code wiki / (root) / nx_mcp_coverage_gate.nx

nx_mcp_coverage_gate.nx

buildroot/runtime/nx_mcp_coverage_gate.nx

3161 B54 linesdepth 5pulls 8 transitivereach 0 importersview sourcekind gate/prooftopic mcp
docsdependenciesstructsconstsfunctions

about

nx_mcp_coverage_gate.nx -- gate for the standing MCP/API exposure coverage organ. T1 the REAL map grades clean: mc_run(coverage_map) returns 0 policy-violations (our seeded map obeys the exposure policy) AND areas>0. T2 NEG blind-wrapping caught: a planted map marking a PRIMITIVE (std_slen) and a GATE (nx_foo_gate) as EXPOSED capabilities -> violations >= 2 (the anti-"expose everything stupidly" tooth fires). T3 the policy classifier is correct on both sides (pure): std_/fc_/sys_/_gate/_test/_smoke = internal-kind; a real capability name (nx_forge_engine) = NOT internal-kind. license_tier: ORIGINAL expect_exit: 0

dependencies 2 imports · 0 importers

nx_mcp_coverage.nx nx_gate_verdict.nx nx_mcp_coverage_gate.nx

imports: nx_mcp_coverage.nxnx_gate_verdict.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main std_putln std_puts std_slen sys_write mc_run_store sov_get_copy sys_mmap nxa_die sys_write ↻ sys_exit nxa_lock_take nxa_lock_addr sys_write ↻ nxa_lock_give nxa_lock_addr ↻ nxa_report_overrun sys_write ↻ nxa_dump_printable sys_write ↻ nxa_dump_sizes sys_write ↻ ss_get sys_mmap ↻ ss_scan sys_mmap ↻ ss_manifest_dyn ss_manifest_file_dyn ss_scan_seglist ss_len sys_mmap ↻ ss_cat ss_readall ss_r32 std_putln ↻ mc_run_buf std_putln ↻ mc_field mc_is_internal_kind std_slen ↻

structs

none

consts

none

functions

13func cvg_write(path: *u8, s: *u8) -> i64
called by 1: main calls 1: std_slen
22func main(argc: i64, argv: *i64) -> i64