Commit Graph

4948 Commits

Author SHA1 Message Date
pulse-triage[bot] b2b67ae0d5 Merge current upstream main into reviewed recovery feedback
Preserve reviewed recovery feedback commits while incorporating Pulse main through 62f6931c1f. Reconcile independent frontend contract additions and retain the latest upstream browser receipt; the recovery receipt remains preserved in commit 036d324460.

Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
2026-09-07 13:19:28 +01:00
rcourtman 2a7019b0fa Use typed Proxmox runners and preserve cross-clock action evidence
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.

Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.

Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
2026-09-07 12:00:48 +01:00
pulse-triage[bot] 036d324460 fix(alerts): retain notification recovery failure feedback
Recovery failures otherwise disappear with their toast, leaving slower readers without the action outcome. Keep a view-local untimed equivalent on Overview and Notifications until clear or a newer confirmed action, independently of queue health.

Separate accepted queue mutations from optional activity-refresh failures. Cover ownership and cancellation in focused tests, and verify both real views with scripted APIs in Chromium at three widths and both themes. This implements the current main-only recovery feedback bet, not a backend delivery fix or release-line backport.

Change-source: pulse-maintainer
2026-09-07 11:44:50 +01:00
rcourtman 09ab5c2d0a Merge pull request #1951 from rcourtman/fix/patrol-filesystem-evidence
Preserve native filesystem evidence and Patrol action history
2026-09-07 10:24:57 +01:00
rcourtman 3a4a3fd62b Preserve native filesystem evidence and Patrol action history
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.

Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.

Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
2026-09-07 09:45:31 +01:00
rcourtman 8b73085e82 Fix release smoke workspace identity on rootless Docker
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.

Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
2026-09-07 08:29:42 +01:00
pulse-triage[bot] edcd1dcc5e Merge batch-start upstream main
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/api-contracts.md
2026-09-06 22:31:11 +01:00
pulse-triage[bot] ad0a70bc75 test(notifications): cover SMTP transaction retry replies
Check permanent, transient and recovered sends at envelope and DATA boundaries without external delivery.

Change-source: pulse-maintainer
2026-09-06 22:26:55 +01:00
pulse-triage[bot] 13e5201f02 Merge candidate 20260906T210510Z-delivery-trust
Change-source: pulse-maintainer
2026-09-06 22:16:05 +01:00
pulse-triage[bot] 92c3297049 ci: add fixed UUID layout diagnostic without release gate waiver
The exact release tree retains a failed paired UUID benchmark check, while push CI cannot repeat that comparison. Provide a reviewed-source route to collect the requested four-condition hosted layout evidence instead of repeating local samples or changing product order.

Fix source/tree/toolchain identities, isolate diagnostic controls, alternate ten rounds, and retain partial receipts without publishing binaries. Execution still needs separate operator authority; collection success does not dispose of the failed gate. Nine focused harness tests and existing benchmark contract tests pass.

Change-source: pulse-maintainer
2026-09-06 22:11:03 +01:00
pulse-triage[bot] 79577981f9 fix(notifications): stop SMTP retries on permanent failures
Respect structured delivery classes in the inner email retry loop, retaining transient retry budgets and accurate attempt counts. Add queue-free SMTP failure regression coverage.

Change-source: pulse-maintainer
2026-09-06 22:10:04 +01:00
pulse-triage[bot] 4a981bc2ec fix(notifications): prioritise HTTP rejection over retry body hints
A provider 403 response mentioning an authentication timeout was treated as a transient network failure and sent again with unchanged credentials. Classify explicit HTTP status before diagnostic text, retaining existing transient status and network fallback behaviour. Add a status/body matrix and a queue-free loopback regression that verifies one request and terminal delivery history.

