nx_swcompare_ladder_candidate.nx source
↩ module page · 2481 lines · 163754 B
1// AUTO-EXTRACTED shared base (nx_oo_extract). license_tier: ORIGINAL No hw writes (Rule 26).
2// functions: w,wc,wn,wj,wq,kv_s,kv_n,c_read,streq,starts,scopy,splitpipe,wnote,rp_base,rp_publish,rp_json,refs_pass
3import "nx_syscalls.nx"
4import "nx_symdecl_lib.nx"
5import "nx_market_ladder_lib.nx"
6import "nx_brand_tokens.nx" // the estate's design-token SSOT -- sc_theme_pass composes it, never a second parser
7import "nx_lineconf_lib.nx" // line-anchored conf reader, ONE owner -- never a private key=value parser
8import "nx_estate_path.nx" // THE ONE probe order for a status artifact -- a stamp written from the serving root must resolve from CWD=buildroot (gauge_pass, gaps_pass)
9import "nx_imgattr_lib.nx" // the ONE definition of how an attribute value and an img tag are written
10import "nx_evprofile_lib.nx" // THE ONE READER of the /compare evidence stamp -- evj_pass below PROJECTS
11import "nx_bench_receipt_lib.nx" // THE ONE READER of a <dom>.bench benchmark receipt -- bench_pass below RENDERS it (2026-09-01)
12import "nx_barfresh_lib.nx" // THE ONE bar-age ruler (2026-09-06) -- plan_pass renders each sotatarget with its sotabar month and freshness state
13import "nx_ladder_lib.nx" // THE ONE ladder ruler (2026-09-06) -- plan_pass renders the targets, the rung-role table and the NOT DECLARED notice
14import "nx_gauge_lib.nx" // THE ONE gauge-heartbeat ruler (codeeffectiveness CE9, 2026-09-06) -- gauge_pass below RENDERS a <dom>.gauge row with the SAME classifier the writing beat uses, so a stale gauge reads STALE and never zero
15 // it into api.json. Its closure adds NOTHING new to this lib: nx_lineconf_lib
16 // above already imports nx_estate_path, and nx_swcompare_matrix already
17 // imports both this base AND nx_evprofile_lib and compiles, so the two
18 // symbol sets are proven compatible rather than assumed so.
19func w(fd: i64, s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } sys_write(fd, s, n); return 0 }
20func wc(fd: i64, code: i64) -> i64 { let t: *u8 = sys_mmap(2); t[0] = code as u8; sys_write(fd, t, 1); return 0 }
21func wn(fd: i64, v: i64) -> i64 {
22 var m: i64 = v; if m < 0 { w(fd, "-" as *u8); m = 0 - m }
23 let t: *u8 = sys_mmap(24); var k: i64 = 0; if m == 0 { t[0] = 48 as u8; k = 1 }
24 while m > 0 { t[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 }
25 let o: *u8 = sys_mmap(24); var i: i64 = 0; while i < k { o[i] = t[k-1-i]; i = i + 1 } sys_write(fd, o, k); return 0
26}
27func wj(fd: i64, s: *u8) -> i64 {
28 var i: i64 = 0
29 while s[i] != (0 as u8) { let c: i64 = s[i] as i64
30 if c == 34 { wc(fd, 92); wc(fd, 34) } else { if c == 92 { wc(fd, 92); wc(fd, 92) } else { if c < 32 { wc(fd, 32) } else { wc(fd, c) } } }
31 i = i + 1 }
32 return 0
33}
34func wq(fd: i64) -> i64 { wc(fd, 34); return 0 }
35func kv_s(fd: i64, key: *u8, val: *u8) -> i64 { wq(fd); w(fd, key); wq(fd); wc(fd, 58); wq(fd); wj(fd, val); wq(fd); return 0 }
36func kv_n(fd: i64, key: *u8, v: i64) -> i64 { wq(fd); w(fd, key); wq(fd); wc(fd, 58); wn(fd, v); return 0 }
37func c_read(path: *u8, buf: *u8, cap: i64) -> i64 {
38 let fd: i64 = sys_openat_rd(path); if fd < 0 { return 0 - 1 }
39 var tot: i64 = 0
40 while tot < cap { let r: i64 = sys_read(fd, (buf as i64 + tot) as *u8, cap - tot); if r <= 0 { break } tot = tot + r }
41 sys_close(fd); return tot
42}
43func streq(a: *u8, b: *u8) -> i64 { var i: i64 = 0; while a[i] != (0 as u8) { if a[i] != b[i] { return 0 } i = i + 1 } if b[i] != (0 as u8) { return 0 } return 1 }
44func starts(s: *u8, pfx: *u8) -> i64 { var i: i64 = 0; while pfx[i] != (0 as u8) { if s[i] != pfx[i] { return 0 } i = i + 1 } return 1 }
45func scopy(dst: *u8, doff: i64, src: *u8) -> i64 { var i: i64 = 0; while src[i] != (0 as u8) { dst[doff+i] = src[i]; i = i + 1 } return doff + i }
46func splitpipe(s: *u8, fld: *i64, maxf: i64) -> i64 {
47 var c: i64 = 1; fld[0] = s as i64; var i: i64 = 0
48 while s[i] != (0 as u8) { if s[i] == (124 as u8) { s[i] = 0 as u8; if c < maxf { fld[c] = (s as i64) + i + 1; c = c + 1 } } i = i + 1 }
49 return c
50}
51func wnote(fd: i64, s: *u8) -> i64 {
52 var i: i64 = 0
53 while s[i] != (0 as u8) {
54 var emitted: i64 = 0
55 if s[i] == (91 as u8) { if s[i+1] == (64 as u8) {
56 var kl: i64 = 0
57 while s[i+2+kl] != (0 as u8) { if s[i+2+kl] == (93 as u8) { break } kl = kl + 1 }
58 if s[i+2+kl] == (93 as u8) { if kl > 0 {
59 w(fd, "<a class='cite' href='" as *u8); wc(fd, 35); w(fd, "ref-" as *u8)
60 var q: i64 = 0
61 while q < kl { wc(fd, s[i+2+q] as i64); q = q + 1 }
62 w(fd, "'>[" as *u8)
63 q = 0
64 while q < kl { wc(fd, s[i+2+q] as i64); q = q + 1 }
65 w(fd, "]</a>" as *u8)
66 i = i + 2 + kl + 1
67 emitted = 1
68 } }
69 } }
70 // ESCAPE THE TAG DELIMITERS, AND DELIBERATELY NOT '&'. Note prose is PROSE, so a '<' in it must
71 // render as TEXT: emitted raw it injects a live element into the published page. MEASURED
72 // 2026-08-26 -- a browser note reading "an <img> is an INLINE_BLOCK" emitted a real empty <img>,
73 // which took that page to a11y-issues=1 and made its whole-page asset claim UNPROVABLE, because
74 // the verifier counted an img tag whose src it could never resolve. One funnel, so both
75 // generators and every domain are fixed at once.
76 // '&' IS LEFT ALONE ON PURPOSE: 48 notes across the fleet (corpus_complete=1) carry intentional
77 // entities such as —, and escaping it would publish those literally on all 48. That is the
78 // imprecision chosen here, named rather than left for the next reader to rediscover.
79 if emitted == 0 {
80 let c: i64 = s[i] as i64
81 if c == 60 { w(fd, "<" as *u8) } else { if c == 62 { w(fd, ">" as *u8) } else { wc(fd, c) } }
82 i = i + 1
83 }
84 }
85 return 0
86}
87// ---- RIVAL-CLAIM PROVENANCE (2026-09-05) ----------------------------------------------------------------
88// Every Yes, Best or Part code in a rival column is a CLAIM about someone else's product, and until this
89// pass those codes were feature-observation reads with nothing behind them: the refs gate proves every
90// declared reference is cited and every mark resolves, but nothing asked whether a row that grades a rival
91// cites anything at all. Measured while evaluating DanceXR against charsim: eleven rows of rival codes typed
92// from a vendor read, zero marks, indistinguishable on the page from a row backed by a pinned mirror.
93// ONE classifier here, read by both generators (the refs_pass precedent), so the split cannot drift:
94// RV_NONE every rival code is 0 -- the row claims nothing about a rival
95// RV_CITED at least one rival code is non-zero AND the note carries a reference mark ( [@key] )
96// RV_UNCITED at least one rival code is non-zero and the note carries no mark: an observation read
97// A mark proves a mirror exists and is pinned (the refs gate's job); it does not prove the mirror SUPPORTS
98// the code -- that residual is stated on the page, never hidden behind the badge.
99const RV_NONE: i64 = 0
100const RV_CITED: i64 = 1
101const RV_UNCITED: i64 = 2
102func rv_code(s: *u8) -> i64 {
103 var v: i64 = 0
104 var any: i64 = 0
105 var i: i64 = 0
106 while s[i] != (0 as u8) { let c: i64 = s[i] as i64; if c >= 48 { if c <= 57 { v = v * 10 + (c - 48); any = 1 } } i = i + 1 }
107 if any == 0 { return 0 }
108 return v
109}
110func rv_note_cited(note: *u8) -> i64 {
111 var i: i64 = 0
112 while note[i] != (0 as u8) { if note[i] == (91 as u8) { if note[i+1] == (64 as u8) { return 1 } } i = i + 1 }
113 return 0
114}
115func rv_class(note: *u8, rf: *i64, rr: i64, stride: i64, ncol: i64) -> i64 {
116 var claims: i64 = 0
117 var cj: i64 = 0
118 while cj < ncol { if rv_code(rf[rr*stride + 4 + cj] as *u8) != 0 { claims = claims + 1 } cj = cj + 1 }
119 if claims == 0 { return RV_NONE }
120 if rv_note_cited(note) == 1 { return RV_CITED }
121 return RV_UNCITED
122}
123// the SOTA dialect grades with letters: B = Best, Y = Yes, ~ = Part are positive claims about a rival; N and blank are not.
124// ONE claim rule per dialect, ONE note rule for both, so the two generators cannot split on what counts as a claim.
125func rv_grade_claims(g: *u8) -> i64 { if g[0] == (66 as u8) { return 1 } if g[0] == (89 as u8) { return 1 } if g[0] == (126 as u8) { return 1 } return 0 }
126func rv_class_grades(note: *u8, rf: *i64, rr: i64, stride: i64, first: i64, count: i64) -> i64 {
127 var claims: i64 = 0
128 var cj: i64 = 0
129 while cj < count { if rv_grade_claims(rf[rr*stride + first + cj] as *u8) == 1 { claims = claims + 1 } cj = cj + 1 }
130 if claims == 0 { return RV_NONE }
131 if rv_note_cited(note) == 1 { return RV_CITED }
132 return RV_UNCITED
133}
134func rv_name(c: i64) -> *u8 {
135 if c == RV_CITED { return "CITED" as *u8 }
136 if c == RV_UNCITED { return "UNCITED" as *u8 }
137 return "NONE" as *u8
138}
139
140func rp_base(p: *u8) -> *u8 {
141 var i: i64 = 0
142 var last: i64 = 0
143 while p[i] != (0 as u8) { if p[i] == (47 as u8) { last = i + 1 } i = i + 1 }
144 return ((p as i64) + last) as *u8
145}
146func rp_publish(mir: *u8, dom: *u8) -> i64 {
147 let src: *u8 = sys_mmap(700)
148 var so: i64 = scopy(src, 0, "../" as *u8)
149 so = scopy(src, so, mir); src[so] = 0 as u8
150 let ln: *i64 = sys_mmap(16) as *i64
151 let body: *u8 = sys_read_file(src, ln)
152 if (body as i64) == 0 { return 0 }
153 if ln[0] <= 0 { return 0 }
154 let dir: *u8 = sys_mmap(700)
155 var dd: i64 = scopy(dir, 0, "../sites/nishifamily/compare/" as *u8)
156 dd = scopy(dir, dd, dom); dd = scopy(dir, dd, "/refs" as *u8); dir[dd] = 0 as u8
157 sys_mkdir(dir, MODE_0755)
158 let fin: *u8 = sys_mmap(700)
159 var fo: i64 = scopy(fin, 0, dir); fo = scopy(fin, fo, "/" as *u8); fo = scopy(fin, fo, rp_base(mir)); fin[fo] = 0 as u8
160 let tmp: *u8 = sys_mmap(700)
161 var to2: i64 = scopy(tmp, 0, fin); to2 = scopy(tmp, to2, ".tmp" as *u8); tmp[to2] = 0 as u8
162 let fd: i64 = sys_openat_wr(tmp, MODE_0644)
163 if fd < 0 { sys_free_file(body, ln[0]); return 0 }
164 let wrote: i64 = sys_write(fd, body, ln[0])
165 sys_close(fd)
166 sys_free_file(body, ln[0])
167 if wrote != ln[0] { return 0 }
168 if sys_renameat(tmp, fin) < 0 { return 0 }
169 return 1
170}
171
172// ---- THE REDISTRIBUTION GATE, ADDED 2026-08-25 ----
173// rp_publish above copies a stored third-party mirror into the PUBLIC docroot, and rp_html then links
174// it as "read in our library". THAT IS REDISTRIBUTION OF SOMEONE ELSE'S WORK, and until today nothing
175// on that path asked whether the licence permits it -- on 80 of the 84 domains carrying a .refs file.
176// The .refs `class` field is a SOURCE-TYPE vocabulary (published-paper, vendor-doc, dataset...), never
177// a rights vocabulary, so it could not have answered the question even in principle.
178//
179// RIGHTS ARE DATA (knowledge/refs_redistribute.conf), never code: clearing a class costs a row edit
180// AFTER someone reads a licence, not a rebuild. The encoding matches nx_licgate_lib and nx_acquire_lib
181// (0 NO / 1 REVIEW / 2 YES) so the three rulers cannot disagree about direction.
182const RP_NO: i64 = 0
183const RP_REVIEW: i64 = 1
184const RP_YES: i64 = 2
185const RP_KEYCAP: i64 = 128
186
187// AN ABSENT ROW IS A REFUSAL, NOT A PERMISSION. lcf_int_of returns LCF_MISS (negative) for a missing
188// key, so a class nobody has adjudicated -- including a brand-new vocabulary word arriving in a future
189// .refs file -- can never show up as an accidental YES. Silence is never permission.
190func rp_may_republish(cls: *u8) -> i64 {
191 let key: *u8 = sys_mmap(RP_KEYCAP)
192 var k: i64 = scopy(key, 0, "class_" as *u8)
193 k = scopy(key, k, cls); key[k] = 0 as u8
194 let v: i64 = lcf_int_of("knowledge/refs_redistribute.conf" as *u8, key)
195 if v < 0 { return RP_NO }
196 if v > RP_YES { return RP_NO }
197 return v
198}
199
200// THE GATE IN FRONT OF THE COPIER.
201// arm=0 (today) is MEASURE-ONLY: behaviour is byte-identical to before, so no published page changes
202// and no link disappears. That is the ONLY way to land this without silently stripping a link from 80
203// domains in a single regen. arm=1 ENFORCES, and flipping it is an OPERATOR decision about a public
204// surface -- the conf says so in its own words.
205// A missing or non-numeric arm row reads LCF_MISS (negative), which is not 1, so a corrupted conf
206// fails toward TODAY'S behaviour rather than toward an unannounced fleet-wide link removal. That is
207// deliberately the opposite default from rp_may_republish: an unreadable POLICY must not silently
208// change a public surface, while an unadjudicated CLASS must never grant a right.
209func rp_publish_gated(mir: *u8, dom: *u8, cls: *u8) -> i64 {
210 let arm: i64 = lcf_int_of("knowledge/refs_redistribute.conf" as *u8, "arm" as *u8)
211 if arm == 1 {
212 if rp_may_republish(cls) != RP_YES { return 0 }
213 }
214 return rp_publish(mir, dom)
215}
216
217func rp_json(fld: *i64, count: i64) -> i64 {
218 if count == 0 { wc(1, 44); wq(1); w(1, "refs" as *u8); wq(1); wc(1, 58); wc(1, 91) } else { wc(1, 44) }
219 wc(1, 123)
220 kv_s(1, "key" as *u8, fld[1] as *u8); wc(1, 44)
221 kv_s(1, "cite" as *u8, fld[2] as *u8); wc(1, 44)
222 kv_s(1, "url" as *u8, fld[3] as *u8); wc(1, 44)
223 kv_s(1, "mirror" as *u8, fld[4] as *u8); wc(1, 44)
224 kv_s(1, "pin" as *u8, fld[5] as *u8); wc(1, 44)
225 kv_s(1, "accessed" as *u8, fld[6] as *u8); wc(1, 44)
226 kv_s(1, "class" as *u8, fld[7] as *u8); wc(1, 44)
227 kv_s(1, "grounds" as *u8, fld[8] as *u8)
228 wc(1, 125)
229 return 0
230}
231// ---- rp_html LIFTED INTO THE BASE 2026-08-23 (lane L). It was a byte-identical copy in BOTH generators
232// while refs_pass here called it as a dangling callback, so nothing else could import this lib (a gate
233// composing watch_pass failed to link on rp_html). One copy now; the only per-generator difference --
234// the section header prose -- travels as the hdr argument. ----
235func rp_html(fld: *i64, count: i64, dom: *u8, hdr: *u8) -> i64 {
236 if count == 0 { w(1, hdr) }
237 w(1, "<li id='ref-" as *u8); w(1, fld[1] as *u8); w(1, "'><span class='rkey'>[" as *u8); w(1, fld[1] as *u8); w(1, "]</span> " as *u8)
238 w(1, fld[2] as *u8)
239 w(1, " <span class='rlinks'><a href='" as *u8); w(1, fld[3] as *u8); w(1, "'>publisher</a>" as *u8)
240 if streq(fld[4] as *u8, "-" as *u8) == 0 {
241 if rp_publish_gated(fld[4] as *u8, dom, fld[7] as *u8) == 1 {
242 w(1, " · <a href='/compare/" as *u8); w(1, dom); w(1, "/refs/" as *u8); w(1, rp_base(fld[4] as *u8)); w(1, "'><b>read in our library</b></a> <code>" as *u8); w(1, fld[4] as *u8); w(1, "</code>" as *u8)
243 } else {
244 w(1, " · mirror <code>" as *u8); w(1, fld[4] as *u8); w(1, "</code>" as *u8)
245 }
246 }
247 if streq(fld[5] as *u8, "-" as *u8) == 0 { w(1, " · pin <code>" as *u8); w(1, fld[5] as *u8); w(1, "</code>" as *u8) }
248 if streq(fld[6] as *u8, "-" as *u8) == 0 { w(1, " · accessed " as *u8); w(1, fld[6] as *u8) }
249 w(1, " · <span class='rgrade'>" as *u8); w(1, fld[7] as *u8); w(1, "</span></span>" as *u8)
250 w(1, "<span class='rg'>Grounds: " as *u8); w(1, fld[8] as *u8); w(1, "</span></li>\n" as *u8)
251 return 0
252}
253func refs_pass(path: *u8, bufz: *u8, capz: i64, mode: i64, dom: *u8, hdr: *u8) -> i64 {
254 // SAME CAP, SAME REMOVAL (2026-08-28, debt 1787937117): the HTML refs render was called with the
255 // 20479-byte plan buffer while the api.json render got a larger one, so on any board whose .refs
256 // exceeds 20479 the page and the JSON disagreed about how many references exist -- 7 of them
257 // measured, aesthetictwin worst at 37446. Size from the file, never from the caller.
258 var fsz: i64 = 0
259 let szfd: i64 = sys_openat_rd(path)
260 if szfd < 0 { return 0 }
261 fsz = sys_lseek(szfd, 0, 2)
262 sys_close(szfd)
263 if fsz <= 0 { return 0 }
264 let buf: *u8 = sys_mmap(fsz + 1)
265 let n: i64 = c_read(path, buf, fsz)
266 if n <= 0 { return 0 }
267 buf[n] = 0 as u8
268 let fld: *i64 = sys_mmap(200) as *i64
269 var count: i64 = 0
270 var p: i64 = 0
271 while p < n {
272 var e: i64 = p
273 while e < n { if buf[e] == (10 as u8) { break } e = e + 1 }
274 buf[e] = 0 as u8
275 let line: *u8 = (buf as i64 + p) as *u8
276 p = e + 1
277 var skip: i64 = 0
278 if line[0] == (0 as u8) { skip = 1 }
279 if line[0] == (35 as u8) { skip = 1 }
280 if skip == 0 {
281 let nf: i64 = splitpipe(line, fld, 12)
282 if streq(fld[0] as *u8, "ref" as *u8) == 1 { if nf >= 9 {
283 if mode == 1 { rp_html(fld, count, dom, hdr) }
284 if mode == 2 { rp_json(fld, count) }
285 count = count + 1
286 } }
287 }
288 }
289 if count > 0 { if mode == 1 { w(1, "</ol>\n" as *u8) } else { if mode == 2 { wc(1, 93) } } }
290 return count
291}
292
293// ---- PLAN RENDERING, LIFTED INTO THE BASE 2026-08-22 (rung DG5) ------------------------------------
294// WHY THIS MOVED. plan_pass lived INSIDE nx_swcompare_matrix, so a domain whose page is emitted by the
295// SOTA generator had its .plan admitted as data and then NEVER RENDERED. Proven with full coverage
296// (matches=0, files=11, corpus_complete=1): the tool plane's own computed build order was invisible on
297// its own page, which is why nx_compare_rank looked like it had nothing to say there.
