporting convergence, with offline regression coverage for mismatched, missing and unavailable downloads. Activation and publication authority remain unchanged.
Change-source: pulse-maintainer
Independent update verification must match the replacement's reported state and reject unhealthy running observations, not just match container identity. Preserve intentionally stopped replacements and keep missing agent readback inconclusive. Reproduced stopped, restarting and unhealthy false confirmations before the fix; 19 focused API tests and three lifecycle replay tests pass. This does not establish the root cause of issue #1891.
Change-source: pulse-maintainer
Real homelab investigations lost metrics behind mismatched resource IDs,
queried only post-restart memory, and filtered every physical disk out.
Resolve canonical metrics targets, use retained history, preserve CPU
topology and chronological samples, and separate disk operation and format.
Keep unattached resource shortcuts blocked while allowing named resources
to be resolved through query search. Report incomplete readiness honestly,
including saved evaluations, without granting Patrol suitability.
Reject mismatched image defaults before packaging; preserve equal and default versions. Reproduced four accepted mismatches before the fix. All 58 focused tests pass; no publication performed.
Change-source: pulse-maintainer
Reproduce draft and unknown publication states reaching the Pages index boundary. Require an explicitly non-draft existing release before uploading, editing or advertising its chart, without implicitly publishing operator drafts.
Exercise the actual publication shell with a fake GitHub CLI and wire its seven retry tests into canonical governance. Existing digest and maturity behaviour remains covered.
Change-source: pulse-maintainer
Real homelab evaluation exposed missing node sensor observations and loss of
recent tool evidence before the model reached its conclusion. Project both
canonical sensor sources and retain observations while context fits.
Add source and selection regressions plus a multi-turn retention proof.
Record the live diagnosis result and the unresolved Patrol provider block.
A zero usage observation was skipped even when positive total capacity, zero used bytes and matching free bytes confirmed an empty store. Allow that consistent observation through the existing capacity lifecycle without treating absent counters or offline storage as recovery.
Reproduced the retained incident before the fix. Added six lifecycle cases and a local production-callback/webhook test for missing capacity, correlated zero recovery, history and duplicate avoidance. Focused storage/capacity tests, repeated webhook tests and race-enabled storage/PBS lifecycle checks pass. This is not installed-artifact qualification.
Change-source: pulse-maintainer
New-finding telemetry lost older activity once the run history reached its
100-entry cap. Persist a bounded daily finding tally with a separate
upgrade cursor, preserving run counts while backfilling retained findings.
Cover restart, repeated saves, upgrade, read failure and UTC-day retention.
Record the measurement boundary and retire the resolved coverage gap.
Receiver-level PBS lifecycle checks reproduced resolved payloads retaining 50% firing usage after measurements fell to 9.765625% or zero. Clone and refresh the canonical metric snapshot before recording recovery so resolved callbacks and recent history carry the clearing value, message and observation time without changing incident identity.
Validated both PBS cases with three repeated integration runs and a race-enabled run, plus focused canonical metric, history, missing telemetry, resolved notification, receipt and queue restart tests. This is local synthetic receiver proof, not installed or off-host qualification.
Change-source: pulse-maintainer
Explain actions previously opened a blank conversation and discarded richer
finding context. Dispatch the selected explanation through shared chat
handling, retain evidence and drafts, and cancel pending work on tenant
switches. Keep unrelated workflow starters out of scoped conversations.
Record the remaining real-model and customer-outcome qualification gap
without treating scripted browser responses as proof of product value.
Chromium receipts showed that the phone table clipped update badges without any horizontal path to recover the text. Wrap existing labels within reduced cell padding and allow expanded drawer names to wrap, preserving Android page-owned scrolling and existing action semantics. Add real text-bound and heading assertions and retain six passing reconnect cases plus inspected synthetic screenshots.
Change-source: pulse-maintainer
Reproduced a false resolved webhook when HTTP-success status contained memory total but omitted used. Require present CPU and memory measurements before marking node metrics available, retaining genuine zero and unrelated-field compatibility. Extend client and real-poller webhook regression coverage and monitoring contract.
Change-source: pulse-maintainer
A successful response containing null or omitted data decoded into zero-valued node metrics. Repeated polls could therefore clear an active memory incident without any usable recovery evidence. Decode the status through a pointer and reject absent data so existing unavailable-metric handling preserves the incident.
Reproduced the failure through the real poller and notification queue with a local webhook. Added absent-envelope client cases and extended lifecycle coverage to assert unavailable metrics, stable incident identity, and genuine recovery. Focused client and monitoring tests pass three repetitions under the race detector; this is not installed or off-host qualification.
Change-source: pulse-maintainer
Downstream release-note syndication repeats the asset check banner even when installed health or release convergence is not qualified. Report asset checks only and state the remaining evidence boundaries for both draft and post-publication banners.
