code wiki / _hdl_build / nx_law_warden.nx
nx_law_warden.nx
buildroot/runtime/_hdl_build/nx_law_warden.nx
about
============================================================================================
FREEZE LIFTED 2026-08-07 -- debt 1785516173 (sev9) is EATEN and the reconstruction is IN THIS FILE.
The banner below used to read "STOP -- DO NOT BUILD OR PROMOTE THIS ORGAN", and it had become
FALSE AND INTERNALLY CONTRADICTORY: its first paragraph said this source "HAS NONE OF countfile /
scancap / gatedry / helperdup / T20" while its own last paragraph said "Already restored here:
countfile ...". All of them are present now -- lw_countfile, lw_file, lw_segamp, lw_file_gatedry,
lw_file_helperdup, lw_file_scancap -- and each was compiled, linked and RUN standalone with a
POSITIVE and TWO NEGATIVE controls before being wired in (see the L009/L010/L011 note below).
★★★★★★A FREEZE NOTICE OUTLIVES THE CONDITION IT DESCRIBES. A DEBT ROW HAS A LIFECYCLE -- open,
eaten -- AND NOTHING EVER CLOSES A COMMENT. The debt was closed; the STOP sign stayed up, and
any reader arriving here would have believed a live sev-9 freeze that no longer existed.
⇒ WHEN A COMMENT ASSERTS A STATE, IT MUST NAME THE ARTIFACT THAT CAN BE QUERIED FOR THAT STATE
(here: `nx_debt show 1785516173`), so the reader can check it instead of trusting it.
THE HAZARD THE FREEZE GUARDED IS REAL AND STILL APPLIES -- read this before rebuilding:
nx_magicratchet CONSUMES `nx_law_warden countfile` -- but it is NOT reached from /api/build.
CORRECTED 2026-08-15 (open sev-8 debt 1785530277, re-confirmed live today). This line used to assert
the wiring as fact. Measured two ways: nx_wiredclaim reports CLAIMED-UNWIRED call_sites=0
comment_mentions=17, and behaviourally FOUR /api/build runs of nx_oo_extract_gate left its baseline at
-1 while a single direct nx_magicratchet call created one. The chokepoint was exercised; nothing refused.
A COMMENT THAT ASSERTS AN ENFORCEMENT IS NOT AN ENFORCEMENT, and this one was load-bearing: it is the
stated reason this organ accepts a design constraint in exchange for a guard that is not in the path.
If a rebuild ever drops that verb, mr_parse_magic returns -1, the ratchet FAILS OPEN BY DESIGN,
and magic-number enforcement plus the hourly autofiler both go silent WITH EVERY GATE STILL GREEN.
⇒ THE MECHANICAL REFEREE, NOT A PROMISE: promote WITHOUT allow_capability_loss. /api/promote
compares the new binary's strings against the live one and REFUSES on capability loss, so the
guard adjudicates this rebuild rather than anyone's reading of this comment. If it refuses,
reconcile -- do not pass the flag to get past it.
★A GATE THAT IS GREEN ON THE BINARY PROVES NOTHING ABOUT THE SOURCE THAT WILL REPLACE IT.
★WHEN SOURCE AND ARTIFACT EACH CONTAIN WORK THE OTHER LACKS, THERE IS NO SAFE DIRECTION.
============================================================================================
nx_law_warden.nx -- MECHANICAL ENFORCEMENT for written laws (ws=cap-autonomy, 2026-07-20).
Operator: "make sure autonomously that our nishi ecosystem is getting sota ... what needs to become mcp or
api or raci or workflows or agents or other modern capabilities just gets logged and worked without me
having to call its need out"; + "our magic number audit and bug stuff dont appear to be autonomous ... lots
of workstreams are flagging them as bugs they hit and then just gave a new number to"; + "callouts of using
webrtc or webassembly ... not building from the first byte up to a sovereign nishi os and browser".