Change-source: pulse-maintainer
2026-09-06 21:54:18 +01:00
rcourtman 3853124a39 Keep Patrol action history consistent with recorded outcomes
Refresh durable investigation lifecycle from authoritative actions while
preserving completed evidence. Keep resolved history reviewable and label
recorded plan facts separately from action outcomes. Follow all resource
pages during qualification and record live approval, rejection and storage
semantic-review results. Integrate current main and preserve its alert
ordering correction.
2026-09-06 21:23:01 +01:00
pulse-triage[bot] 1b060ba48d docs(alerts): explain whole-site outage watchdog verification
Community outage reports expose the difference between local delivery health and a monitor surviving site failure. The existing External watchdog has no troubleshooting entry explaining that boundary. Document its current setup, period-plus-grace timing, secret handling and authorised receipt/recovery checks without adding runtime scope or claiming end-to-end qualification.

Change-source: pulse-maintainer
2026-09-06 21:22:44 +01:00
rcourtman 57ead19484 Preserve Patrol evidence and surface action submission failures
Live funded qualification found hidden tool results and misleading action
submission outcomes. Share the result-bearing transcript across stored chat
and product history, render the retained evidence, and distinguish captured
proposals from broker acceptance. Keep review usable while Patrol is paused.

Record Gemini route pricing and exact qualification limits. Integrate current
main and repeat browser proof for the incoming login flow. Approved/rejected
recovery remains unqualified without the development command agent.
2026-09-06 20:09:54 +01:00
rcourtman b0b39f00dc Qualify Docker storage collection against a live fault
Exercise the production collector through healthy, full and recovered
storage states using the existing bounded disposable lab. Preserve exact
mount configuration while keeping collector proof separate from model
diagnosis and installed-agent qualification.
2026-09-06 18:00:24 +01:00
rcourtman 186ce504c8 Retire disconnected incident recording and preserve archives
The fleet sampler and coordinator had no production alert trigger and could
repeat cached values as fresh incident evidence. Preserve saved recordings
through explicit read-only lookups, propagate read failures and report the
former live incident count as unmeasured. Keep historical status and duration
units explicit without rewriting archived observations.

Integrate main's alert dispatch wording and startup replay qualification.
Canonical incident listing and real-model outcome qualification remain open.
2026-09-06 17:42:24 +01:00
pulse-triage[bot] 495562ef66 fix(alerts): ignore superseded delivery diagnosis responses
Overlapping bulk diagnosis refreshes could resolve out of order and replace a current notifications-disabled warning with older dispatch evidence. Version each request, including empty alert sets, so only the newest response updates card diagnoses.

Pin overlap and empty-set invalidation with component and registered hook regressions. All 47 focused tests and TypeScript pass. Isolated Chromium verifies rendered ordering at three widths; update both subsystem contracts and bind browser proof to the runtime bytes. No backend delivery or recipient receipt is claimed.

Change-source: pulse-maintainer
2026-09-06 17:17:36 +01:00
pulse-triage[bot] 64dba483d0 fix(release): bind forward 6.4.4 checkpoint to release train
The held regression candidate needs an honest forward beta above published 6.4.3-rc.1. Bind only 6.4.4 to release/v6.4 without capturing patch 40 or weakening candidate checks. Exercise the actual release and rehearsal branch-policy shell and retain historical rollback mapping.

Change-source: pulse-maintainer
2026-09-06 16:48:17 +01:00
rcourtman ab6d214000 Merge main into diagnostic evidence improvements
Preserve both monitoring contracts and combine the diagnostic history
correction with current host continuity and delivery evidence changes.
Verify the combined backend, frontend and browser behaviour before
landing the existing diagnostic work.
2026-09-06 16:45:28 +01:00
rcourtman 919331d5b3 Join Docker alert events with canonical resource history
Keep alert and inventory evidence together after container removal and
restart without rewriting retained events or transferring approval and
operator authority. Resolve exact source identities in the shared store
and preserve event replay idempotency across old and current records.

Verify actual retained homelab events, registered tool reads, lifecycle
callbacks, tenant isolation, race behaviour and responsive evidence views.
2026-09-06 16:23:30 +01:00
rcourtman 580a246981 Read incident evidence from canonical resource history
Assistant incident reads used an unconnected cached-metric recorder while
resource history already retained operational events. Read the shared
organization-scoped timeline with original provenance, bounded results
and explicit coverage and failure semantics. Keep legacy archive reads
resource-bound.

