Mount and Retry reads can finish out of order, erasing current attempts and held-event evidence or hiding an unavailable result. Assign refresh ownership and ignore abandoned completions after disposal. Ordinary regression tests and six scripted Chromium cases protect ordering and loading state; this does not qualify installed notification delivery.
Change-source: pulse-maintainer
Record reproduced restart gaps and legacy provenance ambiguity; do not enable destructive cleanup.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Symmetric bridge fixtures can pass when one address inventory loses its filter. Exercise repeated ingestion with one-sided Docker bridges and valid custom management bridges, checking both link directions. Mutation checks reject loss of either filter and the earlier broad bridge exclusion.
Change-source: pulse-maintainer
Limit automatic Docker bridge filtering to the generated br-<12 hex> convention so custom management bridges such as br-mgmt remain eligible for host association. Keep docker-prefixed and non-global-unicast exclusions intact.
Change-source: pulse-maintainer
Mount and retry reads can overlap and overwrite newer delivery evidence. Preserve three explicit expected-failure invariants so the pending repair has deterministic reproduction, plus proof that held events do not delay the primary read. Mock held-event requests rather than leaking network calls from hook tests.
Contract-Neutral: tests only; no runtime or user-visible behaviour changed
Change-source: pulse-maintainer
A Docker bridge or link-local address can be unique among monitored PVE nodes but also exist on an unrelated NAS. Counting PVE owners alone then creates a false reciprocal agent association. Exclude host-local IPs and known Docker bridge interfaces from automatic network evidence, preserving management bridges and explicit unicast report IPs.
Seven synthetic negative cases fail before this repair and pass afterwards. Focused matcher and host-report tests pass under the race detector. This prevents a reproduced backend misassociation; it does not establish the cause or resolution of issue #1930, whose diagnostic payload remains unavailable.
Change-source: pulse-maintainer
Integrate the reviewed Proxmox inventory membership boundary test after the batch-boundary upstream merge while preserving candidate ancestry.
Change-source: pulse-maintainer
Preserve the reviewed alert and TrueNAS work while incorporating the canonical API metrics optimization and patrol qualification record.
Change-source: pulse-maintainer
Issue #1930 shows a NAS with a PVE cluster label but supplies no resource payload. Verify that shared identity labels do not promote a generic host into the PVE model, while a genuine node with no version remains visible. This synthetic boundary test does not reproduce or resolve the reported incident.
Contract-Neutral: Tests only; preserves existing platform membership semantics.
Change-source: pulse-maintainer
Use the normalized connectivity status consistently when deciding whether storage capacity is actionable, preserving the existing offline suppression rule for case and whitespace variants.
Change-source: pulse-maintainer
Do not count empty or unknown storage status as recovery evidence. Normalise status spelling for connectivity checks while leaving capacity evaluation independent and preserving existing inactive/disabled storage behaviour.
Change-source: pulse-maintainer
Route labels classify ASCII digits and hexadecimal UUID bytes. Scan those
bytes directly while preserving numeric precedence, Unicode names and
invalid UTF-8 handling. This reduces the shared normaliser overhead exposed
by paired landing benchmarks without changing the benchmark gate.
Refs #1928
Contract-Neutral: ASCII route-label optimization preserves label values, identifier precedence, Unicode and invalid UTF-8 behavior, and agent lifecycle authority.
The setup fixtures omitted the owner identity required by supported API-key authentication, so they stopped at local validation rather than exercising test, preview, save and capacity denial. Supply the owner and assert it reaches test and create payloads; retain a browser assertion that a missing owner sends no test request.
Validation: reproduced both original Chromium failures and inspected the missing-owner screenshot; corrected spec passes 3/3 with no retries using pulse-heavy-run. Focused TrueNAS state tests pass 36/36 and E2E tier selection passes. No runtime or tier changes.
Change-source: pulse-maintainer
Existing HTTP receipt coverage exercised uninterrupted operation while restart coverage ended at internal callbacks. Recreate both disk-backed managers during a missing-observation incident and after recovery to verify local transport delivery, incident identity, retained history and recurrence together. This does not qualify an installed binary or external provider.
Change-source: pulse-maintainer
Preserve the real Assistant result separately from passing access routing
and disposable fault oracles. Correct tool evidence still produced
unsupported temporal claims, so customer outcome readiness remains open.
Refs #1928
Validate the checked-in dependency and three service restart fault contracts
against disposable Docker resources before using them to assess model output.
Verify baseline, injected fault, refused duplicate injection, explicit fixture
recovery, and two-pass cleanup with unchanged pre-existing inventory.
These opt-in tests make no Pulse or model request. Fixture recovery is teardown
and does not count as an approval, rejection, execution or customer outcome.
Record exact live, owning-package and source-bound proof in the redesign plan.
Resolve monitored topology before checking command connections so unavailable
inspection retains the known resource and parent node. Prevent known targets
from falling through to a colliding agent ID, and preserve the single-agent
requirement when no target is supplied.
Use one failed tool envelope for diagnostic reads and file mutations. Missing
connections neither prove an installation problem nor count as successful
writes. Hypervisor lifecycle authority remains on its canonical action path.