298// This follows the refs_pass precedent exactly -- ONE renderer in the base, BOTH generators call it --
299// so the two surfaces cannot drift into two different plan dialects. A second copy in the sota generator
300// would have been the duplicate-ruler defect, and it would have drifted on the first row kind either
301// generator added.
302// dstate and wlow come WITH it, not after it: NishiLang resolves identifiers in TEXTUAL ORDER, so a lib
303// function cannot call a helper defined later in the importing program. A partial lift does not compile.
304const SWL_DSTATE_CAP: i64 = 20480 // .debtstate sidecar read buffer. The NUL slot is DERIVED (CAP - 1)
305 // rather than a second hand-counted constant beside it: two numbers
306 // describing one buffer drift silently and the parser then reads the
307 // wrong window while still compiling.
308
309// Print what the DEBT PLANE says about an id: open, eaten, or not filed in this scope at all. The state
310// file is `id<TAB>state` per line, refreshed by the regen before any page is emitted.
311func dstate(fd: i64, id: *u8, ds: *u8, dn: i64) -> i64 {
312 if dn <= 0 { return 0 }
313 var i: i64 = 0
314 while i < dn {
315 var e: i64 = i
316 while e < dn { if ds[e] == (10 as u8) { break } e = e + 1 }
317 var k: i64 = 0
318 var ok: i64 = 1
319 var stop: i64 = 0
320 while stop == 0 {
321 if i + k >= e { stop = 1 } else {
322 let c: i64 = ds[i+k] as i64
323 if c == 9 { stop = 1 } else {
324 let ic: i64 = id[k] as i64
325 if ic == 0 { ok = 0; stop = 1 } else { if ic != c { ok = 0; stop = 1 } else { k = k + 1 } }
326 }
327 }
328 }
329 if ok == 1 { if (id[k] as i64) == 0 {
330 var s: i64 = i + k
331 if s < e { if ds[s] == (9 as u8) { s = s + 1 } }
332 w(fd, "<span class='pstate'>" as *u8)
333 var q: i64 = s
334 while q < e { wc(fd, ds[q] as i64); q = q + 1 }
335 w(fd, "</span>" as *u8)
336 return 1
337 } }
338 i = e + 1
339 }
340 // NOT "not filed". The lookup is scoped to THIS domain, so a debt filed under another scope is
341 // absent here while being perfectly real in the plane. Saying "not filed" publishes a false negative
342 // about a colleague's open work.
343 w(fd, "<span class='pstate note'>not in this scope</span>" as *u8)
344 return 0
345}
346// lowercase into a search-key attribute; single AND double quotes neutralised so they cannot close it.
347// wlow writes a lowercase SEARCH TOKEN into a single-quoted data- attribute. It already neutralised
348// both quote characters, which is why the gallery's data-t survived the caption apostrophe that
349// destroyed its sibling alt on the same tag -- HALF A LAW, APPLIED IN ONE ATTRIBUTE AND NOT THE OTHER.
350// It still passed the three markup-significant bytes through raw, so the same hole stood open for any
351// caption carrying an ampersand or an angle bracket. It now hands its result to the ONE attribute
352// escaper rather than carrying a second, weaker copy of that decision (2026-08-26).
353// The bare character codes are gone with it: they are the IA_ identities now.
354func wlow(fd: i64, s: *u8) -> i64 {
355 let n: i64 = ia_slen(s)
356 let low: *u8 = sys_mmap(n + 1)
357 var i: i64 = 0
358 while i < n {
359 var c: i64 = s[i] as i64
360 if c >= IA_UPPER_A { if c <= IA_UPPER_Z { c = c + IA_CASE_DELTA } }
361 if c == IA_SQ { c = IA_SP }
362 if c == IA_DQ { c = IA_SP }
363 low[i] = c as u8
364 i = i + 1
365 }
366 low[n] = 0 as u8
367 let need: i64 = n * IA_MAX_EXPANSION + IA_SEP_AND_NUL
368 let b: *u8 = sys_mmap(need)
369 let tr: *i64 = sys_mmap(IA_SLOT_BYTES) as *i64
370 ia_esc_attr(b, 0, low, need, tr)
371 w(fd, b)
372 return 0
373}
374// ---- LADDER TO SOTA helpers (2026-09-06), defined BEFORE plan_pass because NishiLang resolves in textual order ----
375// Both take SPANS precomputed before the walk: plan_pass's walk NUL-terminates lines and splitpipe zeroes pipes in place,
376// so a field re-parsed at render time on an already-walked line would read one truncated field. The bytes of the fields
377// themselves are untouched, so a span captured first is still readable when its consumer row arrives later in the file.
378// the month and freshness state of the sotabar row whose id is `id`, printed after the target's "dated by <id>"
379func swl_bar_state(fd: i64, buf: *u8, bidoff: *i64, bidlen: *i64, bym: *i64, bst: *i64, nb: i64, id: *u8) -> i64 {
380 var i: i64 = 0
381 while i < nb {
382 if ld_span_is(buf, bidoff[i], bidlen[i], id) == 1 {
383 w(fd, " = " as *u8)
384 if bym[i] == BF_NONE { w(fd, "MALFORMED MONTH" as *u8) } else {
385 let ymb: *u8 = sys_mmap(12)
386 bf_ym_write(ymb, 0, bym[i])
387 w(fd, ymb)
388 }
389 w(fd, " " as *u8); w(fd, bf_state_name(bst[i]))
390 return 1
391 }
392 i = i + 1
393 }
394 w(fd, " = NO SUCH SOTABAR ROW, UNDATED" as *u8)
395 return 0
396}
397// the deps field of the rung row whose id is `id` (what the rung stands on), or a dash
398func swl_rung_deps(fd: i64, buf: *u8, ridoff: *i64, ridlen: *i64, rdoff: *i64, rdlen: *i64, nr: i64, id: *u8) -> i64 {
399 var i: i64 = 0
400 while i < nr {
401 if ld_span_is(buf, ridoff[i], ridlen[i], id) == 1 {
402 if rdlen[i] > 0 { sys_write(fd, (buf as i64 + rdoff[i]) as *u8, rdlen[i]) } else { w(fd, "-" as *u8) }
403 return 1
404 }
405 i = i + 1
406 }
407 w(fd, "-" as *u8)
408 return 0
409}
410// A release date comes from a complete positive decimal epoch, never filtered digits.
411const SWL_RELEASE_I64_MAX: i64 = 9223372036854775807
412func swl_release_epoch(s: *u8) -> i64 {
413 if (s as i64) == 0 { return 0 }
414 if s[0] == (0 as u8) { return 0 }
415 var v: i64 = 0
416 var i: i64 = 0
417 while s[i] != (0 as u8) {
418 let c: i64 = s[i] as i64
419 if c < 48 { return 0 }
420 if c > 57 { return 0 }
421 let d: i64 = c - 48
422 if v > (SWL_RELEASE_I64_MAX - d) / 10 { return 0 }
423 v = v * 10 + d
424 i = i + 1
425 }
426 return v
427}
428// Equal timestamps preserve append-order corrections; older rows cannot replace newer ones.
429func swl_release_candidate(epoch: *u8, kind: *u8, entry: *u8, current: i64, now: i64) -> i64 {
430 if (kind as i64) == 0 { return 0 }
431 if (entry as i64) == 0 { return 0 }
432 if entry[0] == (0 as u8) { return 0 }
433 if streq(kind, "land" as *u8) != 1 { return 0 }
434 let candidate: i64 = swl_release_epoch(epoch)
435 if candidate <= 0 { return 0 }
436 if candidate < current { return 0 }
437 if candidate > now { return 0 }
438 return candidate
439}
440
441func plan_pass(path: *u8, bufz: *u8, capz: i64, phase: i64) -> i64 {
442 // THE 20479-BYTE CAP IS REMOVED, NOT RAISED (2026-08-28, debt 1787937117). The caller handed us a
443 // guessed buffer whose cap silently short-read every .plan over 20479 bytes -- 8 of 93 measured,
444 // browser worst at 63614 -- publishing a PREFIX whose lost rows are always the NEWEST, announced
445 // nowhere. A ceiling that has to be guessed is a defect generator in both directions, and for a FILE
446 // read there is no guess to make: size the buffer from the file itself (lseek END), like sys_read_file.
447 // bufz/capz are kept only so every existing call site still compiles; they are deliberately unused.
448 var fsz: i64 = 0
449 let szfd: i64 = sys_openat_rd(path)
450 if szfd < 0 { return 0 }
451 fsz = sys_lseek(szfd, 0, 2)
452 sys_close(szfd)
453 if fsz <= 0 { return 0 }
454 let buf: *u8 = sys_mmap(fsz + 1)
455 let n: i64 = c_read(path, buf, fsz)
456 if n <= 0 { return 0 }
457 buf[n] = 0 as u8
458 let fld: *i64 = sys_mmap(200) as *i64
459 // the plane's view of each debt id, refreshed by the regen before this page was emitted.
460 // Derived from the plan path so the two files cannot drift apart by name.
461 let dsbuf: *u8 = sys_mmap(SWL_DSTATE_CAP)
462 var dsn: i64 = 0
463 if phase == 3 {
464 let dsp: *u8 = sys_mmap(600)
465 var dq: i64 = 0
466 while path[dq] != (0 as u8) { dsp[dq] = path[dq]; dq = dq + 1 }
467 var cut: i64 = dq
468 while cut > 0 { if dsp[cut] == (46 as u8) { break } cut = cut - 1 }
469 if cut > 0 { dq = cut }
470 dq = scopy(dsp, dq, ".debtstate" as *u8)
471 dsp[dq] = 0 as u8
472 dsn = c_read(dsp, dsbuf, SWL_DSTATE_CAP - 1)
473 if dsn < 0 { dsn = 0 }
474 }
475 var in_rung: i64 = 0
476 var in_ms: i64 = 0
477 var in_biz: i64 = 0
478 var in_lad: i64 = 0
479 var in_log: i64 = 0
480 var release_epoch: i64 = 0
481 let release_now: i64 = sys_now_realtime_sec()
482 var release_entry: *u8 = 0 as *u8
483 var release_rung: *u8 = 0 as *u8
484 // LADDER TO SOTA (2026-09-06): classify the sotabar/barscan and sotatarget/rungrole rows ONCE, before the walk below
485 // NUL-terminates lines and zeroes pipes in place, and bank the spans the render helpers read (see swl_bar_state).
486 let bfnb: i64 = bf_count_rows(buf, n, BF_BAR_TAG)
487 let bfoff: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
488 let bfym: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
489 let bfst: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
490 let bfseen: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
491 let bfc: *i64 = sys_mmap(BF_C_N * 8) as *i64
492 let bfcur: i64 = bf_now_ym()
493 bf_classify(buf, n, bfcur, bfoff, bfym, bfst, bfseen, bfc)
494 let bidoff: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
495 let bidlen: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
496 let sfo: *i64 = sys_mmap(8) as *i64
497 var sbi: i64 = 0
498 while sbi < bfnb { let sbe: i64 = bf_line_end(buf, n, bfoff[sbi]); bidlen[sbi] = bf_field(buf, bfoff[sbi], sbe, BF_F_BAR_ID, sfo); bidoff[sbi] = sfo[0]; sbi = sbi + 1 }
499 let ldnt: i64 = bf_count_rows(buf, n, LD_TARGET_TAG)
500 let ldnr: i64 = bf_count_rows(buf, n, LD_RUNG_TAG)
501 let ldc: *i64 = sys_mmap(LD_N_COUNT * 8) as *i64
502 let ldtoff: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
503 let ldtcls: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
504 let ldtst: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
505 let ldroff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
506 let ldrrole: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
507 let ldrtgt: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
508 let ldrst: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
509 ld_classify(buf, n, ldtoff, ldtcls, ldtst, ldroff, ldrrole, ldrtgt, ldrst, ldc)
510 let ldv: i64 = ld_verdict(ldc)
511 let ridoff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
512 let ridlen: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
513 let rdoff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
514 let rdlen: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
515 var sri: i64 = 0
516 while sri < ldnr { let sre: i64 = bf_line_end(buf, n, ldroff[sri]); ridlen[sri] = bf_field(buf, ldroff[sri], sre, LD_F_R_ID, sfo); ridoff[sri] = sfo[0]; rdlen[sri] = bf_field(buf, ldroff[sri], sre, LD_F_R_DEPS, sfo); rdoff[sri] = sfo[0]; sri = sri + 1 }
517 var in_tgt: i64 = 0
518 var in_role: i64 = 0
519 if phase == 1 { w(1, "<div class='exec-grid'>\n" as *u8) }
520 var p: i64 = 0
521 while p < n {
522 var e: i64 = p
523 while e < n { if buf[e] == (10 as u8) { break } e = e + 1 }
524 buf[e] = 0 as u8
525 let line: *u8 = (buf as i64 + p) as *u8
526 p = e + 1
527 var skip: i64 = 0
528 if line[0] == (0 as u8) { skip = 1 }
529 if line[0] == (35 as u8) { skip = 1 }
530 if skip == 0 {
531 let nf: i64 = splitpipe(line, fld, 20)
532 let kind: *u8 = fld[0] as *u8
533 if phase == 1 {
534 if streq(kind, "log" as *u8) == 1 { if nf == 5 {
535 let candidate: i64 = swl_release_candidate(fld[1] as *u8, fld[3] as *u8, fld[4] as *u8, release_epoch, release_now)
536 if candidate > 0 {
537 release_epoch = candidate
538 release_rung = fld[2] as *u8
539 release_entry = fld[4] as *u8
540 }
541 } }
542 if streq(kind, "pos" as *u8) == 1 { if nf >= 2 { w(1, "<p class='lead'><b>Where we are.</b> " as *u8); wnote(1, fld[1] as *u8); w(1, "</p>\n" as *u8) } }
543 if streq(kind, "goal" as *u8) == 1 { if nf >= 2 { w(1, "<p class='lead'><b>Where we need to go.</b> " as *u8); wnote(1, fld[1] as *u8); w(1, "</p>\n" as *u8) } }
544 if streq(kind, "answer" as *u8) == 1 { if nf >= 4 {
545 w(1, "<div class='answer'><b>" as *u8); w(1, fld[1] as *u8); w(1, ": " as *u8); w(1, fld[2] as *u8); w(1, ".</b> " as *u8); wnote(1, fld[3] as *u8); w(1, "</div>\n" as *u8) } }
546 if streq(kind, "bar" as *u8) == 1 { if nf >= 6 {
547 w(1, "<p class='lead'><b>Research bar.</b> <a href='" as *u8); w(1, fld[2] as *u8); w(1, "'>" as *u8); w(1, fld[1] as *u8); w(1, "</a> is measured on " as *u8); w(1, fld[3] as *u8)
548 w(1, ". Theirs: <b>" as *u8); wnote(1, fld[4] as *u8); w(1, "</b>. Ours: " as *u8); wnote(1, fld[5] as *u8); w(1, ".</p>\n" as *u8) } }
549 if streq(kind, "unit" as *u8) == 1 { if nf >= 2 { w(1, "<div class='meth'><b>The unit.</b> " as *u8); w(1, fld[1] as *u8); w(1, "</div>\n" as *u8) } }
550 // biz|axis|position|figures|decision -- the BUSINESS CASE row kind (investment, opportunity
551 // cost, market, competitive position, go-to-market, buy-vs-build). Rendered as one table in
552 // the executive layer; biz rows belong LAST in a plan's phase-1 block so the table closes clean.
553 if streq(kind, "biz" as *u8) == 1 { if nf >= 5 {
554 if in_biz == 0 { w(1, "<h2>Business case</h2>\n<table class='pl'><thead><tr><th>Axis</th><th>Position</th><th>Figures</th><th>Decision</th></tr></thead><tbody>\n" as *u8); in_biz = 1 }
555 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b></td><td>" as *u8); wnote(1, fld[2] as *u8)
556 w(1, "</td><td class='ct'>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
557 // ladder|level|best_in_class|have|grow|verdict -- the MARKET-ENTRY LADDER row kind (2026-08-24): per level
558 // (hobbyist to research leader) what best-in-class looks like from the mirrored record, what the estate measures
559 // today, what must grow, and the ENTER or HOLD or GROW-FIRST verdict. Rendered as one table after the business
560 // case; ladder rows belong LAST in a plan's phase-1 block. The verdict is DATA here; ml_entry_verdict computes it.
561 if streq(kind, "ladder" as *u8) == 1 { if nf >= 6 {
562 if in_biz == 1 { w(1, "</tbody></table>\n" as *u8); in_biz = 0 }
563 if in_lad == 0 { w(1, "<h2>Market-entry ladder</h2>\n<table class='pl'><thead><tr><th>Level</th><th>Best in class (Aug 2026)</th><th>What we have</th><th>What must grow</th><th>Verdict</th></tr></thead><tbody>\n" as *u8); in_lad = 1 }
564 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b></td><td>" as *u8); wnote(1, fld[2] as *u8)
565 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8)
566 w(1, "</td><td class='ct'>" as *u8); wnote(1, fld[5] as *u8)
567 // the COMPUTED verdict beside the authored one (nx_market_ladder_lib, the one ruler the CLI uses)
568 if nf >= 7 { ml_render_computed_html(1, path, fld[6] as *u8) }
569 w(1, "</td></tr>\n" as *u8) } }
570 }
571 if phase == 3 {
572 if streq(kind, "debt" as *u8) == 1 { if nf >= 5 {
573 if in_rung == 0 { w(1, "<h2>Debt register</h2>\n<table class='pl'><thead><tr><th>Id</th><th class='r'>Sev</th><th>What it is</th><th>Unblock</th></tr></thead><tbody>\n" as *u8); in_rung = 1 }
574 w(1, "<tr><td class='ct'>" as *u8); w(1, fld[1] as *u8)
575 // STATE COMES FROM THE PLANE, NEVER FROM THIS ROW. An id the plane does not know is a
576 // page-local note wearing the shape of a filed debt, and saying so is the honest move.
577 dstate(1, fld[1] as *u8, dsbuf, dsn)
578 w(1, "</td><td class='r'>" as *u8); w(1, fld[2] as *u8)
579 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
580 if streq(kind, "risk" as *u8) == 1 { if nf >= 4 {
581 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
582 if in_ms == 0 { w(1, "<h2>Risk register</h2>\n<table class='pl'><thead><tr><th>Risk</th><th>Likelihood x impact</th><th>Mitigation</th></tr></thead><tbody>\n" as *u8); in_ms = 1 }
583 w(1, "<tr><td>" as *u8); wnote(1, fld[1] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[2] as *u8)
584 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td></tr>\n" as *u8) } }
585 // log|<epoch>|<rung>|<kind>|<text> -- THE WORKED PLAN ON THE BOARD (operator 2026-09-02: a crash must
586 // leave a ledger here, not a transcript to mine). Every leg appends what it measured, landed,
587 // retracted, learned and left queued, per rung; rendered newest-last, each row linking to its rung.
588 if streq(kind, "log" as *u8) == 1 { if nf >= 5 {
589 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
590 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
591 if in_log == 0 { w(1, "<h2 id='worklog'>Release history and work log</h2>\n<div class='meth'><b>The worked plan, on the board.</b> Every leg appends what it measured, landed, retracted, learned and left queued, per rung, so a crash leaves the next seat a ledger here rather than a transcript to mine. Kinds: measure, land, retract, lesson, queue. Newest last.</div>\n<table class='pl'><thead><tr><th>When</th><th>Rung</th><th>Kind</th><th>Entry</th></tr></thead><tbody>\n" as *u8); in_log = 1 }
592 let lep: *u8 = fld[1] as *u8
593 var lv: i64 = 0
594 var li: i64 = 0
595 while lep[li] != (0 as u8) { let lc: i64 = lep[li] as i64; if lc >= 48 { if lc <= 57 { lv = lv*10 + (lc-48) } } li = li + 1 }
596 let ldb: *u8 = sys_mmap(32)
597 let ldn: i64 = bd_ymd(lv, ldb, 0)
598 ldb[ldn] = 0 as u8
599 w(1, "<tr><td class='ct'>" as *u8); w(1, ldb); w(1, "</td><td class='ct'><a href='#" as *u8); wlow(1, fld[2] as *u8); w(1, "'>" as *u8); w(1, fld[2] as *u8)
600 w(1, "</a></td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
601 }
602 if phase == 2 {
603 if streq(kind, "rung" as *u8) == 1 { if nf >= 8 {
604 if in_rung == 0 { w(1, "<table class='pl'><thead><tr><th>Rung</th><th>Closes with</th><th>Definition of done (pre-declared)</th><th>Executor</th><th class='r'>Est.</th></tr></thead><tbody>\n" as *u8); in_rung = 1 }
605 w(1, "<tr id='" as *u8); wlow(1, fld[1] as *u8); w(1, "'><td><b>" as *u8); w(1, fld[2] as *u8); w(1, "</b> (" as *u8); w(1, fld[1] as *u8); w(1, ")" as *u8)
606 if streq(fld[7] as *u8, "-" as *u8) == 0 { w(1, "<br><span class='ct'>after " as *u8); w(1, fld[7] as *u8); w(1, "</span>" as *u8) }
607 w(1, "</td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8)
608 w(1, "</td><td><span class='ex'>" as *u8); w(1, fld[5] as *u8); w(1, "</span></td><td class='r'>" as *u8); w(1, fld[6] as *u8); w(1, " u</td></tr>\n" as *u8) } }
609 // LADDER TO SOTA (2026-09-06): the dated targets, judged by the bar-age ruler, then the rung-role table.
