AGPL-3.0-only native integration for NDS. NDDev OpenNetwork.
crates/agent composes the six compiled-in native adapters: sysinfo, clipboard,
cleaner, updater, GDS and RDS. Each adapter owns its manifest and provider
contract. The Flutter client calls the library to read actual native state;
configuration, untested reachability and a completed observation are distinct.
Mobile consumers share portable view types; local native tools require a
supported desktop host.
crates/io provides separate bounded socket and process capabilities. An
agent shares eight admission slots across its modules, uses finite deadlines
and output limits, and cancels owned work when closed. Native providers retain
their state and policy. Private paths, arguments and response content never
enter telemetry. Module operations carry real OpenTelemetry contexts through
the caller-installed shared telemetry SDK; its local logs do not imply remote
export or delivery.
Run just check, cargo nextest run --locked --workspace, cargo deny check
and cargo audit. OS transport checks exercise real sockets and child
processes. Module repositories own isolated real-provider acceptance; the
agent's Linux acceptance verifies composition against the pinned sysinfo
provider. Dependencies use immutable Git revisions.
This library has no standalone background daemon, remote-command endpoint, maintenance mutation, backup/recovery or private estate configuration.
nds-agent --server <origin> vault list [after_ref] returns bounded metadata and
secret references. vault use <ref> github|cloudflare|digitalocean consumes the
secret natively for the official provider identity check; raw provider output
and credentials are never returned. Sign in through NDS first. The CLI uses the
same native session/device/vault stores and reconciles the server replica before
use; conflicts, revocation and incomplete catch-up deny secret consumption.
The CLI reserves stdout for one JSON operation result; the shared bounded SDK writes redacted diagnostics to stderr. It uses the same accounts sender for signed events and actual native spans, reporting transport acknowledgements, operator policy and undelivered/dropped records separately. Vault list cursors come from the native paginated read model, including tombstones/conflicts.
Provider acceptance never extracts a working CLI account token into fixtures.
The default real GitHub check uses a generated invalid value and verifies denial
without secret/output leakage. A successful provider check requires an explicitly
supplied isolated test account credential via NDS_TEST_ISOLATED_GITHUB_TOKEN_FILE.