code wiki / (root) / nx_craft_feedback_emit_t28.nx

nx_craft_feedback_emit_t28.nx source

↩ module page · 941 lines · 57152 B

1// nx_craft_emit.nx -- THE SOVEREIGN CRAFT SHIP LANE (retires _ops/nx_emit_game.sh's laptop/WSL 2// dependency for /world/craft): gate-check -> .nx -> .wat -> .wasm -> page -> live docroot, 3// every stage BYTE-ASSERTED before the next runs (the emit script's founding law, organ form: 4// a green tool on empty input is not a check -- a 0-byte .wat once shipped a 20-byte "game"). 5// The page itself is built IN-PROCESS by gpe_build (nx_game_page_emit as a LIB -- one emitter, 6// not a fork), and the deploy is tmp+rename with a READ-BACK byte+marker assert (what LANDED 7// is the claim, never what was written). Gate RED = refuses to emit anything at all. 8// usage: nx_craft_emit (runs from nishihost cwd like every registered tool) 9// exit: 0 SHIPPED | 2 gate-red | 3 wat | 4 wasm | 5 page | 6 deploy | 7 readback | 8 recipe-malformed 10// W1 (2026-08-12): worlds come from knowledge/world_recipes.conf rows (name\tvnum\tseed\tout\t 11// title\tcontrols); the builtin three below are the fallback when the file is absent, and the 12// source actually consumed is ANNOUNCED (recipe_src=) on every run. 13// license_tier: ORIGINAL No hw writes (Rule 26). 14import "nx_syscalls.nx" 15import "nx_game_page_recovery_feedback_t28.nx" 16import "nx_softbind.nx" 17// 4b) THE PAGE MUST LEX BEFORE IT SHIPS. 2026-08-25 an emitter edit took /world/beach and 18// /world/craft BLACK through this exact lane with every stage GREEN: nothing here looked at 19// the JavaScript. Composed IN-PROCESS (a lib, one classifier), never forked -- a fork handed a 20// path could walk nothing and report clean. 21import "nx_jsbalance.nx" 22// 4c) ...AND EVERY NAME MUST RESOLVE. The lexer above catches structure; the nxHairTick outage 23// proved a page can lex cleanly and still die on its first frame from one out-of-scope name. 24import "nx_jsscope.nx" 25import "nx_relief_lib.nx" 26import "nx_nxa_fk.nx" 27import "nx_wasm_memory_lib.nx" 28import "nx_wasm_craft.nx" // Source-owned compiler arena/static bounds; build emitter with the same engine revision. 29 30const CE_GATE: *u8 = "nx_wasm_craft_gate.elf" 31const CE_CWAT: *u8 = "nx_compile_wat.elf" 32const CE_WATC: *u8 = "nx_wat_compiler.elf" 33// the wasm-VM gate: runs the EMITTED module in the memory it declares. Sovereign -- our own VM, no 34// browser and no third-party runtime in the shipping path. 35const CE_VMGATE: *u8 = "nx_wasm_craft_vm_gate.elf" 36const CE_SRC: *u8 = "buildroot/runtime/nx_wasm_craft.nx" 37const CE_WAT: *u8 = "buildroot/_build/nx_wasm_craft_emit.wat" 38const CE_WASM: *u8 = "buildroot/_build/nx_wasm_craft_emit.wasm" 39// GE30 THE THREADED TWIN. A second build of the SAME source with an IMPORTED shared memory, so 40// every Worker instantiates one module over ONE WebAssembly.Memory and render_band splits the 41// frame. It is DEPLOYED AS A FILE, not base64-inlined like the plain build: the page already 42// carries one inline copy and a second would double every world page for a capability only an 43// isolated visitor can use. A non-isolated visitor never fetches it and the single-thread path 44// is byte-unchanged. Proven in a real browser 2026-09-03: 4 Workers, 27 ms against 69 ms 45// single-thread, fb_digest identical, with an omitted-band control returning a DIFFERENT digest. 46const CE_WAT_MT: *u8 = "buildroot/_build/nx_wasm_craft_emit_mt.wat" 47const CE_WASM_MT: *u8 = "buildroot/_build/nx_wasm_craft_emit_mt.wasm" 48const CE_MT_TMP: *u8 = "sites/nishifamily/world/craft_mt.wasm.stage" 49const CE_MT_OUT: *u8 = "sites/nishifamily/world/craft_mt.wasm" 50const CE_SHARED: *u8 = "--shared" 51// A shared memory MUST declare a maximum (an unbounded shared memory cannot be grown), so the 52// twin needs a ceiling the plain build never states. 2x the module's OWN declared pages: derived 53// from the artifact, never a hand-picked number, so it tracks the engine as the arena grows. 54const CE_MT_HEADROOM: i64 = 2 55const CE_MT_PAGES_MIN: i64 = 16 56const CE_MT_PAGES_MAX: i64 = 65536 57const CE_TMP: *u8 = "sites/nishifamily/world/craft.html.stage" 58const CE_OUT: *u8 = "sites/nishifamily/world/craft.html" 59const CE_TITLE: *u8 = "NISHI CRAFT - SOVEREIGN 3D" 60const CE_NATIVE: *u8 = "nx_desktop_craft" 61// the REVIEW STAGE (identity v2 = NISHI SHORE): same gated wasm, second spec, second page -- 62// one engine, many worlds is the emission lever actually being pulled 63const CE_TMP2: *u8 = "sites/nishifamily/world/beach.html.stage" 64const CE_OUT2: *u8 = "sites/nishifamily/world/beach.html" 65const CE_TITLE2: *u8 = "NISHI SHORE - REVIEW STAGE" 66const CE_CTRL2: *u8 = "the flat-light REVIEW STAGE: mixed beachwear across the cast (bred, stable per girl) &middot; same engine, same controls as <a href=\"craft\">NISHI CRAFT</a> &middot; ?review=1 auto-frames the nearest girl<br>ISEKAI: cross to <a href=\"craft\">NISHI CRAFT</a> or <a href=\"vale\">NISHI VALE</a> &mdash; level, ledger and party come along" 67// v3 = the medieval VALE: the third world, built from data rows alone. Your traveler carries 68// his ledger and party between all three -- the passport lives under one key for every world. 69const CE_TMP3: *u8 = "sites/nishifamily/world/vale.html.stage" 70const CE_OUT3: *u8 = "sites/nishifamily/world/vale.html" 71const CE_TITLE3: *u8 = "NISHI VALE - THE MEDIEVAL HIGHLAND" 72const CE_CTRL3: *u8 = "deep woods, cold snowline, cave-riddled stone &mdash; and wardens who hunt WIDE by day &middot; your traveler arrives with his ledger, his level and his party from <a href=\"craft\">NISHI CRAFT</a> or <a href=\"beach\">NISHI SHORE</a> &middot; <b>G</b> invites a bonded girl to your party &middot; same controls" 73const CE_CTRL: *u8 = "click canvas = MOUSELOOK (Esc frees) &middot; <b>WASD</b> move &middot; <b>SPACE</b> jump &middot; L/R-click or <b>E</b>/<b>B</b> break/place &middot; <b>Q</b> cycles 7 slots (blocks &middot; HOE &middot; SEEDS) &middot; till grass, plant, let rain or a pond do the rest, break the GOLDEN crop = harvest &middot; <b>E</b> on a girl = meet her, <b>G</b> invites her to your party &middot; nights are the wardens' &middot; <b>H</b> home &middot; gamepad + touch<br>ISEKAI: your level, ledger and party travel with you &mdash; walk into <a href=\"beach\">NISHI SHORE</a> or <a href=\"vale\">NISHI VALE</a> &middot; <a href=\"craft_immersion\">what is broken and what is next</a>" 74const CE_MIN_WAT: i64 = 500000 75const CE_MIN_WASM: i64 = 50000 76const CE_MIN_PAGE: i64 = 100000 77const CE_MODE: i64 = 0x1a4 78 79func ce_slen(s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } return n } 80func ce_puts(s: *u8) -> i64 { sys_write(1, s, ce_slen(s)); return 0 } 81func ce_pn(v: i64) -> i64 { 82 if v == 0 { sys_write(1, "0" as *u8, 1); return 0 } 83 var m: i64 = v 84 if m < 0 { sys_write(1, "-" as *u8, 1); m = 0 - m } 85 let t: *u8 = sys_mmap(32) 86 var k: i64 = 0 87 while m > 0 { t[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 } 88 let o: *u8 = sys_mmap(32) 89 var i: i64 = 0 90 while i < k { o[i] = t[k - 1 - i]; i = i + 1 } 91 sys_write(1, o, k) 92 return 0 93} 94// BUILD STAMP (operator 2026-08-28: "i dont see any improvements" -- five ships landed that day and 95// nobody could say WHICH build a frame showed. Every page <title> and banner <h1> now carries the 96// emit wall-time, so "am I looking at the new build" is answerable at a glance, forever. The serve 97// path is already Cache-Control: no-cache (measured 2026-08-28), so a stale view was ruled out; 98// this closes the HUMAN half of version identity. Composes sys_now_realtime_sec (nx_syscalls). 