code wiki / _hdl_build / nx_sitegen_llm_gate.nx

nx_sitegen_llm_gate.nx

buildroot/runtime/_hdl_build/nx_sitegen_llm_gate.nx

9352 B145 linesdepth 6pulls 9 transitivereach 0 importersview sourcekind gate/prooftopic sitegen
docsdependenciesstructsconstsfunctions

about

nx_sitegen_llm_gate.nx -- the AI-OPTIONAL / GOVERNED-MODEL-SEAM gate. The contract: a local LLM (or any model) may PROPOSE a site only as a `.site` blueprint (data); the sovereign parser+engine treat that output as UNTRUSTED input and either build it safely or refuse it safely. The model is NEVER trusted, NEVER in the build or serve path, and CANNOT (a) change the deterministic output by its formatting, (b) inject script, (c) ship a non-UX-compliant page, (d) crash/smuggle via hallucinated block kinds, or (e) smuggle raw markup through a text field. This proves "using AI" is exactly as safe + sovereign as "without AI" -- AI is optional, only a proposer of data. No new engine: reuses nx_sitegen_parse + nx_sitegen (the governance is already in them; this gate proves it for model-emitted, incl. adversarial, blueprints). Appends "CMSGATE row=nx_sitegen_llm site-builder-ai-seam ... verdict=PASS" to knowledge/status/cms_gate.log on all-pass. Exit 0 iff all pass. license_tier: ORIGINAL

dependencies 3 imports · 0 importers

nx_sitegen_parse.nx nx_sitegen.nx nx_syscalls.nx nx_sitegen_llm_gate.nx

imports: nx_sitegen_parse.nxnx_sitegen.nxnx_syscalls.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main sys_mmap l_build sys_mmap ↻ sgp_parse sys_mmap ↻ sgp_tok sgp_streq sgp_strcpy sys_openat_wr sg_build_page sg_compliant wb_ux_compliant wb_steps_ok wb_doc_open bt_default_brand wb_doc_open_branded wb_w sys_write bas_emit_head bas_emit_one bt_emit_root_fd sys_mmap ↻ bt_emit_root_buf sys_write ↻ bt_emit_dark_fd sys_mmap ↻ bt_emit_dark_root_buf sys_write ↻ pol_emit pol_w bt_len sg_esc sys_mmap ↻ hs_escape hs_emit hs_emitb hs_emitb ↻ wb_header wb_w ↻

structs

none

consts

none

functions

15func lw(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 }
called by 2: lrowmain calls 1: sys_write
16func lnum(v: i64) -> i64 { let bb: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m}; let t: *u8=sys_mmap(28); var k: i64=0; if m==0{t[0]=48 as u8;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{bb[i]=t[k-1-i];i=i+1}; sys_write(1,bb,k); return 0 }
called by 2: lrowmain calls 2: sys_mmapsys_write
17func lcat(dst: *u8, off: i64, s: *u8) -> i64 { var o: i64=off; var k: i64=0; while s[k]!=(0 as u8){dst[o]=s[k];o=o+1;k=k+1} return o }
called by 1: main
18func lcatnum(dst: *u8, off: i64, v: i64) -> i64 { var o: i64=off; let t: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m}; var k: i64=0; if m==0{t[0]=48 as u8;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{dst[o]=t[k-1-i];o=o+1;i=i+1} return o }
called by 1: main calls 1: sys_mmap
20func lrow(id: i64, ok: i64, what: *u8) -> i64
called by 1: main calls 2: lwlnum
27func llen(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} return n }
called by 1: main
29func lslurp(path: *u8, buf: *u8, cap: i64) -> i64
44func lcontains(hay: *u8, hn: i64, needle: *u8) -> i64
called by 1: main
64func lbytes_eq(a: *u8, an: i64, b: *u8, bn: i64) -> i64
called by 1: main
72func l_build(text: *u8, tn: i64, path: *u8, buf: *u8, cap: i64) -> i64
88func main() -> i64