nx_craft_workspace_emit_t48.nx source
↩ module page · 941 lines · 57144 B
1// nx_craft_emit.nx -- THE SOVEREIGN CRAFT SHIP LANE (retires _ops/nx_emit_game.sh's laptop/WSL
2// dependency for /world/craft): gate-check -> .nx -> .wat -> .wasm -> page -> live docroot,
3// every stage BYTE-ASSERTED before the next runs (the emit script's founding law, organ form:
4// a green tool on empty input is not a check -- a 0-byte .wat once shipped a 20-byte "game").
5// The page itself is built IN-PROCESS by gpe_build (nx_game_page_emit as a LIB -- one emitter,
6// not a fork), and the deploy is tmp+rename with a READ-BACK byte+marker assert (what LANDED
7// is the claim, never what was written). Gate RED = refuses to emit anything at all.
8// usage: nx_craft_emit (runs from nishihost cwd like every registered tool)
9// exit: 0 SHIPPED | 2 gate-red | 3 wat | 4 wasm | 5 page | 6 deploy | 7 readback | 8 recipe-malformed
10// W1 (2026-08-12): worlds come from knowledge/world_recipes.conf rows (name\tvnum\tseed\tout\t
11// title\tcontrols); the builtin three below are the fallback when the file is absent, and the
12// source actually consumed is ANNOUNCED (recipe_src=) on every run.
13// license_tier: ORIGINAL No hw writes (Rule 26).
14import "nx_syscalls.nx"
15import "nx_game_page_workspace_t48.nx"
16import "nx_softbind.nx"
17// 4b) THE PAGE MUST LEX BEFORE IT SHIPS. 2026-08-25 an emitter edit took /world/beach and
18// /world/craft BLACK through this exact lane with every stage GREEN: nothing here looked at
19// the JavaScript. Composed IN-PROCESS (a lib, one classifier), never forked -- a fork handed a
20// path could walk nothing and report clean.
21import "nx_jsbalance.nx"
22// 4c) ...AND EVERY NAME MUST RESOLVE. The lexer above catches structure; the nxHairTick outage
23// proved a page can lex cleanly and still die on its first frame from one out-of-scope name.
24import "nx_jsscope.nx"
25import "nx_relief_lib.nx"
26import "nx_nxa_fk.nx"
27import "nx_wasm_memory_lib.nx"
28import "nx_wasm_craft.nx" // Source-owned compiler arena/static bounds; build emitter with the same engine revision.
29
30const CE_GATE: *u8 = "nx_wasm_craft_gate.elf"
31const CE_CWAT: *u8 = "nx_compile_wat.elf"
32const CE_WATC: *u8 = "nx_wat_compiler.elf"
33// the wasm-VM gate: runs the EMITTED module in the memory it declares. Sovereign -- our own VM, no
34// browser and no third-party runtime in the shipping path.
35const CE_VMGATE: *u8 = "nx_wasm_craft_vm_gate.elf"
36const CE_SRC: *u8 = "buildroot/runtime/nx_wasm_craft.nx"
37const CE_WAT: *u8 = "buildroot/_build/nx_wasm_craft_emit.wat"
38const CE_WASM: *u8 = "buildroot/_build/nx_wasm_craft_emit.wasm"
39// GE30 THE THREADED TWIN. A second build of the SAME source with an IMPORTED shared memory, so
40// every Worker instantiates one module over ONE WebAssembly.Memory and render_band splits the
41// frame. It is DEPLOYED AS A FILE, not base64-inlined like the plain build: the page already
42// carries one inline copy and a second would double every world page for a capability only an
43// isolated visitor can use. A non-isolated visitor never fetches it and the single-thread path
44// is byte-unchanged. Proven in a real browser 2026-09-03: 4 Workers, 27 ms against 69 ms
45// single-thread, fb_digest identical, with an omitted-band control returning a DIFFERENT digest.
46const CE_WAT_MT: *u8 = "buildroot/_build/nx_wasm_craft_emit_mt.wat"
47const CE_WASM_MT: *u8 = "buildroot/_build/nx_wasm_craft_emit_mt.wasm"
48const CE_MT_TMP: *u8 = "sites/nishifamily/world/craft_mt.wasm.stage"
49const CE_MT_OUT: *u8 = "sites/nishifamily/world/craft_mt.wasm"
50const CE_SHARED: *u8 = "--shared"
51// A shared memory MUST declare a maximum (an unbounded shared memory cannot be grown), so the
52// twin needs a ceiling the plain build never states. 2x the module's OWN declared pages: derived
53// from the artifact, never a hand-picked number, so it tracks the engine as the arena grows.
54const CE_MT_HEADROOM: i64 = 2
55const CE_MT_PAGES_MIN: i64 = 16
56const CE_MT_PAGES_MAX: i64 = 65536
57const CE_TMP: *u8 = "sites/nishifamily/world/craft.html.stage"
58const CE_OUT: *u8 = "sites/nishifamily/world/craft.html"
59const CE_TITLE: *u8 = "NISHI CRAFT - SOVEREIGN 3D"
60const CE_NATIVE: *u8 = "nx_desktop_craft"
61// the REVIEW STAGE (identity v2 = NISHI SHORE): same gated wasm, second spec, second page --
62// one engine, many worlds is the emission lever actually being pulled
63const CE_TMP2: *u8 = "sites/nishifamily/world/beach.html.stage"
64const CE_OUT2: *u8 = "sites/nishifamily/world/beach.html"
65const CE_TITLE2: *u8 = "NISHI SHORE - REVIEW STAGE"
66const CE_CTRL2: *u8 = "the flat-light REVIEW STAGE: mixed beachwear across the cast (bred, stable per girl) · same engine, same controls as <a href=\"craft\">NISHI CRAFT</a> · ?review=1 auto-frames the nearest girl<br>ISEKAI: cross to <a href=\"craft\">NISHI CRAFT</a> or <a href=\"vale\">NISHI VALE</a> — level, ledger and party come along"
67// v3 = the medieval VALE: the third world, built from data rows alone. Your traveler carries
68// his ledger and party between all three -- the passport lives under one key for every world.
69const CE_TMP3: *u8 = "sites/nishifamily/world/vale.html.stage"
70const CE_OUT3: *u8 = "sites/nishifamily/world/vale.html"
71const CE_TITLE3: *u8 = "NISHI VALE - THE MEDIEVAL HIGHLAND"
72const CE_CTRL3: *u8 = "deep woods, cold snowline, cave-riddled stone — and wardens who hunt WIDE by day · your traveler arrives with his ledger, his level and his party from <a href=\"craft\">NISHI CRAFT</a> or <a href=\"beach\">NISHI SHORE</a> · <b>G</b> invites a bonded girl to your party · same controls"
73const CE_CTRL: *u8 = "click canvas = MOUSELOOK (Esc frees) · <b>WASD</b> move · <b>SPACE</b> jump · L/R-click or <b>E</b>/<b>B</b> break/place · <b>Q</b> cycles 7 slots (blocks · HOE · SEEDS) · till grass, plant, let rain or a pond do the rest, break the GOLDEN crop = harvest · <b>E</b> on a girl = meet her, <b>G</b> invites her to your party · nights are the wardens' · <b>H</b> home · gamepad + touch<br>ISEKAI: your level, ledger and party travel with you — walk into <a href=\"beach\">NISHI SHORE</a> or <a href=\"vale\">NISHI VALE</a> · <a href=\"craft_immersion\">what is broken and what is next</a>"
74const CE_MIN_WAT: i64 = 500000
75const CE_MIN_WASM: i64 = 50000
76const CE_MIN_PAGE: i64 = 100000
77const CE_MODE: i64 = 0x1a4
78
79func ce_slen(s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } return n }
80func ce_puts(s: *u8) -> i64 { sys_write(1, s, ce_slen(s)); return 0 }
81func ce_pn(v: i64) -> i64 {
82 if v == 0 { sys_write(1, "0" as *u8, 1); return 0 }
83 var m: i64 = v
84 if m < 0 { sys_write(1, "-" as *u8, 1); m = 0 - m }
85 let t: *u8 = sys_mmap(32)
86 var k: i64 = 0
87 while m > 0 { t[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 }
88 let o: *u8 = sys_mmap(32)
89 var i: i64 = 0
90 while i < k { o[i] = t[k - 1 - i]; i = i + 1 }
91 sys_write(1, o, k)
92 return 0
93}
94// BUILD STAMP (operator 2026-08-28: "i dont see any improvements" -- five ships landed that day and
95// nobody could say WHICH build a frame showed. Every page <title> and banner <h1> now carries the
96// emit wall-time, so "am I looking at the new build" is answerable at a glance, forever. The serve
97// path is already Cache-Control: no-cache (measured 2026-08-28), so a stale view was ruled out;
98// this closes the HUMAN half of version identity. Composes sys_now_realtime_sec (nx_syscalls).