99func ce_stamp(t: *u8) -> *u8 { 100 let o: *u8 = sys_mmap(192) 101 var i: i64 = 0 102 while t[i] != (0 as u8) { o[i] = t[i]; i = i + 1 } 103 o[i] = 32 as u8; o[i+1] = 98 as u8; i = i + 2 104 var m: i64 = sys_now_realtime_sec() 105 let d: *u8 = sys_mmap(32) 106 var k: i64 = 0 107 while m > 0 { d[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 } 108 while k > 0 { k = k - 1; o[i] = d[k]; i = i + 1 } 109 o[i] = 0 as u8 110 return o 111} 112// the nx_aw_push fork-a-sovereign-sub-ELF pattern (spine shared with nx_emu_probe_wasm_gate) 113// One fork/exec owner for retained small-call wrappers and compiler flag vectors. 114func ce_run_argv(elf: *u8,argv: *i64) -> i64 { 115 if (elf as i64) <= 0 { return 127 } 116 if (argv as i64) <= 0 { return 127 } 117 let envp: *i64 = sys_mmap(16) as *i64 118 if (envp as i64) <= 0 { return 127 } 119 let st: *i64 = sys_mmap(16) as *i64 120 if (st as i64) <= 0 { sys_munmap(envp as *u8,16); return 127 } 121 let envp0: *u8 = "PATH=/usr/bin:/bin" as *u8 122 envp[0] = envp0 as i64; envp[1] = 0 123 let pid: i64 = sys_fork() 124 if pid < 0 { sys_munmap(envp as *u8,16); sys_munmap(st as *u8,16); return 127 } 125 if pid == 0 { 126 sys_execve(elf,argv,envp) 127 sys_exit(127) 128 } 129 let waited: i64 = sys_wait4(pid,st,0) 130 var rc: i64 = 127 131 if waited == pid { rc = wait_status_rc(st[0]) } 132 sys_munmap(envp as *u8,16); sys_munmap(st as *u8,16) 133 return rc 134} 135func ce_run(elf: *u8,a1: *u8,a2: *u8) -> i64 { 136 let argv: *i64 = sys_mmap(4*8) as *i64 137 if (argv as i64) <= 0 { return 127 } 138 argv[0] = elf as i64 139 var ai: i64 = 1 140 if (a1 as i64) != 0 { argv[ai] = a1 as i64; ai = ai+1 } 141 if (a2 as i64) != 0 { argv[ai] = a2 as i64; ai = ai+1 } 142 argv[ai] = 0 143 let rc: i64 = ce_run_argv(elf,argv) 144 sys_munmap(argv as *u8,4*8) 145 return rc 146} 147func ce_run5(elf: *u8,a1: *u8,a2: *u8,a3: *u8,a4: *u8,a5: *u8) -> i64 { 148 let argv: *i64 = sys_mmap(7*8) as *i64 149 if (argv as i64) <= 0 { return 127 } 150 argv[0] = elf as i64 151 var ai: i64 = 1 152 if (a1 as i64) != 0 { argv[ai] = a1 as i64; ai = ai+1 } 153 if (a2 as i64) != 0 { argv[ai] = a2 as i64; ai = ai+1 } 154 if (a3 as i64) != 0 { argv[ai] = a3 as i64; ai = ai+1 } 155 if (a4 as i64) != 0 { argv[ai] = a4 as i64; ai = ai+1 } 156 if (a5 as i64) != 0 { argv[ai] = a5 as i64; ai = ai+1 } 157 argv[ai] = 0 158 let rc: i64 = ce_run_argv(elf,argv) 159 sys_munmap(argv as *u8,7*8) 160 return rc 161} 162// elf + two flag/value pairs + optional shared triple + source/output + null. 163const CE_COMPILE_ARG_WORDS: i64 = 1+2+2+3+2+1 164func ce_compiler_argv(out: *u8,shared_max: *u8,argv: *i64,words: i64,floor_text: *u8,limit_text: *u8) -> i64 { 165 if words < CE_COMPILE_ARG_WORDS { return 0-1 } 166 if (argv as i64) <= 0 { return 0-1 } 167 if (floor_text as i64) <= 0 { return 0-1 } 168 if (limit_text as i64) <= 0 { return 0-1 } 169 if (out as i64) <= 0 { return 0-1 } 170 let floor: i64 = wasm_arena_pages() 171 let limit: i64 = wasm_static_limit_pages() 172 if floor < 1 { return 0-2 }; if limit <= floor { return 0-2 } 173 if limit > CE_MT_PAGES_MAX { return 0-2 } 174 if wasm_static_base_off() != floor*WASM_PAGE_BYTES { return 0-2 } 175 if wasm_static_limit_off() != limit*WASM_PAGE_BYTES { return 0-2 } 176 if CRAFT_TOTAL > wasm_static_base_off() { return 0-2 } 177 ce_num_str(floor,floor_text); ce_num_str(limit,limit_text) 178 let arena_flag: *u8 = "--arena-pages" as *u8 179 let limit_flag: *u8 = "--static-limit-pages" as *u8 180 let source_floor: *u8 = "source" as *u8 181 argv[0] = CE_CWAT as i64 182 argv[1] = arena_flag as i64; argv[2] = floor_text as i64 183 argv[3] = limit_flag as i64; argv[4] = limit_text as i64 184 var ai: i64 = 5 185 if (shared_max as i64) != 0 { 186 argv[ai] = CE_SHARED as i64; argv[ai+1] = source_floor as i64; argv[ai+2] = shared_max as i64 187 ai = ai+3 188 } 189 argv[ai] = CE_SRC as i64; argv[ai+1] = out as i64; argv[ai+2] = 0 190 return ai+2 191} 192func ce_compile_craft(out: *u8,shared_max: *u8) -> i64 { 193 let argv: *i64 = sys_mmap(CE_COMPILE_ARG_WORDS*8) as *i64 194 if (argv as i64) <= 0 { return 3 } 195 let floor_text: *u8 = sys_mmap(32) 196 if (floor_text as i64) <= 0 { sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8); return 3 } 197 let limit_text: *u8 = sys_mmap(32) 198 if (limit_text as i64) <= 0 { sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8); sys_munmap(floor_text,32); return 3 } 199 let argc: i64 = ce_compiler_argv(out,shared_max,argv,CE_COMPILE_ARG_WORDS,floor_text,limit_text) 200 var rc: i64 = 3 201 if argc < 0 { ce_puts("CRAFT compiler layout contract refused\n" as *u8) } 202 if argc >= 0 { rc = ce_run_argv(CE_CWAT,argv) } 203 sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8) 204 sys_munmap(floor_text,32); sys_munmap(limit_text,32) 205 return rc 206} 207 208// ce_num_str -- i64 to decimal into caller storage, NUL terminated, for argv. 209func ce_num_str(v: i64, b: *u8) -> i64 { 210 if v == 0 { b[0] = 48 as u8; b[1] = 0 as u8; return 1 } 211 var t: i64 = v 212 var d: i64 = 0 213 while t > 0 { d = d + 1; t = t / 10 } 214 b[d] = 0 as u8 215 var k: i64 = d 216 t = v 217 while k > 0 { k = k - 1; b[k] = ((t % 10) + 48) as u8; t = t / 10 } 218 return d 219} 220// ce_wat_pages -- READ THE PAGE COUNT OFF THE ARTIFACT THE COMPILER JUST WROTE, never a constant. 