Run the read-only health walk
Runs narya doctor’s own walk over this installation — home directory, config, host lock, socket, store, sessions, package jobs, tool servers, credentials, binary and terminal — and answers both the rendered text and the structured lines behind it. Read-only throughout: every check reads, the store is opened read-only, and a finding names the command that repairs it rather than running one.
It exists so a client does not have to compile the walk to offer /doctor. The walk lives with the engine, and the things a caller knows about itself that a host cannot — which binary is asking, which build produced it, what the caller’s own terminal can render, and which desktop helpers the caller can actually deliver through — travel as parameters rather than being guessed at from the host’s process. A host that is not running cannot answer this at all, which is the one case a client handles itself: it says so and names narya doctor, the command that walks a machine whose host is down.
One line stays the HOST’s own fact whatever a caller says: the keychain check describes the session the host process runs in, since that is the process that stores and reads a credential.
Authorizations
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Query Parameters
The version of the binary ASKING. The walk compares it against the answering host's own, which is what reports a host serving your sessions from a different build than the one on disk. Omitted, the host reports its own version and that comparison cannot fire.
128The build job that produced the asking binary, when there was one — an extension rebuild stamps it. Reported on the binary line.
128What the CALLER's terminal renders, e.g. TrueColor or ANSI256. A daemon's own stdout is a pipe, so a host asked to detect this for a client would report the absence of the client's terminal. Omitted, the host detects its own.
32The platform notification program the CALLER resolved on its own $PATH, e.g. notify-send or osascript, or empty for none found. The caller is the process that delivers a banner, so this is a fact about it and not about the answering host: a host started by systemd or launchd carries a minimal PATH and no desktop session, and answering from its own walk reports "no platform notifier on this machine" to a person sitting at one. Omitted entirely — as narya doctor run against a host omits it — the host walks its own $PATH.
128The audio player the CALLER resolved on its own $PATH, e.g. paplay or afplay, or empty for none found. A fact about the caller for callerNotifier's exact reason: the caller is the process that plays the sound. Omitted, the host walks its own $PATH.
128Response
The health walk, rendered and structured.
One health walk over an installation: the aligned text narya doctor prints, plus the same lines structured so a caller can gate on them without parsing prose.
healthy, failures and narya doctor's exit code are one decision expressed three times, never three that can disagree: healthy is failures == 0, and the command's exit code is its projection. Warnings are compatible with healthy — a warning is something that works today and will bite you later — which is why the counts are carried separately and a stricter consumer can gate on warnings itself.
The walk as narya doctor prints it: one aligned name/status/detail line per check, each finding's remedy indented underneath, and a closing verdict. Carried so a client renders the same walk a terminal does rather than re-implementing the layout and drifting from it.
The version the walk reports for the binary it describes.
The resolved narya home directory this walk describes.
Nothing is broken — no fail-class line. This is what exit 0 means.
Every line that is not ok — warnings plus failures.
x >= 0x >= 0x >= 0Every line of the walk, in the order it was checked.

