Merge pull request 'Design 38: WP4c complete' (#345) from design/38-wp4c-complete into main

This commit was merged in pull request #345.
This commit is contained in:
2026-10-03 23:35:31 +00:00
@@ -319,9 +319,14 @@ plan. **Two corrections the machines taught:** a tool that called a broker's com
runs it inside the broker's own container, because a host package may be uninstallable on a machine
whose package index is stale (mesh-catalog#249); and a module reading its application's own key reads
it through the application's container, because that directory belongs to the account the application
runs as there, which is not the runtime's (mesh-media-catalog#14). **Still in a container:**
mesh-catalog, mongodb and mssql, whose code imports npm packages of its own, which the builder cannot
yet install into a bundle; that builder change is in progress.
runs as there, which is not the runtime's (mesh-media-catalog#14). *Completed 2026-10-04:* the last three — mesh-catalog, mongodb and mssql, whose code imports npm
packages of its own — moved once the builder installs a bundle's own dependencies before compiling,
keeping the toolchain's SDK authoritative (mesh-controller#255, mesh-catalog#250). Their database
clients are now drivers inlined into the bundle, not command-line clients fetched by a container; one
more correction the machines taught: a driver reaching its server on loopback must give TLS a host
name, since the runtime's Node refuses an address (mesh-catalog#252). **No module's own code runs in
a container any more;** every module with tools answers from its node's runtime, proven by calling a
tool of each.
## WP5 — The shell, on a server first