221// The plain build declares `(memory (export "memory") N)`; N is the module's own arena sizing and 222// it moves whenever the engine grows. A hand-copied twin of that number is a second ruler that 223// drifts silently, and the failure mode is a shared memory too small for the framebuffer -- the 224// exact class that shipped /craft black twice. Returns the count, or a NEGATIVE reason code. 225func ce_wat_pages(p: *u8) -> i64 { 226 let box: *i64 = sys_mmap(16) as *i64 227 let b: *u8 = sys_read_file(p, box) 228 if (b as i64) == 0 { return 0 - 1 } 229 let n: i64 = box[0] 230 let needle: *u8 = "(memory (export " as *u8 231 let nl: i64 = ce_slen(needle) 232 var i: i64 = 0 233 var at: i64 = 0 - 1 234 while i + nl <= n { 235 var j: i64 = 0 236 var hit: i64 = 1 237 while j < nl { if b[i + j] != needle[j] { hit = 0; j = nl } else { j = j + 1 } } 238 if hit == 1 { at = i; i = n } else { i = i + 1 } 239 } 240 if at < 0 { return 0 - 2 } 241 var k: i64 = at + nl 242 var v: i64 = 0 243 var seen: i64 = 0 244 while k < n { 245 let c: i64 = b[k] as i64 246 if c >= 48 { 247 if c <= 57 { v = v * 10 + (c - 48); seen = 1; k = k + 1 } 248 else { if seen == 1 { k = n } else { k = k + 1 } } 249 } else { if seen == 1 { k = n } else { k = k + 1 } } 250 } 251 if seen == 0 { return 0 - 3 } 252 return v 253} 254func ce_find(hay: *u8, n: i64, needle: *u8) -> i64 { 255 let nl: i64 = ce_slen(needle) 256 if nl == 0 { return 1 } 257 var i: i64 = 0 258 while i + nl <= n { 259 var j: i64 = 0 260 var hit: i64 = 1 261 while j < nl { if hay[i + j] != needle[j] { hit = 0; j = nl } else { j = j + 1 } } 262 if hit == 1 { return 1 } 263 i = i + 1 264 } 265 return 0 266} 267func ce_fsize(p: *u8) -> i64 { 268 let box: *i64 = sys_mmap(16) as *i64 269 let b: *u8 = sys_read_file(p, box) 270 if (b as i64) == 0 { return 0 - 1 } 271 return box[0] 272} 273 274// cw_npc_atlas -- SHIP-TIME ASSERTION for the atlas rung (the comparewatch contract named 275// cw_npc_atlas in BOTH the charsim and graphics planes): a world page may not ship unless 276// (a) the page carries the NPC-atlas sampling path (the uAtl sampler and the npc_atlas runtime 277// marker) and (b) the served NPC asset carries TEXC+TEXM -- the very maps the page will sample. 278// A clay ship -- either half missing -- REFUSES here, loudly, with the missing half named. 279// This is the flip's PROOF-side twin: the watch measures the symbol; this function makes the 280// symbol load-bearing, because a page that stopped sampling cannot reach the docroot again. 281const CW_NPC_ASSET: *u8 = "sites/nishifamily/world/ref9d.nxa" 282func cw_rd64(b: *u8, off: i64) -> i64 { var v: i64 = 0; var k: i64 = 7; while k >= 0 { v = v*256 + (b[off+k] as i64); k = k - 1 } return v } 283func cw_tag4(b: *u8, off: i64, t: *u8) -> i64 { if b[off] == t[0] { if b[off+1] == t[1] { if b[off+2] == t[2] { if b[off+3] == t[3] { return 1 } } } } return 0 } 284// ---- GR29: THE ADEQUACY CONJUNCT ----------------------------------------------------------- 285// Everything cw_npc_atlas asks below this line is an EXISTENCE question -- is the sampler path in 286// the page, is there a TEXM in the asset. None of them asks the one question that decides whether 287// a viewer sees skin or painted clay: DOES THE ATLAS ACTUALLY CARRY THE BANDS THE BAKER COMPUTED? 288// nx_nxa_texbake_lib has said so in PROSE since it was written -- "at whole body a texel is ~415um, 289// so fine wrinkles (~1.2mm) resolve and PORES (~100um) DO NOT" -- and nothing enforced it, so a 290// bake that computes three bands and clamps two away has been shipping GREEN. 291// 292// THE RESOLUTION IS READ, NEVER ASSUMED. TEXM's payload carries it as header word TXM_W_RES=1 293// (nx_nxa_texm.nx: [nmaps][res][pbr_model][seed][hue][blob_words]) and the TOC entry carries that 294// payload's byte offset at +8, so this reads the resolution the asset was ACTUALLY baked at. 295// Deliberately NOT a constant: hoisting a 2048 to a named const would satisfy the magic-number 296// ratchet and leave the clamp exactly where it is. DERIVATION, NOT NAMING. 297// 298// THE BAR IS rlf_band_resolvable -- THE SAME PREDICATE THE BAKER CLAMPS WITH, imported, not copied. 299// A second copy of that rule here would be the duplicate-ruler defect in the one place it must not 300// be, because the two would drift and the gate would then disagree with the thing it audits. 301// A band under two texels is not baked faint: it is baked as a DIFFERENT, COARSER band wearing its 302// name, which is exactly why the presence of a TEXM proves nothing at all. 303// 304// AMBER, NOT RED, AND THAT IS A DECISION WITH A REASON. At the resolution the cast ships at today 305// every declared band reads carried=0, so a RED here would refuse every world ship from the moment 306// it landed -- the permanently-red detector everyone learns to ignore. It NAMES the band, prints 307// the texel and prints the resolution that would carry it, and does not block. When a per-region 308// atlas lands this goes quiet by itself, which is the shape a ratchet should have. 309const CW_FACE_SPAN_UM: i64 = 250000 // a 250mm head region: the per-region atlas this argues for 310func cw_band_line(nm: *u8, lambda_um: i64, res: i64) -> i64 { 311 let carried: i64 = rlf_band_resolvable(res, lambda_um) 312 ce_puts(" band " as *u8); ce_puts(nm); ce_puts(" lambda=" as *u8); ce_pn(lambda_um) 313 ce_puts("um carried=" as *u8); ce_pn(carried) 314 if carried == 0 { 315 ce_puts(" NEEDS res>=" as *u8); ce_pn(rlf_band_res_needed(RLF_BODY_UM, lambda_um)) 316 ce_puts(" whole-body, or >=" as *u8); ce_pn(rlf_band_res_needed(CW_FACE_SPAN_UM, lambda_um)) 317 ce_puts(" over a 250mm region" as *u8) 318 } 319 ce_puts("\n" as *u8) 320 return carried 321} 322// ---- GE68: THE CHART THE FACE ACTUALLY GETS, MEASURED FROM THE ASSET ------------------------ 323// The whole-body figure below divides RLF_BODY_UM by res, i.e. it ASSUMES the body maps uniformly 324// onto the atlas. It does not. TEXC hands every joint an EQUAL tile of a g x g grid (ntx_apply: 325// g = nt_grid(nj), tw = Q16/g), so the head is allotted exactly the texels a finger is, and the 326// whole-body number describes NO CHART THAT EXISTS. This reads g from TEXC and each bone's own 327// bind span from SKEL and asks the SAME rlf_*_span rulers what each real chart carries -- one 328// convention, never a second. It only ever ADDS lines; the verdict below is untouched. 329// SCOPE, DECLARED RATHER THAN GLOSSED: the unwrap's v axis is the bone length and its u axis is 330// the circumference around it. This measures the V AXIS ONLY -- the u axis needs a limb radius no 331// section carries, so it is named UNMEASURED instead of assumed. An axis that cannot see abstains. 332const CW_NXA_UNIT_UM: i64 = 10 // VERT/SKEL units are 0.01 mm, so one unit is ten microns 333const CW_SKEL_W: i64 = 8 // words per joint: parent, tx ty tz, qx qy qz qw 334const CW_TEXC_W_G: i64 = 2 // TEXC payload word 2 is the atlas grid g 335func cw_bone_span_um(ab: *u8, skoff: i64, nj: i64, j: i64) -> i64 { 336 let par: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W)*8) 337 if par < 0 { return 0 } 338 if par >= nj { return 0 } 339 let jx: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 1)*8) 340 let jy: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 2)*8) 341 let jz: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 3)*8) 342 let px: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 1)*8) 343 let py: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 2)*8) 344 let pz: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 3)*8) 345 let dx: i64 = jx - px 346 let dy: i64 = jy - py 347 let dz: i64 = jz - pz 348 let d2: i64 = dx*dx + dy*dy + dz*dz 349 if d2 <= 0 { return 0 } 350 return nf_isqrt(d2) * CW_NXA_UNIT_UM 351} 352// GE67b: the