code wiki / _hdl_build / nx_law_warden.nx

nx_law_warden.nx

buildroot/runtime/_hdl_build/nx_law_warden.nx

90835 B1785 linesdepth 5pulls 11 transitivereach 0 importersview sourcekind tool
docsdependenciesstructsconstsfunctions

about

============================================================================================ FREEZE LIFTED 2026-08-07 -- debt 1785516173 (sev9) is EATEN and the reconstruction is IN THIS FILE. The banner below used to read "STOP -- DO NOT BUILD OR PROMOTE THIS ORGAN", and it had become FALSE AND INTERNALLY CONTRADICTORY: its first paragraph said this source "HAS NONE OF countfile / scancap / gatedry / helperdup / T20" while its own last paragraph said "Already restored here: countfile ...". All of them are present now -- lw_countfile, lw_file, lw_segamp, lw_file_gatedry, lw_file_helperdup, lw_file_scancap -- and each was compiled, linked and RUN standalone with a POSITIVE and TWO NEGATIVE controls before being wired in (see the L009/L010/L011 note below). ★★★★★★A FREEZE NOTICE OUTLIVES THE CONDITION IT DESCRIBES. A DEBT ROW HAS A LIFECYCLE -- open, eaten -- AND NOTHING EVER CLOSES A COMMENT. The debt was closed; the STOP sign stayed up, and any reader arriving here would have believed a live sev-9 freeze that no longer existed. ⇒ WHEN A COMMENT ASSERTS A STATE, IT MUST NAME THE ARTIFACT THAT CAN BE QUERIED FOR THAT STATE (here: `nx_debt show 1785516173`), so the reader can check it instead of trusting it. THE HAZARD THE FREEZE GUARDED IS REAL AND STILL APPLIES -- read this before rebuilding: nx_magicratchet CONSUMES `nx_law_warden countfile` -- but it is NOT reached from /api/build. CORRECTED 2026-08-15 (open sev-8 debt 1785530277, re-confirmed live today). This line used to assert the wiring as fact. Measured two ways: nx_wiredclaim reports CLAIMED-UNWIRED call_sites=0 comment_mentions=17, and behaviourally FOUR /api/build runs of nx_oo_extract_gate left its baseline at -1 while a single direct nx_magicratchet call created one. The chokepoint was exercised; nothing refused. A COMMENT THAT ASSERTS AN ENFORCEMENT IS NOT AN ENFORCEMENT, and this one was load-bearing: it is the stated reason this organ accepts a design constraint in exchange for a guard that is not in the path. If a rebuild ever drops that verb, mr_parse_magic returns -1, the ratchet FAILS OPEN BY DESIGN, and magic-number enforcement plus the hourly autofiler both go silent WITH EVERY GATE STILL GREEN. ⇒ THE MECHANICAL REFEREE, NOT A PROMISE: promote WITHOUT allow_capability_loss. /api/promote compares the new binary's strings against the live one and REFUSES on capability loss, so the guard adjudicates this rebuild rather than anyone's reading of this comment. If it refuses, reconcile -- do not pass the flag to get past it. ★A GATE THAT IS GREEN ON THE BINARY PROVES NOTHING ABOUT THE SOURCE THAT WILL REPLACE IT. ★WHEN SOURCE AND ARTIFACT EACH CONTAIN WORK THE OTHER LACKS, THERE IS NO SAFE DIRECTION. ============================================================================================ nx_law_warden.nx -- MECHANICAL ENFORCEMENT for written laws (ws=cap-autonomy, 2026-07-20). Operator: "make sure autonomously that our nishi ecosystem is getting sota ... what needs to become mcp or api or raci or workflows or agents or other modern capabilities just gets logged and worked without me having to call its need out"; + "our magic number audit and bug stuff dont appear to be autonomous ... lots of workstreams are flagging them as bugs they hit and then just gave a new number to"; + "callouts of using webrtc or webassembly ... not building from the first byte up to a sovereign nishi os and browser". THE GAP THIS EATS: every conformance surface we own is a CURATED manifest -- nx_favela_census states it outright ("unnamed shanty stays invisible until a row names it"). A written law (CLAUDE rule 11, the

dependencies 5 imports · 0 importers

nx_store_seed_lib.nx nx_syscalls.nx nx_estate_path.nx nx_tool_run.nx nx_gate_verdict.nx nx_law_warden.nx

imports: nx_store_seed_lib.nxnx_syscalls.nxnx_estate_path.nxnx_tool_run.nxnx_gate_verdict.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main ep_anchor sys_openat_rd sys_close sys_chdir sys_mmap nxa_die sys_write sys_exit nxa_lock_take nxa_lock_addr sys_write ↻ nxa_lock_give nxa_lock_addr ↻ nxa_report_overrun sys_write ↻ nxa_dump_printable sys_write ↻ nxa_dump_sizes sys_write ↻ lw_slen lw_span_eq lw_slen ↻ lw_selftest gv_ctr sys_mmap ↻ gv_head gv_puts sys_write ↻ lw_wfile sys_openat_wr sys_write ↻ lw_slen ↻ sys_close ↻ lw_file_lits sys_mmap ↻ sys_read_file sys_openat_rd ↻ sys_lseek sys_mmap ↻