610 // sotatarget and rungrole rows belong AFTER the rung and ms rows in a plan so the ladder renders beneath them.
611 if streq(kind, "sotatarget" as *u8) == 1 { if nf >= 6 {
612 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
613 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
614 if in_tgt == 0 { w(1, "<h2 id='ladder'>Ladder to SOTA</h2>\n<div class='meth'><b>Two dated targets, and every rung's role toward them.</b> Best in class is the proven, deployed leader today; the frontier is the research edge as of its month. Each target is dated by a sotabar row and judged against the current month by the bar-age ruler (FRESH, ATTESTED with the fallback month named, or refused). Each rung is substrate (what the target's own methods consume), an arm (a sovereign arm that triangulates without competing for the number), a contender (its done-rule is a number against the target) or superseded (kept as capability, retired as a claim), and carries the rungs it stands on.</div>\n" as *u8); in_tgt = 1 }
615 w(1, "<div class='answer'><b>" as *u8); w(1, fld[2] as *u8); w(1, " (" as *u8); w(1, fld[1] as *u8); w(1, "), dated by " as *u8); w(1, fld[3] as *u8)
616 swl_bar_state(1, buf, bidoff, bidlen, bfym, bfst, bfnb, fld[3] as *u8)
617 w(1, ".</b> " as *u8); wnote(1, fld[4] as *u8)
618 w(1, " <span class='ct'>ref " as *u8); w(1, fld[5] as *u8); w(1, "</span></div>\n" as *u8) } }
619 if streq(kind, "rungrole" as *u8) == 1 { if nf >= 5 {
620 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
621 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
622 if in_tgt == 0 { w(1, "<h2 id='ladder'>Ladder to SOTA</h2>\n" as *u8); in_tgt = 1 }
623 if in_role == 0 { w(1, "<table class='pl'><thead><tr><th>Rung</th><th>Role</th><th>Toward</th><th>Stands on</th><th>Why</th></tr></thead><tbody>\n" as *u8); in_role = 1 }
624 w(1, "<tr><td class='ct'><a href='#" as *u8); wlow(1, fld[1] as *u8); w(1, "'>" as *u8); w(1, fld[1] as *u8); w(1, "</a></td><td class='ct'>" as *u8); w(1, fld[2] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td class='ct'>" as *u8)
625 swl_rung_deps(1, buf, ridoff, ridlen, rdoff, rdlen, ldnr, fld[1] as *u8)
626 w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
627 if streq(kind, "ms" as *u8) == 1 { if nf >= 5 {
628 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
629 if in_ms == 0 { w(1, "<h2>Milestones</h2>\n<table class='pl'><thead><tr><th>Milestone</th><th>Rungs</th><th class='r'>Cumulative</th></tr></thead><tbody>\n" as *u8); in_ms = 1 }
630 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b> · " as *u8); w(1, fld[2] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[4] as *u8)
631 w(1, "</td><td class='r'>" as *u8); w(1, fld[3] as *u8); w(1, " u</td></tr>\n" as *u8) } }
632 }
633 }
634 }
635 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8) }
636 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8) }
637 if in_biz == 1 { w(1, "</tbody></table>\n" as *u8) }
638 if in_lad == 1 { w(1, "</tbody></table>\n" as *u8) }
639 if in_log == 1 { w(1, "</tbody></table>\n" as *u8) }
640 if in_role == 1 { w(1, "</tbody></table>\n" as *u8) }
641 if phase == 1 {
642 w(1, "<section class='meth' id='release-summary'><h2>Latest recorded release</h2>" as *u8)
643 if release_epoch > 0 {
644 let date: *u8 = sys_mmap(32)
645 let date_len: i64 = bd_ymd(release_epoch, date, 0)
646 date[date_len] = 0 as u8
647 w(1, "<p><b>" as *u8); w(1, date); w(1, "</b> · " as *u8)
648 wnote(1, release_rung); w(1, "</p><p>" as *u8); wnote(1, release_entry)
649 w(1, "</p><p><a href='#worklog'>Release history and work log</a></p>" as *u8)
650 } else {
651 w(1, "<p>No valid dated release entry is recorded for this domain.</p>" as *u8)
652 }
653 w(1, "<p>Release entries describe recorded changes; they do not establish that every capability passed evaluation.</p></section>\n</div>\n" as *u8)
654 }
655 if phase == 2 {
656 // THE TWO VERDICTS, FROM THE RULERS, ON EVERY PAGE WITH A PLAN (2026-09-06). A board that has not declared its
657 // ladder is TOLD so on its own page: an undeclared target is exactly how a seat climbed toward a 2014 bar for a day.
658 w(1, "<div class='meth' id='ladderverdict'><b>Ladder verdict.</b> " as *u8)
659 if ldv == LD_EXIT_NOLADDER {
660 w(1, "<b>NOT DECLARED.</b> This board names no dated best-in-class or frontier target and no rung roles (sotatarget and rungrole rows on its plan); the ranker labels it NO-LADDER until it does, and until then its rungs climb toward a target nobody has written down." as *u8)
661 } else {
662 w(1, "targets " as *u8); wn(1, ldc[LD_N_TARGETS]); w(1, " (best in class " as *u8); wn(1, ldc[LD_N_BIC]); w(1, ", frontier " as *u8); wn(1, ldc[LD_N_FRONTIER]); w(1, ", undated " as *u8); wn(1, ldc[LD_N_UNDATED])
663 w(1, "); rungs " as *u8); wn(1, ldc[LD_N_RUNGS]); w(1, ", placed " as *u8); wn(1, ldc[LD_N_PLACED]); w(1, " (substrate " as *u8); wn(1, ldc[LD_N_SUBSTRATE]); w(1, ", arm " as *u8); wn(1, ldc[LD_N_ARM]); w(1, ", contender " as *u8); wn(1, ldc[LD_N_CONTENDER]); w(1, ", superseded " as *u8); wn(1, ldc[LD_N_SUPERSEDED]); w(1, "), unplaced " as *u8); wn(1, ldc[LD_N_UNPLACED]); w(1, "; verdict <b>" as *u8); w(1, ld_verdict_name(ldv)); w(1, "</b>" as *u8)
664 if ldv == LD_EXIT_PARTIAL { w(1, " -- half-declared: the ranker refuses this board until every target is dated and every rung has a role" as *u8) }
665 }
666 w(1, " Bars: " as *u8); wn(1, bfc[BF_C_BARS]); w(1, " (fresh " as *u8); wn(1, bfc[BF_C_FRESH]); w(1, ", attested " as *u8); wn(1, bfc[BF_C_ATTESTED]); w(1, ", stale " as *u8); wn(1, bfc[BF_C_STALE]); w(1, ", unattested " as *u8); wn(1, bfc[BF_C_UNATTESTED]); w(1, "), verdict <b>" as *u8); w(1, bf_verdict_name(bf_verdict(bfc))); w(1, "</b> against the current month " as *u8)
667 let cymb: *u8 = sys_mmap(12)
668 bf_ym_write(cymb, 0, bfcur)
669 w(1, cymb); w(1, ".</div>\n" as *u8)
670 }
671 return 1
672}
673// ---- WATCH CONTRACTS, MEASURED, FOR EVERY PAGE KIND (2026-08-23, lane L) ----
674// A sota-class page renders <dom>.sota (hand-graded cells) while the ranker reads <dom>.matrix, so a
675// sota domain that also carries a .matrix NEVER FLIPPED on the page when a watch symbol landed
676// (measured on /compare/lang: LN2 landed, the regen republished the page at an IDENTICAL byte size).
677// watch_pass renders the .matrix's symbol rows with their status MEASURED by the one ruler
678// (nx_symdecl_lib sd_declared) -- the same function the matrix generator, the ranker and the regen's
679// comparewatch plane use -- so the page, the plane and the ranker cannot disagree by construction.
680// Writes to fd (a gate captures it through a file), mode 1 = HTML section, mode 2 = JSON array value.
681// An absent .matrix writes NOTHING and returns 0 (a byte-identical emit for every domain without one).
682// Returns the number of symbol rows rendered; the partition it prints must sum to that number.
683const WP_ST_LANDED: i64 = 1
684const WP_ST_WATCHING: i64 = 2
685const WP_ST_PRESENT: i64 = 3
686const WP_ST_MISSING: i64 = 4
687const WP_ST_ABSENT: i64 = 5
688func wp_status_text(st: i64) -> *u8 {
689 if st == WP_ST_LANDED { return "LANDED" as *u8 }
690 if st == WP_ST_WATCHING { return "WATCHING" as *u8 }
691 if st == WP_ST_PRESENT { return "PRESENT" as *u8 }
692 if st == WP_ST_MISSING { return "MISSING" as *u8 }
693 return "ABSENT" as *u8
694}
695func wp_status_class(st: i64) -> *u8 {
696 if st == WP_ST_LANDED { return "me" as *u8 }
697 if st == WP_ST_PRESENT { return "me" as *u8 }
698 if st == WP_ST_WATCHING { return "pa" as *u8 }
699 return "ab" as *u8
700}
701// classify ONE matrix row: organ + symbol field -> status. Measured, never read from the spelling.
702func wp_classify(organ: *u8, sym: *u8, rule_out: *i64) -> i64 {
703 rule_out[0] = 0
704 if streq(sym, "_ABSENT_" as *u8) == 1 { return WP_ST_ABSENT }
705 if starts(sym, "_ABSENT_:" as *u8) == 1 {
706 if sd_present(organ, (sym as i64 + 9) as *u8, rule_out) == 1 { return WP_ST_LANDED }
707 return WP_ST_WATCHING
708 }
709 if sd_present(organ, sym, rule_out) == 1 { return WP_ST_PRESENT }
710 return WP_ST_MISSING
711}
712func watch_pass(mpath: *u8, fd: i64, mode: i64) -> i64 {
713 let ln: *i64 = sys_mmap(16) as *i64
714 let b: *u8 = sys_read_file(mpath, ln)
715 if (b as i64) == 0 { return 0 }
716 let n: i64 = ln[0]
717 if n <= 0 { if mode == 2 { wc(fd, 91); wc(fd, 93) } return 0 }
718 // field capacity derived from the widest row (pipes + 1), never a fixed count
719 var maxf: i64 = 2
720 var pc: i64 = 0
721 var i: i64 = 0
722 while i < n { if b[i] == (124 as u8) { pc = pc + 1 } if b[i] == (10 as u8) { if pc + 1 > maxf { maxf = pc + 1 } pc = 0 } i = i + 1 }
723 if pc + 1 > maxf { maxf = pc + 1 }
724 let fld: *i64 = sys_mmap((maxf + 1) * 8) as *i64
725 let rl: *i64 = sys_mmap(16) as *i64
726 var rows: i64 = 0
727 var c_landed: i64 = 0
728 var c_watching: i64 = 0
729 var c_present: i64 = 0
730 var c_missing: i64 = 0
731 var c_absent: i64 = 0
732 var opened: i64 = 0
733 var p: i64 = 0
734 while p < n {
735 var e: i64 = p
736 while e < n { if b[e] == (10 as u8) { break } e = e + 1 }
737 b[e] = 0 as u8
738 let line: *u8 = (b as i64 + p) as *u8
739 p = e + 1
740 var skip: i64 = 0
741 if line[0] == (0 as u8) { skip = 1 }
742 if line[0] == (35 as u8) { skip = 1 }
743 if line[0] == (64 as u8) { skip = 1 }
744 if skip == 0 {
745 let nf: i64 = splitpipe(line, fld, maxf)
746 if nf >= 4 {
747 let label: *u8 = fld[0] as *u8
748 let organ: *u8 = fld[1] as *u8
749 let sym: *u8 = fld[2] as *u8
750 let note: *u8 = fld[nf - 1] as *u8
751 if sym[0] != (0 as u8) {
752 let st: i64 = wp_classify(organ, sym, rl)
753 if st == WP_ST_LANDED { c_landed = c_landed + 1 }
754 if st == WP_ST_WATCHING { c_watching = c_watching + 1 }
755 if st == WP_ST_PRESENT { c_present = c_present + 1 }
756 if st == WP_ST_MISSING { c_missing = c_missing + 1 }
757 if st == WP_ST_ABSENT { c_absent = c_absent + 1 }
758 var symtext: *u8 = sym
759 if starts(sym, "_ABSENT_:" as *u8) == 1 { symtext = (sym as i64 + 9) as *u8 }
760 if mode == 1 {
761 if opened == 0 {
762 w(fd, "<h2 class='ghead' id='watch'>Watch contracts (measured)</h2>\n<div class='meth'><b>Not a claim, a measurement.</b> Each row names an organ and a symbol; the status is re-measured on every publish by the one ruler the ranker and the hive plane use, and the rule it applied is printed beside it: <b>decl</b> a top-level declaration in a NishiLang organ (a comment or a call site does not count), <b>jsdecl</b> a JS declaration form, <b>exists</b> the organ itself (the symbol is its name), <b>marker</b> a literal the organ carries, <b>data</b> a token in a data file. LANDED / PRESENT = measured present, WATCHING = the named contract is still open, MISSING = the row names something its organ does not carry, ABSENT = no contract named.</div>\n<table class='pl'><thead><tr><th>Axis</th><th>Organ</th><th>Symbol</th><th>Status</th><th>Note</th></tr></thead><tbody>\n" as *u8)
763 opened = 1
764 }
765 w(fd, "<tr><td><b>" as *u8); w(fd, label); w(fd, "</b></td><td class='ct'>" as *u8); w(fd, organ)
766 w(fd, "</td><td class='ct'>" as *u8); w(fd, symtext); w(fd, "</td><td><span class='st " as *u8); w(fd, wp_status_class(st)); w(fd, "'>" as *u8); w(fd, wp_status_text(st))
767 w(fd, "</span>" as *u8)
768 if rl[0] > 0 { w(fd, " <span class='ct'>" as *u8); w(fd, sd_rule_name(rl[0])); w(fd, "</span>" as *u8) }
769 w(fd, "</td><td>" as *u8); wnote(fd, note); w(fd, "</td></tr>\n" as *u8)
770 }
771 if mode == 2 {
772 if opened == 0 { wc(fd, 91); opened = 1 } else { wc(fd, 44) }
773 wc(fd, 123)
774 kv_s(fd, "label" as *u8, label); wc(fd, 44)
775 kv_s(fd, "organ" as *u8, organ); wc(fd, 44)
776 kv_s(fd, "symbol" as *u8, symtext); wc(fd, 44)
777 kv_s(fd, "status" as *u8, wp_status_text(st)); wc(fd, 44)
778 kv_s(fd, "rule" as *u8, sd_rule_name(rl[0])); wc(fd, 44)
779 kv_s(fd, "note" as *u8, note)
780 wc(fd, 125)
781 }
782 rows = rows + 1
783 }
784 }
785 }
786 }
787 if mode == 1 { if opened == 1 {
788 w(fd, "</tbody></table>\n<p class='foot'>watch rows=" as *u8); wn(fd, rows)
789 w(fd, " landed=" as *u8); wn(fd, c_landed); w(fd, " watching=" as *u8); wn(fd, c_watching)
790 w(fd, " present=" as *u8); wn(fd, c_present); w(fd, " missing=" as *u8); wn(fd, c_missing)
791 w(fd, " absent=" as *u8); wn(fd, c_absent); w(fd, " (partition sums)</p>\n" as *u8)
792 } }
793 if mode == 2 { if opened == 1 { wc(fd, 93) } else { wc(fd, 91); wc(fd, 93) } }
794 sys_free_file(b, n)
795 return rows
796}
797
798// ---- PERSON / PRODUCT / PLACE, MEASURED (operator 2026-08-24: "all our compares should have [UI analysis]
799// and august 2026 researched sota ... to tell us how to build a better site than our competitors ... person
800// via privacy and superior cx, product ... design and longevity and features, place ... ease of navigation
801// and ability to accomplish the desired task"). ONE renderer in the base, both generators call it -- the
802// refs_pass / watch_pass precedent. Reads knowledge/compare/<dom>.pppstate, the artefact nx_ppp_probe writes
803// after running ONE ruler on OUR live surface AND on every rival's live front door named in <dom>.ppp:
804// ppp|<col>|<label>|<url>|<json> last line = "# asof=... surfaces=N probed=K ruler=nx_ppp_probe"
805// The page prints per-axis permil AND the raw counts beside it, so the derivation can be argued with, and the
806// direction of the gap per rival is computed HERE from the numbers -- never typed by a seat. A domain with no
807// .pppstate prints a NAMED absence (the worklist: every compare carries this layer; a page not yet measured
808// says so in its own words). Self-contained scoped <style> so it renders in BOTH generators regardless of
809// their page CSS; colours reference the page theme vars with rgb() fallbacks. -1 = unobserved (scores zero
810// for that rule, never acquitted).
