Core library and crates
NetsCLI is split into Rust crates and interface apps. netscli-core owns network behavior, and the CLI, TUI, desktop app, and MCP server call into it rather than carrying separate implementations.
Interface layers use the core Ops facade instead of implementing their own probes, packet parsing, DNS behavior, or scan safety logic.
Crate map
Section titled “Crate map”| Crate or app | Owns |
|---|---|
netscli-core |
Shared network operations, result types, safety limits, packet capture support, persistence, and traffic stats. |
netscli |
CLI subcommands, plain-text/JSON/YAML output, setup and doctor commands, and the terminal UI. |
netscli-mcp |
MCP JSON-RPC server and tool schemas that wrap core operations. |
netscli-gui |
Tauri backend commands plus the React desktop shell, tables, settings, history, exports, and render automation. |
Dependency direction
Section titled “Dependency direction”Dependency flow stays one-way:
Interface crates may depend on the core. The core must not depend on a UI layer, MCP protocol layer, or desktop runtime.
The CLI additionally depends on netscli-mcp, because netscli serve runs
the MCP server in-process. It is the one dependency between two interface crates.
Public facade
Section titled “Public facade”Most consumers start from Ops.
| Type | Role |
|---|---|
Ops |
High-level async operation facade used by the CLI, TUI, Tauri backend, and MCP server. |
OpsConfig |
Runtime defaults for scan, ping and DNS timeouts, plus probe concurrency. |
| Result structs | Shared data returned by scans, discovery, DNS, ARP, interfaces, sweep, inspect, and packet capture. |
Typical integration shape:
use netscli_core::{Ops, OpsConfig};
# async fn example() -> anyhow::Result<()> {let ops = Ops::new(OpsConfig::default());let (_ip, results) = ops .scan_ports("192.168.1.1", Some(vec![22, 80, 443])) .await?;for result in results { println!("{} {:?}", result.port, result.status);}# Ok(())# }Exact method signatures can change as operations gain richer structured data. Prefer the current crate docs and compiler errors over copying examples blindly.
Module map
Section titled “Module map”| Module | Owns |
|---|---|
scan |
TCP and UDP port scanning, status classification, latency, banner, HTTP and TLS probing, and service versions. |
discover |
Host discovery over a subnet. |
inspect |
Host profile data built from reachability, reverse DNS, MAC address, port checks, and the OS hint. |
sweep |
Discovery plus per-host port checks. |
ping |
Reachability probing, with the ICMP and TCP-connect backends. |
trace |
Route hops, over the platform trace tool. |
dns |
Record lookup and reverse lookup behavior. |
mdns |
Local mDNS/DNS-SD service discovery behind the mdns feature. |
arp |
Local neighbor cache and MAC vendor enrichment. |
stats |
Local interface traffic counters. |
pcap |
Optional capture execution and packet parsing behind the pcap feature. |
db |
SQLite persistence for host records and scan history. |
ops |
Cross-interface operation orchestration and limits. |
Safety limits
Section titled “Safety limits”NetsCLI intentionally limits expensive operations:
- Subnets up to
/16. - Up to
4096ports per scan. 256probes in flight by default.- A
500 msscan timeout by default.
Contributing
Section titled “Contributing”The rules for where new code goes, how a new operation reaches every interface, and what has to stay compatible are in ARCHITECTURE.md in the repository.