netcheck: one module, a Go tools bundle and a TypeScript one (hq ADR 0188, 0193) #246

Merged
mesh-admin merged 1 commits from feat/netcheck-a-module-in-two-languages into main 2026-10-03 22:35:32 +00:00
Contributor

One module carrying two tools bundles in two languages, both served by the node's runtime as launched children over MCP stdio (hq ADR 0188, ADR 0193). This is the first catalogue module that does it: until now every tools bundle was TypeScript, and the only Go bundle was the runtime itself.

What the manifest declares

  • tools: netcheck_tcp, netcheck_dns, netcheck_http
  • tools-go: kind: bundle, language: go, system: arch, from: cmd/netcheck, binary: netcheck, loads: [netcheck]. Built with the Go SDK git.novox.be/novox/mesh-sdk/go v0.1.6, which proxy.golang.org serves, so no GOPRIVATE is needed.
  • tools-typescript: kind: bundle, language: typescript, entrypoints/loads: [tools/index.js], using @novox/mesh-sdk ^0.1.6.
  • No container, image, env or resource. The tools need nothing beyond the runtime's own words.

The tools (read-only)

  • netcheck_tcp(host, port, timeout_ms) opens one connection and closes it without sending anything. It answers reachable, elapsed_ms, address and, when unreachable, error.
  • netcheck_dns(name, type A|AAAA|CNAME|TXT|MX, timeout_ms) looks the name up through the machine's resolver: the Go resolver built without cgo, reading /etc/resolv.conf and /etc/hosts. It answers answers, elapsed_ms and, when the lookup fails, error.
  • netcheck_http(url, method HEAD|GET, timeout_ms) sends no body, reads no body, and reports redirects without following them. It answers status, elapsed_ms and a subset of headers. It refuses any URL that is not http(s) and any other method.
  • A timeout defaults to 3 s (5 s for HTTP) and is capped at 30 s.

Proven locally (nothing touched on the live mesh)

  • go test covers the TCP, DNS and timeout checks and the tool list. node --test runs 4 HTTP tests. The tsc typecheck passes.
  • Both bundles were built the way the builder builds them. The Go bundle is static, CGO_ENABLED=0, linux/amd64, with -s -w -X main.builtFor=arch. The TypeScript bundle went through tsc, then the index.serve.mjs launcher, then esbuild one file per entrypoint.
  • Driven by hand over MCP stdio: initialize, tools/list and tools/call answer from both.
  • In the real Go node-tools runtime against a local NATS: serving 3 tool(s) for 1 module(s): netcheck.netcheck_tcp, netcheck.netcheck_dns, netcheck.netcheck_http. All three answer on the bus.
  • mesh-controller module check over every catalogue manifest prints netcheck: ok, 3 tool(s).
  • The controller tests pass with this branch as the sibling catalogue. The one failure is the known, unrelated TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves.
  • A throwaway declaration test, deleted afterwards, composed this manifest with node-tools to two archives (netcheck.bundle-tools-go and netcheck.bundle-tools-typescript) and no container or process, with MESH_TOOL_MODULES=netcheck=/var/lib/mesh/bundles/netcheck/tools-go/netcheck,netcheck=/var/lib/mesh/bundles/netcheck/tools-typescript/tools/index.serve.mjs.

The controller needs no change.

Not built, assigned or pushed on the mesh. That is the live proof, and it is left for after review.