99func ce_stamp(t: *u8) -> *u8 {
100 let o: *u8 = sys_mmap(192)
101 var i: i64 = 0
102 while t[i] != (0 as u8) { o[i] = t[i]; i = i + 1 }
103 o[i] = 32 as u8; o[i+1] = 98 as u8; i = i + 2
104 var m: i64 = sys_now_realtime_sec()
105 let d: *u8 = sys_mmap(32)
106 var k: i64 = 0
107 while m > 0 { d[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 }
108 while k > 0 { k = k - 1; o[i] = d[k]; i = i + 1 }
109 o[i] = 0 as u8
110 return o
111}
112// the nx_aw_push fork-a-sovereign-sub-ELF pattern (spine shared with nx_emu_probe_wasm_gate)
113// One fork/exec owner for retained small-call wrappers and compiler flag vectors.
114func ce_run_argv(elf: *u8,argv: *i64) -> i64 {
115 if (elf as i64) <= 0 { return 127 }
116 if (argv as i64) <= 0 { return 127 }
117 let envp: *i64 = sys_mmap(16) as *i64
118 if (envp as i64) <= 0 { return 127 }
119 let st: *i64 = sys_mmap(16) as *i64
120 if (st as i64) <= 0 { sys_munmap(envp as *u8,16); return 127 }
121 let envp0: *u8 = "PATH=/usr/bin:/bin" as *u8
122 envp[0] = envp0 as i64; envp[1] = 0
123 let pid: i64 = sys_fork()
124 if pid < 0 { sys_munmap(envp as *u8,16); sys_munmap(st as *u8,16); return 127 }
125 if pid == 0 {
126 sys_execve(elf,argv,envp)
127 sys_exit(127)
128 }
129 let waited: i64 = sys_wait4(pid,st,0)
130 var rc: i64 = 127
131 if waited == pid { rc = wait_status_rc(st[0]) }
132 sys_munmap(envp as *u8,16); sys_munmap(st as *u8,16)
133 return rc
134}
135func ce_run(elf: *u8,a1: *u8,a2: *u8) -> i64 {
136 let argv: *i64 = sys_mmap(4*8) as *i64
137 if (argv as i64) <= 0 { return 127 }
138 argv[0] = elf as i64
139 var ai: i64 = 1
140 if (a1 as i64) != 0 { argv[ai] = a1 as i64; ai = ai+1 }
141 if (a2 as i64) != 0 { argv[ai] = a2 as i64; ai = ai+1 }
142 argv[ai] = 0
143 let rc: i64 = ce_run_argv(elf,argv)
144 sys_munmap(argv as *u8,4*8)
145 return rc
146}
147func ce_run5(elf: *u8,a1: *u8,a2: *u8,a3: *u8,a4: *u8,a5: *u8) -> i64 {
148 let argv: *i64 = sys_mmap(7*8) as *i64
149 if (argv as i64) <= 0 { return 127 }
150 argv[0] = elf as i64
151 var ai: i64 = 1
152 if (a1 as i64) != 0 { argv[ai] = a1 as i64; ai = ai+1 }
153 if (a2 as i64) != 0 { argv[ai] = a2 as i64; ai = ai+1 }
154 if (a3 as i64) != 0 { argv[ai] = a3 as i64; ai = ai+1 }
155 if (a4 as i64) != 0 { argv[ai] = a4 as i64; ai = ai+1 }
156 if (a5 as i64) != 0 { argv[ai] = a5 as i64; ai = ai+1 }
157 argv[ai] = 0
158 let rc: i64 = ce_run_argv(elf,argv)
159 sys_munmap(argv as *u8,7*8)
160 return rc
161}
162// elf + two flag/value pairs + optional shared triple + source/output + null.
163const CE_COMPILE_ARG_WORDS: i64 = 1+2+2+3+2+1
164func ce_compiler_argv(out: *u8,shared_max: *u8,argv: *i64,words: i64,floor_text: *u8,limit_text: *u8) -> i64 {
165 if words < CE_COMPILE_ARG_WORDS { return 0-1 }
166 if (argv as i64) <= 0 { return 0-1 }
167 if (floor_text as i64) <= 0 { return 0-1 }
168 if (limit_text as i64) <= 0 { return 0-1 }
169 if (out as i64) <= 0 { return 0-1 }
170 let floor: i64 = wasm_arena_pages()
171 let limit: i64 = wasm_static_limit_pages()
172 if floor < 1 { return 0-2 }; if limit <= floor { return 0-2 }
173 if limit > CE_MT_PAGES_MAX { return 0-2 }
174 if wasm_static_base_off() != floor*WASM_PAGE_BYTES { return 0-2 }
175 if wasm_static_limit_off() != limit*WASM_PAGE_BYTES { return 0-2 }
176 if CRAFT_TOTAL > wasm_static_base_off() { return 0-2 }
177 ce_num_str(floor,floor_text); ce_num_str(limit,limit_text)
178 let arena_flag: *u8 = "--arena-pages" as *u8
179 let limit_flag: *u8 = "--static-limit-pages" as *u8
180 let source_floor: *u8 = "source" as *u8
181 argv[0] = CE_CWAT as i64
182 argv[1] = arena_flag as i64; argv[2] = floor_text as i64
183 argv[3] = limit_flag as i64; argv[4] = limit_text as i64
184 var ai: i64 = 5
185 if (shared_max as i64) != 0 {
186 argv[ai] = CE_SHARED as i64; argv[ai+1] = source_floor as i64; argv[ai+2] = shared_max as i64
187 ai = ai+3
188 }
189 argv[ai] = CE_SRC as i64; argv[ai+1] = out as i64; argv[ai+2] = 0
190 return ai+2
191}
192func ce_compile_craft(out: *u8,shared_max: *u8) -> i64 {
193 let argv: *i64 = sys_mmap(CE_COMPILE_ARG_WORDS*8) as *i64
194 if (argv as i64) <= 0 { return 3 }
195 let floor_text: *u8 = sys_mmap(32)
196 if (floor_text as i64) <= 0 { sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8); return 3 }
197 let limit_text: *u8 = sys_mmap(32)
198 if (limit_text as i64) <= 0 { sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8); sys_munmap(floor_text,32); return 3 }
199 let argc: i64 = ce_compiler_argv(out,shared_max,argv,CE_COMPILE_ARG_WORDS,floor_text,limit_text)
200 var rc: i64 = 3
201 if argc < 0 { ce_puts("CRAFT compiler layout contract refused\n" as *u8) }
202 if argc >= 0 { rc = ce_run_argv(CE_CWAT,argv) }
203 sys_munmap(argv as *u8,CE_COMPILE_ARG_WORDS*8)
204 sys_munmap(floor_text,32); sys_munmap(limit_text,32)
205 return rc
206}
207
208// ce_num_str -- i64 to decimal into caller storage, NUL terminated, for argv.
209func ce_num_str(v: i64, b: *u8) -> i64 {
210 if v == 0 { b[0] = 48 as u8; b[1] = 0 as u8; return 1 }
211 var t: i64 = v
212 var d: i64 = 0
213 while t > 0 { d = d + 1; t = t / 10 }
214 b[d] = 0 as u8
215 var k: i64 = d
216 t = v
217 while k > 0 { k = k - 1; b[k] = ((t % 10) + 48) as u8; t = t / 10 }
218 return d
219}
220// ce_wat_pages -- READ THE PAGE COUNT OFF THE ARTIFACT THE COMPILER JUST WROTE, never a constant.
221// The plain build declares `(memory (export "memory") N)`; N is the module's own arena sizing and
222// it moves whenever the engine grows. A hand-copied twin of that number is a second ruler that
223// drifts silently, and the failure mode is a shared memory too small for the framebuffer -- the
224// exact class that shipped /craft black twice. Returns the count, or a NEGATIVE reason code.
