nx_edge_refusal_gate.nx
buildroot/runtime/nx_edge_refusal_gate.nx
about
nx_edge_refusal_gate.nx -- the REFEREE for nx_edge_refusal_lib, and the guard that debt row EC32 named as
owed the moment its fix shipped. The 503 change went live on 2026-09-03 and witnessed itself on a real
write within minutes, but a witness that HAPPENED TO OCCUR is not a control: it proves the branch can
fire, never that it fires on exactly the right inputs and no others. These teeth pin both directions.
WHY THIS IS AN IN-PROCESS GATE AND NOT A SOCKET FIXTURE. Proving the branch end to end needs a backend
that ACCEPTS a request and then stays silent for the whole edge window -- a fixture that is slow by
construction and that shares the front door every seat calls through. Extracting the decision into a lib
made it testable in microseconds with no socket and no shared surface, which is why the extraction came
first. The residual is stated rather than hidden: these teeth prove the DECISION, not the WIRING. The
wiring is evidenced separately by nx_contentdiff showing both emitted strings present in the live binary.
license_tier: ORIGINAL. Reads nothing, writes only stdout. No hw writes (Rule 26).
dependencies 3 imports · 0 importers
imports: nx_syscalls.nxnx_gate_verdict.nxnx_edge_refusal_lib.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| 17 | const EG_BUF: i64 = 256 |
| 18 | const EG_PBR_CONNECT_FAILED: i64 = 0 - 1 |
| 19 | const EG_PBR_DEADLINE_EXPIRED: i64 = 0 - 2 |
| 20 | const EG_PBR_REAL_BODY: i64 = 1024 |
functions
| 22 | func eg_set(b: *u8, s: *u8) -> i64 called by 1: main |
| 29 | func main(argc: i64, argv: **u8) -> i64 |