code wiki / _hdl_build / nx_adnet_submit_gate.nx
nx_adnet_submit_gate.nx
buildroot/runtime/_hdl_build/nx_adnet_submit_gate.nx
about
nx_adnet_submit_gate.nx -- GATE for the self-serve intake surface (nx_adnet_submit). Proves: the GET form
renders zero-JS with all fields; a VALID POST stages a row (read-back verified) and shows confirmation; a
malicious POST (external img / javascript: click / bad slug) is REJECTED, re-populates the form ESCAPED,
and stages NOTHING (load-bearing negative control on the live journal); reflected XSS in a field stays
escaped. expect_exit: 0 license_tier: ORIGINAL
dependencies 2 imports · 0 importers
imports: nx_syscalls.nxnx_adnet_submit.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| none |
functions
| 9 | func fg_puts(s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } sys_write(1, s, n); return 0 } |
| 10 | func fg_putn(v: i64) -> i64 { var m: i64 = v; if m < 0 { fg_puts("-" as *u8); m = 0 - m } let t: *u8 = sys_mmap(24); var k: i64 = 0; if m == 0 { t[0] = 48 as u8; k = 1 } while m > 0 { t[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 } let o: *u8 = sys_mmap(24); var i: i64 = 0; while i < k { o[i] = t[k - 1 - i]; i = i + 1 } sys_write(1, o, k); return 0 } |
| 12 | func fg_has(hay: *u8, n: i64, needle: *u8) -> i64 called by 1: main |
| 27 | func fg_slen(s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } return n } called by 1: main |
| 29 | func fg_readn(path: *u8, box: *i64) -> *u8 |
| 34 | func main() -> i64 |