225func ce_wat_pages(p: *u8) -> i64 {
226 let box: *i64 = sys_mmap(16) as *i64
227 let b: *u8 = sys_read_file(p, box)
228 if (b as i64) == 0 { return 0 - 1 }
229 let n: i64 = box[0]
230 let needle: *u8 = "(memory (export " as *u8
231 let nl: i64 = ce_slen(needle)
232 var i: i64 = 0
233 var at: i64 = 0 - 1
234 while i + nl <= n {
235 var j: i64 = 0
236 var hit: i64 = 1
237 while j < nl { if b[i + j] != needle[j] { hit = 0; j = nl } else { j = j + 1 } }
238 if hit == 1 { at = i; i = n } else { i = i + 1 }
239 }
240 if at < 0 { return 0 - 2 }
241 var k: i64 = at + nl
242 var v: i64 = 0
243 var seen: i64 = 0
244 while k < n {
245 let c: i64 = b[k] as i64
246 if c >= 48 {
247 if c <= 57 { v = v * 10 + (c - 48); seen = 1; k = k + 1 }
248 else { if seen == 1 { k = n } else { k = k + 1 } }
249 } else { if seen == 1 { k = n } else { k = k + 1 } }
250 }
251 if seen == 0 { return 0 - 3 }
252 return v
253}
254func ce_find(hay: *u8, n: i64, needle: *u8) -> i64 {
255 let nl: i64 = ce_slen(needle)
256 if nl == 0 { return 1 }
257 var i: i64 = 0
258 while i + nl <= n {
259 var j: i64 = 0
260 var hit: i64 = 1
261 while j < nl { if hay[i + j] != needle[j] { hit = 0; j = nl } else { j = j + 1 } }
262 if hit == 1 { return 1 }
263 i = i + 1
264 }
265 return 0
266}
267func ce_fsize(p: *u8) -> i64 {
268 let box: *i64 = sys_mmap(16) as *i64
269 let b: *u8 = sys_read_file(p, box)
270 if (b as i64) == 0 { return 0 - 1 }
271 return box[0]
272}
273
274// cw_npc_atlas -- SHIP-TIME ASSERTION for the atlas rung (the comparewatch contract named
275// cw_npc_atlas in BOTH the charsim and graphics planes): a world page may not ship unless
276// (a) the page carries the NPC-atlas sampling path (the uAtl sampler and the npc_atlas runtime
277// marker) and (b) the served NPC asset carries TEXC+TEXM -- the very maps the page will sample.
278// A clay ship -- either half missing -- REFUSES here, loudly, with the missing half named.
279// This is the flip's PROOF-side twin: the watch measures the symbol; this function makes the
280// symbol load-bearing, because a page that stopped sampling cannot reach the docroot again.
281const CW_NPC_ASSET: *u8 = "sites/nishifamily/world/ref9d.nxa"
282func cw_rd64(b: *u8, off: i64) -> i64 { var v: i64 = 0; var k: i64 = 7; while k >= 0 { v = v*256 + (b[off+k] as i64); k = k - 1 } return v }
283func cw_tag4(b: *u8, off: i64, t: *u8) -> i64 { if b[off] == t[0] { if b[off+1] == t[1] { if b[off+2] == t[2] { if b[off+3] == t[3] { return 1 } } } } return 0 }
284// ---- GR29: THE ADEQUACY CONJUNCT -----------------------------------------------------------
285// Everything cw_npc_atlas asks below this line is an EXISTENCE question -- is the sampler path in
286// the page, is there a TEXM in the asset. None of them asks the one question that decides whether
287// a viewer sees skin or painted clay: DOES THE ATLAS ACTUALLY CARRY THE BANDS THE BAKER COMPUTED?
288// nx_nxa_texbake_lib has said so in PROSE since it was written -- "at whole body a texel is ~415um,
289// so fine wrinkles (~1.2mm) resolve and PORES (~100um) DO NOT" -- and nothing enforced it, so a
290// bake that computes three bands and clamps two away has been shipping GREEN.
291//
292// THE RESOLUTION IS READ, NEVER ASSUMED. TEXM's payload carries it as header word TXM_W_RES=1
293// (nx_nxa_texm.nx: [nmaps][res][pbr_model][seed][hue][blob_words]) and the TOC entry carries that
294// payload's byte offset at +8, so this reads the resolution the asset was ACTUALLY baked at.
295// Deliberately NOT a constant: hoisting a 2048 to a named const would satisfy the magic-number
296// ratchet and leave the clamp exactly where it is. DERIVATION, NOT NAMING.
297//
298// THE BAR IS rlf_band_resolvable -- THE SAME PREDICATE THE BAKER CLAMPS WITH, imported, not copied.
299// A second copy of that rule here would be the duplicate-ruler defect in the one place it must not
300// be, because the two would drift and the gate would then disagree with the thing it audits.
301// A band under two texels is not baked faint: it is baked as a DIFFERENT, COARSER band wearing its
302// name, which is exactly why the presence of a TEXM proves nothing at all.
303//
304// AMBER, NOT RED, AND THAT IS A DECISION WITH A REASON. At the resolution the cast ships at today
305// every declared band reads carried=0, so a RED here would refuse every world ship from the moment
306// it landed -- the permanently-red detector everyone learns to ignore. It NAMES the band, prints
307// the texel and prints the resolution that would carry it, and does not block. When a per-region
308// atlas lands this goes quiet by itself, which is the shape a ratchet should have.
309const CW_FACE_SPAN_UM: i64 = 250000 // a 250mm head region: the per-region atlas this argues for
310func cw_band_line(nm: *u8, lambda_um: i64, res: i64) -> i64 {
311 let carried: i64 = rlf_band_resolvable(res, lambda_um)
312 ce_puts(" band " as *u8); ce_puts(nm); ce_puts(" lambda=" as *u8); ce_pn(lambda_um)
313 ce_puts("um carried=" as *u8); ce_pn(carried)
314 if carried == 0 {
315 ce_puts(" NEEDS res>=" as *u8); ce_pn(rlf_band_res_needed(RLF_BODY_UM, lambda_um))
316 ce_puts(" whole-body, or >=" as *u8); ce_pn(rlf_band_res_needed(CW_FACE_SPAN_UM, lambda_um))
317 ce_puts(" over a 250mm region" as *u8)
318 }
319 ce_puts("\n" as *u8)
320 return carried
321}
322// ---- GE68: THE CHART THE FACE ACTUALLY GETS, MEASURED FROM THE ASSET ------------------------
323// The whole-body figure below divides RLF_BODY_UM by res, i.e. it ASSUMES the body maps uniformly
324// onto the atlas. It does not. TEXC hands every joint an EQUAL tile of a g x g grid (ntx_apply:
325// g = nt_grid(nj), tw = Q16/g), so the head is allotted exactly the texels a finger is, and the
326// whole-body number describes NO CHART THAT EXISTS. This reads g from TEXC and each bone's own
327// bind span from SKEL and asks the SAME rlf_*_span rulers what each real chart carries -- one
328// convention, never a second. It only ever ADDS lines; the verdict below is untouched.
329// SCOPE, DECLARED RATHER THAN GLOSSED: the unwrap's v axis is the bone length and its u axis is
330// the circumference around it. This measures the V AXIS ONLY -- the u axis needs a limb radius no
331// section carries, so it is named UNMEASURED instead of assumed. An axis that cannot see abstains.
332const CW_NXA_UNIT_UM: i64 = 10 // VERT/SKEL units are 0.01 mm, so one unit is ten microns
333const CW_SKEL_W: i64 = 8 // words per joint: parent, tx ty tz, qx qy qz qw
334const CW_TEXC_W_G: i64 = 2 // TEXC payload word 2 is the atlas grid g
335func cw_bone_span_um(ab: *u8, skoff: i64, nj: i64, j: i64) -> i64 {
336 let par: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W)*8)
337 if par < 0 { return 0 }
338 if par >= nj { return 0 }
339 let jx: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 1)*8)
340 let jy: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 2)*8)
341 let jz: i64 = cw_rd64(ab, skoff + 8 + (j*CW_SKEL_W + 3)*8)
342 let px: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 1)*8)
343 let py: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 2)*8)
344 let pz: i64 = cw_rd64(ab, skoff + 8 + (par*CW_SKEL_W + 3)*8)
345 let dx: i64 = jx - px
346 let dy: i64 = jy - py
347 let dz: i64 = jz - pz
348 let d2: i64 = dx*dx + dy*dy + dz*dz
349 if d2 <= 0 { return 0 }
350 return nf_isqrt(d2) * CW_NXA_UNIT_UM
351}
352// GE67b: the chart's v axis is its rect HEIGHT (v01 scales by rh in ntx_apply), so its texel
353// count is h*res/Q16. rectoff<=0 is a legacy asset with no table: fall back to the uniform cell
354// and let the caller say so, rather than reporting a rect that was never cut.