chart's v axis is its rect HEIGHT (v01 scales by rh in ntx_apply), so its texel 353// count is h*res/Q16. rectoff<=0 is a legacy asset with no table: fall back to the uniform cell 354// and let the caller say so, rather than reporting a rect that was never cut. 355const CW_Q16: i64 = 65536 356func cw_chart_vres(ab: *u8, tc: i64, rectoff: i64, j: i64, res: i64, g: i64) -> i64 { 357 if rectoff <= 0 { return res / g } 358 let h: i64 = cw_rd64(ab, tc + (rectoff + j*4 + 3)*8) 359 if h <= 0 { return res / g } 360 return h * res / CW_Q16 361} 362func cw_chart_line(nm: *u8, jj: i64, span: i64, cres: i64) -> i64 { 363 let m: i64 = rlf_bands_carried_span(span, cres) 364 let n: i64 = rlf_bands_count(m) 365 ce_puts(" chart " as *u8); ce_puts(nm) 366 ce_puts(" joint=" as *u8); ce_pn(jj) 367 ce_puts(" span=" as *u8); ce_pn(span) 368 ce_puts("um res=" as *u8); ce_pn(cres) 369 ce_puts(" texel=" as *u8); ce_pn(rlf_texel_um_span(span, cres)) 370 ce_puts("um bands_carried=" as *u8); ce_pn(n) 371 ce_puts(" of 4 (v axis only; u axis UNMEASURED)\n" as *u8) 372 return n 373} 374func cw_chart_adequacy(ab: *u8, res: i64) -> i64 { 375 let ns: i64 = cw_rd64(ab, 16) 376 var tc: i64 = 0 - 1 377 var sk: i64 = 0 - 1 378 var s: i64 = 0 379 while s < ns { 380 let e: i64 = 32 + s*32 381 if cw_tag4(ab, e, "TEXC" as *u8) == 1 { tc = cw_rd64(ab, e + 8) } 382 if cw_tag4(ab, e, "SKEL" as *u8) == 1 { sk = cw_rd64(ab, e + 8) } 383 s = s + 1 384 } 385 if tc < 0 { ce_puts(" npc-atlas per-chart UNMEASURED: no TEXC, so no chart layout to read\n" as *u8); return 0 - 1 } 386 if sk < 0 { ce_puts(" npc-atlas per-chart UNMEASURED: no SKEL, so no bone span to measure against\n" as *u8); return 0 - 1 } 387 let g: i64 = cw_rd64(ab, tc + CW_TEXC_W_G*8) 388 let nj: i64 = cw_rd64(ab, sk) 389 if g < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: TEXC carries no usable grid word\n" as *u8); return 0 - 1 } 390 if nj < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: SKEL carries no joints\n" as *u8); return 0 - 1 } 391 // GE67b landed a per-joint rect table in TEXC payload word 3 (0 on a legacy asset, which is 392 // exactly the uniform-grid signal). Read it when present so this check measures the chart the 393 // allocator ACTUALLY cut, and falls back to the uniform cell only when there is no table. 394 let rectoff: i64 = cw_rd64(ab, tc + 3*8) 395 let cres: i64 = res / g 396 var hj: i64 = 0 - 1 397 var hz: i64 = 0 398 var wj: i64 = 0 - 1 399 var wspan: i64 = 0 400 var hspan: i64 = 0 401 var measured: i64 = 0 402 var j: i64 = 0 403 while j < nj { 404 let sp: i64 = cw_bone_span_um(ab, sk, nj, j) 405 if sp > 0 { 406 measured = measured + 1 407 let z: i64 = cw_rd64(ab, sk + 8 + (j*CW_SKEL_W + 3)*8) 408 if hj < 0 { hj = j; hz = z; hspan = sp } 409 if z > hz { hj = j; hz = z; hspan = sp } 410 if sp > wspan { wspan = sp; wj = j } 411 } 412 j = j + 1 413 } 414 ce_puts(" npc-atlas PER-CHART (GE68): a chart is a FRACTION of the atlas, never the " as *u8); ce_pn(res) 415 ce_puts(" the whole-body line above divides by; the legacy uniform cell of the " as *u8); ce_pn(g) 416 ce_puts("x" as *u8); ce_pn(g); ce_puts(" grid would be " as *u8); ce_pn(cres) 417 ce_puts(" texels, and each chart's REAL size is on its own line below.\n" as *u8) 418 ce_puts(" charts_with_a_span=" as *u8); ce_pn(measured); ce_puts(" of " as *u8); ce_pn(nj) 419 ce_puts(" joints (a root has no parent bone and no span: counted out, never counted in)\n" as *u8) 420 if measured < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: no joint carries a parent bone\n" as *u8); return 0 - 1 } 421 if rectoff > 0 { ce_puts(" allocation=PER-REGION (GE67b rect table present at payload word 3)\n" as *u8) } 422 if rectoff <= 0 { ce_puts(" allocation=LEGACY-UNIFORM (no rect table: every joint gets one equal cell)\n" as *u8) } 423 let hb: i64 = cw_chart_line("highest (the head, what a close-up reads)" as *u8, hj, hspan, cw_chart_vres(ab, tc, rectoff, hj, res, g)) 424 let wb: i64 = cw_chart_line("longest (the worst chart on the body) " as *u8, wj, wspan, cw_chart_vres(ab, tc, rectoff, wj, res, g)) 425 // NEG-CONTROL, evaluated every run: a uniform grid of ONE tile would make the per-chart 426 // measure identical to the whole-body one and this whole axis decorative. g > 1 is what makes 427 // the two spans different questions, so it is asserted here rather than assumed. 428 ce_puts(" neg-control chart-is-not-the-atlas: g=" as *u8); ce_pn(g) 429 if g <= 1 { ce_puts(" <== CONTROL FAILED: one tile means the chart IS the atlas and this axis is decorative\n" as *u8) } 430 if g > 1 { ce_puts(" OK (a chart is a fraction of the atlas, so the two spans are different questions)\n" as *u8) } 431 if hb > wb { ce_puts(" the head chart carries MORE than the worst body chart at the same tile size\n" as *u8) } 432 return hb 433} 434func cw_atlas_adequate(ab: *u8, tmoff: i64) -> i64 { 435 let res: i64 = cw_rd64(ab, tmoff + 8) 436 if res <= 0 { 437 ce_puts(" npc-atlas adequacy UNMEASURED: TEXM carries no usable RES word (read " as *u8) 438 ce_pn(res) 439 ce_puts("). NOT scored -- an axis that cannot see must abstain, never acquit.\n" as *u8) 440 return 0 - 1 441 } 442 ce_puts(" npc-atlas ADEQUACY at the resolution this asset was BAKED at: res=" as *u8) 443 ce_pn(res); ce_puts(" texel=" as *u8); ce_pn(rlf_texel_um(res)) 444 ce_puts("um over a " as *u8); ce_pn(RLF_BODY_UM); ce_puts("um body\n" as *u8) 445 var carried: i64 = 0 446 carried = carried + cw_band_line("primary " as *u8, RLF_RELIEF_LAMBDA_UM, res) 447 carried = carried + cw_band_line("secondary" as *u8, RLF_SEC_LAMBDA_UM, res) 448 carried = carried + cw_band_line("pore-grid" as *u8, RLF_PORE_PITCH_UM, res) 449 // The pore ORIFICE is a STRICTER bar than its lattice and they are NOT the same question: a 450 // grid that resolves while the 100um pit does not gives evenly spaced sub-texel dimples -- the 451 // lattice reads and the pore does not. Named separately so nobody reports the easier number 452 // and calls the pore band carried. 453 carried = carried + cw_band_line("pore-orif" as *u8, RLF_PORE_DIA_UM, res) 454 // NEG-CONTROL, evaluated every run: the whole-body span must keep reporting 0 for a band that a 455 // 250mm region carries. If these two ever agree, the span has been quietly redefined and this 456 // whole check has become decorative -- which is the failure mode an adequacy check invites. 457 let wb: i64 = rlf_band_resolvable_span(RLF_BODY_UM, res, RLF_SEC_LAMBDA_UM) 458 let rg: i64 = rlf_band_resolvable_span(CW_FACE_SPAN_UM, res, RLF_SEC_LAMBDA_UM) 459 ce_puts(" neg-control span-discriminates: whole-body=" as *u8); ce_pn(wb) 460 ce_puts(" region=" as *u8); ce_pn(rg) 461 if wb == rg { 462 ce_puts(" <== CONTROL FAILED: the span no longer discriminates, this check is decorative\n" as *u8) 463 } 464 if wb != rg { ce_puts(" OK (the region carries what the whole body cannot)\n" as *u8) } 465 cw_chart_adequacy(ab, res) 466 if carried < 4 { 467 ce_puts(" NPC-ATLAS AMBER: " as *u8); ce_pn(4 - carried) 468 ce_puts(" of 4 declared bands are COMPUTED BY THE BAKER AND CLAMPED AWAY at this resolution.