package builder import ( "bufio" "bytes" "context" "encoding/json" "errors" "fmt" "io" "net" "os" "os/exec" "path/filepath" "regexp" "strings" "time" "github.com/novox/mesh-controller/internal/artifacts" "github.com/novox/mesh-controller/internal/facts" ) // A pull request's merge check, run on the build seat (novox/hq to-be 45 §9, ADR 0237). // // **The build machine already has what a check needs**: the repositories, a container runtime, the // artifact store where the controller keeps the facts snapshot, and a Go toolchain. So a check is one // more kind of work on the build seat's queue rather than a CI the mesh would have to run beside itself. // // **Two layers, each its own status on the pull request** (ADR 0237 as amended, 2026-10-06): // // - **the gate** (`mesh/merge-gate`) runs when the change touches a module of the mesh's graph — the // controller, which holds the graph, says which (Modules) and which directories it adds a module in // (New). The touched manifests through `module check`; every machine of the facts snapshot composed // with the change and validated by the node-engine's own validator; then mesh-lab's replays. The // judge is the controller the mesh runs — or, for a change to the controller, the change's own // controller, and for a change to the node-engine, the running controller with the change's validator // in place of the one it vendors. The graph decides whether this runs, never the repository. // - **the repository's own check** (`mesh/repo-check`): its merge-check.sh, its unit tests and code // quality, run when present in the toolchain it declares (`# mesh-check-toolchain: go|typescript` // among its first lines; go when it declares none). A repository that reaches the build seat with // none is said as a warning: it is the mesh's, and nothing of its own is tested before it merges. // **A repository in two languages declares the other part too** (`# mesh-check-also: //