mesh_serve
Register a shell command as a callable mesh procedure, letting verified callers invoke it repeatedly until unserved. Useful for exposing local services over the mesh.
Instructions
Serve a procedure on the mesh, answered by a local shell command run once per inbound call (its stdin is the caller's JSON payload, its stdout is the reply, MACULA_MCP_CALLER is the caller's verified node_id). It is served in this agent's own namespace: callers call ~/, which the result names. THIS IS A STANDING INBOUND SURFACE, not a one-shot action: once registered, any mesh caller can trigger the command repeatedly until mesh_unserve is called or this process exits. Never register a command you would not want a stranger able to run repeatedly on this machine. Pair with mesh_unserve to stop serving deliberately. Bytes in the caller's payload appear on stdin as {"$bytes": ""}; write bytes to stdout in the same form. MACULA_MCP_SEALED is 1 when the call came sealed to this agent's KEM key, 0 when it came in the clear; callers seal only when this server runs with MACULA_MCP_KEM_ADVERTISE=1.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| exec | Yes | Shell command to run once per inbound call. Receives the call's JSON payload on stdin and the caller's node_id in MACULA_MCP_CALLER; its entire stdout is parsed as the JSON reply (empty stdout replies null). Bytes appear as {"$bytes": "<base64>"} both ways. | |
| name | Yes | The procedure's name in this agent's own namespace, one segment, e.g. "summarize" (served as ~<node_id>/summarize). | |
| confidential | No | "preferred" (default): with MACULA_MCP_KEM_ADVERTISE=1 this agent's KEM key is named so callers seal, and a clear call is taken only while its last keyless advertisement could still be served, then refused sealed_required, so a caller older than macula 13 / macula-go 0.18 / @macula-io/ts 0.24 cannot call it after that; without it, served in the clear. "required": every clear call is refused (sealed_required); needs MACULA_MCP_KEM_ADVERTISE=1, else code=confidentiality (reason=kem_advertise_disabled), and a caller older than macula 13 / macula-go 0.18 / @macula-io/ts 0.24 cannot call it. "off": served in the clear. To change it on a served name, mesh_unserve it first. | |
| exec_timeout_seconds | No | How long one invocation may run before it's killed (default 10, max 60). |