\n" as *u8) 469 ce_puts(" REMEDY IS A PER-REGION ATLAS, NOT A BIGGER WHOLE-BODY ONE: the whole-body numbers\n" as *u8) 470 ce_puts(" above are absurd, the 250mm-region ones are already met by the resolution we ship.\n" as *u8) 471 ce_puts(" Advisory by design: a detector that is permanently RED is one everyone ignores.\n" as *u8) 472 } 473 return carried 474} 475func cw_npc_atlas(page: *u8, pn: i64) -> i64 { 476 if ce_find(page, pn, "uAtl" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the uAtl sampler path\n" as *u8); return 1 } 477 if ce_find(page, pn, "npc_atlas" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the npc_atlas runtime marker\n" as *u8); return 1 } 478 if ce_find(page, pn, "NXNPCS=[" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the NXNPCS visiting-cast roster\n" as *u8); return 1 } 479 if ce_find(page, pn, "loadDonors" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the loadDonors path\n" as *u8); return 1 } 480 if ce_find(page, pn, "uAuth" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the authored-surface (uAuth) mode\n" as *u8); return 1 } 481 if ce_find(page, pn, "NXNPCS=[" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the NXNPCS visiting-cast roster\n" as *u8); return 1 } 482 if ce_find(page, pn, "loadDonors" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the loadDonors path\n" as *u8); return 1 } 483 if ce_find(page, pn, "uAuth" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the authored-surface (uAuth) mode\n" as *u8); return 1 } 484 let box9: *i64 = sys_mmap(16) as *i64 485 let ab: *u8 = sys_read_file(CW_NPC_ASSET, box9) 486 if (ab as i64) == 0 { ce_puts("NPC-ATLAS RED: NPC asset unreadable\n" as *u8); return 1 } 487 let ns9: i64 = cw_rd64(ab, 16) 488 var texc: i64 = 0 489 var texm: i64 = 0 490 var tmoff: i64 = 0 491 var s9: i64 = 0 492 while s9 < ns9 { 493 let e9: i64 = 32 + s9*32 494 if cw_tag4(ab, e9, "TEXC" as *u8) == 1 { texc = 1 } 495 if cw_tag4(ab, e9, "TEXM" as *u8) == 1 { texm = 1; tmoff = cw_rd64(ab, e9 + 8) } 496 s9 = s9 + 1 497 } 498 if texc == 0 { ce_puts("NPC-ATLAS RED: asset has no TEXC (no UVs to sample with)\n" as *u8); return 1 } 499 if texm == 0 { ce_puts("NPC-ATLAS RED: asset has no TEXM (no maps to sample)\n" as *u8); return 1 } 500 ce_puts("npc-atlas GREEN (page samples, asset carries TEXC+TEXM, sections=" as *u8); ce_pn(ns9); ce_puts(")\n" as *u8) 501 cw_atlas_adequate(ab, tmoff) 502 return 0 503} 504 505// cw_donors -- SHIP-TIME ASSERTION for the visiting cast (donors-into-world 2026-08-23): every 506// roster row in knowledge/world_npcs.conf must resolve to a SERVED asset carrying TEXC+TEXM. 507// A page that names a cast the docroot cannot serve, or a visitor that would arrive clay, 508// REFUSES the ship with the donor named. Absent conf = empty cast = GREEN (declared fallback, 509// never silence). This is the load-bearing twin of the page-side per-visitor refusal legs. 510func cw_donors() -> i64 { 511 let ln: *i64 = sys_mmap(16) as *i64 512 let buf: *u8 = sys_read_file("knowledge/world_npcs.conf" as *u8, ln) 513 if (buf as i64) == 0 { ce_puts("visiting-cast: conf absent, empty cast (declared)\n" as *u8); return 0 } 514 let n: i64 = ln[0] 515 var i: i64 = 0 516 var checked: i64 = 0 517 while i < n { 518 let ls: i64 = i 519 var le: i64 = ls 520 var scan: i64 = 1 521 while scan == 1 { if le >= n { scan = 0 } else { if buf[le] == (10 as u8) { scan = 0 } else { le = le + 1 } } } 522 if le >= n { ce_puts("VISITING-CAST RED: npcs.conf has no trailing newline\n" as *u8); return 1 } 523 i = le + 1 524 if le > ls { if buf[ls] != (35 as u8) { 525 buf[le] = 0 as u8 526 var q: i64 = ls 527 var asx: i64 = 0 528 var nf: i64 = 0 529 while q < le { 530 if buf[q] == (9 as u8) { buf[q] = 0 as u8; nf = nf + 1; if nf == 1 { asx = q + 1 } } 531 q = q + 1 532 } 533 if nf < 3 { ce_puts("VISITING-CAST RED: npcs.conf row needs 4 tab fields\n" as *u8); return 1 } 534 let pth: *u8 = sys_mmap(256) 535 var w: i64 = 0 536 let pre: *u8 = "sites/nishifamily/world/" as *u8 537 while pre[w] != (0 as u8) { pth[w] = pre[w]; w = w + 1 } 538 var a2: i64 = asx 539 while buf[a2] != (0 as u8) { pth[w] = buf[a2]; w = w + 1; a2 = a2 + 1 } 540 let sfx: *u8 = ".nxa" as *u8 541 var s2: i64 = 0 542 while sfx[s2] != (0 as u8) { pth[w] = sfx[s2]; w = w + 1; s2 = s2 + 1 } 543 pth[w] = 0 as u8 544 let bx: *i64 = sys_mmap(16) as *i64 545 let ab: *u8 = sys_read_file(pth, bx) 546 if (ab as i64) == 0 { ce_puts("VISITING-CAST RED: donor asset unreadable: " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 } 547 let ns9: i64 = cw_rd64(ab, 16) 548 var texc: i64 = 0 549 var texm: i64 = 0 550 var s9: i64 = 0 551 while s9 < ns9 { 552 let e9: i64 = 32 + s9*32 553 if cw_tag4(ab, e9, "TEXC" as *u8) == 1 { texc = 1 } 554 if cw_tag4(ab, e9, "TEXM" as *u8) == 1 { texm = 1 } 555 s9 = s9 + 1 556 } 557 if texc == 0 { ce_puts("VISITING-CAST RED: donor lacks TEXC: " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 } 558 if texm == 0 { ce_puts("VISITING-CAST RED: donor lacks TEXM (clay visitor): " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 } 559 checked = checked + 1 560 } } 561 } 562 ce_puts("visiting-cast GREEN (donors verified TEXC+TEXM: " as *u8); ce_pn(checked); ce_puts(")\n" as *u8) 563 return 0 564} 565 566// ===== PUBLISHED EVIDENCE, COMPUTED AT EMIT TIME ========================================= 567// Operator standing requirement 2026-08-25: the beach must PUBLISH its own evidence so the 568// claim cannot drift from the code. Transcribed prose rots -- these figures are CALLED out of 569// the shipping derivation (nx_softbind), so the page and the physics are the SAME SOURCE. If 570// the derivation moves, this line moves with it; there is nothing to keep in sync by hand. 571const CE_EV_CAP: i64 = 8192 572func ce_cat(d: *u8, p: i64, s: *u8) -> i64 { 573 var i: i64 = 0 574 while s[i] != (0 as u8) { d[p+i] = s[i]; i = i + 1 } 575 return p + i 576} 577func ce_catn(d: *u8, p: i64, v: i64) -> i64 { 578 if v == 0 { d[p] = 48 as u8; return p + 1 } 579 var t: i64 = v 580 var n: i64 = 0 581 while t > 0 { t = t/10; n = n + 1 } 582 var k: i64 = n 583 var u: i64 = v 584 while k > 0 { d[p+k-1] = ((u % 10) + 48) as u8; u = u/10; k = k - 1 } 585 return p + n 586} 587func ce_evidence(base_ctrl: *u8, out: *u8) -> i64 { 588 var p: i64 = ce_cat(out, 0, base_ctrl) 589 p = ce_cat(out, p, "<br><b>TISSUE PHYSICS, DERIVED NOT TUNED</b> &mdash; every figure here is COMPUTED by the shipping solver as this page is written, so it cannot drift from the code running above it. Chest plant " as *u8) 590 p = ce_catn(out, p, sb_fn_mhz(0)) 591 p = ce_cat(out, p, "&ndash;" as *u8) 592 p = ce_catn(out, p, sb_fn_mhz(SB_FIRM_MAX)) 593 p = ce_cat(out, p, " mHz across bred bodies (cited tissue_fn_mhz 4000&ndash;5200, free-vibration