355const CW_Q16: i64 = 65536
356func cw_chart_vres(ab: *u8, tc: i64, rectoff: i64, j: i64, res: i64, g: i64) -> i64 {
357 if rectoff <= 0 { return res / g }
358 let h: i64 = cw_rd64(ab, tc + (rectoff + j*4 + 3)*8)
359 if h <= 0 { return res / g }
360 return h * res / CW_Q16
361}
362func cw_chart_line(nm: *u8, jj: i64, span: i64, cres: i64) -> i64 {
363 let m: i64 = rlf_bands_carried_span(span, cres)
364 let n: i64 = rlf_bands_count(m)
365 ce_puts(" chart " as *u8); ce_puts(nm)
366 ce_puts(" joint=" as *u8); ce_pn(jj)
367 ce_puts(" span=" as *u8); ce_pn(span)
368 ce_puts("um res=" as *u8); ce_pn(cres)
369 ce_puts(" texel=" as *u8); ce_pn(rlf_texel_um_span(span, cres))
370 ce_puts("um bands_carried=" as *u8); ce_pn(n)
371 ce_puts(" of 4 (v axis only; u axis UNMEASURED)\n" as *u8)
372 return n
373}
374func cw_chart_adequacy(ab: *u8, res: i64) -> i64 {
375 let ns: i64 = cw_rd64(ab, 16)
376 var tc: i64 = 0 - 1
377 var sk: i64 = 0 - 1
378 var s: i64 = 0
379 while s < ns {
380 let e: i64 = 32 + s*32
381 if cw_tag4(ab, e, "TEXC" as *u8) == 1 { tc = cw_rd64(ab, e + 8) }
382 if cw_tag4(ab, e, "SKEL" as *u8) == 1 { sk = cw_rd64(ab, e + 8) }
383 s = s + 1
384 }
385 if tc < 0 { ce_puts(" npc-atlas per-chart UNMEASURED: no TEXC, so no chart layout to read\n" as *u8); return 0 - 1 }
386 if sk < 0 { ce_puts(" npc-atlas per-chart UNMEASURED: no SKEL, so no bone span to measure against\n" as *u8); return 0 - 1 }
387 let g: i64 = cw_rd64(ab, tc + CW_TEXC_W_G*8)
388 let nj: i64 = cw_rd64(ab, sk)
389 if g < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: TEXC carries no usable grid word\n" as *u8); return 0 - 1 }
390 if nj < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: SKEL carries no joints\n" as *u8); return 0 - 1 }
391 // GE67b landed a per-joint rect table in TEXC payload word 3 (0 on a legacy asset, which is
392 // exactly the uniform-grid signal). Read it when present so this check measures the chart the
393 // allocator ACTUALLY cut, and falls back to the uniform cell only when there is no table.
394 let rectoff: i64 = cw_rd64(ab, tc + 3*8)
395 let cres: i64 = res / g
396 var hj: i64 = 0 - 1
397 var hz: i64 = 0
398 var wj: i64 = 0 - 1
399 var wspan: i64 = 0
400 var hspan: i64 = 0
401 var measured: i64 = 0
402 var j: i64 = 0
403 while j < nj {
404 let sp: i64 = cw_bone_span_um(ab, sk, nj, j)
405 if sp > 0 {
406 measured = measured + 1
407 let z: i64 = cw_rd64(ab, sk + 8 + (j*CW_SKEL_W + 3)*8)
408 if hj < 0 { hj = j; hz = z; hspan = sp }
409 if z > hz { hj = j; hz = z; hspan = sp }
410 if sp > wspan { wspan = sp; wj = j }
411 }
412 j = j + 1
413 }
414 ce_puts(" npc-atlas PER-CHART (GE68): a chart is a FRACTION of the atlas, never the " as *u8); ce_pn(res)
415 ce_puts(" the whole-body line above divides by; the legacy uniform cell of the " as *u8); ce_pn(g)
416 ce_puts("x" as *u8); ce_pn(g); ce_puts(" grid would be " as *u8); ce_pn(cres)
417 ce_puts(" texels, and each chart's REAL size is on its own line below.\n" as *u8)
418 ce_puts(" charts_with_a_span=" as *u8); ce_pn(measured); ce_puts(" of " as *u8); ce_pn(nj)
419 ce_puts(" joints (a root has no parent bone and no span: counted out, never counted in)\n" as *u8)
420 if measured < 1 { ce_puts(" npc-atlas per-chart UNMEASURED: no joint carries a parent bone\n" as *u8); return 0 - 1 }
421 if rectoff > 0 { ce_puts(" allocation=PER-REGION (GE67b rect table present at payload word 3)\n" as *u8) }
422 if rectoff <= 0 { ce_puts(" allocation=LEGACY-UNIFORM (no rect table: every joint gets one equal cell)\n" as *u8) }
423 let hb: i64 = cw_chart_line("highest (the head, what a close-up reads)" as *u8, hj, hspan, cw_chart_vres(ab, tc, rectoff, hj, res, g))
424 let wb: i64 = cw_chart_line("longest (the worst chart on the body) " as *u8, wj, wspan, cw_chart_vres(ab, tc, rectoff, wj, res, g))
425 // NEG-CONTROL, evaluated every run: a uniform grid of ONE tile would make the per-chart
426 // measure identical to the whole-body one and this whole axis decorative. g > 1 is what makes
427 // the two spans different questions, so it is asserted here rather than assumed.
428 ce_puts(" neg-control chart-is-not-the-atlas: g=" as *u8); ce_pn(g)
429 if g <= 1 { ce_puts(" <== CONTROL FAILED: one tile means the chart IS the atlas and this axis is decorative\n" as *u8) }
430 if g > 1 { ce_puts(" OK (a chart is a fraction of the atlas, so the two spans are different questions)\n" as *u8) }
431 if hb > wb { ce_puts(" the head chart carries MORE than the worst body chart at the same tile size\n" as *u8) }
432 return hb
433}
434func cw_atlas_adequate(ab: *u8, tmoff: i64) -> i64 {
435 let res: i64 = cw_rd64(ab, tmoff + 8)
436 if res <= 0 {
437 ce_puts(" npc-atlas adequacy UNMEASURED: TEXM carries no usable RES word (read " as *u8)
438 ce_pn(res)
439 ce_puts("). NOT scored -- an axis that cannot see must abstain, never acquit.\n" as *u8)
440 return 0 - 1
441 }
442 ce_puts(" npc-atlas ADEQUACY at the resolution this asset was BAKED at: res=" as *u8)
443 ce_pn(res); ce_puts(" texel=" as *u8); ce_pn(rlf_texel_um(res))
444 ce_puts("um over a " as *u8); ce_pn(RLF_BODY_UM); ce_puts("um body\n" as *u8)
445 var carried: i64 = 0
446 carried = carried + cw_band_line("primary " as *u8, RLF_RELIEF_LAMBDA_UM, res)
447 carried = carried + cw_band_line("secondary" as *u8, RLF_SEC_LAMBDA_UM, res)
448 carried = carried + cw_band_line("pore-grid" as *u8, RLF_PORE_PITCH_UM, res)
449 // The pore ORIFICE is a STRICTER bar than its lattice and they are NOT the same question: a
450 // grid that resolves while the 100um pit does not gives evenly spaced sub-texel dimples -- the
451 // lattice reads and the pore does not. Named separately so nobody reports the easier number
452 // and calls the pore band carried.
453 carried = carried + cw_band_line("pore-orif" as *u8, RLF_PORE_DIA_UM, res)
454 // NEG-CONTROL, evaluated every run: the whole-body span must keep reporting 0 for a band that a
455 // 250mm region carries. If these two ever agree, the span has been quietly redefined and this
456 // whole check has become decorative -- which is the failure mode an adequacy check invites.