Record the separately reproduced alert identity split at the shared
write boundary. This read-path correction does not qualify complete
incident diagnosis or recovery.
2026-09-06 15:33:44 +01:00
pulse-triage[bot] 9ddee2f8f9 fix(alerts): distinguish dispatch from notification receipt
LastNotified is recorded before delivery callbacks, so the active card cannot use it as evidence of destination success. Name dispatch and cooldown eligibility explicitly while preserving policy and timestamp fallbacks.

Pin the evidence boundary in presentation and Overview regressions, subsystem contracts and an isolated real-browser qualification. Scripted diagnoses verify labels and wrapping, not installed delivery or recipient receipt.

Change-source: pulse-maintainer
2026-09-06 15:12:07 +01:00
rcourtman 6e18777d30 Preserve tmpfs mount evidence through collection and queries
Docker can report tmpfs mounts only in HostConfig.Tmpfs. Preserve those
entries in shared inventory and retain type, options and canonical write
access in diagnostic queries. Configured size is not measured free space.

Record the failed ordinary storage diagnosis and independently verified
recovery without claiming autonomous or installed-collector qualification.
2026-09-06 14:50:11 +01:00
rcourtman f5f440dbad Separate command connectivity from monitoring evidence
Name command transport explicitly in shared query results and preserve
unobserved connection state in topology and Assistant inventory context.
Keep parent-node transport distinct from a direct guest connection so
monitoring evidence cannot imply command access or collection downtime.

Existing execution policy and approval checks remain authoritative.
2026-09-06 14:10:11 +01:00
rcourtman 4d302109ce Record storage diagnosis qualification limits
Bind the ordinary read-only storage assessment to the corrected runtime and
persisted tool evidence. Keep useful capacity observations separate from
unsupported causal and temporal claims so completion is not counted as a
qualified diagnosis or autonomous outcome.
2026-09-06 13:38:54 +01:00
rcourtman 355ac1f0a4 Resolve configuration reads from current inventory
Native container config reads confused missing session discovery with a
missing resource and could reuse stale placement. Read identity and
capability from canonical inventory while preserving explicit query
restrictions and existing action authority.

Keep unavailable providers, unsupported adapters and empty observations
distinct from resource absence, with the tool error bit preserved.
2026-09-06 13:25:00 +01:00
pulse-triage[bot] 3b21ed22a4 fix(pbs): evaluate configured datastore alerts on live polls
Connect fresh PBS storage observations to the existing capacity and connectivity evaluator. Exercise HTTP polling through unified sync, absent counter retention, confirmed empty recovery and recurrence with alternate counter names.

Change-source: pulse-maintainer
2026-09-06 12:59:04 +01:00
rcourtman f48c806718 Preserve observed Docker storage evidence
Missing block I/O and container image sizes could become false evidence
for diagnosis. Preserve per-direction counter presence and measured zero
through collection, resource conversion and browser rendering. Separate
new observed history from ambiguous retained disk series without deleting
old rows or changing public metric names.

Keep partial host rates distinct and persist a newly enabled Disk I/O
column across the first preference reload.
2026-09-06 12:45:40 +01:00
pulse-triage[bot] be74f56aff Merge upstream main at 20260906T105913Z batch boundary
Change-source: pulse-maintainer

# Conflicts:
#	frontend-modern/browser-verification.json
2026-09-06 12:02:03 +01:00
rcourtman 33b852f66b fix(assistant): preserve tool evidence identity
Concurrent calls with the same tool name could collapse pending activity or
remove a sibling approval. Deep transcript reconciliation also mutated shared
tool objects when status rows disappeared, replacing earlier evidence with a
later result. Match supplied invocation IDs strictly and key immutable message
rows without reconciling their nested evidence.