modes) &middot; damping " as *u8) 594 p = ce_catn(out, p, SB_ZETA_PERMIL) 595 p = ce_cat(out, p, " permil (haake-scurr-2010 measured 475, and what our own XPBD ringdown read) &middot; downward stiffness " as *u8) 596 p = ce_catn(out, p, sb_k_dn(sb_fn_mhz(0))*10/sb_k_up(sb_fn_mhz(0))) 597 p = ce_cat(out, p, " tenths of the upward branch (cai2018 piecewise, selected by one sign test) &middot; anisotropy AP " as *u8) 598 p = ce_catn(out, p, SB_ANISO_AP_PERMIL) 599 p = ce_cat(out, p, " / ML " as *u8) 600 p = ce_catn(out, p, SB_ANISO_ML_PERMIL) 601 p = ce_cat(out, p, " permil of vertical (mills2025) &middot; " as *u8) 602 p = ce_catn(out, p, SB_FULL_N) 603 p = ce_cat(out, p, " distinct bodies drawn from each girl's whole genome, where there were 4 &middot; proven by nx_gamefeel_oracle_gate and nx_softbind_gate." as *u8) 604 out[p] = 0 as u8 605 return p 606} 607 608func main() -> i64 { 609 // 1) THE GATE DECIDES: a RED world ships nothing (the emit script's step-2 law) 610 ce_puts("[1/5] gate " as *u8) 611 let g: i64 = ce_run(CE_GATE, 0 as *u8, 0 as *u8) 612 if g != 0 { ce_puts("RED rc=" as *u8); ce_pn(g); ce_puts(" -- REFUSED, nothing emitted\n" as *u8); return 2 } 613 ce_puts("GREEN\n" as *u8) 614 615 // 1b) THE FEEL ORACLE: every tunable inside its banked, cited reference band (the KAT 616 // pattern applied to feel) -- out-of-band tuning cannot ship through this lane 617 ce_puts("[1b/5] feel-oracle " as *u8) 618 let g2: i64 = ce_run("nx_gamefeel_oracle_gate.elf" as *u8, 0 as *u8, 0 as *u8) 619 if g2 != 0 { ce_puts("RED rc=" as *u8); ce_pn(g2); ce_puts(" -- REFUSED, nothing emitted\n" as *u8); return 2 } 620 ce_puts("GREEN\n" as *u8) 621 622 // 1c) THE VISITING CAST: roster-declared donors must be servable and textured BEFORE any 623 // page is built around them (the ship-time twin of the page-side per-visitor refusals). 624 ce_puts("[1c/5] visiting-cast " as *u8) 625 if cw_donors() != 0 { ce_puts("-- REFUSED, nothing emitted\n" as *u8); return 2 } 626 627 // 2) .nx -> .wat (byte-asserted: the historic silent 0-byte .wat is the class this kills) 628 let r1: i64 = ce_compile_craft(CE_WAT,0 as *u8) 629 let wn1: i64 = ce_fsize(CE_WAT) 630 ce_puts("[2/5] wat rc=" as *u8); ce_pn(r1); ce_puts(" bytes=" as *u8); ce_pn(wn1); ce_puts("\n" as *u8) 631 if wn1 < CE_MIN_WAT { ce_puts("EMIT-FAIL: wat under floor\n" as *u8); return 3 } 632 633 // 3) .wat -> .wasm (magic-checked -- a "GREEN" assembler on empty input still writes a stub) 634 let r2: i64 = ce_run(CE_WATC, CE_WAT, CE_WASM) 635 let box: *i64 = sys_mmap(16) as *i64 636 let wasm: *u8 = sys_read_file(CE_WASM, box) 637 ce_puts("[3/5] wasm rc=" as *u8); ce_pn(r2); ce_puts(" bytes=" as *u8); ce_pn(box[0]); ce_puts("\n" as *u8) 638 if (wasm as i64) == 0 { ce_puts("EMIT-FAIL: no wasm\n" as *u8); return 4 } 639 if box[0] < CE_MIN_WASM { ce_puts("EMIT-FAIL: wasm under floor\n" as *u8); return 4 } 640 if wasm[0] != (0 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 } 641 if wasm[1] != (97 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 } 642 if wasm[2] != (115 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 } 643 if wasm[3] != (109 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 } 644 645 // 3b) ★RUN THE WASM WE JUST BUILT, IN THE MEMORY THE BROWSER WILL GIVE IT. 646 // Every check above this line inspects the wasm as BYTES -- size floors and the magic header. 647 // None of them can tell a module that RUNS from one that traps on its first frame. On 2026-08-14 648 // /craft shipped black TWICE through this pipeline: the arena had outgrown the module's declared 649 // linear memory, so the browser trapped with "index out of bounds", while every stage here 650 // reported GREEN and the NATIVE gate at [1/5] reported 59/59 -- because that gate sys_mmaps its 651 // own arena and therefore never meets the wasm bound at all. 652 // ★A PIPELINE THAT VALIDATES A DIFFERENT BUILD THAN THE ONE IT SHIPS IS NOT VALIDATING THE 653 // PRODUCT. nx_wasm_craft_vm_gate loads THIS file into the estate's own VM with memory sized to 654 // exactly what the module declares, proves the framebuffer fits at q=1, and renders a frame to 655 // prove the renderer actually executes. Placed HERE, after the wasm exists and before any page 656 // is written, so a module that cannot run can no longer reach a visitor. 657 ce_puts("[3b/5] wasm-vm " as *u8) 658 let g3: i64 = ce_run(CE_VMGATE, 0 as *u8, 0 as *u8) 659 if g3 != 0 { ce_puts("RED rc=" as *u8); ce_pn(g3); ce_puts(" -- the built wasm does not run in its own declared memory; REFUSED, nothing emitted\n" as *u8); return 4 } 660 ce_puts("GREEN\n" as *u8) 661 662 // 3c) GE30 THE THREADED TWIN. Same source, same generation, IMPORTED shared memory. Its page 663 // count is read off the plain wat above so the two builds can never disagree about the arena. 664 // ★IT MAY NOT REFUSE THE SHIP. Threading is a door on a ladder, not a requirement: a visitor 665 // without cross-origin isolation must still get the world. But a STALE twin is worse than no 666 // twin -- it would serve a DIFFERENT engine generation to isolated visitors than the inlined 667 // build every other visitor runs -- so any failure RETIRES the live file instead of leaving it. 668 // ★A WRONG-BUT-POSITIVE PARSE IS THE DANGEROUS CASE: the twin would build, carry a real shared 669 // import, pass every magic and floor check, and hand isolated visitors a memory too small for 670 // the framebuffer -- a trap on the first frame, which is exactly how /craft shipped black. A 671 // plausibility band turns that silent class into a named refusal. 16 pages is 1 MiB, under 672 // which no 3D arena fits; 65536 pages is the wasm32 ceiling, so anything outside is parse junk. 673 var mtp: i64 = ce_wat_pages(CE_WAT) 674 if mtp > 0 { 675 if mtp < CE_MT_PAGES_MIN { 676 ce_puts("[3c/5] mt page count " as *u8); ce_pn(mtp) 677 ce_puts(" is below the ") ; ce_pn(CE_MT_PAGES_MIN) 678 ce_puts("-page floor -- treating as a PARSE FAILURE, not an arena\n" as *u8) 679 mtp = 0 - 4 680 } 681 if mtp > CE_MT_PAGES_MAX { 682 ce_puts("[3c/5] mt page count " as *u8); ce_pn(mtp) 683 ce_puts(" exceeds the wasm32 ceiling -- treating as a PARSE FAILURE\n" as *u8) 684 mtp = 0 - 5 685 } 686 } 687 var mt_ok: i64 = 0 688 let mt_limits: *i64=sys_mmap(WM_FIELDS*8) as *i64 689 if mtp < 1 { 690 ce_puts("[3c/5] mt SKIPPED: could not read the page count off the plain wat (code " as *u8) 691 ce_pn(mtp); ce_puts(")\n" as *u8) 692 } else { 693 let pbuf: *u8 = sys_mmap(32) 694 let mbuf: *u8 = sys_mmap(32) 695 ce_num_str(mtp, pbuf) 696 ce_num_str(mtp * CE_MT_HEADROOM, mbuf) 697 // Preserve source-derived addresses; the plain module already includes static data. 698 let m1: i64 = ce_compile_craft(CE_WAT_MT,mbuf) 699 let mw: i64 = ce_fsize(CE_WAT_MT) 700 ce_puts("[3c/5] mt wat rc=" as *u8); ce_pn(m1) 701 ce_puts(" pages=" as *u8); ce_pn(mtp) 702 ce_puts(" max=" as *u8); ce_pn(mtp * CE_MT_HEADROOM) 703 ce_puts(" bytes=" as *u8); ce_pn(mw); ce_puts("\n" as *u8) 704 if m1 == 0 { 705 if mw >= CE_MIN_WAT { 706 let m2: i64 = ce_run(CE_WATC, CE_WAT_MT, CE_MT_TMP) 707 let mbox: *i64 = sys_mmap(16) as *i64 708 let mbytes: *u8 = sys_read_file(CE_MT_TMP, mbox) 709 if m2 == 0 { 710 if (mbytes as i64) != 0 { 711 if mbox[0] >= CE_MIN_WASM { 712 // Same magic check the shipped build gets: a GREEN assembler on bad 713 // input still writes a stub, and a stub would trap on the visitor. 