457 let wb: i64 = rlf_band_resolvable_span(RLF_BODY_UM, res, RLF_SEC_LAMBDA_UM)
458 let rg: i64 = rlf_band_resolvable_span(CW_FACE_SPAN_UM, res, RLF_SEC_LAMBDA_UM)
459 ce_puts(" neg-control span-discriminates: whole-body=" as *u8); ce_pn(wb)
460 ce_puts(" region=" as *u8); ce_pn(rg)
461 if wb == rg {
462 ce_puts(" <== CONTROL FAILED: the span no longer discriminates, this check is decorative\n" as *u8)
463 }
464 if wb != rg { ce_puts(" OK (the region carries what the whole body cannot)\n" as *u8) }
465 cw_chart_adequacy(ab, res)
466 if carried < 4 {
467 ce_puts(" NPC-ATLAS AMBER: " as *u8); ce_pn(4 - carried)
468 ce_puts(" of 4 declared bands are COMPUTED BY THE BAKER AND CLAMPED AWAY at this resolution.\n" as *u8)
469 ce_puts(" REMEDY IS A PER-REGION ATLAS, NOT A BIGGER WHOLE-BODY ONE: the whole-body numbers\n" as *u8)
470 ce_puts(" above are absurd, the 250mm-region ones are already met by the resolution we ship.\n" as *u8)
471 ce_puts(" Advisory by design: a detector that is permanently RED is one everyone ignores.\n" as *u8)
472 }
473 return carried
474}
475func cw_npc_atlas(page: *u8, pn: i64) -> i64 {
476 if ce_find(page, pn, "uAtl" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the uAtl sampler path\n" as *u8); return 1 }
477 if ce_find(page, pn, "npc_atlas" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the npc_atlas runtime marker\n" as *u8); return 1 }
478 if ce_find(page, pn, "NXNPCS=[" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the NXNPCS visiting-cast roster\n" as *u8); return 1 }
479 if ce_find(page, pn, "loadDonors" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the loadDonors path\n" as *u8); return 1 }
480 if ce_find(page, pn, "uAuth" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the authored-surface (uAuth) mode\n" as *u8); return 1 }
481 if ce_find(page, pn, "NXNPCS=[" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the NXNPCS visiting-cast roster\n" as *u8); return 1 }
482 if ce_find(page, pn, "loadDonors" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the loadDonors path\n" as *u8); return 1 }
483 if ce_find(page, pn, "uAuth" as *u8) == 0 { ce_puts("NPC-ATLAS RED: page lacks the authored-surface (uAuth) mode\n" as *u8); return 1 }
484 let box9: *i64 = sys_mmap(16) as *i64
485 let ab: *u8 = sys_read_file(CW_NPC_ASSET, box9)
486 if (ab as i64) == 0 { ce_puts("NPC-ATLAS RED: NPC asset unreadable\n" as *u8); return 1 }
487 let ns9: i64 = cw_rd64(ab, 16)
488 var texc: i64 = 0
489 var texm: i64 = 0
490 var tmoff: i64 = 0
491 var s9: i64 = 0
492 while s9 < ns9 {
493 let e9: i64 = 32 + s9*32
494 if cw_tag4(ab, e9, "TEXC" as *u8) == 1 { texc = 1 }
495 if cw_tag4(ab, e9, "TEXM" as *u8) == 1 { texm = 1; tmoff = cw_rd64(ab, e9 + 8) }
496 s9 = s9 + 1
497 }
498 if texc == 0 { ce_puts("NPC-ATLAS RED: asset has no TEXC (no UVs to sample with)\n" as *u8); return 1 }
499 if texm == 0 { ce_puts("NPC-ATLAS RED: asset has no TEXM (no maps to sample)\n" as *u8); return 1 }
500 ce_puts("npc-atlas GREEN (page samples, asset carries TEXC+TEXM, sections=" as *u8); ce_pn(ns9); ce_puts(")\n" as *u8)
501 cw_atlas_adequate(ab, tmoff)
502 return 0
503}
504
505// cw_donors -- SHIP-TIME ASSERTION for the visiting cast (donors-into-world 2026-08-23): every
506// roster row in knowledge/world_npcs.conf must resolve to a SERVED asset carrying TEXC+TEXM.
507// A page that names a cast the docroot cannot serve, or a visitor that would arrive clay,
508// REFUSES the ship with the donor named. Absent conf = empty cast = GREEN (declared fallback,
509// never silence). This is the load-bearing twin of the page-side per-visitor refusal legs.
510func cw_donors() -> i64 {
511 let ln: *i64 = sys_mmap(16) as *i64
512 let buf: *u8 = sys_read_file("knowledge/world_npcs.conf" as *u8, ln)
513 if (buf as i64) == 0 { ce_puts("visiting-cast: conf absent, empty cast (declared)\n" as *u8); return 0 }
514 let n: i64 = ln[0]
515 var i: i64 = 0
516 var checked: i64 = 0
517 while i < n {
518 let ls: i64 = i
519 var le: i64 = ls
520 var scan: i64 = 1
521 while scan == 1 { if le >= n { scan = 0 } else { if buf[le] == (10 as u8) { scan = 0 } else { le = le + 1 } } }
522 if le >= n { ce_puts("VISITING-CAST RED: npcs.conf has no trailing newline\n" as *u8); return 1 }
523 i = le + 1
524 if le > ls { if buf[ls] != (35 as u8) {
525 buf[le] = 0 as u8
526 var q: i64 = ls
527 var asx: i64 = 0
528 var nf: i64 = 0
529 while q < le {
530 if buf[q] == (9 as u8) { buf[q] = 0 as u8; nf = nf + 1; if nf == 1 { asx = q + 1 } }
531 q = q + 1
532 }
533 if nf < 3 { ce_puts("VISITING-CAST RED: npcs.conf row needs 4 tab fields\n" as *u8); return 1 }
534 let pth: *u8 = sys_mmap(256)
535 var w: i64 = 0
536 let pre: *u8 = "sites/nishifamily/world/" as *u8
537 while pre[w] != (0 as u8) { pth[w] = pre[w]; w = w + 1 }
538 var a2: i64 = asx
539 while buf[a2] != (0 as u8) { pth[w] = buf[a2]; w = w + 1; a2 = a2 + 1 }
540 let sfx: *u8 = ".nxa" as *u8
541 var s2: i64 = 0
542 while sfx[s2] != (0 as u8) { pth[w] = sfx[s2]; w = w + 1; s2 = s2 + 1 }
543 pth[w] = 0 as u8
544 let bx: *i64 = sys_mmap(16) as *i64
545 let ab: *u8 = sys_read_file(pth, bx)
546 if (ab as i64) == 0 { ce_puts("VISITING-CAST RED: donor asset unreadable: " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 }
547 let ns9: i64 = cw_rd64(ab, 16)
548 var texc: i64 = 0
549 var texm: i64 = 0
550 var s9: i64 = 0
551 while s9 < ns9 {
552 let e9: i64 = 32 + s9*32
553 if cw_tag4(ab, e9, "TEXC" as *u8) == 1 { texc = 1 }
554 if cw_tag4(ab, e9, "TEXM" as *u8) == 1 { texm = 1 }
555 s9 = s9 + 1
556 }
557 if texc == 0 { ce_puts("VISITING-CAST RED: donor lacks TEXC: " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 }
558 if texm == 0 { ce_puts("VISITING-CAST RED: donor lacks TEXM (clay visitor): " as *u8); ce_puts(pth); ce_puts("\n" as *u8); return 1 }
559 checked = checked + 1
560 } }
561 }
562 ce_puts("visiting-cast GREEN (donors verified TEXC+TEXM: " as *u8); ce_pn(checked); ce_puts(")\n" as *u8)
563 return 0
564}
565
566// ===== PUBLISHED EVIDENCE, COMPUTED AT EMIT TIME =========================================
567// Operator standing requirement 2026-08-25: the beach must PUBLISH its own evidence so the
568// claim cannot drift from the code. Transcribed prose rots -- these figures are CALLED out of
569// the shipping derivation (nx_softbind), so the page and the physics are the SAME SOURCE. If
570// the derivation moves, this line moves with it; there is nothing to keep in sync by hand.
571const CE_EV_CAP: i64 = 8192
572func ce_cat(d: *u8, p: i64, s: *u8) -> i64 {
573 var i: i64 = 0
574 while s[i] != (0 as u8) { d[p+i] = s[i]; i = i + 1 }
575 return p + i
576}
577func ce_catn(d: *u8, p: i64, v: i64) -> i64 {
578 if v == 0 { d[p] = 48 as u8; return p + 1 }
579 var t: i64 = v
580 var n: i64 = 0
581 while t > 0 { t = t/10; n = n + 1 }
582 var k: i64 = n
583 var u: i64 = v
584 while k > 0 { d[p+k-1] = ((u % 10) + 48) as u8; u = u/10; k = k - 1 }
585 return p + n
586}
587func ce_evidence(base_ctrl: *u8, out: *u8) -> i64 {
588 var p: i64 = ce_cat(out, 0, base_ctrl)
589 p = ce_cat(out, p, "<br><b>TISSUE PHYSICS, DERIVED NOT TUNED</b> — every figure here is COMPUTED by the shipping solver as this page is written, so it cannot drift from the code running above it. Chest plant " as *u8)
590 p = ce_catn(out, p, sb_fn_mhz(0))
591 p = ce_cat(out, p, "–" as *u8)
592 p = ce_catn(out, p, sb_fn_mhz(SB_FIRM_MAX))
593 p = ce_cat(out, p, " mHz across bred bodies (cited tissue_fn_mhz 4000–5200, free-vibration modes) · damping " as *u8)
594 p = ce_catn(out, p, SB_ZETA_PERMIL)
595 p = ce_cat(out, p, " permil (haake-scurr-2010 measured 475, and what our own XPBD ringdown read) · downward stiffness " as *u8)
596 p = ce_catn(out, p, sb_k_dn(sb_fn_mhz(0))*10/sb_k_up(sb_fn_mhz(0)))
597 p = ce_cat(out, p, " tenths of the upward branch (cai2018 piecewise, selected by one sign test) · anisotropy AP " as *u8)
598 p = ce_catn(out, p, SB_ANISO_AP_PERMIL)
599 p = ce_cat(out, p, " / ML " as *u8)
600 p = ce_catn(out, p, SB_ANISO_ML_PERMIL)
601 p = ce_cat(out, p, " permil of vertical (mills2025) · " as *u8)
602 p = ce_catn(out, p, SB_FULL_N)
603 p = ce_cat(out, p, " distinct bodies drawn from each girl's whole genome, where there were 4 · proven by nx_gamefeel_oracle_gate and nx_softbind_gate." as *u8)
604 out[p] = 0 as u8
605 return p
606}
607
608func main() -> i64 {
609 // 1) THE GATE DECIDES: a RED world ships nothing (the emit script's step-2 law)
610 ce_puts("[1/5] gate " as *u8)
611 let g: i64 = ce_run(CE_GATE, 0 as *u8, 0 as *u8)
612 if g != 0 { ce_puts("RED rc=" as *u8); ce_pn(g); ce_puts(" -- REFUSED, nothing emitted\n" as *u8); return 2 }
613 ce_puts("GREEN\n" as *u8)
614
615 // 1b) THE FEEL ORACLE: every tunable inside its banked, cited reference band (the KAT
616 // pattern applied to feel) -- out-of-band tuning cannot ship through this lane
617 ce_puts("[1b/5] feel-oracle " as *u8)
618 let g2: i64 = ce_run("nx_gamefeel_oracle_gate.elf" as *u8, 0 as *u8, 0 as *u8)
619 if g2 != 0 { ce_puts("RED rc=" as *u8); ce_pn(g2); ce_puts(" -- REFUSED, nothing emitted\n" as *u8); return 2 }
620 ce_puts("GREEN\n" as *u8)
621
622 // 1c) THE VISITING CAST: roster-declared donors must be servable and textured BEFORE any
623 // page is built around them (the ship-time twin of the page-side per-visitor refusals).