Add regressions for both causes and record desktop, intermediate and narrow
browser replay of all 23 captured tool results. Record the healthy and dependency
model qualification limits separately from renderer and fixture-cleanup proof.
2026-09-06 11:21:10 +01:00
pulse-triage[bot] 7a0fced1f7 Merge candidate 20260906T095829Z-delivery-trust
Change-source: pulse-maintainer
2026-09-06 11:18:09 +01:00
pulse-triage[bot] 449f3b1bc8 fix(monitoring): persist operator host node link intent
Commit link and unlink journal updates before publishing state, preserve manual selections across report and provider refresh boundaries, and reserve dormant owners across restart. Re-evaluate known automatic associations using provider names while retaining legacy unknown links.

Change-source: pulse-maintainer
2026-09-06 11:13:59 +01:00
pulse-triage[bot] cbfe0d8eac ci: retain exact benchmark collection provenance
PR #1933 failed paired normalization benchmarks despite unchanged hot-path source. Preserve actual checkout identities, selected toolchains and sample order so investigation does not confuse PR head metadata with measured source. Keep thresholds and sample collection unchanged.

Change-source: pulse-maintainer
2026-09-06 11:12:42 +01:00
pulse-triage[bot] e05776356e Merge candidate 20260906T091009Z-web-product
Change-source: pulse-maintainer
2026-09-06 10:37:42 +01:00
pulse-triage[bot] c27c8abc77 fix(web): retain current delivery evidence across overlapping reads
Mount and Retry reads can finish out of order, erasing current attempts and held-event evidence or hiding an unavailable result. Assign refresh ownership and ignore abandoned completions after disposal. Ordinary regression tests and six scripted Chromium cases protect ordering and loading state; this does not qualify installed notification delivery.

Change-source: pulse-maintainer
2026-09-06 10:19:46 +01:00
pulse-triage[bot] c268d25e54 test(monitoring): protect manual links against stale association cleanup
Record reproduced restart gaps and legacy provenance ambiguity; do not enable destructive cleanup.\n\nChange-source: pulse-maintainer

Change-source: pulse-maintainer
2026-09-06 10:19:41 +01:00
pulse-triage[bot] 7f80c2c0b8 test(monitoring): protect asymmetric bridge association boundaries
Symmetric bridge fixtures can pass when one address inventory loses its filter. Exercise repeated ingestion with one-sided Docker bridges and valid custom management bridges, checking both link directions. Mutation checks reject loss of either filter and the earlier broad bridge exclusion.

Change-source: pulse-maintainer
2026-09-06 09:33:06 +01:00
pulse-triage[bot] 2ed9965968 fix(monitoring): preserve custom bridge link evidence
Limit automatic Docker bridge filtering to the generated br-<12 hex> convention so custom management bridges such as br-mgmt remain eligible for host association. Keep docker-prefixed and non-global-unicast exclusions intact.

Change-source: pulse-maintainer
2026-09-06 09:28:51 +01:00
pulse-triage[bot] 386fc0415e fix(monitoring): reject host-local addresses in agent auto-linking
A Docker bridge or link-local address can be unique among monitored PVE nodes but also exist on an unrelated NAS. Counting PVE owners alone then creates a false reciprocal agent association. Exclude host-local IPs and known Docker bridge interfaces from automatic network evidence, preserving management bridges and explicit unicast report IPs.

Seven synthetic negative cases fail before this repair and pass afterwards. Focused matcher and host-report tests pass under the race detector. This prevents a reproduced backend misassociation; it does not establish the cause or resolution of issue #1930, whose diagnostic payload remains unavailable.

Change-source: pulse-maintainer
2026-09-06 09:18:59 +01:00
pulse-triage[bot] 088f597907 Merge current upstream main after PR #1929
Preserve the reviewed alert and TrueNAS work while incorporating the canonical API metrics optimization and patrol qualification record.

Change-source: pulse-maintainer
2026-09-06 09:12:03 +01:00
pulse-triage[bot] 9a8ee6a5a7 fix(alerts): keep normalized offline capacity suppressed
Use the normalized connectivity status consistently when deciding whether storage capacity is actionable, preserving the existing offline suppression rule for case and whitespace variants.