811const PL_MAXROWS: i64 = 32
812// first integer value of "<key>": at or after `from`; -999 = key absent (distinct from a real -1 unobserved)
813func pl_jint(buf: *u8, n: i64, from: i64, key: *u8) -> i64 {
814 var klen: i64 = 0
815 while key[klen] != (0 as u8) { klen = klen + 1 }
816 var i: i64 = from
817 var at: i64 = 0 - 1
818 while i + klen <= n {
819 var k: i64 = 0
820 var m: i64 = 1
821 while k < klen { if buf[i + k] != key[k] { m = 0; k = klen } else { k = k + 1 } }
822 if m == 1 { at = i; i = n } else { i = i + 1 }
823 }
824 if at < 0 { return 0 - 999 }
825 var j: i64 = at + klen
826 var neg: i64 = 0
827 if j < n { if buf[j] == (45 as u8) { neg = 1; j = j + 1 } }
828 var v: i64 = 0
829 var got: i64 = 0
830 while j < n {
831 let c: i64 = buf[j] as i64
832 if c >= 48 { if c <= 57 { v = v * 10 + (c - 48); got = 1; j = j + 1 } else { j = n } } else { j = n }
833 }
834 if got == 0 { return 0 - 999 }
835 if neg == 1 { return 0 - v }
836 return v
837}
838// offset of the literal `name` inside buf, or 0 (name is chosen to be unique in the row json)
839func pl_off(buf: *u8, n: i64, name: *u8) -> i64 {
840 var nl: i64 = 0
841 while name[nl] != (0 as u8) { nl = nl + 1 }
842 var i: i64 = 0
843 while i + nl <= n {
844 var k: i64 = 0
845 var m: i64 = 1
846 while k < nl { if buf[i + k] != name[k] { m = 0; k = nl } else { k = k + 1 } }
847 if m == 1 { return i }
848 i = i + 1
849 }
850 return 0
851}
852func pl_cell(fd: i64, v: i64) -> i64 {
853 if v == 0 - 999 { w(fd, "<td class='ct'>-</td>" as *u8); return 0 }
854 if v < 0 { w(fd, "<td class='ct'>unobs</td>" as *u8); return 0 }
855 w(fd, "<td class='r'>" as *u8); wn(fd, v); w(fd, "</td>" as *u8)
856 return 0
857}
858func ppp_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
859 let sp: *u8 = sys_mmap(600)
860 var o: i64 = scopy(sp, 0, "knowledge/compare/" as *u8)
861 o = scopy(sp, o, dom); o = scopy(sp, o, ".pppstate" as *u8); sp[o] = 0 as u8
862 let ln: *i64 = sys_mmap(16) as *i64
863 let b: *u8 = sys_read_file(sp, ln)
864 if (b as i64) == 0 {
865 if mode == 2 { w(fd, "{\"measured\":false}" as *u8); return 0 }
866 w(fd, "<h2 class='ghead' id='ppp'>Person · product · place — not yet measured for this domain</h2>\n<div class='meth'><b>Every compare carries this layer.</b> Declare <code>knowledge/compare/" as *u8); w(fd, dom)
867 w(fd, ".ppp</code> (rows <code>surface|nishi or c1..c4|label|url|connect</code> naming OUR live surface and each rival's front door), run <code>nx_ppp_probe domain " as *u8); w(fd, dom)
868 w(fd, "</code>, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).</div>\n" as *u8)
869 return 0
870 }
871 let n: i64 = ln[0]
872 if n <= 0 { sys_free_file(b, n); if mode == 2 { w(fd, "{\"measured\":false}" as *u8) } return 0 }
873 // the stamp is the LAST non-empty line; capture it BEFORE the parser NUL-splits anything
874 var ls: i64 = n
875 if ls > 0 { if b[ls - 1] == (10 as u8) { ls = ls - 1 } }
876 while ls > 0 { if b[ls - 1] == (10 as u8) { break } ls = ls - 1 }
877 let stamp: i64 = (b as i64) + ls
878 var se: i64 = ls
879 while se < n { if b[se] == (10 as u8) { break } se = se + 1 }
880 b[se] = 0 as u8
881 // collect data-row offsets (lines beginning 'p' = 'ppp|')
882 let roff: *i64 = sys_mmap(PL_MAXROWS * 8) as *i64
883 let rlen: *i64 = sys_mmap(PL_MAXROWS * 8) as *i64
884 var rows: i64 = 0
885 var p: i64 = 0
886 while p < ls {
887 var e: i64 = p
888 while e < ls { if b[e] == (10 as u8) { break } e = e + 1 }
889 if b[p] == (112 as u8) { if rows < PL_MAXROWS { roff[rows] = p; rlen[rows] = e - p; rows = rows + 1 } }
890 p = e + 1
891 }
892 let fld: *i64 = sys_mmap(8 * 8) as *i64
893 if mode == 2 {
894 w(fd, "{\"stamp\":\"" as *u8); wj(fd, stamp as *u8); w(fd, "\",\"surfaces\":[" as *u8)
895 var rj: i64 = 0
896 var emitted: i64 = 0
897 while rj < rows {
898 b[roff[rj] + rlen[rj]] = 0 as u8
899 let line: *u8 = (b as i64 + roff[rj]) as *u8
900 let nf: i64 = splitpipe(line, fld, 5)
901 if nf >= 5 {
902 if emitted > 0 { wc(fd, 44) }
903 w(fd, fld[4] as *u8)
904 emitted = emitted + 1
905 }
906 rj = rj + 1
907 }
908 w(fd, "]}" as *u8)
909 sys_free_file(b, n)
910 return rows
911 }
912 // ---- mode 1: HTML ----
913 w(fd, "<style>.pppsec{overflow-x:auto;margin:6px 0 2px}.pppt{border-collapse:collapse;width:100%;font-size:12.5px;min-width:760px}.pppt th{text-align:left;padding:8px 9px 8px 0;border-bottom:1px solid var(--fg,rgb(26,26,28));color:var(--mut,rgb(120,126,134));font-size:10px;letter-spacing:.06em;text-transform:uppercase;white-space:nowrap}.pppt td{border-bottom:1px solid var(--line,rgb(219,216,208));padding:9px 9px 9px 0;vertical-align:top;line-height:1.4}.pppt td.r{text-align:right;font-variant-numeric:tabular-nums;white-space:nowrap}.pppt td.ct{font-family:var(--mono,ui-monospace,Consolas,monospace);font-size:11px;color:var(--mut,rgb(120,126,134))}.pppt tr.ours td{background:var(--tint,rgba(120,90,220,.06))}.pppt tr.ours td.ni b{color:var(--ac,rgb(88,64,180))}.pppt a{color:var(--ac,rgb(88,64,180));text-decoration:none}</style>\n" as *u8)
914 w(fd, "<h2 class='ghead' id='ppp'>Person · product · place — the same ruler on our live surface and on theirs</h2>\n" as *u8)
915 w(fd, "<div class='meth'><b>Measured on both sides, from the bytes a first visitor receives.</b> <code>nx_ppp_probe</code> fetched every surface below over the sovereign TLS stack and scored three axes by declared rules, each a count against a published Aug-2026 bar. <b>Person</b> (privacy + CX): third-party asset/script hosts, the tracker classes The Markup's Blacklight tests for, consent-banner markers, <code>Set-Cookie</code> on the first consent-less response (the CNIL bar), the OWASP secure headers. <b>Product</b> (design + longevity): design-system hygiene (/12), computed WCAG 2.2 contrast over the page's real colour tokens, the static Core-Web-Vitals predictors (render-blocking css/js, unsized media — the source-visible causes of poor LCP/CLS), script count, dark-mode and reduced-motion queries, canonical URL. <b>Place</b> (findability + task): nav/main/footer landmarks, a skip link, on-site search, breadcrumb, exactly one h1, internal links, lang, viewport, title. Envelope: static HTML plus response headers, no render, no script execution — a client-rendered app is graded on what a no-JS first visitor receives, which is the progressive-enhancement bar itself. <b>unobs</b> = the probe could not see that sub-measure and scored it zero rather than acquit. Stamp: <code>" as *u8)
916 w(fd, stamp as *u8); w(fd, "</code></div>\n" as *u8)
917 w(fd, "<div class='pppsec'><table class='pppt'><thead><tr><th>Surface</th><th class='r'>Person</th><th class='r'>Product</th><th class='r'>Place</th><th class='r'>3p script hosts</th><th class='r'>trackers</th><th class='r'>set-cookie</th><th class='r'>sec hdr /5</th><th class='r'>design /12</th><th class='r'>contrast fails</th><th class='r'>blocking css+js</th><th class='r'>unsized img</th><th class='r'>scripts</th><th class='r'>KB</th><th>nav main skip search crumb</th></tr></thead><tbody>\n" as *u8)
918 var ours_pe: i64 = 0 - 1
919 var ours_pr: i64 = 0 - 1
920 var ours_pl: i64 = 0 - 1
921 var best_pe: i64 = 0 - 1
922 var best_pr: i64 = 0 - 1
923 var best_pl: i64 = 0 - 1
924 var rr: i64 = 0
925 while rr < rows {
926 b[roff[rr] + rlen[rr]] = 0 as u8
927 let line: *u8 = (b as i64 + roff[rr]) as *u8
928 let nf: i64 = splitpipe(line, fld, 5)
929 if nf >= 5 {
930 let col: *u8 = fld[1] as *u8
931 let label: *u8 = fld[2] as *u8
932 let url: *u8 = fld[3] as *u8
933 let js: *u8 = fld[4] as *u8
934 var jn: i64 = 0
935 while js[jn] != (0 as u8) { jn = jn + 1 }
936 var ours: i64 = 0
937 if streq(col, "nishi" as *u8) == 1 { ours = 1 }
938 if ours == 1 { w(fd, "<tr class='ours'><td class='ni'><b>" as *u8) } else { w(fd, "<tr><td><b>" as *u8) }
939 w(fd, label); w(fd, "</b><br><a href='" as *u8); w(fd, url); w(fd, "' rel='nofollow'><span class='ct'>" as *u8); w(fd, url); w(fd, "</span></a></td>" as *u8)
940 let unreach: i64 = pl_jint(js, jn, 0, "\"unreachable\":" as *u8)
941 if unreach != 0 - 999 {
942 w(fd, "<td colspan='13'>UNREACHABLE (probe code " as *u8); wn(fd, unreach); w(fd, ") — no measurement, no score; re-run the probe rather than infer a number</td></tr>\n" as *u8)
943 } else {
944 let sp_pe: i64 = pl_off(js, jn, "\"person\":{" as *u8)
945 let sp_pr: i64 = pl_off(js, jn, "\"product\":{" as *u8)
946 let sp_pl: i64 = pl_off(js, jn, "\"place\":{" as *u8)
947 let pe: i64 = pl_jint(js, jn, sp_pe, "\"score_permil\":" as *u8)
948 let pr: i64 = pl_jint(js, jn, sp_pr, "\"score_permil\":" as *u8)
949 let pl: i64 = pl_jint(js, jn, sp_pl, "\"score_permil\":" as *u8)
950 if ours == 1 {
951 if pe > ours_pe { ours_pe = pe }
952 if pr > ours_pr { ours_pr = pr }
953 if pl > ours_pl { ours_pl = pl }
954 } else {
955 if pe > best_pe { best_pe = pe }
956 if pr > best_pr { best_pr = pr }
957 if pl > best_pl { best_pl = pl }
958 }
959 pl_cell(fd, pe); pl_cell(fd, pr); pl_cell(fd, pl)
960 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"third_party_script_hosts\":" as *u8))
961 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"tracker_hits\":" as *u8))
962 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"set_cookie\":" as *u8))
963 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"sec_headers\":" as *u8))
964 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"design_hygiene\":" as *u8))
965 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"contrast_fails\":" as *u8))
966 let bc: i64 = pl_jint(js, jn, sp_pr, "\"blocking_css\":" as *u8)
967 let bj: i64 = pl_jint(js, jn, sp_pr, "\"blocking_js\":" as *u8)
968 if bc < 0 { pl_cell(fd, bc) } else { if bj < 0 { pl_cell(fd, bj) } else { pl_cell(fd, bc + bj) } }
969 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"unsized_media\":" as *u8))
970 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"script_tags\":" as *u8))
971 let bytes: i64 = pl_jint(js, jn, 0, "\"bytes\":" as *u8)
972 if bytes > 0 { w(fd, "<td class='r'>" as *u8); wn(fd, bytes / 1024); w(fd, "</td>" as *u8) } else { w(fd, "<td class='ct'>-</td>" as *u8) }
973 w(fd, "<td class='r ct'>" as *u8)
974 wn(fd, pl_jint(js, jn, sp_pl, "\"nav\":" as *u8)); wc(fd, 32); wn(fd, pl_jint(js, jn, sp_pl, "\"main\":" as *u8)); wc(fd, 32)
975 wn(fd, pl_jint(js, jn, sp_pl, "\"skip_link\":" as *u8)); wc(fd, 32); wn(fd, pl_jint(js, jn, sp_pl, "\"site_search\":" as *u8)); wc(fd, 32)
976 wn(fd, pl_jint(js, jn, sp_pl, "\"breadcrumb\":" as *u8)); w(fd, "</td></tr>\n" as *u8)
977 }
978 }
979 rr = rr + 1
980 }
981 w(fd, "</tbody></table></div>\n" as *u8)
982 // the direction of the gap, computed from the numbers above
983 w(fd, "<div class='meth'><b>Where to beat them, from the numbers.</b> " as *u8)
984 if ours_pe >= 0 { if best_pe >= 0 {
985 w(fd, "PERSON ours " as *u8); wn(fd, ours_pe); w(fd, " vs best rival " as *u8); wn(fd, best_pe)
986 if ours_pe > best_pe { w(fd, " — we lead; hold it (zero third-party hosts, zero trackers, headers 5/5 is the ceiling). " as *u8) } else { w(fd, " — behind: the higher-scoring rival shows which privacy rule we lose. " as *u8) }
987 } }
988 if ours_pr >= 0 { if best_pr >= 0 {
989 w(fd, "PRODUCT ours " as *u8); wn(fd, ours_pr); w(fd, " vs best rival " as *u8); wn(fd, best_pr)
990 if ours_pr > best_pr { w(fd, " — we lead on measurable hygiene; the perceptual premium is a judged rung, not this ruler. " as *u8) } else { w(fd, " — behind: design/12, contrast, blocking, unsized and scripts name the rule. " as *u8) }
991 } }
992 if ours_pl >= 0 { if best_pl >= 0 {
993 w(fd, "PLACE ours " as *u8); wn(fd, ours_pl); w(fd, " vs best rival " as *u8); wn(fd, best_pl)
994 if ours_pl > best_pl { w(fd, " — we lead on the findability floor; task completion by a real user is the next ruler. " as *u8) } else { w(fd, " — behind: nav main skip search crumb, in that order. " as *u8) }
995 } }
996 w(fd, "Re-measured by the beat; nothing here is typed by a seat.</div>\n" as *u8)
997 sys_free_file(b, n)
998 return rows
999}
1000
1001// ============================================================================
1002// SC THEME PASS (2026-08-25) -- ONE palette, emitted from the estate's TOKEN SSOT
1003// (nx_brand_tokens), for BOTH domain generators. It is lifted HERE for the same
1004// reason plan_pass, dstate and wlow were lifted here: this module is the base class
1005// the two generators already share, so a palette that lives here CANNOT drift
1006// between them. Two hand-landed dark blocks in two files is the duplicate-ruler
1007// defect wearing a stylesheet.
1008//
1009// WHY IT EXISTS. Measured 2026-08-25 against the LIVE pages, not inherited:
1010// /compare/search scored theme-aware 0/2 and prefers-color-scheme occurred ZERO
1011// times in 79,499 bytes of matrix source. The dark PALETTE was already authored and
1012// already shipping as html[data-theme='dark'] -- it was simply unreachable from the
1013// operating system's own preference. ***A THEME THAT EXISTS BUT CANNOT BE REACHED
1014// WITHOUT HUNTING FOR A CHIP IS A CAPABILITY THE PAGE IS PAYING FOR AND NOT
1015// DELIVERING.*** Nothing here invents a palette, so no contrast pair moved: the dark
1016// values below are byte-identical to the literal they replace, which makes the dark
1017// rendering unchanged BY CONSTRUCTION rather than by inspection.
1018//
1019// ***THE DARK VALUES ARE DECLARED ONCE AND EMITTED TWICE.*** The same parsed rows go
1020// out under html[data-theme='dark'] (the chip) AND under the media query (the OS
1021// preference). Keeping two copies in step is exactly how a chip theme and an auto
1022// theme drift apart; here a drift is not merely unlikely, it is UNREPRESENTABLE --
1023// there is only one copy of the data, and it is re-SELECTED, never re-PARSED, so the
1024// SSOT keeps its 3-pipe field rule, its bt_ident_safe/bt_value_safe injection screens
1025// and its silent-skip semantics. A second brand parser here would be a second ruler.
1026//
1027// ***THE MEDIA BLOCK IS GUARDED :root:not([data-theme]) AND THAT GUARD IS LOAD-BEARING.***
1028// This page ships a three-way switcher (paper/ink/dark) whose sett() calls
1029// setAttribute('data-theme', n) for ALL THREE values -- paper INCLUDED -- and a boot
1030// script restores the stored choice before first paint. But PAPER IS THE BARE :root
1031// DEFAULT: there is no html[data-theme='paper'] rule to out-rank anything. So an
1032// UNGUARDED @media(prefers-color-scheme:dark){:root{...}} would carry EQUAL
1033// specificity to that default and sit LATER in the cascade, and would therefore
1034// repaint a user who had just explicitly chosen Paper on an OS-dark machine. Every
1035// explicit choice sets the attribute, so :not([data-theme]) makes all three chips win
1036// over the OS preference with ONE selector, while a visitor who has chosen nothing
1037// still gets their system preference. ***A DARK BLOCK ADDED WITHOUT FIRST ASKING
1038// WHETHER THE PAGE ALREADY HAS A THEME SWITCHER SILENTLY OVERRIDES AN EXPLICIT USER
1039// CHOICE -- AND FROM THE USER'S SIDE THAT IS INDISTINGUISHABLE FROM A BROKEN BUTTON.***
1040// nx_brand_tokens' bt_emit_dark_root_buf emits the UNGUARDED selector, which is
1041// CORRECT for a page with no switcher (nx_games_page). The difference is the switcher,
1042// not the SSOT, so the fix belongs at this call site and NOT in the shared emitter.
1043//
1044// BREAKPOINTS ARE THE ESTATE'S ONE LADDER, NOT A THIRD SET. 860/640 are taken from
1045// sites/nishifamily/nishi-ds.css section 5 RESPONSIVE -- the same two numbers
1046// nx_games_page adopted, for the same reason: a third ladder would be a duplicate
1047// ruler wearing a constant and nothing downstream could tell the two apart. They
1048// redefine TOKENS ONLY, never components: a token carries no paint, so a breakpoint
1049// cannot restyle anything the page did not already opt into by reading that token.
1050//
1051// MEMORY: the two scratch buffers are deliberately NOT munmap'd per call -- this is a
1052// one-shot page emitter that exits, and sc_theme_pass is called exactly once per page.
1053// Declared rather than left silent.
1054const SC_TOKCAP: i64 = 16384
1055const SC_BP_MD: i64 = 860
1056const SC_BP_SM: i64 = 640
1057
1058// The compare palette AS DATA. Light rows first, then the dark overrides. A token with
1059// NO dark row is theme-independent by construction -- that is why --nx-font-mono and
1060// the layout tokens carry none: a monospace stack and a wrap width are not chrome.
1061func sc_brand() -> *u8 {
1062 return "token|color|bg|rgb(243,241,236)\ntoken|color|fg|rgb(26,26,28)\ntoken|color|accent|rgb(88,64,180)\ntoken|color|panel|rgb(249,247,243)\ntoken|color|soft|rgb(236,233,226)\ntoken|color|tint|rgb(236,233,226)\ntoken|color|line|rgb(219,216,208)\ntoken|color|mut|rgb(92,96,104)\ntoken|color|faint|rgb(138,141,148)\ntoken|color|gk|rgb(60,64,72)\ntoken|color|goff|rgb(198,195,187)\ntoken|color|ghalf|rgb(122,126,134)\ntoken|color|codebg|rgb(229,226,218)\ntoken|color|ok|rgb(26,127,55)\ntoken|color|part|rgb(178,106,0)\ntoken|color|absent|rgb(179,38,30)\ntoken|color|exceed|rgb(130,80,223)\ntoken|font|mono|ui-monospace,Consolas,monospace\ntoken|layout|wrap|clamp(20rem,95vw,110rem)\ntoken|layout|gutter|clamp(14px,3vw,28px)\ntoken|layout|measure|66ch\ntoken|layout|capmin|27rem\ntoken|layout|capgap|clamp(10px,1.6vw,20px)\ntoken|layout|rail|13rem\ndark|color|bg|rgb(16,18,23)\ndark|color|fg|rgb(226,229,235)\ndark|color|accent|rgb(171,152,238)\ndark|color|panel|rgb(23,26,34)\ndark|color|soft|rgb(30,34,43)\ndark|color|tint|rgb(23,26,34)\ndark|color|line|rgb(43,47,56)\ndark|color|mut|rgb(139,146,158)\ndark|color|faint|rgb(100,107,119)\ndark|color|gk|rgb(168,175,186)\ndark|color|goff|rgb(58,63,73)\ndark|color|ghalf|rgb(120,127,138)\ndark|color|codebg|rgb(35,39,48)\ndark|color|ok|rgb(121,224,167)\ndark|color|part|rgb(255,166,120)\ndark|color|absent|rgb(118,130,154)\ndark|color|exceed|rgb(255,209,122)\n" as *u8
1063}
1064
1065// The SSOT's own dark wrapper, named once so its LENGTH is DERIVED and never
1066// hand-counted beside the literal -- a hand-counted length is a second copy of the
1067// string's shape and the two drift silently.
1068func sc_dark_open() -> *u8 { return "@media(prefers-color-scheme:dark){:root{\n" as *u8 }
1069func sc_dark_close() -> *u8 { return "}}\n" as *u8 }
1070
1071func sc_theme_pass(fd: i64) -> i64 {
1072 let bd: *u8 = sc_brand()
1073 let bn: i64 = bt_len(bd)
1074 let tb: *u8 = sys_mmap(SC_TOKCAP)
1075 // ---- light :root, straight from the SSOT ----
1076 let lw: i64 = bt_emit_root_buf(bd, bn, tb, SC_TOKCAP)
1077 if lw < 0 { w(2, "FATAL sc_theme_pass: brand parsed ZERO light tokens -- refusing to emit a page with no palette\n" as *u8); sys_exit(2); return 2 }
1078 // bt_app SATURATES at cap instead of failing, so an undersized buffer truncates the
1079 // palette mid-block and still returns a POSITIVE count. ***A CAP REACHED IN SILENCE
1080 // BECOMES A MEASUREMENT NOBODY KNOWS IS PARTIAL*** -- refuse at the boundary instead.
1081 if lw >= SC_TOKCAP - 1 { w(2, "FATAL sc_theme_pass: light block reached SC_TOKCAP -- this palette is TRUNCATED, not complete\n" as *u8); sys_exit(2); return 2 }
1082 sys_write(fd, tb, lw)
1083 // ---- page-local ALIASES over the SSOT names: one indirection, so a brand DATA edit
1084 // re-themes the whole page and every rule below keeps reading the short name it
1085 // always read. They are var() REFERENCES, not copies, so they resolve at use time --
1086 // which is why ONE alias block serves paper, ink, dark and the OS preference alike.
