The previous recovery browser fixture owned the edited URL in a synthetic parent, leaving the production configuration-state integration untested. Mount the real Alerts settings surface and assert edits and dirty state survive recovery without reload or implicit save, then reach the explicit save boundary intact.
Two serialized Chromium runs passed 12 cases each, including six real settings-parent cases. Record the exact script hash and final result; retain earlier harness failures and distinguish mocked API evidence from persistence, installed recovery and recipient receipt.
Change-source: pulse-maintainer
A large Retry-After integer can overflow time.Duration during multiplication and become zero, defeating the existing 30-second cap. Clamp seconds before conversion and parse at a consistent 64-bit width. Preserve existing negative-value and HTTP-date handling.
Validation: new parser cases fail before the repair; focused parser, HTTP error classification and synthetic terminal-rejection tests pass with -race -count=20. No persistent queue tests or release qualification performed.
Change-source: pulse-maintainer
The recovery browser fixture used no-op configuration setters, so prior passes could not demonstrate unsaved-value retention. Exercise a reactive synthetic ping URL and dirty flag through rejection, cancellation, refresh failure and message clearing without expanding the product surface. All 12 serialized Chromium cases pass, including six edited-value cases; installed and assistive-technology acceptance remain separate.
Change-source: pulse-maintainer
The populated Ceph thresholds browser test reproduced Space on the disclosure moving focus to search instead of collapsing it. Leave Space to buttons, summaries and role buttons, while preserving ordinary type-to-search input. Protect the keyboard journey with a full collapsed focus cycle and reopened action focus, plus focused hook coverage. Chromium failed before this repair and passes after it; 59 focused unit tests pass.
Change-source: pulse-maintainer
Threshold table tests replace the disclosure with a mock, so they cannot protect the controlled collapse/reopen behaviour used by snapshot controls. Exercise the real disclosure with reactive parent state and verify accessibility attributes and retained input identity/value without claiming browser focus or installed-release recovery evidence.
Change-source: pulse-maintainer
Integrate the reviewed settings-shell assertion corrections after confirming the canonical parent reconciliation is tree-identical to the verified candidate base. Preserve exact commit 096480a4e3 and its 33-test Chromium/mobile browser evidence.
Change-source: pulse-maintainer
Keep the shared tool classification contract while removing assertions that
require the retired session state machine and inferred recovery behavior.
Refs #1782
Fresh multi-tenant browser runs reproduced desktop-title expectations on mobile organization panels. Match the compact navigation labels, update the server-updates title, and assert canonical URLs including the legacy AI route redirect. All 33 settings-shell checks pass across Chromium, mobile Chrome and mobile Safari; production presentation policy is unchanged.
Change-source: pulse-maintainer
Incorporate the landed recovery-feedback history without rewriting accepted commit 82ad139f0a. The upstream and local patches have no path overlap.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Let the configured model choose investigation steps within explicit budgets.
Keep canonical planning, permissions and independent verification authoritative,
and preserve streamed conclusions in conversation history.
Expose recorded action outcomes so cached inventory cannot stand in for an
approval or execution receipt. Retain full plan context and make the exact
action review reachable from Assistant, including on narrow screens.
Refs #1782
The multi-tenant bootstrap granted white_label, which security/status maps to commercial suppression. Settings shell tests then reached General instead of the expected billing pages. Keep the shared fixture non-white-label and assert that both general-purpose profiles exclude this presentation-changing entitlement. Dedicated commercial-boundary tests and production policy are unchanged.
Change-source: pulse-maintainer
Apply the repository Prettier contract to the accepted toast accessibility test so the Frontend publication check can evaluate the complete recovery-feedback batch.
Change-source: pulse-maintainer
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.
Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.
Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
Recovery failures otherwise disappear with their toast, leaving slower readers without the action outcome. Keep a view-local untimed equivalent on Overview and Notifications until clear or a newer confirmed action, independently of queue health.
Separate accepted queue mutations from optional activity-refresh failures. Cover ownership and cancellation in focused tests, and verify both real views with scripted APIs in Chromium at three widths and both themes. This implements the current main-only recovery feedback bet, not a backend delivery fix or release-line backport.
Change-source: pulse-maintainer
Recovery feedback must distinguish accepted queue actions from failed health reads. Assert the success and error channels for both actions, including cancelled and rejected requests, before persistent feedback is implemented. This adds unit coverage only; it does not qualify browser behaviour or change the UI.
Change-source: pulse-maintainer
Incorporate upstream commit 96db010415, which existed before this coordination batch began.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Recovery feedback must remain available without stealing keyboard focus. Cover existing error/warning and success/info live-region distinctions, atomic contextual text and retained focus through the public toast entry point. This protects accessibility behaviour without adding product scope; DOM assertions do not establish screen-reader acceptance.
Change-source: pulse-maintainer
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.
Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.
Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
Existing outage coverage exercises attempted deliveries only. Protect held-only histories from appearing readable during an outage, and verify recovery uses the current held state rather than stale rows or a misleading empty result.
Change-source: pulse-maintainer
Replace the superseded local ACL alternative with the exact three files reviewed and merged in PR #1948 (03848a932f). Preserve locked CLI execution, private workspace permissions and failure gates. Rootless daemon identity selects container 0:0; rootful uses the host UID/GID. Probe runtime before expensive qualification. This is main-line reconciliation, not a release-line backport or release qualification.
Change-source: pulse-maintainer
The exact rehearsal passed its test suites and image build but its browser
could not enter the private bind mount. A host UID is remapped to an unrelated
subordinate identity inside rootless Docker. Use the daemon owner's container
identity for rootless Docker and the host UID/GID for rootful Docker.
Execute the locked Playwright CLI directly and probe it during integration
preparation, before expensive suites, so missing dependencies or inaccessible
mounts fail early without fetching an unqualified CLI version.
Rootless Docker maps the unchanged browser UID to a subordinate host UID, so the host-owned 0770 integration tree is inaccessible. Grant that mapped identity POSIX ACL access only within the disposable integration mount, without following symlinks or granting world access. Inherit host access for generated evidence and fail closed on mapping or ACL errors. Preserve container UID/GID, image selection, direct installed CLI, browser gates and failure propagation. Focused fixtures cover identity mapping, subordinate mapping and preparation failures; exact release qualification remains separate.
Change-source: pulse-maintainer
The current notification diagnostic demand records confusion between failed delivery and intentional silence. Pin precedence of current holds over historic dispatch, known event reason labels and unknown-reason fallback so future UI changes do not erase that distinction. This adds regression coverage only; it does not establish recipient delivery.
Change-source: pulse-maintainer
Exact admission attempted to fetch playwright@1.63.0 when the mounted runner was unavailable. Invoke the npm-ci-installed CLI directly so missing or inaccessible dependencies fail closed without substituting a registry package. Preserve the existing container identity and gates; this does not claim to resolve the observed EACCES. Exercise shell arguments and failure propagation with a mocked Docker command.
Change-source: pulse-maintainer
Operator feedback distinguishes successful job completion from protection of every guest. Lock down the existing model boundary with mixed protected, unprotected, failed and unevaluated guests so aggregate success cannot silently erase missing coverage. Task success must not substitute for canonical posture evidence.
Change-source: pulse-maintainer
Copy the reviewed troubleshooting guidance into the shipped frontend mirror so public docs and repository docs remain identical.\n\nChange-source: pulse-maintainer
Change-source: pulse-maintainer
Apply the repository formatter to the accepted stale-delivery evidence regression test. This changes layout only and preserves the reviewed assertions.
Change-source: pulse-maintainer