Change-source: pulse-maintainer
2026-09-06 08:45:39 +01:00
pulse-triage[bot] 2e661e075a fix(alerts): preserve storage incidents when connectivity is unknown
Do not count empty or unknown storage status as recovery evidence. Normalise status spelling for connectivity checks while leaving capacity evaluation independent and preserving existing inactive/disabled storage behaviour.

Change-source: pulse-maintainer
2026-09-06 08:40:29 +01:00
rcourtman a2f0ef8817 perf(api): avoid rune decoding in route label checks
Route labels classify ASCII digits and hexadecimal UUID bytes. Scan those
bytes directly while preserving numeric precedence, Unicode names and
invalid UTF-8 handling. This reduces the shared normaliser overhead exposed
by paired landing benchmarks without changing the benchmark gate.

Refs #1928

Contract-Neutral: ASCII route-label optimization preserves label values, identifier precedence, Unicode and invalid UTF-8 behavior, and agent lifecycle authority.
2026-09-06 08:31:26 +01:00
rcourtman ba69933da3 docs(patrol): record current diagnostic qualification failure
Preserve the real Assistant result separately from passing access routing
and disposable fault oracles. Correct tool evidence still produced
unsupported temporal claims, so customer outcome readiness remains open.

Refs #1928
2026-09-06 08:06:58 +01:00
rcourtman 173d74a8e4 test(patrol): exercise dependency and restart fault oracles
Validate the checked-in dependency and three service restart fault contracts
against disposable Docker resources before using them to assess model output.
Verify baseline, injected fault, refused duplicate injection, explicit fixture
recovery, and two-pass cleanup with unchanged pre-existing inventory.

These opt-in tests make no Pulse or model request. Fixture recovery is teardown
and does not count as an approval, rejection, execution or customer outcome.
Record exact live, owning-package and source-bound proof in the redesign plan.
2026-09-06 07:42:32 +01:00
rcourtman 58caeda69b fix(assistant): retain monitored targets without command access
Resolve monitored topology before checking command connections so unavailable
inspection retains the known resource and parent node. Prevent known targets
from falling through to a colliding agent ID, and preserve the single-agent
requirement when no target is supplied.

Use one failed tool envelope for diagnostic reads and file mutations. Missing
connections neither prove an installation problem nor count as successful
writes. Hypervisor lifecycle authority remains on its canonical action path.

Verify disconnected and unknown targets, collision isolation, all affected
tool handlers, token/WebSocket scope boundaries, and the linked Patrol and
Assistant failure journey at desktop and narrow widths.
2026-09-06 07:27:05 +01:00
rcourtman 1f41fa174d perf(metrics): avoid ordinal binding allocations
The 500-node dashboard query triggered repeated ordinal string conversions
in the SQLite driver while matching numbered parameters. Use alphabetic
named bindings to preserve current values and shared query branches without
that allocation cost.

Cover large cached scopes with changed resource families, identities,
metric filters and windows, including IDs that resemble SQL syntax.

Refs #1928
2026-09-06 06:54:40 +01:00
rcourtman b964eea767 fix(hostmetrics): retire disk probes before publishing results
A completed probe remained discoverable after its first caller returned,
allowing the next collection to reuse stale filesystem measurements.
Remove it and publish completion within one registry critical section.
Keep in-flight sharing, cancellation and timeout behaviour intact.

The controlled regression fails before this change. Twenty full package
runs and three race runs pass on the worker.

Refs #1928
2026-09-06 06:28:00 +01:00
rcourtman 618700db5e test(patrol): qualify bounded service storage failures
Add a disposable service-storage fault with an independent filesystem
oracle, bounded tmpfs writes, identity checks and verified recovery.
Exercise overwrite and symlink refusal without contacting a model.

Align the published schema with supported summary-term groups and validate
the complete catalogue in CI. Record the exact proof and remaining model
and missing-access qualification limits in the customer-journey plan.
2026-09-06 06:04:56 +01:00