1087 w(fd, ":root{--bg:var(--nx-color-bg);--fg:var(--nx-color-fg);--ac:var(--nx-color-accent);--panel:var(--nx-color-panel);--soft:var(--nx-color-soft);--tint:var(--nx-color-tint);--line:var(--nx-color-line);--mut:var(--nx-color-mut);--faint:var(--nx-color-faint);--gk:var(--nx-color-gk);--goff:var(--nx-color-goff);--ghalf:var(--nx-color-ghalf);--codebg:var(--nx-color-codebg);--mono:var(--nx-font-mono);--y:var(--nx-color-ok);--p:var(--nx-color-part);--n:var(--nx-color-absent);--ex:var(--nx-color-exceed)}\n" as *u8)
1088 // ---- dark: ONE parse, TWO selectors ----
1089 let dw: i64 = bt_emit_dark_root_buf(bd, bn, tb, SC_TOKCAP)
1090 // bt_emit_dark_root_buf returns 0 (never negative) when the brand carries no dark
1091 // rows, so this guard is <= 0. A < 0 guard here would be a tooth that CANNOT FIRE.
1092 if dw <= 0 { w(2, "FATAL sc_theme_pass: brand carries NO dark override -- the page would ship theme-blind\n" as *u8); sys_exit(2); return 2 }
1093 if dw >= SC_TOKCAP - 1 { w(2, "FATAL sc_theme_pass: dark block reached SC_TOKCAP -- TRUNCATED, not complete\n" as *u8); sys_exit(2); return 2 }
1094 let op: *u8 = sc_dark_open()
1095 let ol: i64 = bt_len(op)
1096 let cl: i64 = bt_len(sc_dark_close())
1097 // The re-selection is only valid if the SSOT still emits the wrapper we expect. If it
1098 // ever changes, slicing past a stale prefix would emit a CORRUPT block that still
1099 // looks like CSS -- so verify the prefix and refuse loudly rather than guess.
1100 var gi: i64 = 0
1101 while gi < ol { if tb[gi] != op[gi] { w(2, "FATAL sc_theme_pass: nx_brand_tokens changed its dark wrapper -- re-selecting it would corrupt the block\n" as *u8); sys_exit(2); return 2 } gi = gi + 1 }
1102 let rs: i64 = ol
1103 let re: i64 = dw - cl
1104 if re <= rs { w(2, "FATAL sc_theme_pass: dark block carried no rows between its wrapper\n" as *u8); sys_exit(2); return 2 }
1105 let rb: *u8 = sys_mmap(SC_TOKCAP)
1106 var k: i64 = 0
1107 while rs + k < re { rb[k] = tb[rs + k]; k = k + 1 }
1108 w(fd, "html[data-theme='dark']{\n" as *u8)
1109 sys_write(fd, rb, k)
1110 w(fd, "}\n" as *u8)
1111 w(fd, "@media(prefers-color-scheme:dark){:root:not([data-theme]){\n" as *u8)
1112 sys_write(fd, rb, k)
1113 w(fd, "}}\n" as *u8)
1114 // ---- breakpoints: TOKENS ONLY, on the estate's one ladder ----
1115 w(fd, "@media (max-width:" as *u8); wn(fd, SC_BP_MD); w(fd, "px){:root{--nx-layout-gutter:clamp(12px,3.6vw,18px)}}\n" as *u8)
1116 w(fd, "@media (max-width:" as *u8); wn(fd, SC_BP_SM); w(fd, "px){:root{--nx-layout-wrap:100%;--nx-layout-gutter:12px}}\n" as *u8)
1117 return 0
1118}
1119
1120// ---- sc_layout_pass: THE ONE LAYOUT EMITTER FOR EVERY COMPARE PAGE (2026-08-31) ----
1121// WHY THIS EXISTS. The body rule was hand-copied into SEVEN generators and had already drifted to
1122// SIX different page widths (960/980/1000/1040/1080/1180) -- the duplicate-ruler defect living in
1123// emitted CSS, where nothing compares the copies. Worse, the two layout TOKENS the SSOT publishes
1124// (--nx-layout-wrap/--nx-layout-gutter) were DEFINED on every page and REFERENCED by none of the
1125// sota-class ones: they hardcoded max-width:980px and a second clamp() straight over the top.
1126// ***A TOKEN DEFINED AND NEVER READ IS NOT A DESIGN SYSTEM, IT IS DEAD BYTES THAT LOOK LIKE ONE***
1127// -- and the page it governed rendered as one narrow column down the middle of a 1920px display.
1128//
1129// FULL CANVAS WITHOUT UNREADABLE PROSE. These are two different width budgets and the fix is to stop
1130// spending one on the other. The PAGE takes a fluid clamp (95vw, capped) so the LAYOUT uses the
1131// display; PROSE keeps its own measure cap (--nx-layout-measure, 66ch) applied to the text element
1132// itself, never to its container. Surplus width therefore cannot lengthen a line -- it has nowhere
1133// to go except into more capability cards side by side, which is more information on screen rather
1134// than a 200-character sentence.
1135//
1136// WHY SC_CAP_SPLIT IS A CONST AND NOT A TOKEN. Every other layout number here is a --nx-layout-*
1137// token, per rule 11. This one CANNOT be: a CSS container/media query CONDITION does not accept
1138// var(), so the threshold must reach the stylesheet as a literal. A named const emitted through wn()
1139// is the same guarantee by the only mechanism CSS allows -- it is not an exception to the rule, it is
1140// the rule honoured where var() is structurally unavailable. 496px is where a card can seat the
1141// 13rem rail beside a main column still wider than the rail; below it the card stacks.
1142//
1143// CONTAINER QUERY, NOT A BREAKPOINT, FOR THE CARD. The same .cap renders one-per-row on a phone and
1144// three-across on a desktop, so its reflow depends on ITS OWN width, not the window's. @container is
1145// Baseline Widely Available (2025-08-14). The container-name is declared explicitly and queried by
1146// name: an unresolvable container silently falls back to small-viewport units rather than erroring,
1147// so the anonymous form would fail as a confident wrong answer.
1148const SC_CAP_SPLIT: i64 = 496
1149func sc_layout_pass(fd: i64) -> i64 {
1150 // page shell -- reads the SSOT tokens, so a brand DATA edit re-widths every compare page at once
1151 w(fd, "*{box-sizing:border-box}html{scrollbar-gutter:stable}\n" as *u8)
1152 w(fd, "body{background:var(--bg);font-family:-apple-system,Segoe UI,Roboto,sans-serif;max-width:var(--nx-layout-wrap);margin:0 auto;padding:0 var(--nx-layout-gutter) 6vh;color:var(--fg);line-height:1.6;font-size:1rem}\n" as *u8)
1153 // min-width:0 defeats the min-content floor that grid/flex children carry by default. Without it a
1154 // single wide table forces every ancestor wider than its track and THE PAGE scrolls sideways --
1155 // the overflow lands on the document, which is the one place it must never land.
1156 w(fd, "main{min-width:0}main>*{min-width:0;max-width:100%}table{max-width:100%}\n" as *u8)
1157 // long unbroken identifiers (organ names, hashes, paths) are the only real width bombs on these
1158 // pages; break them where they occur instead of letting them set the table's minimum width
1159 w(fd, ".pl .ct,.ev code,.rlinks code,.watch{overflow-wrap:anywhere}\n" as *u8)
1160 // ---- PROSE MEASURE: ONE cap for the prose blocks BOTH archetypes emit ----
1161 // THE REGRESSION THIS FUNCTION CAUSED, AND WHY THE FIX LANDS HERE. Widening body from a fixed 980px
1162 // to a fluid clamp is right for the LAYOUT and wrong for PROSE unless the prose carries its own cap.
1163 // Matrix learned that on 2026-08-25 and capped .meth/.lead/.answer/.verdict at 72ch. Sota never
1164 // received it: measured over the whole corpus, 72ch occurs 5 times in the estate and ALL FIVE are in
1165 // nx_swcompare_matrix (coverage_complete=1 corpus_complete=1 over 23,407 files). So sota's .meth --
1166 // the ~1,100-character "How this is scored" block, the FIRST prose a reader meets -- went from
1167 // inheriting 980px (~130 characters a line) to inheriting up to 1760px (~240), roughly 3x the WCAG
1168 // 1.4.8 (AAA) 80-character ceiling. ***A FIX THAT LIVES IN ONE ORGAN AND NOT ITS SIBLING IS HALF A
1169 // FIX***, and widening the canvas converted this one from latent to acute.
1170 //
1171 // WHY THE TOKEN AND NOT A SECOND 72ch. --nx-layout-measure is already the SSOT's declared prose
1172 // measure and is already read by .cap-note. Hard-coding 72ch a second time -- in the SHARED lib, no
1173 // less -- is the duplicate-ruler defect this extraction exists to remove, and nothing downstream
1174 // could tell the two copies apart. It does NOT overrule matrix: matrix emits its own .meth/.verdict
1175 // rules AFTER this one at equal specificity, so matrix still renders at 72ch and its emitted bytes
1176 // are unchanged. Only sota, which carried NO cap at all, changes. .lead and .answer are deliberately
1177 // NOT here -- they are matrix-only classes already carrying their own 72ch, so listing them would
1178 // add a second ruler for a page that already has one.
1179 w(fd, ".lead,.answer,.meth,.verdict{max-width:var(--nx-layout-measure);text-wrap:pretty}\n" as *u8)
1180 w(fd, ".exec-grid{display:grid;grid-template-columns:repeat(auto-fill,minmax(min(100%,var(--nx-layout-capmin)),1fr));gap:var(--nx-layout-capgap);align-items:start;margin:var(--nx-layout-capgap) 0}.exec-grid>*{min-width:0;overflow-wrap:anywhere}.exec-grid>.lead,.exec-grid>.answer,.exec-grid>.meth{max-width:min(100%,var(--nx-layout-measure));margin:0}.exec-grid>h2,.exec-grid>table{grid-column:1/-1}.table-scroll{max-width:100%;overflow-x:auto;overscroll-behavior-inline:contain}.table-scroll>table{max-width:none;min-width:100%;width:max-content}.table-scroll th,.table-scroll td{white-space:nowrap}.table-scroll th:first-child,.table-scroll td:first-child{white-space:normal;width:var(--nx-layout-capmin);min-width:min(100vw - 2 * var(--nx-layout-gutter),var(--nx-layout-capmin));max-width:var(--nx-layout-capmin)}.table-scroll:focus-visible{outline:3px solid var(--ac);outline-offset:2px}\n" as *u8)
1181 // ---- the capability board: a responsive multi-column grid ----
1182 // auto-FILL, never auto-fit: auto-fit collapses the empty tracks and stretches a lone card across
1183 // the whole canvas, which re-creates at component scale the exact single-wide-column defect this
1184 // function exists to remove. min(100%,...) inside minmax is load-bearing: the auto-repeat count is
1185 // computed from the track MINIMUM, so a bare minmax(27rem,1fr) overflows any container narrower
1186 // than 27rem instead of dropping to one column.
1187 w(fd, ".caps{display:grid;grid-template-columns:repeat(auto-fill,minmax(min(100%,var(--nx-layout-capmin)),1fr));gap:var(--nx-layout-capgap);align-items:start;margin:6px 0}\n" as *u8)
1188 // the category headings are emitted INSIDE .caps, so they are grid items too and must span the row
1189 w(fd, ".caps>.ghead{grid-column:1/-1}\n" as *u8)
1190 // THE CARD IS SCOPED .caps>.cap, NOT BARE .cap, FOR THE SAME REASON .ghead ABOVE IS. "cap" is an
1191 // overloaded name in this estate and a bare rule in a SHARED lib claims it globally. Measured over
1192 // the whole corpus (coverage_complete=1 corpus_complete=1, 23,407 files) there are four other
1193 // holders: nx_swcompare_crm:64 and nx_swcompare_sending:65 both emit <td class='cap'> inside a <tr>,
1194 // and _hdl_build/nx_rewards:175 emits <span class='cap'> -- none of them a child of .caps, so the
1195 // child combinator excludes all three BY CONSTRUCTION. That matters because the roadmap is to
1196 // convert those generators onto this emitter, and display:grid landing on a <td> overrides
1197 // display:table-cell and destroys the table. Scoping costs 6 bytes and removes the trap before
1198 // anyone can walk into it.
1199 //
1200 // ***THIS IS NOT A COMPLETE FENCE AND MUST NOT BE READ AS ONE.*** The same census found a FIFTH
1201 // holder that the child combinator does NOT exclude: nx_compare_unified:281 emits
1202 // <div class='caps'> with <span class='cap on'> as its DIRECT CHILDREN, so .caps>.cap matches its
1203 // chip row exactly. It is harmless today -- nx_compare_unified does not call sc_layout_pass (the
1204 // four callers, RE-CENSUSED 2026-08-31 at coverage_complete=1 corpus_complete=1 over 23,407 files,
1205 // are nx_swcompare_sota, nx_swcompare_matrix, nx_swcompare_hub and nx_swcompare_watch_gate -- an
1206 // earlier revision of this comment said THREE and omitted hub. LINE NUMBERS ARE DELIBERATELY NOT
1207 // CITED HERE: hub's call site moved 729 -> 863 while this comment was being written, so a line
1208 // citation would rot faster than the fact it carries -- re-derive it with a grep for the symbol.
1209 // That undercount is load-bearing, not cosmetic: this enumeration IS the whole basis for calling the
1210 // collision harmless, so a fence that miscounts its own callers asserts a gap it never measured) -- but
1211 // whoever converts nx_compare_unified inherits a live collision, and a chip is not a card. Naming
1212 // the residual here rather than in a report nobody re-reads: a count without a worklist is not
1213 // actionable, and a fence published as "done" is worse than one published with its gap.
1214 w(fd, ".caps>.cap{container-type:inline-size;container-name:nxcap;display:grid;grid-template-columns:minmax(0,1fr) minmax(0,var(--nx-layout-rail));gap:6px 18px;padding:14px 16px;border:1px solid var(--line);border-radius:14px;background:var(--panel);align-items:start;min-width:0}\n" as *u8)
1215 w(fd, ".caps>.cap>.capmain,.caps>.cap>.capside{grid-column:1/-1}.capmain{min-width:0}.cap-note{max-width:var(--nx-layout-measure);text-wrap:pretty}\n" as *u8)
1216 w(fd, ".capside{display:flex;flex-direction:row;flex-wrap:wrap;align-items:center;gap:8px}.rw{max-width:100%}\n" as *u8)
1217 w(fd, "@container nxcap (min-width:" as *u8); wn(fd, SC_CAP_SPLIT); w(fd, "px){.caps>.cap>.capmain{grid-column:1;grid-row:1}.caps>.cap>.capside{grid-column:2;grid-row:1;flex-direction:column;align-items:flex-end}.caps>.cap .rw{justify-content:flex-end;max-width:var(--nx-layout-rail)}}\n" as *u8)
1218 sg_css(fd)
1219 return 0
1220}
1221
1222// ---- THE EVIDENCE PROFILE AS MACHINE-READABLE DATA (2026-08-31, frontier F1208) -------------------
1223// ONE RENDERER IN THE BASE, BOTH GENERATORS CALL IT -- the refs_pass / plan_pass precedent exactly. The
1224// HTML band (ev_pass, in nx_swcompare_matrix) and this JSON projection read THE SAME stamp through THE
1225// SAME reader, nx_evprofile_lib, so a board page and its api.json cannot disagree about that domain's
1226// gaps: there is one artifact and one parser, and this function only PROJECTS what evp_parse already
1227// read. THE GENERATOR ADDS A READER, NEVER A MEASUREMENT -- every field below is already materialised
1228// verbatim on knowledge/status/evstamp_<domain>.verdict by nx_swcompare_evidence.
1229//
1230// ABSTAIN, NEVER ACQUIT -- AND HERE THE ABSTAIN PATH IS THE COMMON PATH. 92 of the 95 live stamps are
1231// v1 (measured 2026-08-31), so the branch that emits NO NUMBERS is the one nearly every board takes,
1232// and it is therefore the one that has to be right: a v1 stamp carries none of the profile keys,
1233// evp_parse leaves every slot -1, and writing a 0 there would publish a gapless board for a domain
1234// nobody ever measured. AN ALWAYS-ZERO FIELD READS AS EVIDENCE.
1235// The evidence key is emitted on EVERY path, including the abstentions. An ABSENT key is
1236// indistinguishable from an emitter that never shipped, so the abstention is published as a VALUE --
1237// status UNKNOWN / UNSTAMPED / AMBIGUOUS -- and never as a silence.
1238//
1239// NO SCALAR GRADE, DELIBERATELY. Counts WITH their denominators, the partition sums, and the list of
1240// gap classes that FIRE. A stored scalar is a field a seat can edit; a counted partition is not, and
1241// any consumer can recompute whatever ranking it wants from these numbers at read time.
1242//
1243// NO PATH IS BUILT HERE. evp_load composes ep_artifact_path, so this behaves identically whether the
1244// generator was launched from the estate root or -- as nx_compare_regen launches it -- from buildroot,
1245// whose knowledge/status holds ZERO evstamp files. A bare relative read there would confidently render
1246// no-evidence for all 96 domains.
1247func evj_class(fired: i64, name: *u8, n: *i64) -> i64 {
1248 if fired != 1 { return 0 }
1249 if n[0] > 0 { wc(1, 44) }
1250 wq(1); wj(1, name); wq(1)
1251 n[0] = n[0] + 1
1252 return 1
1253}
1254
1255func evj_pass(dom: *u8) -> i64 {
1256 let buf: *u8 = sys_mmap(EVP_STAMP_CAP)
1257 let pathout: *u8 = sys_mmap(EVP_PATH_CAP)
1258 let flags: *i64 = sys_mmap(8 * EVP_NFLAG) as *i64
1259 let n: i64 = evp_load(dom, buf, EVP_STAMP_CAP, pathout, flags)
1260 wc(1, 44); wq(1); w(1, "evidence" as *u8); wq(1); wc(1, 58); wc(1, 123)
1261 kv_s(1, "producer" as *u8, "nx_swcompare_evidence" as *u8); wc(1, 44)
1262 kv_s(1, "reader" as *u8, "nx_evprofile_lib" as *u8); wc(1, 44)
1263 // Two different files answering to one name is REFUSED, not silently decided: ep_open_rd probes the
1264 // caller CWD first on purpose, so a stray copy beside the generator would win, and win silently.
1265 if n == EVP_RC_AMBIGUOUS {
1266 kv_s(1, "evidence_status" as *u8, "AMBIGUOUS" as *u8); wc(1, 44)
1267 kv_s(1, "source" as *u8, pathout); wc(1, 44)
1268 kv_s(1, "note" as *u8, "two different files answer to one stamp name -- one under the generator working directory, one at the estate root, and their bytes differ. No reader may pick one, so no numbers are published." as *u8)
1269 wc(1, 125)
1270 return 0
1271 }
1272 if n < 0 {
1273 kv_s(1, "evidence_status" as *u8, "UNSTAMPED" as *u8); wc(1, 44)
1274 kv_s(1, "note" as *u8, "no evidence stamp exists for this domain yet: run nx_swcompare_evidence on it and this object fills itself on the next beat. Not one numeric field is emitted, deliberately -- a zero-filled profile reads as a board with no gaps, which is the one wrong answer nobody would question." as *u8)
1275 wc(1, 125)
1276 return 0
1277 }
1278 let f: *i64 = sys_mmap(8 * EVP_NF) as *i64
1279 evp_parse(buf, n, f)
1280 kv_s(1, "source" as *u8, pathout); wc(1, 44)
1281 kv_n(1, "stamp_version" as *u8, f[EVP_F_V]); wc(1, 44)
1282 kv_n(1, "stamp_read_capped" as *u8, flags[EVP_FL_BRIM]); wc(1, 44)
1283 // THE VERSION IS DERIVED FROM THE WIRE, NEVER DECLARED ON IT: a v1 stamp simply has no profile keys.
1284 if f[EVP_F_V] < 2 {
1285 kv_s(1, "evidence_status" as *u8, "UNKNOWN" as *u8); wc(1, 44)
1286 kv_s(1, "note" as *u8, "this stamp predates the gap profile and carries none of its keys, so the reader abstains rather than acquit. UNKNOWN IS NOT ZERO. Re-stamp with nx_swcompare_evidence on this domain and the counts below appear." as *u8)
1287 wc(1, 125)
1288 return 0
1289 }
1290 let now: i64 = sys_now_realtime_sec()
1291 let ttl: i64 = evp_ttl_sec()
1292 let stale: i64 = evp_stale(f, now, ttl)
1293 var age: i64 = now - f[EVP_F_EPOCH]
1294 if age < 0 { age = 0 }
1295 kv_s(1, "evidence_status" as *u8, "MEASURED" as *u8); wc(1, 44)
1296 kv_n(1, "ok" as *u8, f[EVP_F_OK]); wc(1, 44)
1297 kv_n(1, "epoch" as *u8, f[EVP_F_EPOCH]); wc(1, 44)
1298 kv_n(1, "age_sec" as *u8, age); wc(1, 44)
1299 kv_n(1, "ttl_sec" as *u8, ttl); wc(1, 44)
1300 kv_n(1, "stale" as *u8, stale); wc(1, 44)
1301 // EVERY COUNT CARRIES ITS DENOMINATOR: a bare grounded=14 is not a fact about a board.