624 ce_puts("[1c/5] visiting-cast " as *u8)
625 if cw_donors() != 0 { ce_puts("-- REFUSED, nothing emitted\n" as *u8); return 2 }
626
627 // 2) .nx -> .wat (byte-asserted: the historic silent 0-byte .wat is the class this kills)
628 let r1: i64 = ce_compile_craft(CE_WAT,0 as *u8)
629 let wn1: i64 = ce_fsize(CE_WAT)
630 ce_puts("[2/5] wat rc=" as *u8); ce_pn(r1); ce_puts(" bytes=" as *u8); ce_pn(wn1); ce_puts("\n" as *u8)
631 if wn1 < CE_MIN_WAT { ce_puts("EMIT-FAIL: wat under floor\n" as *u8); return 3 }
632
633 // 3) .wat -> .wasm (magic-checked -- a "GREEN" assembler on empty input still writes a stub)
634 let r2: i64 = ce_run(CE_WATC, CE_WAT, CE_WASM)
635 let box: *i64 = sys_mmap(16) as *i64
636 let wasm: *u8 = sys_read_file(CE_WASM, box)
637 ce_puts("[3/5] wasm rc=" as *u8); ce_pn(r2); ce_puts(" bytes=" as *u8); ce_pn(box[0]); ce_puts("\n" as *u8)
638 if (wasm as i64) == 0 { ce_puts("EMIT-FAIL: no wasm\n" as *u8); return 4 }
639 if box[0] < CE_MIN_WASM { ce_puts("EMIT-FAIL: wasm under floor\n" as *u8); return 4 }
640 if wasm[0] != (0 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 }
641 if wasm[1] != (97 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 }
642 if wasm[2] != (115 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 }
643 if wasm[3] != (109 as u8) { ce_puts("EMIT-FAIL: bad magic\n" as *u8); return 4 }
644
645 // 3b) ★RUN THE WASM WE JUST BUILT, IN THE MEMORY THE BROWSER WILL GIVE IT.
646 // Every check above this line inspects the wasm as BYTES -- size floors and the magic header.
647 // None of them can tell a module that RUNS from one that traps on its first frame. On 2026-08-14
648 // /craft shipped black TWICE through this pipeline: the arena had outgrown the module's declared
649 // linear memory, so the browser trapped with "index out of bounds", while every stage here
650 // reported GREEN and the NATIVE gate at [1/5] reported 59/59 -- because that gate sys_mmaps its
651 // own arena and therefore never meets the wasm bound at all.
652 // ★A PIPELINE THAT VALIDATES A DIFFERENT BUILD THAN THE ONE IT SHIPS IS NOT VALIDATING THE
653 // PRODUCT. nx_wasm_craft_vm_gate loads THIS file into the estate's own VM with memory sized to
654 // exactly what the module declares, proves the framebuffer fits at q=1, and renders a frame to
655 // prove the renderer actually executes. Placed HERE, after the wasm exists and before any page
656 // is written, so a module that cannot run can no longer reach a visitor.
657 ce_puts("[3b/5] wasm-vm " as *u8)
658 let g3: i64 = ce_run(CE_VMGATE, 0 as *u8, 0 as *u8)
659 if g3 != 0 { ce_puts("RED rc=" as *u8); ce_pn(g3); ce_puts(" -- the built wasm does not run in its own declared memory; REFUSED, nothing emitted\n" as *u8); return 4 }
660 ce_puts("GREEN\n" as *u8)
661
662 // 3c) GE30 THE THREADED TWIN. Same source, same generation, IMPORTED shared memory. Its page
663 // count is read off the plain wat above so the two builds can never disagree about the arena.
664 // ★IT MAY NOT REFUSE THE SHIP. Threading is a door on a ladder, not a requirement: a visitor
665 // without cross-origin isolation must still get the world. But a STALE twin is worse than no
666 // twin -- it would serve a DIFFERENT engine generation to isolated visitors than the inlined
667 // build every other visitor runs -- so any failure RETIRES the live file instead of leaving it.
668 // ★A WRONG-BUT-POSITIVE PARSE IS THE DANGEROUS CASE: the twin would build, carry a real shared
669 // import, pass every magic and floor check, and hand isolated visitors a memory too small for
670 // the framebuffer -- a trap on the first frame, which is exactly how /craft shipped black. A
671 // plausibility band turns that silent class into a named refusal. 16 pages is 1 MiB, under
672 // which no 3D arena fits; 65536 pages is the wasm32 ceiling, so anything outside is parse junk.
673 var mtp: i64 = ce_wat_pages(CE_WAT)
674 if mtp > 0 {
675 if mtp < CE_MT_PAGES_MIN {
676 ce_puts("[3c/5] mt page count " as *u8); ce_pn(mtp)
677 ce_puts(" is below the ") ; ce_pn(CE_MT_PAGES_MIN)
678 ce_puts("-page floor -- treating as a PARSE FAILURE, not an arena\n" as *u8)
679 mtp = 0 - 4
680 }
681 if mtp > CE_MT_PAGES_MAX {
682 ce_puts("[3c/5] mt page count " as *u8); ce_pn(mtp)
683 ce_puts(" exceeds the wasm32 ceiling -- treating as a PARSE FAILURE\n" as *u8)
684 mtp = 0 - 5
685 }
686 }
687 var mt_ok: i64 = 0
688 let mt_limits: *i64=sys_mmap(WM_FIELDS*8) as *i64
689 if mtp < 1 {
690 ce_puts("[3c/5] mt SKIPPED: could not read the page count off the plain wat (code " as *u8)
691 ce_pn(mtp); ce_puts(")\n" as *u8)
692 } else {
693 let pbuf: *u8 = sys_mmap(32)
694 let mbuf: *u8 = sys_mmap(32)
695 ce_num_str(mtp, pbuf)
696 ce_num_str(mtp * CE_MT_HEADROOM, mbuf)
697 // Preserve source-derived addresses; the plain module already includes static data.
698 let m1: i64 = ce_compile_craft(CE_WAT_MT,mbuf)
699 let mw: i64 = ce_fsize(CE_WAT_MT)
700 ce_puts("[3c/5] mt wat rc=" as *u8); ce_pn(m1)
701 ce_puts(" pages=" as *u8); ce_pn(mtp)
702 ce_puts(" max=" as *u8); ce_pn(mtp * CE_MT_HEADROOM)
703 ce_puts(" bytes=" as *u8); ce_pn(mw); ce_puts("\n" as *u8)
704 if m1 == 0 {
705 if mw >= CE_MIN_WAT {
706 let m2: i64 = ce_run(CE_WATC, CE_WAT_MT, CE_MT_TMP)
707 let mbox: *i64 = sys_mmap(16) as *i64
708 let mbytes: *u8 = sys_read_file(CE_MT_TMP, mbox)
709 if m2 == 0 {
710 if (mbytes as i64) != 0 {
711 if mbox[0] >= CE_MIN_WASM {
712 // Same magic check the shipped build gets: a GREEN assembler on bad
713 // input still writes a stub, and a stub would trap on the visitor.
714 var mg: i64 = 1
715 if mbytes[0] != (0 as u8) { mg = 0 }
716 if mbytes[1] != (97 as u8) { mg = 0 }
717 if mbytes[2] != (115 as u8) { mg = 0 }
718 if mbytes[3] != (109 as u8) { mg = 0 }
719 if mg == 1 {
720 // The twin must carry an IMPORTED memory. Without it every Worker
721 // gets a PRIVATE memory, no thread sees another's pixels, and the
722 // page would render a torn frame while every byte check passed.
