code wiki / (root) / nx_mcp_coverage_gate.nx

nx_mcp_coverage_gate.nx

buildroot/runtime/nx_mcp_coverage_gate.nx

3161 B54 linesdepth 5pulls 8 transitivereach 0 importersview sourcekind gate/proof
docsdependenciesstructsconstsfunctions

about

nx_mcp_coverage_gate.nx -- gate for the standing MCP/API exposure coverage organ. T1 the REAL map grades clean: mc_run(coverage_map) returns 0 policy-violations (our seeded map obeys the exposure policy) AND areas>0. T2 NEG blind-wrapping caught: a planted map marking a PRIMITIVE (std_slen) and a GATE (nx_foo_gate) as EXPOSED capabilities -> violations >= 2 (the anti-"expose everything stupidly" tooth fires). T3 the policy classifier is correct on both sides (pure): std_/fc_/sys_/_gate/_test/_smoke = internal-kind; a real capability name (nx_forge_engine) = NOT internal-kind. license_tier: ORIGINAL expect_exit: 0

dependencies 2 imports · 0 importers

nx_mcp_coverage.nx nx_gate_verdict.nx nx_mcp_coverage_gate.nx

imports: nx_mcp_coverage.nxnx_gate_verdict.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main std_putln std_puts std_slen sys_write mc_run_store sov_get_copy sys_mmap ss_get sys_mmap ↻ ss_scan sys_mmap ↻ ss_manifest_dyn ss_manifest_file_dyn ss_scan_seglist ss_len sys_mmap ↻ ss_cat ss_readall ss_r32 std_putln ↻ mc_run_buf std_putln ↻ mc_field mc_is_internal_kind std_slen ↻ fc_contains std_streq std_puts ↻ std_pdec sys_mmap ↻ std_itoa sys_mmap ↻ sys_write ↻ std_puts ↻ std_pdec ↻ cvg_write sys_openat_wr std_slen ↻ mc_run

structs

none

consts

none

functions

13func cvg_write(path: *u8, s: *u8) -> i64
called by 1: main calls 2: sys_openat_wrstd_slen
22func main(argc: i64, argv: *i64) -> i64