1302 wq(1); w(1, "grounded" as *u8); wq(1); wc(1, 58); wc(1, 123)
1303 kv_n(1, "count" as *u8, f[EVP_F_GROUNDED]); wc(1, 44); kv_n(1, "of" as *u8, f[EVP_F_PRESENT])
1304 wc(1, 125); wc(1, 44)
1305 kv_n(1, "unsupported" as *u8, f[EVP_F_UNGROUND]); wc(1, 44)
1306 wq(1); w(1, "gates" as *u8); wq(1); wc(1, 58); wc(1, 123)
1307 kv_n(1, "green" as *u8, f[EVP_F_GREEN]); wc(1, 44)
1308 kv_n(1, "ran" as *u8, f[EVP_F_RAN]); wc(1, 44)
1309 kv_n(1, "declared" as *u8, f[EVP_F_DECLARED]); wc(1, 44)
1310 kv_n(1, "skipped" as *u8, f[EVP_F_SKIPPED]); wc(1, 44)
1311 kv_n(1, "hashed" as *u8, f[EVP_F_HASHED]); wc(1, 44)
1312 kv_n(1, "redseen" as *u8, f[EVP_F_REDSEEN]); wc(1, 44)
1313 kv_n(1, "vacuous" as *u8, f[EVP_F_VACUOUS])
1314 wc(1, 125); wc(1, 44)
1315 wq(1); w(1, "gaps" as *u8); wq(1); wc(1, 58); wc(1, 123)
1316 kv_n(1, "open" as *u8, f[EVP_F_ABSENT]); wc(1, 44)
1317 kv_n(1, "named" as *u8, f[EVP_F_ABSNAMED]); wc(1, 44)
1318 kv_n(1, "unnamed" as *u8, f[EVP_F_ABSBARE])
1319 wc(1, 125); wc(1, 44)
1320 kv_n(1, "flips_ready" as *u8, f[EVP_F_LANDED]); wc(1, 44)
1321 // A PARTITION IS A CLAIM: PUBLISH THE PARTS AND THE SUM SO A LEAK CANNOT HIDE BEHIND A TOTAL.
1322 // reconciles is THREE-STATE on purpose -- 1 sums, 0 LEAKS, -1 not measurable from this stamp --
1323 // because a partition we could not check and one that failed are different facts.
1324 wq(1); w(1, "partition" as *u8); wq(1); wc(1, 58); wc(1, 123)
1325 kv_n(1, "grounded_plus_unsupported" as *u8, f[EVP_F_GROUNDED] + f[EVP_F_UNGROUND]); wc(1, 44)
1326 kv_n(1, "present_axes" as *u8, f[EVP_F_PRESENT]); wc(1, 44)
1327 kv_n(1, "named_plus_unnamed" as *u8, f[EVP_F_ABSNAMED] + f[EVP_F_ABSBARE]); wc(1, 44)
1328 kv_n(1, "open" as *u8, f[EVP_F_ABSENT]); wc(1, 44)
1329 kv_n(1, "reconciles" as *u8, evp_reconciles(f))
1330 wc(1, 125); wc(1, 44)
1331 // THE FAILING CONJUNCT, NAMED. A bare verdict is a disjunction and the reader always guesses the
1332 // alarming third; GPqN and gPQN are the same word and opposite work. evp_conj_char is the WRITER's
1333 // own function, so these letters cannot drift from the letters the referee stamped.
1334 wq(1); w(1, "conj" as *u8); wq(1); wc(1, 58); wq(1)
1335 wc(1, evp_conj_char(f[EVP_F_CJ_G], 71, 103))
1336 wc(1, evp_conj_char(f[EVP_F_CJ_P], 80, 112))
1337 wc(1, evp_conj_char(f[EVP_F_CJ_Q], 81, 113))
1338 wc(1, evp_conj_char(f[EVP_F_CJ_N], 78, 110))
1339 wq(1); wc(1, 44)
1340 kv_s(1, "first_failing_conjunct" as *u8, evp_conj_name(evp_conj_fail(f))); wc(1, 44)
1341 // WHICH DOCUMENT WAS GRADED. There are two knowledge trees and their copies of a matrix differ, so a
1342 // verdict that cannot name its subject document is not a verdict about the published board.
1343 wq(1); w(1, "graded_document" as *u8); wq(1); wc(1, 58); wc(1, 123)
1344 kv_s(1, "tree" as *u8, evp_tree_name(f[EVP_F_MROOT])); wc(1, 44)
1345 kv_n(1, "bytes" as *u8, f[EVP_F_MBYTES]); wc(1, 44)
1346 kv_n(1, "read_capped" as *u8, f[EVP_F_MCAPPED])
1347 wc(1, 125); wc(1, 44)
1348 kv_s(1, "gates_map_tree" as *u8, evp_tree_name(f[EVP_F_GATESROOT])); wc(1, 44)
1349 // THE GAP CLASSES THAT FIRE -- the machine half of the worklist. SEPARATE, NEVER MERGED: CLAIM-ONLY
1350 // needs a gate WRITTEN and GATE-FAILING needs one FIXED, and a single blended number sends a seat at
1351 // the wrong work. The remedy prose lives on the board page and is deliberately NOT copied here: two
1352 // copies of one sentence is a duplicate ruler that drifts on the first edit.
1353 wq(1); w(1, "classes" as *u8); wq(1); wc(1, 58); wc(1, 91)
1354 let cn: *i64 = sys_mmap(16) as *i64
1355 cn[0] = 0
1356 evj_class(evp_claim_only(f), "CLAIM-ONLY" as *u8, cn)
1357 evj_class(evp_gate_failing(f), "GATE-FAILING" as *u8, cn)
1358 evj_class(evp_fabricated(f), "UNSUPPORTED-CLAIM" as *u8, cn)
1359 evj_class(evp_flip_ready(f), "FLIP-READY" as *u8, cn)
1360 evj_class(evp_unnamed_gap(f), "UNNAMED-GAP" as *u8, cn)
1361 evj_class(evp_vacuous_gate(f), "VACUOUS-GATE" as *u8, cn)
1362 evj_class(stale, "STALE" as *u8, cn)
1363 wc(1, 93); wc(1, 44)
1364 kv_n(1, "classes_fired" as *u8, cn[0])
1365 wc(1, 125)
1366 return cn[0]
1367}
1368
1369// ---- MEASURED HEAD-TO-HEAD RECEIPTS (2026-09-01, lang leg) ---------------------------------------------
1370// OPERATOR: "meet and exceed gcc and rust and all the other languages independently verified with evidence
1371// documented and our /compare properly storing and making the evidence reproducible and visible and have that
1372// be an ecosystem wide capability". A performance number typed into a note is a CLAIM; this section renders a
1373// RECEIPT. knowledge/compare/<dom>.bench is written by a measuring organ (nx_lang_h2h for lang) and carries
1374// the host, every toolchain version, every source and binary sha256, min and median microseconds per arm, the
1375// checksum every arm had to agree on, and the exact command that regenerates it. ONE reader
1376// (nx_bench_receipt_lib) is shared by the writer, this renderer and the gate, and the verdict on the page is
1377// RE-DERIVED from the rows here, never copied from the file's own @verdict line -- the two are printed side by
1378// side and an agreement flag says whether the writer and the reader concur.
1379// ONE renderer in the base, BOTH generators call it (the refs_pass / plan_pass / watch_pass precedent), so a
1380// matrix board and a sota board publish the same bench dialect. A domain with no .bench emits NOTHING in both
1381// modes: every board without a receipt is byte-identical by construction.
1382const BD_SECS_PER_DAY: i64 = 86400
1383const BD_DAYS_TO_CIVIL_SHIFT: i64 = 719468 // days from 0000-03-01 to 1970-01-01 (Hinnant, civil_from_days)
1384const BD_DAYS_PER_ERA: i64 = 146097
1385const BD_DAYS_PER_4Y: i64 = 1460
1386const BD_DAYS_PER_100Y: i64 = 36524
1387const BD_DAYS_PER_ERA_LESS1: i64 = 146096
1388const BD_DAYS_PER_YEAR: i64 = 365
1389const BD_YEARS_PER_ERA: i64 = 400
1390const BD_MONTH_NUM: i64 = 153
1391const BD_MONTH_SHIFT: i64 = 2
1392const BD_MONTH_SCALE: i64 = 5
1393const BD_MARCH: i64 = 3
1394const BD_JAN_FROM_MP: i64 = 9
1395const BD_MP_WRAP: i64 = 10
1396const BD_FEB: i64 = 2
1397const BD_TEN: i64 = 10
1398const BD_SHA_SHOWN: i64 = 12
1399// YYYY-MM-DD from unix seconds (proleptic Gregorian, UTC); a non-positive epoch prints a dash
1400func bd_ymd(epoch: i64, dst: *u8, off: i64) -> i64 {
1401 if epoch <= 0 { return br_cat(dst, off, "-" as *u8) }
1402 let z: i64 = epoch / BD_SECS_PER_DAY + BD_DAYS_TO_CIVIL_SHIFT
1403 let era: i64 = z / BD_DAYS_PER_ERA
1404 let doe: i64 = z - era * BD_DAYS_PER_ERA
1405 let yoe: i64 = (doe - doe / BD_DAYS_PER_4Y + doe / BD_DAYS_PER_100Y - doe / BD_DAYS_PER_ERA_LESS1) / BD_DAYS_PER_YEAR
1406 let doy: i64 = doe - (BD_DAYS_PER_YEAR * yoe + yoe / 4 - yoe / 100)
1407 let mp: i64 = (BD_MONTH_SCALE * doy + BD_MONTH_SHIFT) / BD_MONTH_NUM
1408 let d: i64 = doy - (BD_MONTH_NUM * mp + BD_MONTH_SHIFT) / BD_MONTH_SCALE + 1
1409 var m: i64 = mp + BD_MARCH
1410 if mp >= BD_MP_WRAP { m = mp - BD_JAN_FROM_MP }
1411 var y: i64 = yoe + era * BD_YEARS_PER_ERA
1412 if m <= BD_FEB { y = y + 1 }
1413 var o: i64 = br_catn(dst, off, y)
1414 o = br_put(dst, o, 45)
1415 if m < BD_TEN { o = br_put(dst, o, 48) }
1416 o = br_catn(dst, o, m)
1417 o = br_put(dst, o, 45)
1418 if d < BD_TEN { o = br_put(dst, o, 48) }
1419 o = br_catn(dst, o, d)
1420 return o
1421}
1422// the first BD_SHA_SHOWN hex digits of a digest, or the whole thing when shorter
1423func bd_sha_short(fd: i64, s: *u8) -> i64 {
1424 var i: i64 = 0
1425 while s[i] != (0 as u8) { if i < BD_SHA_SHOWN { wc(fd, s[i] as i64) } i = i + 1 }
1426 return 0
1427}
1428func bd_status_class(st: i64) -> *u8 {
1429 if st == BR_ST_VALID { return "ok" as *u8 }
1430 if st == BR_ST_VOID { return "void" as *u8 }
1431 if st == BR_ST_UNMEASURABLE { return "unm" as *u8 }
1432 return "fail" as *u8
1433}
1434// ---- IM3 (intelmine, 2026-09-05): MINED INTELLIGENCE ON THE BOARD -- knowledge/compare/<dom>.proposed, rendered by the base for both generators ----
1435// nx_intelmine_propose routes review and competitive signals (nx_reviewmine_lib over Steam reviews under the
1436// exceeds / meets / mixed / does-not-meet rubric, the installed-title census) through capability_map.conf and APPENDS
1437// prop|epoch|appid|name|signal|kind|term|domain|rung-title|evidence (PR_NF fields; the writer dedupes on appid+kind+term)
1438// The proposer writes DATA and never a page. This is the ONE renderer, so every domain inherits the band on its next
1439// beat and a one-off report can never be built beside it (the grow-the-emitter law). An ABSENT file emits NOTHING --
1440// no section, no JSON key: an empty band would read as "the field has nothing to say", the one wrong answer nobody
1441// questions. A malformed row is COUNTED beside the rendered ones, never dropped in silence. A proposal is a LEAD, never
1442// a rung: it closes only when a rung with a gate lands, and the page says so in its own words.
1443const PR_READ_CAP: i64 = 65536 // announces when it binds; a .proposed file is rows, not a corpus
1444const PR_PATH_CAP: i64 = 600 // knowledge/compare/<dom>.proposed -- the reserve its sibling passes use
1445const PR_I64_BYTES: i64 = 8
1446const PR_NF: i64 = 10 // fields per prop| row, from the writer's own emit order (ip_emit)
1447const PR_SPLIT: i64 = 16 // field table: PR_NF plus room, so an over-long row is read whole rather than clipped to fit
1448const PR_F_TAG: i64 = 0
1449const PR_F_EPOCH: i64 = 1
1450const PR_F_APPID: i64 = 2
1451const PR_F_NAME: i64 = 3
1452const PR_F_SIGNAL: i64 = 4
1453const PR_F_KIND: i64 = 5
1454const PR_F_TERM: i64 = 6
1455const PR_F_DOMAIN: i64 = 7
1456const PR_F_TITLE: i64 = 8
1457const PR_F_EVIDENCE: i64 = 9
1458const PR_CH_COMMENT: i64 = 35
1459const PR_CH_LF: i64 = 10
1460const PR_CH_COMMA: i64 = 44
1461const PR_CH_COLON: i64 = 58
1462const PR_CH_LBRACE: i64 = 123
1463const PR_CH_RBRACE: i64 = 125
1464const PR_CH_LBRACKET: i64 = 91
1465const PR_CH_RBRACKET: i64 = 93
1466// RENDER-TIME TITLE (intelmine IM23/IM27, 2026-09-05): a row whose name column is its appid was written before any
1467// census or platform-api name existed, and the writer dedupes rows so it never rewrites them. The banked name
1468// (nx_steam_reviews name <appid> -> <appid>.name, one line) is read HERE instead, from the estate root as the mgmt
1469// daemon sees it AND from one directory up as the regen sees it (CWD = buildroot) -- the two-root read, announced
1470// per row as name_src=banked, never a silent guess. Absent in both: the row prints its appid and says so.
1471const PR_NAME_CAP: i64 = 256
1472const PR_NAME_DIR: *u8 = "knowledge/reviews/steam/"
1473const PR_NAME_DIR_UP: *u8 = "../knowledge/reviews/steam/"
1474const PR_NAME_SUFFIX: *u8 = ".name"
1475func pr_name_read(dir: *u8, appid: *u8, out: *u8, cap: i64) -> i64 {
1476 let path: *u8 = sys_mmap(PR_PATH_CAP)
1477 var o: i64 = scopy(path, 0, dir)
1478 o = scopy(path, o, appid); o = scopy(path, o, PR_NAME_SUFFIX); path[o] = 0 as u8
1479 let n: i64 = c_read(path, out, cap - 1)
1480 if n <= 0 { return 0 - 1 }
1481 var e: i64 = 0
1482 while e < n { if out[e] == (PR_CH_LF as u8) { break } e = e + 1 }
1483 out[e] = 0 as u8
1484 if e <= 0 { return 0 - 1 }
1485 return e
1486}
1487func pr_name_lookup(appid: *u8, out: *u8, cap: i64) -> i64 {
1488 let n: i64 = pr_name_read(PR_NAME_DIR, appid, out, cap)
1489 if n > 0 { return n }
1490 return pr_name_read(PR_NAME_DIR_UP, appid, out, cap)
1491}
1492func prop_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1493 let path: *u8 = sys_mmap(PR_PATH_CAP)
1494 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1495 o = scopy(path, o, dom); o = scopy(path, o, ".proposed" as *u8); path[o] = 0 as u8
1496 let buf: *u8 = sys_mmap(PR_READ_CAP)
1497 let n: i64 = c_read(path, buf, PR_READ_CAP - 1)
1498 if n <= 0 { return 0 }
1499 var capped: i64 = 0
1500 if n >= PR_READ_CAP - 1 { capped = 1 }
1501 buf[n] = 0 as u8
1502 let fld: *i64 = sys_mmap(PR_SPLIT * PR_I64_BYTES) as *i64
1503 if mode == 2 {
1504 wc(fd, PR_CH_COMMA); wq(fd); w(fd, "proposed" as *u8); wq(fd); wc(fd, PR_CH_COLON); wc(fd, PR_CH_LBRACE)
1505 kv_s(fd, "file" as *u8, path); wc(fd, PR_CH_COMMA)
1506 kv_s(fd, "writer" as *u8, "nx_intelmine_propose" as *u8); wc(fd, PR_CH_COMMA)
1507 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, PR_CH_COLON); wc(fd, PR_CH_LBRACKET)
1508 }
1509 if mode == 1 {
1510 w(fd, "<h2>Mined from the field — review and competitive intelligence proposed to this board</h2>\n" as *u8)
1511 if capped == 1 { w(fd, "<div class='meth'>proposed artefact READ-CAPPED at " as *u8); wn(fd, PR_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1512 w(fd, "<p class='lead'>Rows written by <code>nx_intelmine_propose</code> from <code>nx_reviewmine_lib</code> signals (Steam reviews under the exceeds / meets / mixed / does-not-meet rubric, the installed-title census) and routed here by <code>capability_map.conf</code>. <b>DEFECT</b> names a rival failing that a rung here answers; <b>DEMANDED</b> a capability buyers ask for and do not get; <b>WE-DO-BETTER</b> an exceed the reviews corroborate; <b>THEY-DO-WELL</b> a bar this board must meet; <b>SHIPS</b> a rival capability to match. <b>A proposal is a lead, never a rung</b> — it closes only when a rung with a gate lands, and nothing in this band changes a measured cell.</p>\n" as *u8)
1513 w(fd, "<table class='pl'><thead><tr><th>Signal</th><th>Kind</th><th>Term</th><th>Title</th><th>Proposed rung</th><th>Evidence</th></tr></thead><tbody>\n" as *u8)
1514 }
1515 var rows: i64 = 0
1516 var malformed: i64 = 0
1517 let nbuf: *u8 = sys_mmap(PR_NAME_CAP)
1518 var p: i64 = 0
1519 while p < n {
1520 var e: i64 = p
1521 while e < n { if buf[e] == (PR_CH_LF as u8) { break } e = e + 1 }
1522 buf[e] = 0 as u8
1523 let line: *u8 = (buf as i64 + p) as *u8
1524 p = e + 1
1525 if line[0] != (PR_CH_COMMENT as u8) { if line[0] != (0 as u8) {
1526 let nf: i64 = splitpipe(line, fld, PR_SPLIT)
1527 var ok: i64 = 0
1528 if nf >= PR_NF { if streq(fld[PR_F_TAG] as *u8, "prop" as *u8) == 1 { ok = 1 } }
1529 if ok == 0 { malformed = malformed + 1 } else {
1530 rows = rows + 1
1531 let name: *u8 = fld[PR_F_NAME] as *u8
1532 let appid: *u8 = fld[PR_F_APPID] as *u8
1533 // the proposer wrote the appid as the name when nothing named the title: try the banked name at render
1534 // time (name_src=banked), and only when that is absent too print the number AND say so (name_src=appid)
1535 var shown: *u8 = name
1536 var nsrc: *u8 = "row" as *u8
1537 if streq(name, appid) == 1 {
1538 nsrc = "appid" as *u8
1539 if pr_name_lookup(appid, nbuf, PR_NAME_CAP) > 0 { shown = nbuf; nsrc = "banked" as *u8 }
1540 }
1541 if mode == 1 {
1542 w(fd, "<tr><td><span class='ex'>" as *u8); wnote(fd, fld[PR_F_SIGNAL] as *u8); w(fd, "</span></td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_KIND] as *u8)
1543 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_TERM] as *u8); w(fd, "</td><td>" as *u8)
1544 if streq(nsrc, "appid" as *u8) == 1 { w(fd, "appid <span class='ct'>" as *u8); wnote(fd, appid); w(fd, "</span> (title unresolved: no census row and no banked name)" as *u8) } else { wnote(fd, shown); w(fd, " <span class='ct'>" as *u8); wnote(fd, appid); w(fd, "</span>" as *u8) }
1545 w(fd, "</td><td><b>" as *u8); wnote(fd, fld[PR_F_TITLE] as *u8); w(fd, "</b></td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_EVIDENCE] as *u8); w(fd, "</td></tr>\n" as *u8)
1546 }
1547 if mode == 2 {
1548 if rows > 1 { wc(fd, PR_CH_COMMA) }
1549 wc(fd, PR_CH_LBRACE)
1550 kv_s(fd, "epoch" as *u8, fld[PR_F_EPOCH] as *u8); wc(fd, PR_CH_COMMA)
1551 kv_s(fd, "appid" as *u8, appid); wc(fd, PR_CH_COMMA)
1552 kv_s(fd, "name" as *u8, shown); wc(fd, PR_CH_COMMA)
1553 kv_s(fd, "name_src" as *u8, nsrc); wc(fd, PR_CH_COMMA)
1554 kv_s(fd, "signal" as *u8, fld[PR_F_SIGNAL] as *u8); wc(fd, PR_CH_COMMA)
1555 kv_s(fd, "kind" as *u8, fld[PR_F_KIND] as *u8); wc(fd, PR_CH_COMMA)
1556 kv_s(fd, "term" as *u8, fld[PR_F_TERM] as *u8); wc(fd, PR_CH_COMMA)
1557 kv_s(fd, "domain" as *u8, fld[PR_F_DOMAIN] as *u8); wc(fd, PR_CH_COMMA)
1558 kv_s(fd, "title" as *u8, fld[PR_F_TITLE] as *u8); wc(fd, PR_CH_COMMA)
1559 kv_s(fd, "evidence" as *u8, fld[PR_F_EVIDENCE] as *u8)
1560 wc(fd, PR_CH_RBRACE)
1561 }
1562 }
1563 } }
1564 }
1565 if mode == 1 {
1566 w(fd, "</tbody></table>\n<p class='stats'>proposals <b>" as *u8); wn(fd, rows); w(fd, "</b><span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed)
1567 w(fd, "</b> (counted, never rendered: a row that is not <code>prop|</code> with " as *u8); wn(fd, PR_NF); w(fd, " fields)<span class='sep'>|</span>read-capped <b>" as *u8); wn(fd, capped); w(fd, "</b></p>\n" as *u8)
1568 }
1569 if mode == 2 {
1570 wc(fd, PR_CH_RBRACKET); wc(fd, PR_CH_COMMA)
1571 kv_n(fd, "count" as *u8, rows); wc(fd, PR_CH_COMMA)
1572 kv_n(fd, "malformed" as *u8, malformed); wc(fd, PR_CH_COMMA)
1573 kv_n(fd, "read_capped" as *u8, capped)
1574 wc(fd, PR_CH_RBRACE)
1575 }
1576 return rows
1577}
1578// THE DISCOVERED FIELD (fieldwatch FW1, 2026-09-05; operator: the six columns "arent a good sample of the industry").