723 let wbox: *i64 = sys_mmap(16) as *i64
724 let wsrc: *u8 = sys_read_file(CE_WAT_MT, wbox)
725 var imp: i64 = 0
726 // " shared))" closes the memory IMPORT and nothing else: the
727 // unshared path writes "(memory (export ...) N)" with no such
728 // token. A bare "memory 0)" would also match memory.init/copy
729 // operands, so it is deliberately not the needle.
730 if (wsrc as i64) != 0 { imp = ce_find(wsrc, wbox[0], " shared))" as *u8) }
731 let ml_rc: i64=wmem_read(mbytes,mbox[0],mt_limits)
732 if ml_rc!=0 { imp=0;ce_puts("[3c/5] mt memory descriptor refused code=" as *u8);ce_pn(ml_rc);ce_puts("\n" as *u8) }
733 if ml_rc==0 {
734 if mt_limits[2]!=1 { imp=0 }
735 if mt_limits[3]!=1 { imp=0 }
736 }
737 if imp == 1 {
738 if sys_renameat(CE_MT_TMP, CE_MT_OUT) >= 0 {
739 mt_ok = 1
740 ce_puts("[3c/5] mt wasm bytes=" as *u8); ce_pn(mbox[0])
741 ce_puts(" shared-import=yes -> " as *u8); ce_puts(CE_MT_OUT)
742 ce_puts("\n" as *u8)
743 } else { ce_puts("[3c/5] mt rename FAILED\n" as *u8) }
744 } else { ce_puts("[3c/5] mt REFUSED: no imported memory in the twin wat\n" as *u8) }
745 } else { ce_puts("[3c/5] mt REFUSED: bad wasm magic\n" as *u8) }
746 } else { ce_puts("[3c/5] mt REFUSED: wasm under floor\n" as *u8) }
747 } else { ce_puts("[3c/5] mt REFUSED: no wasm written\n" as *u8) }
748 } else { ce_puts("[3c/5] mt REFUSED: assembler rc=" as *u8); ce_pn(m2); ce_puts("\n" as *u8) }
749 } else { ce_puts("[3c/5] mt REFUSED: wat under floor\n" as *u8) }
750 } else { ce_puts("[3c/5] mt REFUSED: compiler rc=" as *u8); ce_pn(m1); ce_puts("\n" as *u8) }
751 }
752 if mt_ok == 0 {
753 // RETIRE rather than leave a mismatched generation live. Renaming onto the stage path is
754 // reversible and uses the one primitive this organ already ships with.
755 if sys_renameat(CE_MT_OUT, CE_MT_TMP) >= 0 {
756 ce_puts("[3c/5] mt RETIRED the previously live twin -- isolated visitors fall back to one thread\n" as *u8)
757 } else {
758 ce_puts("[3c/5] mt absent, nothing to retire -- single thread for every visitor\n" as *u8)
759 }
760 }
761 // DECLARE THE TWIN TO THE PAGE BUILDER, and only when one is actually live. The page must build a
762 // WebAssembly.Memory that matches the twin's declared import EXACTLY or instantiation fails, so
763 // these numbers travel from the stage that DERIVED them rather than being typed again page-side --
764 // two copies of one arena size is the duplicate-ruler defect with a browser trap at the end of it.
765 // Left at zero when the twin did not ship, which emits a page with no threading code at all.
766 if mt_ok == 1 {
767 gpe_mt_pages = mt_limits[0]
768 gpe_mt_max = mt_limits[1]
769 ce_puts("[3c/5] mt declared to the page builder: pages=" as *u8); ce_pn(gpe_mt_pages)
770 ce_puts(" max=" as *u8); ce_pn(gpe_mt_max); ce_puts("\n" as *u8)
771 }
772
773 // 4+5) THE WORLD RECIPE PLANE (W1, /world/procgen): rows from knowledge/world_recipes.conf
774 // drive EVERY page; the builtin three below remain the fallback when the file is absent
775 // (config-hierarchy law), and the source actually consumed is ANNOUNCED either way. A
776 // malformed recipe REFUSES the whole ship -- half a multiverse must not go live.
777 let R: *i64 = sys_mmap(GPR_MAXW*8*8) as *i64
778 let nr: i64 = gpe_recipes_load("knowledge/world_recipes.conf" as *u8, R)
779 if nr < 0 { ce_puts("EMIT-FAIL: recipe file malformed (row named on stderr); NOTHING shipped\n" as *u8); return 8 }
780 if nr > 0 {
781 ce_puts("recipe_src=file rows=" as *u8); ce_pn(nr); ce_puts("\n" as *u8)
782 let outw: *u8 = sys_mmap(GPE_OUT_CAP)
783 let sp: *u8 = sys_mmap(512)
784 let evw: *u8 = sys_mmap(CE_EV_CAP)
785 var w: i64 = 0
786 while w < nr {
787 let b: i64 = w*8
788 ce_evidence(R[b+5] as *u8, evw)
789 let pw: i64 = gpe_build_s(wasm, box[0], ce_stamp(R[b+4] as *u8), CE_NATIVE, evw, R[b+1], R[b+2], R[b+6] as *u8, outw)
790 ce_puts("[4/5] world=" as *u8); ce_puts(R[b+0] as *u8)
791 ce_puts(" page bytes=" as *u8); ce_pn(pw); ce_puts("\n" as *u8)
792 if pw < CE_MIN_PAGE { ce_puts("EMIT-FAIL: page under floor\n" as *u8); return 5 }
793 if cw_npc_atlas(outw, pw) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 }
794 let op: *u8 = R[b+3] as *u8
795 var q: i64 = 0
796 while op[q] != (0 as u8) { sp[q] = op[q]; q = q + 1 }
797 let sfx: *u8 = ".stage" as *u8
798 var q2: i64 = 0
799 while sfx[q2] != (0 as u8) { sp[q+q2] = sfx[q2]; q2 = q2 + 1 }
800 sp[q+q2] = 0 as u8
801 if ce_ship(outw, pw, sp, op) != 0 { return 6 }
802 w = w + 1
803 }
804 return 0
805 }
806 ce_puts("recipe_src=builtin rows=3\n" as *u8)
807 // 4) the page, IN-PROCESS (gpe_build is the ONE emitter; no second template can drift)
808 let out: *u8 = sys_mmap(GPE_OUT_CAP)
809 let pn: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE), CE_NATIVE, CE_CTRL, 0, out)
810 ce_puts("[4/5] page bytes=" as *u8); ce_pn(pn); ce_puts("\n" as *u8)
811 if pn < CE_MIN_PAGE { ce_puts("EMIT-FAIL: page under floor\n" as *u8); return 5 }
812 if cw_npc_atlas(out, pn) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 }
813
814 // 5) deploy tmp+rename, then READ BACK: bytes equal AND the loader marker present in what
815 // LANDED -- the filesystem is the oracle for an evidence row
816 if ce_ship(out, pn, CE_TMP, CE_OUT) != 0 { return 6 }
817 // 5b) THE REVIEW STAGE: identity v2 over the SAME gated wasm bytes
818 let out2: *u8 = sys_mmap(GPE_OUT_CAP)
819 let ev2: *u8 = sys_mmap(CE_EV_CAP)
820 ce_evidence(CE_CTRL2, ev2)
821 let pn2: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE2), CE_NATIVE, ev2, 2, out2)
822 if pn2 < CE_MIN_PAGE { ce_puts("EMIT-FAIL: shore page under floor\n" as *u8); return 5 }
823 if cw_npc_atlas(out2, pn2) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 }
824 if ce_ship(out2, pn2, CE_TMP2, CE_OUT2) != 0 { return 6 }
825 // 5c) THE THIRD WORLD, same gated wasm bytes -- one engine, three identities
826 let out3: *u8 = sys_mmap(GPE_OUT_CAP)
827 let pn3: i64 = gpe_build(wasm, box[0], ce_stamp(CE_TITLE3), CE_NATIVE, CE_CTRL3, 3, out3)
828 if pn3 < CE_MIN_PAGE { ce_puts("EMIT-FAIL: vale page under floor\n" as *u8); return 5 }
829 if cw_npc_atlas(out3, pn3) != 0 { ce_puts("EMIT-FAIL: npc-atlas contract (cw_npc_atlas) -- NOTHING shipped\n" as *u8); return 9 }
830 if ce_ship(out3, pn3, CE_TMP3, CE_OUT3) != 0 { return 6 }
831 return 0
832}
833
834func ce_ship(out: *u8, pn: i64, tmpp: *u8, outp: *u8) -> i64 {
835 // A page whose script does not lex shows NOTHING -- not even the CPU fallback runs -- so
836 // this refuses by name before a byte reaches the docroot. Same exit as the other page
837 // faults (5) so callers need no new branch.
