code wiki / _hdl_build / nx_cwe_scan_gate.nx

nx_cwe_scan_gate.nx

buildroot/runtime/_hdl_build/nx_cwe_scan_gate.nx

15450 B183 linesdepth 5pulls 6 transitivereach 0 importersview sourcekind gate/proof
docsdependenciesstructsconstsfunctions

about

nx_cwe_scan_gate.nx -- gates the ISO-5055 scanner on BOTH directions, because a detector that only ever fires is as useless as one that never does. Each rule gets a POSITIVE fixture (must be caught) AND a NEGATIVE control -- the same construct written safely (must NOT be caught). That negative half is the whole point: it proves the scanner discriminates rather than pattern-matching everything, which is what makes a zero finding meaningful. T1 CWE-476 unguarded read caught, guarded one ignored · T2 CWE-252 unchecked fd caught, checked ignored T3 CWE-798 embedded cap-token caught · T4 CWE-1050 mmap-in-loop caught, mmap outside a loop ignored T5 comment lines never fire (prose is not a defect) · T6 fail-closed with no taxonomy plane. license_tier: ORIGINAL expect_exit: 0

dependencies 3 imports · 0 importers

nx_store_seed_lib.nx nx_seg_store.nx nx_syscalls.nx nx_cwe_scan_gate.nx

imports: nx_store_seed_lib.nxnx_seg_store.nxnx_syscalls.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main cg_puts sys_write sys_mkdir sts_seed ss_begin_cap sys_mmap sts_mm sys_mmap ↻ sts_werr sys_write ↻ sys_exit sts_rowkey ss_catn sys_mmap ↻ ss_add ss_add2 ss_w32 ss_len ss_catn ↻ ss_commit ss_segid_ok sys_mmap ↻ ss_cat ss_catn ↻ sys_write ↻ ss_write_seg ss_segid_ok ↻ sys_mmap ↻ ss_cat ↻ ss_catn ↻ sys_write ↻ ss_segname ss_cat ↻ ss_catn ↻ ss_writefile sys_openat_wr sys_write ↻ sys_close sys_fsync

structs

none

consts

none

functions

13func cg_puts(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 }
called by 1: main calls 1: sys_write
14func cg_pn(v: i64) -> i64 { let b: *u8=sys_mmap(32) as *u8; var x: i64=v; var ng: i64=0; if x<0{ng=1;x=0-x} var i: i64=31; if x==0{b[i]=48 as u8;i=i-1} while x>0{b[i]=(48+x%10) as u8;x=x/10;i=i-1} if ng==1{b[i]=45 as u8;i=i-1} sys_write(1,(b as i64+i+1) as *u8,31-i); return 0 }
called by 1: main calls 2: sys_mmapsys_write
15func cg_slen(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} return n }
called by 3: cg_wfilecg_hasmain
16func cg_wfile(path: *u8, content: *u8) -> i64
23func cg_has(buf: *u8, n: i64, needle: *u8) -> i64
called by 1: main calls 1: cg_slen
40func cg_run(elf: *u8, dir: *u8, a1: *u8) -> i64
57func main(argc: i64, argv: *i64) -> i64