One module carrying two tools bundles in two languages, both served by the node's runtime as launched children over MCP stdio (hq ADR 0188, ADR 0193). This is the first catalogue module that does it: until now every tools bundle was TypeScript, and the only Go bundle was the runtime itself. ## What the manifest declares - `tools`: `netcheck_tcp`, `netcheck_dns`, `netcheck_http` - `tools-go`: `kind: bundle`, `language: go`, `system: arch`, `from: cmd/netcheck`, `binary: netcheck`, `loads: [netcheck]`. Built with the Go SDK `git.novox.be/novox/mesh-sdk/go` v0.1.6, which proxy.golang.org serves, so no GOPRIVATE is needed. - `tools-typescript`: `kind: bundle`, `language: typescript`, `entrypoints`/`loads: [tools/index.js]`, using `@novox/mesh-sdk` ^0.1.6. - No container, image, `env` or resource. The tools need nothing beyond the runtime's own words. ## The tools (read-only) - `netcheck_tcp(host, port, timeout_ms)` opens one connection and closes it without sending anything. It answers `reachable`, `elapsed_ms`, `address` and, when unreachable, `error`. - `netcheck_dns(name, type A|AAAA|CNAME|TXT|MX, timeout_ms)` looks the name up through the machine's resolver: the Go resolver built without cgo, reading /etc/resolv.conf and /etc/hosts. It answers `answers`, `elapsed_ms` and, when the lookup fails, `error`. - `netcheck_http(url, method HEAD|GET, timeout_ms)` sends no body, reads no body, and reports redirects without following them. It answers `status`, `elapsed_ms` and a subset of headers. It refuses any URL that is not http(s) and any other method. - A timeout defaults to 3 s (5 s for HTTP) and is capped at 30 s. ## Proven locally (nothing touched on the live mesh) - `go test` covers the TCP, DNS and timeout checks and the tool list. `node --test` runs 4 HTTP tests. The tsc typecheck passes. - Both bundles were built the way the builder builds them. The Go bundle is static, `CGO_ENABLED=0`, linux/amd64, with `-s -w -X main.builtFor=arch`. The TypeScript bundle went through tsc, then the `index.serve.mjs` launcher, then esbuild one file per entrypoint. - Driven by hand over MCP stdio: `initialize`, `tools/list` and `tools/call` answer from both. - In the real Go node-tools runtime against a local NATS: `serving 3 tool(s) for 1 module(s): netcheck.netcheck_tcp, netcheck.netcheck_dns, netcheck.netcheck_http`. All three answer on the bus. - `mesh-controller module check` over every catalogue manifest prints `netcheck: ok, 3 tool(s)`. - The controller tests pass with this branch as the sibling catalogue. The one failure is the known, unrelated `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves`. - A throwaway declaration test, deleted afterwards, composed this manifest with node-tools to two archives (`netcheck.bundle-tools-go` and `netcheck.bundle-tools-typescript`) and no container or process, with `MESH_TOOL_MODULES=netcheck=/var/lib/mesh/bundles/netcheck/tools-go/netcheck,netcheck=/var/lib/mesh/bundles/netcheck/tools-typescript/tools/index.serve.mjs`. The controller needs no change. Not built, assigned or pushed on the mesh. That is the live proof, and it is left for after review.
mesh-admin added 1 commit 2026-10-03 22:34:49 +00:00
ADR 0193 says the node's runtime launches every served bundle over MCP stdio and knows no
language, and ADR 0188 says one module may carry several bundles in any language. Nothing in
the catalogue shows both at once: every tools bundle is TypeScript, and the only Go bundle is
the runtime itself. netcheck is the smallest real module that does — read-only checks from a
machine, worth having on their own:

- tools-go (Go SDK go/v0.1.6): netcheck_tcp (one connect, nothing sent) and netcheck_dns
  (A/AAAA/CNAME/TXT/MX through the machine's resolver).
- tools-typescript (@novox/mesh-sdk): netcheck_http (HEAD or GET, body neither sent nor read,
  redirects reported not followed, anything but http(s) refused).

Both say loads; the module lists its tools. No container, no image, no env: nothing to be
given, so the runtime's own words suffice.
mesh-admin merged commit 7e889adf71 into main 2026-10-03 22:35:32 +00:00
mesh-admin deleted branch feat/netcheck-a-module-in-two-languages 2026-10-03 22:35:32 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#246