838 let jo: *i64 = sys_mmap(JSB_O_N*8) as *i64
839 // NEG-CONTROL IN THE PATH, EVERY RUN: the ruler must still bite a planted unclosed brace
840 // before it is allowed to acquit the real page. A lexer that has gone blind would otherwise
841 // wave every page through and this stage would be decoration. Length DERIVED, never counted.
842 let bad: *u8 = "f(){" as *u8
843 if jsb_check(bad, ce_slen(bad), jo) == JSB_OK {
844 ce_puts("EMIT-FAIL: the JS lexer ACQUITTED a planted unclosed brace -- ruler is blind, NOTHING shipped\n" as *u8)
845 return 5
846 }
847 let jrc: i64 = jsb_check_page(out, pn, jo)
848 if jrc != JSB_OK {
849 ce_puts("EMIT-FAIL: page JavaScript does not lex (code " as *u8); ce_pn(jrc)
850 ce_puts(" brace=" as *u8); ce_pn(jo[JSB_O_BRACE])
851 ce_puts(" paren=" as *u8); ce_pn(jo[JSB_O_PAREN])
852 ce_puts(" state=" as *u8); ce_pn(jo[JSB_O_STATE])
853 ce_puts(" first_negative_at=" as *u8); ce_pn(jo[JSB_O_NEGAT])
854 ce_puts(" unterminated_from=" as *u8); ce_pn(jo[JSB_O_OPENAT])
855 ce_puts(") -- NOTHING shipped to " as *u8); ce_puts(outp); ce_puts("\n" as *u8)
856 return 5
857 }
858 ce_puts("[4b/5] page JS lexes: scanned=" as *u8); ce_pn(jo[JSB_O_SCAN]); ce_puts(" brace=0 paren=0 brack=0, planted-bad control BIT\n" as *u8)
859 // 4c) EVERY NAME ON THE PAGE MUST RESOLVE TO AN ENCLOSING SCOPE. The nxHairTick outage class:
860 // a page that LEXES cleanly can still throw ReferenceError on its first frame and silently
861 // drop every visitor to the CPU tier. nx_jsscope resolves statically over the sovereign
862 // ECMAScript parser; browser globals are DATA (knowledge/js_globals.conf, calibrated from the
863 // scope gate's own measured misses, each row carrying its reason).
864 let gbox: *i64 = sys_mmap(16) as *i64
865 let glob: *u8 = sys_read_file("knowledge/js_globals.conf" as *u8, gbox)
866 if (glob as i64) == 0 { ce_puts("EMIT-FAIL: js_globals.conf unreadable -- the scope referee cannot run, NOTHING shipped\n" as *u8); return 5 }
867 // NEG-CONTROL IN THE PATH, EVERY RUN: the resolver must still flag a planted undeclared name
868 // before it may acquit the real page. A resolver gone blind acquits everything.
869 let plant: *u8 = "q7planted()" as *u8
870 let pst: *i64 = jss_check(plant, ce_slen(plant), glob, gbox[0])
871 if (pst as i64) == 0 { ce_puts("EMIT-FAIL: scope referee cannot PARSE its planted control -- ruler broken, NOTHING shipped\n" as *u8); return 5 }
872 if pst[JS_ST_NRP] == 0 { ce_puts("EMIT-FAIL: scope referee ACQUITTED a planted undeclared name -- ruler blind, NOTHING shipped\n" as *u8); return 5 }
873 // the page's behaviour lives in its first <script> body -- the same extraction the scope gate
874 // judges, byte for byte, so the ship stage and the gate cannot disagree about the subject
875 // LARGEST script body, not the first: the boot-guard tag now precedes the engine, and a
876 // referee that judged the 450-byte guard while the 433KB engine went unjudged would be a
877 // referee that silently lost its subject.
878 var jss_s: i64 = 0 - 1
879 var jss_e: i64 = pn
880 var cs9: i64 = 0 - 1
881 var jsi: i64 = 0
882 while jsi + 8 < pn {
883 if cs9 < 0 {
884 if (out[jsi]&255)==60 { if (out[jsi+1]&255)==115 { if (out[jsi+2]&255)==99 { if (out[jsi+3]&255)==114 {
885 var jsj: i64 = jsi
886 while jsj < pn && (out[jsj]&255) != 62 { jsj = jsj + 1 }
887 cs9 = jsj + 1
888 jsi = jsj
889 } } } }
890 } else {
891 if (out[jsi]&255)==60 { if (out[jsi+1]&255)==47 { if (out[jsi+2]&255)==115 { if (out[jsi+3]&255)==99 {
892 if jsi - cs9 > jss_e - jss_s { if jss_s >= 0 { jss_e = jsi; jss_s = cs9 } }
893 if jss_s < 0 { jss_s = cs9; jss_e = jsi }
894 cs9 = 0 - 1
895 } } } }
896 }
897 jsi = jsi + 1
898 }
899 if jss_s < 0 { ce_puts("EMIT-FAIL: no <script> body found on the page -- nothing for the scope referee to judge, NOTHING shipped\n" as *u8); return 5 }
900 let sst: *i64 = jss_check(((out as i64) + jss_s) as *u8, jss_e - jss_s, glob, gbox[0])
901 if (sst as i64) == 0 { ce_puts("EMIT-FAIL: page does not PARSE under the sovereign JS parser (grammar gap or real defect -- run nx_jsscope_gate for the exact byte), NOTHING shipped\n" as *u8); return 5 }
902 if sst[JS_ST_OVER] != 0 { ce_puts("EMIT-FAIL: scope referee hit a table cap -- its verdict would be a BOUND, not a proof; NOTHING shipped\n" as *u8); return 5 }
903 if sst[JS_ST_NRP] != 0 {
904 let rp0: *i64 = (sst[JS_ST_RP]) as *i64
905 let jctx: *i64 = (sst[JS_ST_CTX]) as *i64
906 ce_puts("EMIT-FAIL: " as *u8); ce_pn(sst[JS_ST_NRP])
907 ce_puts(" scope-referee finding(s) (1=UNRESOLVED 2=OUT-OF-SCOPE 3=REDECLARED-AT-SCRIPT-SCOPE) -- NOTHING shipped\n" as *u8)
908 var fi9: i64 = 0
909 var fn9: i64 = sst[JS_ST_NRP]
910 if fn9 > 8 { fn9 = 8 }
911 while fi9 < fn9 {
912 ce_puts(" FINDING kind=" as *u8); ce_pn(rp0[fi9*RP_ROW])
913 ce_puts(" tok=" as *u8)
914 sys_write(1, ((jss_src(jctx) as i64) + jss_tok_start(jctx, rp0[fi9*RP_ROW+1])) as *u8, jss_tok_len(jctx, rp0[fi9*RP_ROW+1]))
915 ce_puts(" scope=" as *u8); ce_pn(rp0[fi9*RP_ROW+2])
916 ce_puts(" declscope=" as *u8); ce_pn(rp0[fi9*RP_ROW+3])
917 ce_puts("\n" as *u8)
918 fi9 = fi9 + 1
919 }
920 if sst[JS_ST_NRP] > 8 { ce_puts(" (list is a PREFIX of the count -- first 8 of the total)\n" as *u8) }
921 return 5
922 }
923 ce_puts("[4c/5] page scopes resolve: refs=" as *u8); ce_pn(sst[JS_ST_NREF]); ce_puts(" reports=0, planted-undeclared control BIT\n" as *u8)
924 let fd: i64 = sys_openat_wr(tmpp, CE_MODE)
925 if fd < 0 { ce_puts("EMIT-FAIL: stage open\n" as *u8); return 6 }
926 var off: i64 = 0
927 while off < pn {
928 let w: i64 = sys_write(fd, ((out as i64) + off) as *u8, pn - off)
929 if w <= 0 { sys_close(fd); ce_puts("EMIT-FAIL: stage write\n" as *u8); return 6 }
930 off = off + w
931 }
932 sys_close(fd)
933 if sys_renameat(tmpp, outp) < 0 { ce_puts("EMIT-FAIL: rename\n" as *u8); return 6 }
934 let box2: *i64 = sys_mmap(16) as *i64
935 let back: *u8 = sys_read_file(outp, box2)
936 if (back as i64) == 0 { ce_puts("EMIT-FAIL: readback\n" as *u8); return 7 }
937 if box2[0] != pn { ce_puts("EMIT-FAIL: readback bytes " as *u8); ce_pn(box2[0]); ce_puts(" != " as *u8); ce_pn(pn); ce_puts("\n" as *u8); return 7 }
938 if ce_find(back, box2[0], "WebAssembly.instantiate" as *u8) == 0 { ce_puts("EMIT-FAIL: loader marker missing\n" as *u8); return 7 }
939 ce_puts("[5/5] SHIPPED " as *u8); ce_pn(pn); ce_puts(" bytes -> " as *u8); ce_puts(outp); ce_puts(" (read back, marker verified)\n" as *u8)
940 return 0
941}