code wiki / _hdl_build / nx_promote_deny_gate.nx

nx_promote_deny_gate.nx

buildroot/runtime/_hdl_build/nx_promote_deny_gate.nx

4131 B72 linesdepth 6pulls 17 transitivereach 0 importersview sourcekind gate/proof
docsdependenciesstructsconstsfunctions

about

nx_promote_deny_gate.nx -- the safety proof for narrowing md_promote_deny_hard from a raw SUBSTRING to a TOKEN-BOUNDARY match plus an oracle exemption (debt 1785511766, 2026-07-31). This guard is NON-OVERRIDABLE by design: no conf row may make a credential organ promotable, or the role registry becomes a privilege-escalation surface. So the burden of proof for touching it is one-directional -- EVERY REAL CREDENTIAL ORGAN MUST STILL DENY (T1-T8). The false positives it removes (T9-T12) are only worth anything if that holds. A change to a security guard that only tests the newly-allowed cases is how a hole ships. license_tier: ORIGINAL

dependencies 3 imports · 0 importers

nx_mgmt_data.nx nx_gate.nx nx_gate_verdict.nx nx_promote_deny_gate.nx

imports: nx_mgmt_data.nxnx_gate.nxnx_gate_verdict.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main gw sys_write gv_ctr sys_mmap pd_deny md_promote_deny_hard md_name_is_oracle mdh_len mdh_tail_eq mdh_len ↻ md_tok_at mdh_len ↻ gv_cat gv_check gv_puts sys_write ↻ gv_verdict gv_puts ↻ gv_num sys_mmap ↻ sys_write ↻ sys_munmap gv_journal sys_openat_append sys_mmap ↻ gv_catn sys_mmap ↻ sys_munmap ↻ sys_now_realtime_sec sys_mmap ↻ sys_clock_gettime_real gv_cat ↻ sys_write ↻ sys_close sys_munmap ↻

structs

none

consts

none

functions

17func pd_deny(g: *u8, nm: *u8, want: i64, pass: *i64, tot: *i64) -> i64
37func main() -> i64