1579// knowledge/compare/<dom>.field is WRITTEN by nx_field_discover from <dom>.seeds -- public lists (Wikipedia wikitext,
1580// GitHub topics, awesome lists) read mechanically -- and rendered here by the ONE reader for both generators. The page
1581// shows the field, then measures the matrix's own @cols as a SUBSET of it: columns_in_field of columns, and how many
1582// discovered rivals have no column at all. A seat's pick is thereby shown for what it is. Absent file = no section.
1583const FI_READ_CAP: i64 = 262144 // announces when it binds: a .field is rows, not a corpus
1584const FI_PATH_CAP: i64 = 600
1585const FI_I64_BYTES: i64 = 8
1586const FI_NF: i64 = 7 // rival|name|seeds_hit|mentions|first_seed|link|kind (nx_field_lib fl_emit)
1587const FI_SPLIT: i64 = 12
1588const FI_F_TAG: i64 = 0
1589const FI_F_NAME: i64 = 1
1590const FI_F_SEEDS: i64 = 2
1591const FI_F_MENTIONS: i64 = 3
1592const FI_F_FIRST: i64 = 4
1593const FI_F_LINK: i64 = 5
1594const FI_F_KIND: i64 = 6
1595const FI_SHOW: i64 = 60 // rows rendered; the rest are COUNTED and the stats line says shown of count
1596const FI_COLS_MAX: i64 = 16
1597const FI_CH_COMMENT: i64 = 35
1598const FI_CH_LF: i64 = 10
1599const FI_CH_PIPE: i64 = 124
1600const FI_CH_COMMA: i64 = 44
1601const FI_CH_COLON: i64 = 58
1602const FI_CH_LBRACE: i64 = 123
1603const FI_CH_RBRACE: i64 = 125
1604const FI_CH_LBRACKET: i64 = 91
1605const FI_CH_RBRACKET: i64 = 93
1606const FI_UPPER_A: i64 = 65
1607const FI_UPPER_Z: i64 = 90
1608const FI_CASE_DELTA: i64 = 32
1609func fi_lc(c: i64) -> i64 { if c >= FI_UPPER_A { if c <= FI_UPPER_Z { return c + FI_CASE_DELTA } } return c }
1610// case-insensitive: does hay contain needle (needle non-empty)?
1611func fi_ci_contains(hay: *u8, needle: *u8) -> i64 {
1612 var nl: i64 = 0
1613 while needle[nl] != (0 as u8) { nl = nl + 1 }
1614 if nl < 1 { return 0 }
1615 var hl: i64 = 0
1616 while hay[hl] != (0 as u8) { hl = hl + 1 }
1617 var i: i64 = 0
1618 while i + nl <= hl {
1619 var m: i64 = 0
1620 var j: i64 = 0
1621 while j < nl { if fi_lc(hay[i + j] as i64) == fi_lc(needle[j] as i64) { m = m + 1 } j = j + 1 }
1622 if m == nl { return 1 }
1623 i = i + 1
1624 }
1625 return 0
1626}
1627// the leading words of a column label (up to the first space) -- "Blender 4.5 plus addons" matches a rival named Blender
1628func fi_head_word(col: *u8, out: *u8, cap: i64) -> i64 {
1629 var i: i64 = 0
1630 while col[i] != (0 as u8) { if col[i] == (32 as u8) { break } if i < cap - 1 { out[i] = col[i] } i = i + 1 }
1631 if i > cap - 1 { i = cap - 1 }
1632 out[i] = 0 as u8
1633 return i
1634}
1635// colv/ncols: the matrix generator's ALREADY-SPLIT @cols vector (one owner of the split); the sota generator passes 0/0.
1636func field_pass(dom: *u8, fd: i64, mode: i64, colv: *i64, ncols_in: i64) -> i64 {
1637 let path: *u8 = sys_mmap(FI_PATH_CAP)
1638 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1639 o = scopy(path, o, dom); o = scopy(path, o, ".field" as *u8); path[o] = 0 as u8
1640 let buf: *u8 = sys_mmap(FI_READ_CAP)
1641 let n: i64 = c_read(path, buf, FI_READ_CAP - 1)
1642 if n <= 0 { return 0 }
1643 var capped: i64 = 0
1644 if n >= FI_READ_CAP - 1 { capped = 1 }
1645 buf[n] = 0 as u8
1646 var ncols: i64 = ncols_in
1647 if ncols > FI_COLS_MAX { ncols = FI_COLS_MAX }
1648 if ncols < 0 { ncols = 0 }
1649 let colhit: *i64 = sys_mmap(FI_COLS_MAX * FI_I64_BYTES) as *i64
1650 let head: *u8 = sys_mmap(FI_PATH_CAP)
1651 let fld: *i64 = sys_mmap(FI_SPLIT * FI_I64_BYTES) as *i64
1652 var summary: *u8 = "" as *u8
1653 var rows: i64 = 0
1654 var shown: i64 = 0
1655 var malformed: i64 = 0
1656 var p: i64 = 0
1657 // pass 1: the summary row and the column coverage (every row, never a prefix)
1658 while p < n {
1659 var e: i64 = p
1660 while e < n { if buf[e] == (FI_CH_LF as u8) { break } e = e + 1 }
1661 buf[e] = 0 as u8
1662 let line: *u8 = (buf as i64 + p) as *u8
1663 p = e + 1
1664 if line[0] != (FI_CH_COMMENT as u8) { if line[0] != (0 as u8) {
1665 if starts(line, "field|" as *u8) == 1 { summary = line } else {
1666 let nf: i64 = splitpipe(line, fld, FI_SPLIT)
1667 var ok: i64 = 0
1668 if nf >= FI_NF { if streq(fld[FI_F_TAG] as *u8, "rival" as *u8) == 1 { ok = 1 } }
1669 if ok == 0 { malformed = malformed + 1 } else {
1670 rows = rows + 1
1671 var c: i64 = 0
1672 while c < ncols {
1673 if colhit[c] == 0 {
1674 fi_head_word(colv[c] as *u8, head, FI_PATH_CAP)
1675 if fi_ci_contains(fld[FI_F_NAME] as *u8, head) == 1 { colhit[c] = 1 }
1676 }
1677 c = c + 1
1678 }
1679 }
1680 }
1681 } }
1682 }
1683 var cols_in: i64 = 0
1684 var c2: i64 = 0
1685 while c2 < ncols { if colhit[c2] == 1 { cols_in = cols_in + 1 } c2 = c2 + 1 }
1686 // pass 2: render (re-read, because splitpipe NUL-terminates in place)
1687 let n2: i64 = c_read(path, buf, FI_READ_CAP - 1)
1688 buf[n2] = 0 as u8
1689 if mode == 2 {
1690 wc(fd, FI_CH_COMMA); wq(fd); w(fd, "field" as *u8); wq(fd); wc(fd, FI_CH_COLON); wc(fd, FI_CH_LBRACE)
1691 kv_s(fd, "file" as *u8, path); wc(fd, FI_CH_COMMA)
1692 kv_s(fd, "writer" as *u8, "nx_field_discover" as *u8); wc(fd, FI_CH_COMMA)
1693 kv_s(fd, "summary" as *u8, summary); wc(fd, FI_CH_COMMA)
1694 kv_n(fd, "columns" as *u8, ncols); wc(fd, FI_CH_COMMA)
1695 kv_n(fd, "columns_in_field" as *u8, cols_in); wc(fd, FI_CH_COMMA)
1696 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, FI_CH_COLON); wc(fd, FI_CH_LBRACKET)
1697 }
1698 if mode == 1 {
1699 w(fd, "<h2 id='field'>The field — discovered, not chosen</h2>\n" as *u8)
1700 if capped == 1 { w(fd, "<div class='meth'>field artefact READ-CAPPED at " as *u8); wn(fd, FI_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1701 w(fd, "<p class='lead'>Rows written by <code>nx_field_discover</code> from <code>" as *u8); wnote(fd, dom); w(fd, ".seeds</code>: the industry's own lists (Wikipedia wikitext, GitHub topics, awesome lists) read mechanically, every candidate counted across seeds. The matrix columns above are a SEAT'S pick; this band is the population they were picked from, and the stats line measures one against the other. A rival here is a lead, never a verdict — it earns a column when its capabilities are read and pinned.</p>\n" as *u8)
1702 w(fd, "<div class='meth'><code>" as *u8); wnote(fd, summary); w(fd, "</code></div>\n" as *u8)
1703 w(fd, "<table class='pl'><thead><tr><th>Rank</th><th>Rival</th><th>Seeds</th><th>Mentions</th><th>First seed</th><th>Kind</th><th>Link</th></tr></thead><tbody>\n" as *u8)
1704 }
1705 var p2: i64 = 0
1706 var rank: i64 = 0
1707 while p2 < n2 {
1708 var e: i64 = p2
1709 while e < n2 { if buf[e] == (FI_CH_LF as u8) { break } e = e + 1 }
1710 buf[e] = 0 as u8
1711 let line: *u8 = (buf as i64 + p2) as *u8
1712 p2 = e + 1
1713 if line[0] != (FI_CH_COMMENT as u8) { if line[0] != (0 as u8) { if starts(line, "rival|" as *u8) == 1 {
1714 let nf: i64 = splitpipe(line, fld, FI_SPLIT)
1715 if nf >= FI_NF { if shown < FI_SHOW {
1716 rank = rank + 1
1717 shown = shown + 1
1718 if mode == 1 {
1719 w(fd, "<tr><td class='ct'>" as *u8); wn(fd, rank); w(fd, "</td><td><b>" as *u8); wnote(fd, fld[FI_F_NAME] as *u8)
1720 w(fd, "</b></td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_SEEDS] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_MENTIONS] as *u8)
1721 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_FIRST] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_KIND] as *u8)
1722 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_LINK] as *u8); w(fd, "</td></tr>\n" as *u8)
1723 }
1724 if mode == 2 {
1725 if shown > 1 { wc(fd, FI_CH_COMMA) }
1726 wc(fd, FI_CH_LBRACE)
1727 kv_s(fd, "name" as *u8, fld[FI_F_NAME] as *u8); wc(fd, FI_CH_COMMA)
1728 kv_s(fd, "seeds" as *u8, fld[FI_F_SEEDS] as *u8); wc(fd, FI_CH_COMMA)
1729 kv_s(fd, "mentions" as *u8, fld[FI_F_MENTIONS] as *u8); wc(fd, FI_CH_COMMA)
1730 kv_s(fd, "first_seed" as *u8, fld[FI_F_FIRST] as *u8); wc(fd, FI_CH_COMMA)
1731 kv_s(fd, "link" as *u8, fld[FI_F_LINK] as *u8); wc(fd, FI_CH_COMMA)
1732 kv_s(fd, "kind" as *u8, fld[FI_F_KIND] as *u8)
1733 wc(fd, FI_CH_RBRACE)
1734 }
1735 } }
1736 } } }
1737 }
1738 if mode == 1 {
1739 w(fd, "</tbody></table>\n<p class='stats'>field candidates <b>" as *u8); wn(fd, rows); w(fd, "</b><span class='sep'>|</span>shown <b>" as *u8); wn(fd, shown)
1740 w(fd, "</b> of " as *u8); wn(fd, rows); w(fd, "<span class='sep'>|</span>matrix columns in the field <b>" as *u8); wn(fd, cols_in); w(fd, "</b> of " as *u8); wn(fd, ncols)
1741 w(fd, "<span class='sep'>|</span>discovered rivals with no column <b>" as *u8); wn(fd, rows - cols_in); w(fd, "</b><span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed)
1742 w(fd, "</b> (counted, never rendered)<span class='sep'>|</span>read-capped <b>" as *u8); wn(fd, capped); w(fd, "</b></p>\n" as *u8)
1743 }
1744 if mode == 2 {
1745 wc(fd, FI_CH_RBRACKET); wc(fd, FI_CH_COMMA)
1746 kv_n(fd, "count" as *u8, rows); wc(fd, FI_CH_COMMA)
1747 kv_n(fd, "shown" as *u8, shown); wc(fd, FI_CH_COMMA)
1748 kv_n(fd, "no_column" as *u8, rows - cols_in); wc(fd, FI_CH_COMMA)
1749 kv_n(fd, "malformed" as *u8, malformed); wc(fd, FI_CH_COMMA)
1750 kv_n(fd, "read_capped" as *u8, capped)
1751 wc(fd, FI_CH_RBRACE)
1752 }
1753 return rows
1754}
1755// ---- GAUGE HEARTBEATS (codeeffectiveness CE9, 2026-09-06): A GAUGE CELL THAT READS STALE, NEVER ZERO ----
1756// <dom>.gauge rows: gauge|<label>|<stamp-path>|<cadence_s>|<note> (cadence_s 0 = take it from the stamp)
1757// WHY THIS IS IN THE BASE. The estate paid once for its effectiveness gauge going dark for 28 days and reading as
1758// "no movement": a number with no heartbeat is a claim with an expiry date nobody recorded. Every gauge row here is
1759// re-judged on every publish by THE ONE ruler the writing beat also uses (nx_gauge_lib.ga_judge), so the page and the
1760// beat cannot disagree: FRESH shows the value, STALE withholds it (age beyond two beats), BLIND withholds it (an axis
1761// abstained), ABSENT means nothing has measured. In api.json the "gauge" value key exists ONLY on a FRESH row -- a
1762// consumer that reads a missing key as zero is the defect this pass exists to make impossible on the page.
1763const GP_PATH_CAP: i64 = 600
1764const GP_READ_CAP: i64 = 65536
1765const GP_SPLIT: i64 = 8
1766const GP_NF: i64 = 5
1767const GP_F_LABEL: i64 = 1
1768const GP_F_PATH: i64 = 2
1769const GP_F_CAD: i64 = 3
1770const GP_F_NOTE: i64 = 4
1771const GP_ROW_CAP: i64 = 1024
1772const GP_CH_NL: i64 = 10
1773const GP_CH_HASH: i64 = 35
1774const GP_CH_COMMA: i64 = 44
1775const GP_CH_COLON: i64 = 58
1776const GP_CH_LBRACKET: i64 = 91
1777const GP_CH_RBRACKET: i64 = 93
1778const GP_CH_LBRACE: i64 = 123
1779const GP_CH_RBRACE: i64 = 125
1780func gauge_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1781 let path: *u8 = sys_mmap(GP_PATH_CAP)
1782 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1783 o = scopy(path, o, dom); o = scopy(path, o, ".gauge" as *u8); path[o] = 0 as u8
1784 let buf: *u8 = sys_mmap(GP_READ_CAP)
1785 let n: i64 = c_read(path, buf, GP_READ_CAP - 1)
1786 if n <= 0 { return 0 }
1787 var capped: i64 = 0
1788 if n >= GP_READ_CAP - 1 { capped = 1 }
1789 let now: i64 = sys_now_realtime_sec()
1790 let fld: *i64 = sys_mmap(GP_SPLIT * GA_WORD) as *i64
1791 let f: *i64 = sys_mmap(GA_F_SLOTS * GA_WORD) as *i64
1792 let rb: *u8 = sys_mmap(GP_ROW_CAP)
1793 var rows: i64 = 0
1794 var malformed: i64 = 0
1795 var c_fresh: i64 = 0
1796 var c_stale: i64 = 0
1797 var c_blind: i64 = 0
1798 var c_absent: i64 = 0
1799 if mode == 2 {
1800 wc(fd, GP_CH_COMMA); wq(fd); w(fd, "gauge" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACE)
1801 kv_s(fd, "file" as *u8, path); wc(fd, GP_CH_COMMA)
1802 kv_s(fd, "reader" as *u8, "nx_gauge_lib" as *u8); wc(fd, GP_CH_COMMA)
1803 kv_n(fd, "now" as *u8, now); wc(fd, GP_CH_COMMA)
1804 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACKET)
1805 }
1806 if mode == 1 {
1807 w(fd, "<h2 id='gauge'>Gauges — a heartbeat, never a bare number</h2>\n" as *u8)
1808 if capped == 1 { w(fd, "<div class='meth'>gauge artefact READ-CAPPED at " as *u8); wn(fd, GP_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1809 w(fd, "<p class='lead'>Each row names a gauge stamp written by its measuring beat. This page re-judges the stamp on every publish with the same ruler the beat uses (<code>nx_gauge_lib</code>): <b>FRESH</b> shows the value; <b>STALE</b> withholds it (older than two beats); <b>BLIND</b> withholds it (an axis abstained); <b>ABSENT</b> means nothing has measured. A stale gauge never reads as zero.</p>\n" as *u8)
1810 w(fd, "<table class='gauge-tab'><thead><tr><th>gauge</th><th>state</th><th>reading</th><th>note</th></tr></thead><tbody>\n" as *u8)
1811 }
1812 var p: i64 = 0
1813 while p < n {
1814 var e: i64 = p
1815 while e < n { if buf[e] == (GP_CH_NL as u8) { break } e = e + 1 }
1816 buf[e] = 0 as u8
1817 let line: *u8 = (buf as i64 + p) as *u8
1818 p = e + 1
1819 if line[0] != (GP_CH_HASH as u8) { if line[0] != (0 as u8) { if starts(line, "gauge|" as *u8) == 1 {
1820 let nf: i64 = splitpipe(line, fld, GP_SPLIT)
1821 if nf < GP_NF { malformed = malformed + 1 } else {
1822 let cs: *u8 = fld[GP_F_CAD] as *u8
1823 let cad: i64 = sj_atoi_span(cs, 0, sj_vlen(cs))
1824 // RESOLVE BEFORE JUDGING (2026-09-06): the regen runs with CWD=buildroot while every beat stamps from the serving root, so a
1825 // bare stamp path read ABSENT on the page for a stamp FRESH on disk (measured: knowledge/status/stepsolve.stamp 66 B at the
1826 // root, absent under buildroot). ep_artifact_path is the ONE probe order; an absent stamp still judges ABSENT through the same ruler.