THE GAP THIS EATS: every conformance surface we own is a CURATED manifest -- nx_favela_census states it
outright ("unnamed shanty stays invisible until a row names it"). A written law (CLAUDE rule 11, the
dependencies 5 imports · 0 importers
imports: nx_store_seed_lib.nxnx_syscalls.nxnx_estate_path.nxnx_tool_run.nxnx_gate_verdict.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| 81 | const LW_OUT: i64 = 262144 |
| 82 | const LW_DIRBUF: i64 = 131072 |
| 83 | const LW_PLANE: i64 = 1048576 |
| 84 | const LW_PATH: i64 = 512 |
| 85 | const LW_NAMEMAX: i64 = 256 |
| 86 | const LW_SCRATCH: i64 = 64 |
| 102 | const LW_FILECAP: i64 = 50000 |
| 103 | const LW_COLS: i64 = 8 |
| 104 | const LW_COLS_MAX: i64 = 9 |
| 105 | const LW_FLD_BYTES: i64 = 128 |
| 106 | const LW_OVF: i64 = 100000000000 |
| 107 | const LW_MODE: i64 = 0x1a4 |
| 108 | const LW_NL: i64 = 10 |
| 109 | const LW_TAB: i64 = 9 |
| 110 | const LW_HASH: i64 = 35 |
| 111 | const LW_SP: i64 = 32 |
| 112 | const LW_COMMA: i64 = 44 |
| 113 | const LW_DQ: i64 = 34 |
| 114 | const LW_BSL: i64 = 92 |
| 115 | const LW_SL: i64 = 47 |
| 118 | const LW_CH_M: i64 = 109 |
| 119 | const LW_CH_F: i64 = 102 |
| 125 | const LW_MAGIC_THR: i64 = 1024 |
| 126 | const LW_MODE_LIT: i64 = 1 |
| 127 | const LW_MODE_ELF: i64 = 2 |
| 128 | const LW_MODE_TOK: i64 = 3 |
| 150 | const LW_SEGMAX: i64 = 4096 |
| 151 | const LW_SEGNAME: i64 = 64 |
| 152 | const LW_SEGTAB: i64 = 262144 |
| 153 | const LW_SEGCNT: i64 = 32768 |
| 154 | const LW_DIRMODE: i64 = 0x1ed |
| 155 | const LW_ST_SLOTS: i64 = 64 |
| 386 | const LW_MODE_VNAME: i64 = 4 |
| 392 | const LW_MODE_GATEDRY: i64 = 5 |
| 393 | const LW_MODE_HELPERDUP: i64 = 6 |
| 394 | const LW_MODE_SCANCAP: i64 = 7 |
| 1008 | const LW_SELFTEST_THRESHOLD: i64 = 1024 |
functions
| 158 | func lw_slen(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} return n } |
| 159 | func lw_cat(o: *u8, at: i64, s: *u8) -> i64 { var a: i64=at; var i: i64=0; while s[i]!=(0 as u8){o[a]=s[i]; a=a+1; i=i+1} return a } |
| 160 | func lw_catf(o: *u8, at: i64, p: *u8, n: i64) -> i64 { var a: i64=at; var i: i64=0; while i<n { o[a]=p[i]; a=a+1; i=i+1 } return a } |
| 162 | func lw_catesc(o: *u8, at: i64, p: *u8, n: i64) -> i64 |
| 173 | func lw_catn(o: *u8, at: i64, v: i64) -> i64 |
| 185 | func lw_count(buf: *u8, n: i64, needle: *u8) -> i64 |
| 199 | func lw_span_eq(b: *u8, s: i64, l: i64, lit: *u8) -> i64 |
| 206 | func lw_ends(nm: *u8, suf: *u8) -> i64 |
| 214 | func lw_join(dst: *u8, dir: *u8, nm: *u8) -> i64 |
| 223 | func lw_wfile(path: *u8, content: *u8) -> i64 |
| 232 | func lw_line_start(b: *u8, ls: i64, le: i64) -> i64 |
| 239 | func lw_is_const(b: *u8, ls: i64, le: i64) -> i64 |
| 250 | func lw_is_comment(b: *u8, ls: i64, le: i64) -> i64 |
| 269 | func lw_line_lits(b: *u8, ls: i64, le: i64, thr: i64) -> i64 called by 1: lw_file_lits |
| 317 | func lw_file_lits(path: *u8, thr: i64) -> i64 called by 3: lw_countfilelw_walklw_selftest calls 5: sys_mmapsys_read_filelw_is_commentlw_is_constlw_line_lits |
| 346 | func lw_countfile(path: *u8) -> i64 |
| 397 | func lw_digits(v: i64, out: *u8) -> i64 |
| 408 | func lw_span_has(b: *u8, s: i64, e: i64, pat: *u8, pl: i64) -> i64 called by 1: lw_line_valuenamed |
| 422 | func lw_line_valuenamed(b: *u8, ls: i64, le: i64) -> i64 |
| 465 | func lw_file_valuenamed(f: *u8, n: i64) -> i64 |
| 481 | func lw_field0_has(buf: *u8, n: i64, name: *u8) -> i64 |
| 524 | func lw_manifest_count(dir: *u8, plane: *u8) -> i64 |
| 544 | func lw_segamp(dir: *u8, thr: i64, cx: *i64, worst: *u8) -> i64 called by 2: lw_selftestlw_scan calls 11: sys_openat_rdsys_mmapsys_getdents64dirent_namelw_endslw_slen+5 |
| 655 | func lw_debt_id(b: *u8, n: i64) -> i64 |
| 686 | func lw_file_gatedry(b: *u8, n: i64) -> i64 |
| 695 | func lw_file_helperdup(b: *u8, n: i64) -> i64 |
| 709 | func lw_file_scancap(b: *u8, n: i64) -> i64 |
| 720 | func lw_walk(dir: *u8, cx: *i64, worst: *u8, abuf: *u8) -> i64 called by 2: lw_selftestlw_scan calls 18: sys_openat_rdsys_mmapsys_getdents64dirent_namelw_endslw_join+12 |
| 873 | func lw_count_lines(b: *u8, n: i64, needle: *u8, excl: *u8) -> i64 |
| 889 | func lw_token_scan(corpus: *u8, csv: *u8, cx: *i64, worst: *u8, excl: *u8) -> i64 |
| 928 | func lw_last_ts(buf: *u8, n: i64) -> i64 |
| 953 | func lw_filed_has(buf: *u8, n: i64, lawid: *u8) -> i64 |
| 972 | func lw_allow_path(abuf: *u8, an: i64, name: *u8, out: *u8) -> i64 |
| 1010 | func lw_selftest() -> i64 |
| 1280 | func lw_scan(prefix: *u8) -> i64 |
| 1543 | func lw_plane_find(rb: *u8, rn: i64, lawid: *u8, gs: *i64, gl: *i64) -> i64 |
| 1566 | func lw_file(prefix: *u8, toolname: *u8) -> i64 |
| 1754 | func main(argc: i64, argv: *i64) -> i64 |