From ff5220869c6b5aa5aff4e7a45efbaa33a97998a1 Mon Sep 17 00:00:00 2001 From: archipelago Date: Wed, 7 Oct 2026 20:58:54 -0400 Subject: [PATCH] Label Fleet alert provenance and distrust cached identity claims --- docs/fleet-recovery-qualification-20261007.md | 22 +++++++++ neode-ui/src/views/fleet/FleetAlerts.vue | 5 ++- .../__tests__/FleetPartialFailure.test.ts | 45 ++++++++++++++++++- neode-ui/src/views/fleet/useFleetData.ts | 26 ++++++++--- 4 files changed, 89 insertions(+), 9 deletions(-) diff --git a/docs/fleet-recovery-qualification-20261007.md b/docs/fleet-recovery-qualification-20261007.md index 16321fc6..c395e73c 100644 --- a/docs/fleet-recovery-qualification-20261007.md +++ b/docs/fleet-recovery-qualification-20261007.md @@ -165,3 +165,25 @@ The exact app-project typecheck also passed again after the history follow-up, with the same 2 GB bound; log `/tmp/archy-fleet-history-typecheck.log`. Completed logs and browser fixture sources are archived at `~/.local/state/archipelago/release-qualification/fleet-acceptance-20261007/`. + +## Alert provenance and cache migration follow-up + +Alert rows now reuse the same explicit provenance label as node cards, with a +wrapping header for narrow displays. Collector alerts do not inherit trust from +the claimed/truncated node ID. Existing cached node and alert provenance is +stripped on read: historical unsigned collector responses could supply those +fields. Content, metrics and staleness remain available; only a fresh corrected +backend response may restore authenticated labels. Invalid cached alert rows +are discarded. Regression checks cover cached claimed trust and a later fresh +response, as well as actual alert-panel labels. This does not authenticate a +collector identity or replace the required backend gate. + +The unchanged combined baseline passed **1,459 tests in 177 files** from a frozen +771-input copy, all hashes unchanged, at +`~/.local/state/archipelago/release-qualification/fleet-combined-ui-20261007/`. +The subsequent three-file alert/cache delta passed **31 focused tests in five +files** and the exact app-project typecheck (2 GB cap, exit 0), logs +`/tmp/archy-fleet-alert-cache-corrected.log` and +`/tmp/archy-fleet-alert-cache-typecheck.log`. This is full baseline plus focused +delta evidence, not a full-suite rerun after the delta. No production deployment +or additional artwork investigation occurred. diff --git a/neode-ui/src/views/fleet/FleetAlerts.vue b/neode-ui/src/views/fleet/FleetAlerts.vue index dbb18a1c..e7960e5b 100644 --- a/neode-ui/src/views/fleet/FleetAlerts.vue +++ b/neode-ui/src/views/fleet/FleetAlerts.vue @@ -20,8 +20,9 @@ :class="alertSeverityDot(alert.rule)" >
-
+
{{ alert.node_id.slice(0, 8) }} + {{ fleetSourceLabel(alert) }} {{ alertTypeLabel(alert.rule) }}

{{ alert.message }}

@@ -33,7 +34,7 @@