714 var mg: i64 = 1 715 if mbytes[0] != (0 as u8) { mg = 0 } 716 if mbytes[1] != (97 as u8) { mg = 0 } 717 if mbytes[2] != (115 as u8) { mg = 0 } 718 if mbytes[3] != (109 as u8) { mg = 0 } 719 if mg == 1 { 720 // The twin must carry an IMPORTED memory. Without it every Worker 721 // gets a PRIVATE memory, no thread sees another's pixels, and the 722 // page would render a torn frame while every byte check passed. 723 let wbox: *i64 = sys_mmap(16) as *i64 724 let wsrc: *u8 = sys_read_file(CE_WAT_MT, wbox) 725 var imp: i64 = 0 726 // " shared))" closes the memory IMPORT and nothing else: the 727 // unshared path writes "(memory (export ...) N)" with no such 728 // token. A bare "memory 0)" would also match memory.init/copy 729 // operands, so it is deliberately not the needle. 730 if (wsrc as i64) != 0 { imp = ce_find(wsrc, wbox[0], " shared))" as *u8) } 731 let ml_rc: i64=wmem_read(mbytes,mbox[0],mt_limits) 732 if ml_rc!=0 { imp=0;ce_puts("[3c/5] mt memory descriptor refused code=" as *u8);ce_pn(ml_rc);ce_puts("\n" as *u8) } 733 if ml_rc==0 { 734 if mt_limits[2]!=1 { imp=0 } 735 if mt_limits[3]!=1 { imp=0 } 736 } 737 if imp == 1 { 738 if sys_renameat(CE_MT_TMP, CE_MT_OUT) >= 0 { 739 mt_ok = 1 740 ce_puts("[3c/5] mt wasm bytes=" as *u8); ce_pn(mbox[0]) 741 ce_puts(" shared-import=yes -> " as *u8); ce_puts(CE_MT_OUT) 742 ce_puts("\n" as *u8) 743 } else { ce_puts("[3c/5] mt rename FAILED\n" as *u8) } 744 } else { ce_puts("[3c/5] mt REFUSED: no imported memory in the twin wat\n" as *u8) } 745 } else { ce_puts("[3c/5] mt REFUSED: bad wasm magic\n" as *u8) } 746 } else { ce_puts("[3c/5] mt REFUSED: wasm under floor\n" as *u8) } 747 } else { ce_puts("[3c/5] mt REFUSED: no wasm written\n" as *u8) } 748 } else { ce_puts("[3c/5] mt REFUSED: assembler rc=" as *u8); ce_pn(m2); ce_puts("\n" as *u8) } 749 } else { ce_puts("[3c/5] mt REFUSED: wat under floor\n" as *u8) } 750 } else { ce_puts("[3c/5] mt REFUSED: compiler rc=" as *u8); ce_pn(m1); ce_puts("\n" as *u8) } 751 } 752 if mt_ok == 0 { 753 // RETIRE rather than leave a mismatched generation live. Renaming onto the stage path is 754 // reversible and uses the one primitive this organ already ships with. 755 if sys_renameat(CE_MT_OUT, CE_MT_TMP) >= 0 { 756 ce_puts("[3c/5] mt RETIRED the previously live twin -- isolated visitors fall back to one thread\n" as *u8) 757 } else { 758 ce_puts("[3c/5] mt absent, nothing to retire -- single thread for every visitor\n" as *u8) 759 } 760 } 761 // DECLARE THE TWIN TO THE PAGE BUILDER, and only when one is actually live. The page must build a 762 // WebAssembly.Memory that matches the twin's declared import EXACTLY or instantiation fails, so 763 // these numbers travel from the stage that DERIVED them rather than being typed again page-side -- 764 // two copies of one arena size is the duplicate-ruler defect with a browser trap at the end of it. 765 // Left at zero when the twin did not ship, which emits a page with no threading code at all. 766 if mt_ok == 1 { 767 gpe_mt_pages = mt_limits[0] 768 gpe_mt_max = mt_limits[1] 769 ce_puts("[3c/5] mt declared to the page builder: pages=" as *u8); ce_pn(gpe_mt_pages) 770 ce_puts(" max=" as *u8); ce_pn(gpe_mt_max); ce_puts("\n" as *u8) 771 } 772 773 // 4+5) THE WORLD RECIPE PLANE (W1, /world/procgen): rows from knowledge/world_recipes.conf 774 // drive EVERY page; the builtin three below remain the fallback when the file is absent 775 // (config-hierarchy law), and the source actually consumed is ANNOUNCED either way. A 776 // malformed recipe REFUSES the whole ship -- half a multiverse must not go live. 777 let R: *i64 = sys_mmap(GPR_MAXW*8*8) as *i64 778 let nr: i64 = gpe_recipes_load("knowledge/world_recipes.conf" as *u8, R) 779 if nr < 0 { ce_puts("EMIT-FAIL: recipe file malformed (row named on stderr); NOTHING shipped\n" as *u8); return 8 } 780 if nr > 0 { 781 ce_puts("recipe_src=file rows=" as *u8); ce_pn(nr); ce_puts("\n" as *u8) 782 let outw: *u8 = sys_mmap(GPE_OUT_CAP) 783 let sp: *u8 = sys_mmap(512) 784 let evw: *u8 = sys_mmap(CE_EV_CAP) 785 var w: i64 = 0 786 while w < nr { 787 let b: i64 = w*8 788 ce_evidence(R[b+5] as *u8, evw) 789 let pw: i64 = gpe_build_s(wasm, box[0], ce_stamp(R[b+4] as *u8), CE_NATIVE, evw, R[b+1], R[b+2], R[b+6] as *u8, outw) 790 ce_puts("[4/5] world=" as *u8); ce_puts(R[b+0] as *u8) 791 ce_puts(" page bytes=" as *u8); ce_pn(pw); ce_puts("\n" as *u8) 792 if pw < CE_MIN_PAGE { ce_puts("EMIT-FAIL: page under floor\n" as *u8); return 5 } 793 if cw_npc_atlas(outw, pw) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 } 794 let op: *u8 = R[b+3] as *u8 795 var q: i64 = 0 796 while op[q] != (0 as u8) { sp[q] = op[q]; q = q + 1 } 797 let sfx: *u8 = ".stage" as *u8 798 var q2: i64 = 0 799 while sfx[q2] != (0 as u8) { sp[q+q2] = sfx[q2]; q2 = q2 + 1 } 800 sp[q+q2] = 0 as u8 801 if ce_ship(outw, pw, sp, op) != 0 { return 6 } 802 w = w + 1 803 } 804 return 0 805 } 806 ce_puts("recipe_src=builtin rows=3\n" as *u8) 807 // 4) the page, IN-PROCESS (gpe_build is the ONE emitter; no second template can drift) 808 let out: *u8 = sys_mmap(GPE_OUT_CAP) 809 let pn: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE), CE_NATIVE, CE_CTRL, 0, out) 810 ce_puts("[4/5] page bytes=" as *u8); ce_pn(pn); ce_puts("\n" as *u8) 811 if pn < CE_MIN_PAGE { ce_puts("EMIT-FAIL: page under floor\n" as *u8); return 5 } 812 if cw_npc_atlas(out, pn) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 } 813 814 // 5) deploy tmp+rename, then READ BACK: bytes equal AND the loader marker present in what 815 // LANDED -- the filesystem is the oracle for an evidence row 816 if ce_ship(out, pn, CE_TMP, CE_OUT) != 0 { return 6 } 817 // 5b) THE REVIEW STAGE: identity v2 over the SAME gated wasm bytes 818 let out2: *u8 = sys_mmap(GPE_OUT_CAP) 819 let ev2: *u8 = sys_mmap(CE_EV_CAP) 820 ce_evidence(CE_CTRL2, ev2) 821 let pn2: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE2), CE_NATIVE, ev2, 2, out2) 822 if pn2 < CE_MIN_PAGE { ce_puts("EMIT-FAIL: shore page under floor\n" as *u8); return 5 } 823 if cw_npc_atlas(out2, pn2) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 } 824 if ce_ship(out2, pn2, CE_TMP2, CE_OUT2) != 0 { return 6 } 825 // 5c) THE THIRD WORLD, same gated wasm bytes -- one engine, three identities 826 let out3: *u8 = sys_mmap(GPE_OUT_CAP) 827 let pn3: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE3), CE_NATIVE, CE_CTRL3, 3, out3) 828 if pn3 < CE_MIN_PAGE { ce_puts("EMIT-FAIL: vale page under floor\n" as *u8); return 5 } 829 if cw_npc_atlas(out3, pn3) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 } 830 if ce_ship(out3, pn3, CE_TMP3, CE_OUT3) != 0 { return 6 } 831 return 0 832} 833 834func ce_ship(out: *u8, pn: i64, tmpp: *u8, outp: *u8) -> i64 { 835 // A page whose script does not lex shows NOTHING -- not even the CPU fallback runs -- so 836 // this refuses by name before a byte reaches the docroot. Same exit as the other page 837 // faults (5) so callers need no new branch. 