Verify disconnected and unknown targets, collision isolation, all affected
tool handlers, token/WebSocket scope boundaries, and the linked Patrol and
Assistant failure journey at desktop and narrow widths.
The 500-node dashboard query triggered repeated ordinal string conversions
in the SQLite driver while matching numbered parameters. Use alphabetic
named bindings to preserve current values and shared query branches without
that allocation cost.
Cover large cached scopes with changed resource families, identities,
metric filters and windows, including IDs that resemble SQL syntax.
Refs #1928
A completed probe remained discoverable after its first caller returned,
allowing the next collection to reuse stale filesystem measurements.
Remove it and publish completion within one registry critical section.
Keep in-flight sharing, cancellation and timeout behaviour intact.
The controlled regression fails before this change. Twenty full package
runs and three race runs pass on the worker.
Refs #1928
Add a disposable service-storage fault with an independent filesystem
oracle, bounded tmpfs writes, identity checks and verified recovery.
Exercise overwrite and symlink refusal without contacting a model.
Align the published schema with supported summary-term groups and validate
the complete catalogue in CI. Record the exact proof and remaining model
and missing-access qualification limits in the customer-journey plan.
Canonical tier reconciliation rebuilt SQL and probed absent preferred tiers
for each fallback point, regressing batch reads and allocation costs. Reuse
bounded query shapes with current bindings and snapshot-scoped absence
checks, then append consecutive points directly to their output series.
Preserve coverage and ordering semantics and verify fresh bindings after
new preferred observations arrive. Integrate current main test additions.
The published upstream merge has the same tree as the reviewed batch base; retain the accepted local tip and join the histories without rewriting it.
Change-source: pulse-maintainer
Extend abrupt-exit resolution coverage through the real notification processor and local HTTP receiver. Assert surviving grouped members and the resolved event, retaining terminal cancellation and dispatch assertions. This does not establish installed provider receipt or exactly-once crash delivery.
Validation: restart/crash tests passed ten race-enabled repetitions; broader receipt/restart selection passed three. Negative control erasing the recovery event fails the HTTP event/member assertion.
Change-source: pulse-maintainer
The runtime and three restart scenarios use health_process_stop, but the
published schema rejected it. Accept that implemented injector and check
actual catalogue fault types against the schema to prevent recurrence.
Record the remaining missing-access and storage qualification gaps.
Integrate the latest alert, delivery and action-result changes with the
Patrol evidence conversation. Replace the conflicted browser receipt
with current source-bound qualification and fix shared warning-card
wrapping exposed by the intermediate-width check.
Real diagnostic and autonomous action outcome qualification stays open.
Manager callback tests do not establish notification transport receipt. Exercise real monitor callbacks and the queued generic webhook path through firing, missing metrics, recovery and a distinct renewed breach, protecting against false recovery messages when PBS observations disappear.
Validation: ten focused race-enabled repetitions passed; three paired repetitions with the existing guest recovery transport test passed. Removing the PBS missing-metrics guard makes this test fail on a false recovery webhook. No runtime behaviour changes.
Change-source: pulse-maintainer
Remove contextless evaluator and assessment passes, signal-count budgets,
and post-finding prompt replacement. Keep evidence tools available until
explicit run limits and retain incomplete assessments and provider errors
alongside accepted decisions. Failed file reads now preserve error status
through the model, telemetry and saved Assistant history.
Full chat, AI and tools packages, focused Patrol API and race tests pass.
Real read-only and scripted browser checks preserve failed reads and linked
uncertainty. Real-model and verified action outcome qualification remain open.
SQLite remains authoritative when the JSON recovery mirror cannot be renamed. Exercise firing and resolved snapshots across restart so a failed mirror cannot silently lose or resurrect an incident. Close the event store before shutdown to prevent a second checkpoint from masking failure; also verify error reporting and temporary-file cleanup.
Change-source: pulse-maintainer
Run 34005581846 reports duplicate incident-count matches in the main page and mobile investigation sheet. Scope the existing count assertion to the active surface without selecting an arbitrary count match or changing product behaviour. Remove the unused panel locator. Browser requalification remains required; only diff whitespace validation was run locally.
Change-source: pulse-maintainer
Missing capacity and a measured empty datastore both report zero usage. Protect the existing distinction across durable manager restarts so missing observations cannot send a false recovery, while genuine recovery and subsequent high usage still dispatch callbacks. Assert incident identity and persisted lifecycle event counts as well as the callback boundary.
Change-source: pulse-maintainer
Execute plain retained reconciliation in one current SQLite snapshot and
reuse bounded compiled statements. Preserve per-series chronology without
a metric sort while keeping display aggregation ordering explicit.
Exact-base worker comparisons cover the prior PR benchmark failures. Full
metrics/database and focused concurrent race checks pass. Final CI and
real diagnostic outcome qualification remain open.
Tool-call totals do not establish diagnostic sufficiency. Preserve seed-only
and failed-read conclusions, remove count-based completion instructions from
evidence, and retain configured limits and authority checks.
Keep findings grouped under alerts selectable in the shared review panel so
their investigations and access limits remain available to Assistant.