structs

none

consts

81const LW_OUT: i64 = 262144
82const LW_DIRBUF: i64 = 131072
83const LW_PLANE: i64 = 1048576
84const LW_PATH: i64 = 512
85const LW_NAMEMAX: i64 = 256
86const LW_SCRATCH: i64 = 64
102const LW_FILECAP: i64 = 50000
103const LW_COLS: i64 = 8
104const LW_COLS_MAX: i64 = 9
105const LW_FLD_BYTES: i64 = 128
106const LW_OVF: i64 = 100000000000
107const LW_MODE: i64 = 0x1a4
108const LW_NL: i64 = 10
109const LW_TAB: i64 = 9
110const LW_HASH: i64 = 35
111const LW_SP: i64 = 32
112const LW_COMMA: i64 = 44
113const LW_DQ: i64 = 34
114const LW_BSL: i64 = 92
115const LW_SL: i64 = 47
118const LW_CH_M: i64 = 109
119const LW_CH_F: i64 = 102
125const LW_MAGIC_THR: i64 = 1024
126const LW_MODE_LIT: i64 = 1
127const LW_MODE_ELF: i64 = 2
128const LW_MODE_TOK: i64 = 3
150const LW_SEGMAX: i64 = 4096
151const LW_SEGNAME: i64 = 64
152const LW_SEGTAB: i64 = 262144
153const LW_SEGCNT: i64 = 32768
154const LW_DIRMODE: i64 = 0x1ed
155const LW_ST_SLOTS: i64 = 64
386const LW_MODE_VNAME: i64 = 4
392const LW_MODE_GATEDRY: i64 = 5
393const LW_MODE_HELPERDUP: i64 = 6
394const LW_MODE_SCANCAP: i64 = 7
1008const LW_SELFTEST_THRESHOLD: i64 = 1024

functions

158func lw_slen(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} return n }
159func lw_cat(o: *u8, at: i64, s: *u8) -> i64 { var a: i64=at; var i: i64=0; while s[i]!=(0 as u8){o[a]=s[i]; a=a+1; i=i+1} return a }
160func lw_catf(o: *u8, at: i64, p: *u8, n: i64) -> i64 { var a: i64=at; var i: i64=0; while i<n { o[a]=p[i]; a=a+1; i=i+1 } return a }
162func lw_catesc(o: *u8, at: i64, p: *u8, n: i64) -> i64
called by 2: lw_scanlw_file
173func lw_catn(o: *u8, at: i64, v: i64) -> i64
185func lw_count(buf: *u8, n: i64, needle: *u8) -> i64
199func lw_span_eq(b: *u8, s: i64, l: i64, lit: *u8) -> i64
206func lw_ends(nm: *u8, suf: *u8) -> i64
called by 2: lw_segamplw_walk calls 1: lw_slen
214func lw_join(dst: *u8, dir: *u8, nm: *u8) -> i64
called by 1: lw_walk calls 1: lw_cat
223func lw_wfile(path: *u8, content: *u8) -> i64
232func lw_line_start(b: *u8, ls: i64, le: i64) -> i64
239func lw_is_const(b: *u8, ls: i64, le: i64) -> i64
250func lw_is_comment(b: *u8, ls: i64, le: i64) -> i64
269func lw_line_lits(b: *u8, ls: i64, le: i64, thr: i64) -> i64
called by 1: lw_file_lits
317func lw_file_lits(path: *u8, thr: i64) -> i64
346func lw_countfile(path: *u8) -> i64
397func lw_digits(v: i64, out: *u8) -> i64
called by 1: lw_line_valuenamed calls 1: sys_mmap
408func lw_span_has(b: *u8, s: i64, e: i64, pat: *u8, pl: i64) -> i64
called by 1: lw_line_valuenamed
422func lw_line_valuenamed(b: *u8, ls: i64, le: i64) -> i64
465func lw_file_valuenamed(f: *u8, n: i64) -> i64
481func lw_field0_has(buf: *u8, n: i64, name: *u8) -> i64
called by 1: lw_walk calls 1: lw_slen
524func lw_manifest_count(dir: *u8, plane: *u8) -> i64
544func lw_segamp(dir: *u8, thr: i64, cx: *i64, worst: *u8) -> i64
655func lw_debt_id(b: *u8, n: i64) -> i64
called by 1: lw_file calls 1: lw_slen
686func lw_file_gatedry(b: *u8, n: i64) -> i64
called by 1: lw_walk calls 1: lw_count
695func lw_file_helperdup(b: *u8, n: i64) -> i64
called by 1: lw_walk calls 1: lw_count
709func lw_file_scancap(b: *u8, n: i64) -> i64
called by 1: lw_walk calls 1: lw_count
720func lw_walk(dir: *u8, cx: *i64, worst: *u8, abuf: *u8) -> i64
873func lw_count_lines(b: *u8, n: i64, needle: *u8, excl: *u8) -> i64
called by 1: lw_token_scan calls 2: lw_slenlw_count
889func lw_token_scan(corpus: *u8, csv: *u8, cx: *i64, worst: *u8, excl: *u8) -> i64
928func lw_last_ts(buf: *u8, n: i64) -> i64
called by 2: lw_selftestlw_file
953func lw_filed_has(buf: *u8, n: i64, lawid: *u8) -> i64
972func lw_allow_path(abuf: *u8, an: i64, name: *u8, out: *u8) -> i64
1010func lw_selftest() -> i64
1280func lw_scan(prefix: *u8) -> i64
1543func lw_plane_find(rb: *u8, rn: i64, lawid: *u8, gs: *i64, gl: *i64) -> i64
1566func lw_file(prefix: *u8, toolname: *u8) -> i64
1754func main(argc: i64, argv: *i64) -> i64