838 let jo: *i64 = sys_mmap(JSB_O_N*8) as *i64 839 // NEG-CONTROL IN THE PATH, EVERY RUN: the ruler must still bite a planted unclosed brace 840 // before it is allowed to acquit the real page. A lexer that has gone blind would otherwise 841 // wave every page through and this stage would be decoration. Length DERIVED, never counted. 842 let bad: *u8 = "f(){" as *u8 843 if jsb_check(bad, ce_slen(bad), jo) == JSB_OK { 844 ce_puts("EMIT-FAIL: the JS lexer ACQUITTED a planted unclosed brace -- ruler is blind, NOTHING shipped\n" as *u8) 845 return 5 846 } 847 let jrc: i64 = jsb_check_page(out, pn, jo) 848 if jrc != JSB_OK { 849 ce_puts("EMIT-FAIL: page JavaScript does not lex (code " as *u8); ce_pn(jrc) 850 ce_puts(" brace=" as *u8); ce_pn(jo[JSB_O_BRACE]) 851 ce_puts(" paren=" as *u8); ce_pn(jo[JSB_O_PAREN]) 852 ce_puts(" state=" as *u8); ce_pn(jo[JSB_O_STATE]) 853 ce_puts(" first_negative_at=" as *u8); ce_pn(jo[JSB_O_NEGAT]) 854 ce_puts(" unterminated_from=" as *u8); ce_pn(jo[JSB_O_OPENAT]) 855 ce_puts(") -- NOTHING shipped to " as *u8); ce_puts(outp); ce_puts("\n" as *u8) 856 return 5 857 } 858 ce_puts("[4b/5] page JS lexes: scanned=" as *u8); ce_pn(jo[JSB_O_SCAN]); ce_puts(" brace=0 paren=0 brack=0, planted-bad control BIT\n" as *u8) 859 // 4c) EVERY NAME ON THE PAGE MUST RESOLVE TO AN ENCLOSING SCOPE. The nxHairTick outage class: 860 // a page that LEXES cleanly can still throw ReferenceError on its first frame and silently 861 // drop every visitor to the CPU tier. nx_jsscope resolves statically over the sovereign 862 // ECMAScript parser; browser globals are DATA (knowledge/js_globals.conf, calibrated from the 863 // scope gate's own measured misses, each row carrying its reason). 864 let gbox: *i64 = sys_mmap(16) as *i64 865 let glob: *u8 = sys_read_file("knowledge/js_globals.conf" as *u8, gbox) 866 if (glob as i64) == 0 { ce_puts("EMIT-FAIL: js_globals.conf unreadable -- the scope referee cannot run, NOTHING shipped\n" as *u8); return 5 } 867 // NEG-CONTROL IN THE PATH, EVERY RUN: the resolver must still flag a planted undeclared name 868 // before it may acquit the real page. A resolver gone blind acquits everything. 869 let plant: *u8 = "q7planted()" as *u8 870 let pst: *i64 = jss_check(plant, ce_slen(plant), glob, gbox[0]) 871 if (pst as i64) == 0 { ce_puts("EMIT-FAIL: scope referee cannot PARSE its planted control -- ruler broken, NOTHING shipped\n" as *u8); return 5 } 872 if pst[JS_ST_NRP] == 0 { ce_puts("EMIT-FAIL: scope referee ACQUITTED a planted undeclared name -- ruler blind, NOTHING shipped\n" as *u8); return 5 } 873 // the page's behaviour lives in its first <script> body -- the same extraction the scope gate 874 // judges, byte for byte, so the ship stage and the gate cannot disagree about the subject 875 // LARGEST script body, not the first: the boot-guard tag now precedes the engine, and a 876 // referee that judged the 450-byte guard while the 433KB engine went unjudged would be a 877 // referee that silently lost its subject. 878 var jss_s: i64 = 0 - 1 879 var jss_e: i64 = pn 880 var cs9: i64 = 0 - 1 881 var jsi: i64 = 0 882 while jsi + 8 < pn { 883 if cs9 < 0 { 884 if (out[jsi]&255)==60 { if (out[jsi+1]&255)==115 { if (out[jsi+2]&255)==99 { if (out[jsi+3]&255)==114 { 885 var jsj: i64 = jsi 886 while jsj < pn && (out[jsj]&255) != 62 { jsj = jsj + 1 } 887 cs9 = jsj + 1 888 jsi = jsj 889 } } } } 890 } else { 891 if (out[jsi]&255)==60 { if (out[jsi+1]&255)==47 { if (out[jsi+2]&255)==115 { if (out[jsi+3]&255)==99 { 892 if jsi - cs9 > jss_e - jss_s { if jss_s >= 0 { jss_e = jsi; jss_s = cs9 } } 893 if jss_s < 0 { jss_s = cs9; jss_e = jsi } 894 cs9 = 0 - 1 895 } } } } 896 } 897 jsi = jsi + 1 898 } 899 if jss_s < 0 { ce_puts("EMIT-FAIL: no <script> body found on the page -- nothing for the scope referee to judge, NOTHING shipped\n" as *u8); return 5 } 900 let sst: *i64 = jss_check(((out as i64) + jss_s) as *u8, jss_e - jss_s, glob, gbox[0]) 901 if (sst as i64) == 0 { ce_puts("EMIT-FAIL: page does not PARSE under the sovereign JS parser (grammar gap or real defect -- run nx_jsscope_gate for the exact byte), NOTHING shipped\n" as *u8); return 5 } 902 if sst[JS_ST_OVER] != 0 { ce_puts("EMIT-FAIL: scope referee hit a table cap -- its verdict would be a BOUND, not a proof; NOTHING shipped\n" as *u8); return 5 } 903 if sst[JS_ST_NRP] != 0 { 904 let rp0: *i64 = (sst[JS_ST_RP]) as *i64 905 let jctx: *i64 = (sst[JS_ST_CTX]) as *i64 906 ce_puts("EMIT-FAIL: " as *u8); ce_pn(sst[JS_ST_NRP]) 907 ce_puts(" scope-referee finding(s) (1=UNRESOLVED 2=OUT-OF-SCOPE 3=REDECLARED-AT-SCRIPT-SCOPE) -- NOTHING shipped\n" as *u8) 908 var fi9: i64 = 0 909 var fn9: i64 = sst[JS_ST_NRP] 910 if fn9 > 8 { fn9 = 8 } 911 while fi9 < fn9 { 912 ce_puts(" FINDING kind=" as *u8); ce_pn(rp0[fi9*RP_ROW]) 913 ce_puts(" tok=" as *u8) 914 sys_write(1, ((jss_src(jctx) as i64) + jss_tok_start(jctx, rp0[fi9*RP_ROW+1])) as *u8, jss_tok_len(jctx, rp0[fi9*RP_ROW+1])) 915 ce_puts(" scope=" as *u8); ce_pn(rp0[fi9*RP_ROW+2]) 916 ce_puts(" declscope=" as *u8); ce_pn(rp0[fi9*RP_ROW+3]) 917 ce_puts("\n" as *u8) 918 fi9 = fi9 + 1 919 } 920 if sst[JS_ST_NRP] > 8 { ce_puts(" (list is a PREFIX of the count -- first 8 of the total)\n" as *u8) } 921 return 5 922 } 923 ce_puts("[4c/5] page scopes resolve: refs=" as *u8); ce_pn(sst[JS_ST_NREF]); ce_puts(" reports=0, planted-undeclared control BIT\n" as *u8) 924 let fd: i64 = sys_openat_wr(tmpp, CE_MODE) 925 if fd < 0 { ce_puts("EMIT-FAIL: stage open\n" as *u8); return 6 } 926 var off: i64 = 0 927 while off < pn { 928 let w: i64 = sys_write(fd, ((out as i64) + off) as *u8, pn - off) 929 if w <= 0 { sys_close(fd); ce_puts("EMIT-FAIL: stage write\n" as *u8); return 6 } 930 off = off + w 931 } 932 sys_close(fd) 933 if sys_renameat(tmpp, outp) < 0 { ce_puts("EMIT-FAIL: rename\n" as *u8); return 6 } 934 let box2: *i64 = sys_mmap(16) as *i64 935 let back: *u8 = sys_read_file(outp, box2) 936 if (back as i64) == 0 { ce_puts("EMIT-FAIL: readback\n" as *u8); return 7 } 937 if box2[0] != pn { ce_puts("EMIT-FAIL: readback bytes " as *u8); ce_pn(box2[0]); ce_puts(" != " as *u8); ce_pn(pn); ce_puts("\n" as *u8); return 7 } 938 if ce_find(back, box2[0], "WebAssembly.instantiate" as *u8) == 0 { ce_puts("EMIT-FAIL: loader marker missing\n" as *u8); return 7 } 939 ce_puts("[5/5] SHIPPED " as *u8); ce_pn(pn); ce_puts(" bytes -> " as *u8); ce_puts(outp); ce_puts(" (read back, marker verified)\n" as *u8) 940 return 0 941}