Change-source: pulse-maintainer
Shell-only signal traps could leave browser descendants writing sensitive state after cleanup, and simultaneous runs shared the same cookie cache. Give the Linux qualification runner an invocation-owned cookie root and a child-subreaper supervisor so catchable interruption waits for writers before removing owned artifacts. Preserve normal reports for inspection and fail closed if writers cannot be reaped. Focused fixtures cover all three signals, late detached writers, concurrent isolation and forced termination; no real-browser cleanup or release readiness is claimed.
Change-source: pulse-maintainer
A reachable PBS can deny or fail its node-status endpoint while datastore collection succeeds. The resulting zero values previously resolved active CPU and memory alerts without a healthy measurement. Carry internal availability evidence from polling and skip metric evaluation for those samples, preserving independent connectivity and policy suppression. Add failing-before unit coverage and an HTTP polling lifecycle regression for dispatch and recent recovery history.
Change-source: pulse-maintainer
Scoped local sessions correctly lose privileged security-status fields, but Settings relied on the configured admin username and hid owner controls. Expose the validated current principal without broadening capabilities, and use it for organisation identity.
Include the API and dependent subsystem contracts, recognised payload and settings-shell tests, and a source-bound desktop/narrow browser receipt in this commit. Fresh matrices each pass six scenarios with one expected disabled-feature skip. Admission/reconnect and interruption cleanup remain separate unfinished qualification.
Change-source: pulse-maintainer
Count all activation marker names before validating their metadata so a malformed duplicate cannot pass the immutable packet boundary. Reproduced acceptance with a valid uploaded marker plus a zero-size pending duplicate; both valid and malformed duplicates now fail before attestation or download.
Validation: 13 focused integrity tests and 46 promotion policy tests pass; bash syntax and git diff checks pass. No publication or deployment performed.
Change-source: pulse-maintainer
A gateway body quoting API error 403 must not discard cached backups. Use the client's typed response status before legacy text fallback; cover gateway failures and genuine terminal responses.
Change-source: pulse-maintainer
Reproduced the restricted primary token being refused after organisation reload. Keep token isolation intact and exercise the sharing flow with a cookie session, with explicit authentication preconditions.
The diagnostic still fails on missing acceptance controls; retain that failure, quarantine and exact runtime receipts. Record process-group TERM cleanup limits rather than claiming complete artifact cleanup.
Change-source: pulse-maintainer
The shell multi-tenant suite previously selected a spec ignored by every project, preventing real backend diagnosis. Add an explicit desktop-only configuration that rejects tier identity, while retaining the normal quarantine. Cover discovery and tier refusal and document the evidence boundaries. A local source-built diagnostic returned five passes, one failure at organisation-switch login, and one skip; this is not release qualification.
Change-source: pulse-maintainer
Incorporate the upstream main frontier recorded before this coordination batch while retaining the reviewed runner-isolation commit unchanged.
Change-source: pulse-maintainer
Withdraw the imposed minor-release calendar following clarified founder
intent. Preserve exact-candidate and clean-soak requirements while leaving
scope, version, maturity and timing to evidence-informed judgment.
Keep required backend matrix check names present on documentation-only
changes so policy updates can land without weakening branch protection.
Contract-Neutral: Backend CI check reporting only. The shard test commands,
dependency security proof and deployment contracts are unchanged.
Installed PBS qualification must distinguish accurate metric history from API load and persistence write traffic. File growth and whole-device counters alone cannot attribute write cost to Pulse, so an unqualified measurement could lead to incorrect regression or wear claims.
Document matched baseline and repaired measurement windows, counter limitations and backup I/O separation without changing runtime behaviour or claiming installed recovery.
Validation: git diff --check passed; documentation-only change. Installed artifact qualification remains dependent on an authorised environment.
Change-source: pulse-maintainer
Aggregate historical row counts across unlike resources do not establish whether the integrated PBS source-time repair works on an installed artifact. Release qualification needs common observation windows and independent source timestamps to distinguish valid unchanged-value samples from restamped cached data.
Document an operator-run check covering mixed polling, outage, recovery and whole-process restart, with exact artifact identity and per-metric SQL measurements. This provides acceptance criteria, not installed proof or grounds to close#1882.
Validation: documented SQL previously exercised against synthetic SQLite healthy-cadence, duplicate-identity and empty-window cases; git diff --check passes. Documentation only; no production behaviour changed.
Change-source: pulse-maintainer
A reproduced admission HTTP 503 after socket recovery removed platform destinations despite populated inventory. Retain the last valid facet on request failure, keep tenant resets and successful empty responses authoritative, and cover desktop/mobile interruption and recovery.
Change-source: pulse-maintainer