1827 let gpath: *u8 = sys_mmap(GP_PATH_CAP)
1828 if ep_artifact_path(gpath, fld[GP_F_PATH] as *u8) == 0 { let go: i64 = scopy(gpath, 0, fld[GP_F_PATH] as *u8); gpath[go] = 0 as u8 }
1829 let st: i64 = ga_judge(gpath, now, cad, f)
1830 var age: i64 = 0 - 1
1831 if f[GA_F_TS] > 0 { age = now - f[GA_F_TS] }
1832 var mcad: i64 = cad
1833 if mcad <= 0 { mcad = f[GA_F_CADENCE] }
1834 let rl: i64 = ga_render(rb, 0, st, age, ga_max_age(mcad), f[GA_F_GAUGE], f[GA_F_KNOWN], f[GA_F_TOTAL])
1835 rb[rl] = 0 as u8
1836 if st == GA_FRESH { c_fresh = c_fresh + 1 }
1837 if st == GA_STALE { c_stale = c_stale + 1 }
1838 if st == GA_BLIND { c_blind = c_blind + 1 }
1839 if st == GA_ABSENT { c_absent = c_absent + 1 }
1840 if mode == 1 {
1841 w(fd, "<tr><td><b>" as *u8); wnote(fd, fld[GP_F_LABEL] as *u8); w(fd, "</b></td><td class='ct'>" as *u8); w(fd, ga_state_name(st))
1842 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, rb); w(fd, "</td><td>" as *u8); wnote(fd, fld[GP_F_NOTE] as *u8); w(fd, "</td></tr>\n" as *u8)
1843 }
1844 if mode == 2 {
1845 if rows > 0 { wc(fd, GP_CH_COMMA) }
1846 wc(fd, GP_CH_LBRACE)
1847 kv_s(fd, "label" as *u8, fld[GP_F_LABEL] as *u8); wc(fd, GP_CH_COMMA)
1848 kv_s(fd, "stamp" as *u8, fld[GP_F_PATH] as *u8); wc(fd, GP_CH_COMMA)
1849 kv_s(fd, "state" as *u8, ga_state_name(st)); wc(fd, GP_CH_COMMA)
1850 kv_n(fd, "age_s" as *u8, age); wc(fd, GP_CH_COMMA)
1851 kv_n(fd, "max_age_s" as *u8, ga_max_age(mcad)); wc(fd, GP_CH_COMMA)
1852 kv_n(fd, "axes_known" as *u8, f[GA_F_KNOWN]); wc(fd, GP_CH_COMMA)
1853 kv_n(fd, "axes_total" as *u8, f[GA_F_TOTAL]); wc(fd, GP_CH_COMMA)
1854 if st == GA_FRESH { kv_n(fd, "gauge" as *u8, f[GA_F_GAUGE]); wc(fd, GP_CH_COMMA) }
1855 kv_s(fd, "reading" as *u8, rb); wc(fd, GP_CH_COMMA)
1856 kv_s(fd, "note" as *u8, fld[GP_F_NOTE] as *u8)
1857 wc(fd, GP_CH_RBRACE)
1858 }
1859 rows = rows + 1
1860 }
1861 } } }
1862 }
1863 if mode == 2 {
1864 wc(fd, GP_CH_RBRACKET); wc(fd, GP_CH_COMMA)
1865 kv_n(fd, "count" as *u8, rows); wc(fd, GP_CH_COMMA)
1866 kv_n(fd, "fresh" as *u8, c_fresh); wc(fd, GP_CH_COMMA)
1867 kv_n(fd, "stale" as *u8, c_stale); wc(fd, GP_CH_COMMA)
1868 kv_n(fd, "blind" as *u8, c_blind); wc(fd, GP_CH_COMMA)
1869 kv_n(fd, "absent" as *u8, c_absent); wc(fd, GP_CH_COMMA)
1870 kv_n(fd, "malformed" as *u8, malformed); wc(fd, GP_CH_COMMA)
1871 kv_n(fd, "read_capped" as *u8, capped)
1872 wc(fd, GP_CH_RBRACE)
1873 }
1874 if mode == 1 {
1875 w(fd, "</tbody></table>\n<p class='stats'>gauges <b>" as *u8); wn(fd, rows)
1876 w(fd, "</b><span class='sep'>|</span>fresh <b>" as *u8); wn(fd, c_fresh); w(fd, "</b><span class='sep'>|</span>stale <b>" as *u8); wn(fd, c_stale)
1877 w(fd, "</b><span class='sep'>|</span>blind <b>" as *u8); wn(fd, c_blind); w(fd, "</b><span class='sep'>|</span>absent <b>" as *u8); wn(fd, c_absent)
1878 w(fd, "</b> (partition sums)<span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed); w(fd, "</b> (counted, never rendered)</p>\n" as *u8)
1879 }
1880 return rows
1881}
1882// ---- GAPS FROM THE RECORD (ecosystem EC38, 2026-09-06) ------------------------------------------------------
1883// Renders the record census (nx_goalmap record): organs the estate invokes and directives its own plan queue rows
1884// name that NO board row carries. The feed is the plane's own bytes written beside the conf by the same run
1885// (knowledge/recordgaps.conf.rows), resolved through ep_artifact_path like every status artifact, and its freshness
1886// is judged from the sibling stamp with the ONE gauge ruler: a stale census renders its rows under a STALE state
1887// and a BLIND one says how many declared sources are still unread; neither ever reads as "no gaps".
1888// Per board: this board's own directive rows (board == dom) always; the estate-wide UNASSIGNED organs in full on
1889// the ecosystem hub and as a COUNT everywhere else (hundreds of rows on every page would be the site saying one
1890// thing a hundred times). mode 1 = HTML section, mode 2 = api.json object. Absent feed = no section, returns 0.
1891const GX_FEED: *u8 = "knowledge/recordgaps.conf.rows"
1892const GX_STAMP: *u8 = "knowledge/recordgaps.conf.stamp"
1893const GX_READ_CAP: i64 = 4194304
1894const GX_NF: i64 = 5
1895const GX_F_KIND: i64 = 0
1896const GX_F_NAME: i64 = 1
1897const GX_F_BOARD: i64 = 2
1898const GX_F_SRC: i64 = 3
1899const GX_F_EV: i64 = 4
1900const GX_HUB: *u8 = "ecosystem"
1901const GX_UNASSIGNED: *u8 = "UNASSIGNED"
1902func gaps_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1903 let path: *u8 = sys_mmap(GP_PATH_CAP)
1904 if ep_artifact_path(path, GX_FEED) == 0 { return 0 }
1905 let buf: *u8 = sys_mmap(GX_READ_CAP)
1906 let n: i64 = c_read(path, buf, GX_READ_CAP - 1)
1907 if n <= 0 { return 0 }
1908 var capped: i64 = 0
1909 if n >= GX_READ_CAP - 1 { capped = 1 }
1910 let now: i64 = sys_now_realtime_sec()
1911 let spath: *u8 = sys_mmap(GP_PATH_CAP)
1912 if ep_artifact_path(spath, GX_STAMP) == 0 { let so: i64 = scopy(spath, 0, GX_STAMP); spath[so] = 0 as u8 }
1913 let f: *i64 = sys_mmap(GA_F_SLOTS * GA_WORD) as *i64
1914 var st: i64 = ga_judge(spath, now, 0, f)
1915 if f[GA_F_CADENCE] > 0 { st = ga_judge(spath, now, f[GA_F_CADENCE], f) }
1916 var age: i64 = 0 - 1
1917 if f[GA_F_TS] > 0 { age = now - f[GA_F_TS] }
1918 let fld: *i64 = sys_mmap(GP_SPLIT * GA_WORD) as *i64
1919 var hub: i64 = 0
1920 if streq(dom, GX_HUB) == 1 { hub = 1 }
1921 var total: i64 = 0
1922 var own: i64 = 0
1923 var unassigned: i64 = 0
1924 var malformed: i64 = 0
1925 var shown: i64 = 0
1926 if mode == 2 {
1927 wc(fd, GP_CH_COMMA); wq(fd); w(fd, "gaps" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACE)
1928 kv_s(fd, "feed" as *u8, path); wc(fd, GP_CH_COMMA)
1929 kv_s(fd, "stamp" as *u8, spath); wc(fd, GP_CH_COMMA)
1930 kv_s(fd, "state" as *u8, ga_state_name(st)); wc(fd, GP_CH_COMMA)
1931 kv_n(fd, "age_s" as *u8, age); wc(fd, GP_CH_COMMA)
1932 kv_n(fd, "sources_read" as *u8, f[GA_F_KNOWN]); wc(fd, GP_CH_COMMA)
1933 kv_n(fd, "sources_declared" as *u8, f[GA_F_TOTAL]); wc(fd, GP_CH_COMMA)
1934 kv_n(fd, "hub" as *u8, hub); wc(fd, GP_CH_COMMA)
1935 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACKET)
1936 }
1937 if mode == 1 {
1938 w(fd, "<h2 id='gaps'>Gaps from the record — what the estate does that no board carries</h2>\n" as *u8)
1939 w(fd, "<p class='lead'>The record census (<code>nx_goalmap record</code>) reads the invoked-tool population and every plan queue row and files each organ or directive that NO matrix, plan or gates row names. A row here is a callout the boards missed: adjudicate it onto a board or declare it infrastructure. Census state <b>" as *u8)
1940 w(fd, ga_state_name(st)); w(fd, "</b>" as *u8)
1941 if age >= 0 { w(fd, " (age " as *u8); wn(fd, age); w(fd, " s)" as *u8) }
1942 w(fd, ", sources read <b>" as *u8); wn(fd, f[GA_F_KNOWN]); w(fd, "</b> of <b>" as *u8); wn(fd, f[GA_F_TOTAL])
1943 w(fd, "</b> declared — a BLIND census is a FLOOR: unread sources can only add rows.</p>\n" as *u8)
1944 if capped == 1 { w(fd, "<div class='meth'>feed READ-CAPPED at " as *u8); wn(fd, GX_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1945 w(fd, "<table class='gaps-tab'><thead><tr><th>kind</th><th>name</th><th>board</th><th>source</th><th>evidence</th></tr></thead><tbody>\n" as *u8)
1946 }
1947 var p: i64 = 0
1948 while p < n {
1949 var e: i64 = p
1950 while e < n { if buf[e] == (GP_CH_NL as u8) { break } e = e + 1 }
1951 buf[e] = 0 as u8
1952 let line: *u8 = (buf as i64 + p) as *u8
1953 p = e + 1
1954 if line[0] != (GP_CH_HASH as u8) { if line[0] != (0 as u8) {
1955 let nf: i64 = splitpipe(line, fld, GP_SPLIT)
1956 if nf < GX_NF { malformed = malformed + 1 } else {
1957 total = total + 1
1958 var render: i64 = 0
1959 if streq(fld[GX_F_BOARD] as *u8, dom) == 1 { own = own + 1; render = 1 }
1960 if streq(fld[GX_F_BOARD] as *u8, GX_UNASSIGNED) == 1 { unassigned = unassigned + 1; if hub == 1 { render = 1 } }
1961 if render == 1 {
1962 if mode == 1 {
1963 w(fd, "<tr><td class='ct'>" as *u8); wnote(fd, fld[GX_F_KIND] as *u8); w(fd, "</td><td><code>" as *u8); wnote(fd, fld[GX_F_NAME] as *u8)
1964 w(fd, "</code></td><td class='ct'>" as *u8); wnote(fd, fld[GX_F_BOARD] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[GX_F_SRC] as *u8)
1965 w(fd, "</td><td>" as *u8); wnote(fd, fld[GX_F_EV] as *u8); w(fd, "</td></tr>\n" as *u8)
1966 }
1967 if mode == 2 {
1968 if shown > 0 { wc(fd, GP_CH_COMMA) }
1969 wc(fd, GP_CH_LBRACE)
1970 kv_s(fd, "kind" as *u8, fld[GX_F_KIND] as *u8); wc(fd, GP_CH_COMMA)
1971 kv_s(fd, "name" as *u8, fld[GX_F_NAME] as *u8); wc(fd, GP_CH_COMMA)
1972 kv_s(fd, "board" as *u8, fld[GX_F_BOARD] as *u8); wc(fd, GP_CH_COMMA)
1973 kv_s(fd, "source" as *u8, fld[GX_F_SRC] as *u8); wc(fd, GP_CH_COMMA)
1974 kv_s(fd, "evidence" as *u8, fld[GX_F_EV] as *u8)
1975 wc(fd, GP_CH_RBRACE)
1976 }
1977 shown = shown + 1
1978 }
1979 }
1980 } }
1981 }
1982 if mode == 2 {
1983 wc(fd, GP_CH_RBRACKET); wc(fd, GP_CH_COMMA)
1984 kv_n(fd, "shown" as *u8, shown); wc(fd, GP_CH_COMMA)
1985 kv_n(fd, "own" as *u8, own); wc(fd, GP_CH_COMMA)
1986 kv_n(fd, "estate_unassigned" as *u8, unassigned); wc(fd, GP_CH_COMMA)
1987 kv_n(fd, "total" as *u8, total); wc(fd, GP_CH_COMMA)
1988 kv_n(fd, "malformed" as *u8, malformed); wc(fd, GP_CH_COMMA)
1989 kv_n(fd, "read_capped" as *u8, capped)
1990 wc(fd, GP_CH_RBRACE)
1991 }
1992 if mode == 1 {
1993 w(fd, "</tbody></table>\n<p class='stats'>rows shown <b>" as *u8); wn(fd, shown)
1994 w(fd, "</b><span class='sep'>|</span>this board's directives <b>" as *u8); wn(fd, own)
1995 w(fd, "</b><span class='sep'>|</span>estate-wide un-boarded organs <b>" as *u8); wn(fd, unassigned)
1996 if hub == 0 { w(fd, "</b> (listed in full on <a href='/compare/ecosystem'>/compare/ecosystem</a>)<span class='sep'>|</span>census rows <b>" as *u8) } else { w(fd, "</b><span class='sep'>|</span>census rows <b>" as *u8) }
1997 wn(fd, total); w(fd, "</b><span class='sep'>|</span>malformed <b>" as *u8); wn(fd, malformed); w(fd, "</b> (counted, never rendered)</p>\n" as *u8)
1998 }
1999 return shown
2000}
2001func bench_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
2002 let path: *u8 = sys_mmap(600)
2003 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
2004 o = scopy(path, o, dom); o = scopy(path, o, ".bench" as *u8); path[o] = 0 as u8
2005 let hdr: *i64 = sys_mmap(BR_H_N * 8) as *i64
2006 let arms: *i64 = sys_mmap(BR_MAXARMS * BR_STRIDE * 8) as *i64
2007 let n: i64 = br_load(path, hdr, arms)
2008 if n < 0 { return 0 }
2009 let verdict: i64 = br_verdict(hdr, arms, n)
2010 let written: i64 = hdr[BR_H_WRITTEN_VERDICT]
2011 var agree: i64 = 0
2012 if written == verdict { agree = 1 }
2013 var c_valid: i64 = 0; var c_void: i64 = 0; var c_unm: i64 = 0; var c_bf: i64 = 0; var c_rf: i64 = 0; var c_unk: i64 = 0
2014 var i: i64 = 0
2015 while i < n {
2016 let st: i64 = arms[i * BR_STRIDE + BR_A_STATUS]
2017 if st == BR_ST_VALID { c_valid = c_valid + 1 } else { if st == BR_ST_VOID { c_void = c_void + 1 } else {
2018 if st == BR_ST_UNMEASURABLE { c_unm = c_unm + 1 } else { if st == BR_ST_BUILDFAIL { c_bf = c_bf + 1 } else {
2019 if st == BR_ST_RUNFAIL { c_rf = c_rf + 1 } else { c_unk = c_unk + 1 } } } } }
2020 i = i + 1
2021 }
2022 let ymd: *u8 = sys_mmap(32)
2023 bd_ymd(hdr[BR_H_ASOF], ymd, 0)
2024 let rt: *u8 = sys_mmap(32)
2025 if mode == 2 {
2026 wc(fd, 44); wq(fd); w(fd, "bench" as *u8); wq(fd); wc(fd, 58); wc(fd, 123)
2027 kv_s(fd, "file" as *u8, path); wc(fd, 44)
2028 kv_s(fd, "reader" as *u8, "nx_bench_receipt_lib" as *u8); wc(fd, 44)
2029 kv_s(fd, "writer" as *u8, hdr[BR_H_WRITER] as *u8); wc(fd, 44)
2030 kv_s(fd, "title" as *u8, hdr[BR_H_TITLE] as *u8); wc(fd, 44)
2031 kv_s(fd, "workload" as *u8, hdr[BR_H_WORKLOAD] as *u8); wc(fd, 44)
2032 kv_s(fd, "host" as *u8, hdr[BR_H_HOST] as *u8); wc(fd, 44)
2033 kv_n(fd, "runs" as *u8, hdr[BR_H_RUNS]); wc(fd, 44)
2034 kv_s(fd, "ref" as *u8, hdr[BR_H_REF] as *u8); wc(fd, 44)
2035 kv_n(fd, "asof" as *u8, hdr[BR_H_ASOF]); wc(fd, 44)
2036 kv_s(fd, "asof_ymd" as *u8, ymd); wc(fd, 44)
2037 kv_s(fd, "repro" as *u8, hdr[BR_H_REPRO] as *u8); wc(fd, 44)
2038 kv_s(fd, "verdict" as *u8, br_verdict_name(verdict)); wc(fd, 44)
2039 kv_s(fd, "written_verdict" as *u8, br_verdict_name(written)); wc(fd, 44)
2040 kv_n(fd, "writer_reader_agree" as *u8, agree); wc(fd, 44)
2041 kv_n(fd, "arms" as *u8, n); wc(fd, 44)
2042 kv_n(fd, "valid" as *u8, c_valid); wc(fd, 44); kv_n(fd, "void" as *u8, c_void); wc(fd, 44)
2043 kv_n(fd, "unmeasurable" as *u8, c_unm); wc(fd, 44); kv_n(fd, "build_fail" as *u8, c_bf); wc(fd, 44)
2044 kv_n(fd, "run_fail" as *u8, c_rf); wc(fd, 44); kv_n(fd, "unknown" as *u8, c_unk); wc(fd, 44)
2045 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, 58); wc(fd, 91)
2046 var j: i64 = 0
2047 while j < n {
2048 let b: i64 = j * BR_STRIDE
2049 if j > 0 { wc(fd, 44) }
2050 wc(fd, 123)
2051 kv_s(fd, "arm" as *u8, arms[b + BR_A_NAME] as *u8); wc(fd, 44)
2052 kv_s(fd, "toolchain" as *u8, arms[b + BR_A_TOOL] as *u8); wc(fd, 44)
2053 kv_s(fd, "version" as *u8, arms[b + BR_A_VER] as *u8); wc(fd, 44)
2054 kv_s(fd, "source" as *u8, arms[b + BR_A_SRC] as *u8); wc(fd, 44)
2055 kv_s(fd, "source_sha256" as *u8, arms[b + BR_A_SRCSHA] as *u8); wc(fd, 44)
2056 kv_n(fd, "bin_bytes" as *u8, arms[b + BR_A_BINBYTES]); wc(fd, 44)
2057 kv_s(fd, "bin_sha256" as *u8, arms[b + BR_A_BINSHA] as *u8); wc(fd, 44)
2058 kv_n(fd, "runs" as *u8, arms[b + BR_A_RUNS]); wc(fd, 44)
2059 kv_n(fd, "min_us" as *u8, arms[b + BR_A_MIN]); wc(fd, 44)
2060 kv_n(fd, "median_us" as *u8, arms[b + BR_A_MED]); wc(fd, 44)
2061 kv_n(fd, "checksum" as *u8, arms[b + BR_A_CHK]); wc(fd, 44)
2062 kv_s(fd, "status" as *u8, br_status_name(arms[b + BR_A_STATUS])); wc(fd, 44)
2063 kv_n(fd, "ratio_permil" as *u8, arms[b + BR_A_RATIO]); wc(fd, 44)
2064 kv_s(fd, "note" as *u8, arms[b + BR_A_NOTE] as *u8)
2065 wc(fd, 125)
2066 j = j + 1
2067 }
2068 wc(fd, 93)
2069 wc(fd, 125)
2070 return n
2071 }
2072 if mode == 1 {
2073 // scoped style so the section renders identically under both generators' sheets; theme vars with fallbacks
2074 w(fd, "<style>.bench-tab{width:100%;border-collapse:collapse;font-size:.84rem}.bench-tab th,.bench-tab td{text-align:left;padding:6px 8px;border-bottom:1px solid var(--line,rgb(60,64,72));vertical-align:top}.bench-tab th{font-size:.7rem;letter-spacing:.08em;text-transform:uppercase;color:var(--mut,rgb(150,162,186))}.bench-tab td.num{font-variant-numeric:tabular-nums;text-align:right;white-space:nowrap}.bench-tab code{font-family:ui-monospace,Consolas,monospace;font-size:.78rem}.bst{font-size:.66rem;letter-spacing:.08em;text-transform:uppercase;font-weight:650;padding:2px 8px;border-radius:8px;display:inline-block;white-space:nowrap;border:1px solid var(--line,rgb(60,64,72))}.bst.ok{color:var(--nx-color-ok,rgb(26,127,55))}.bst.void{color:var(--nx-color-absent,rgb(179,38,30))}.bst.unm{color:var(--mut,rgb(150,162,186))}.bst.fail{color:var(--nx-color-part,rgb(178,106,0))}.bench-repro{font-family:ui-monospace,Consolas,monospace;font-size:.78rem;background:var(--soft,rgb(40,46,64));padding:8px 10px;border-radius:8px;overflow-x:auto;white-space:pre}.bench-ref{font-weight:600}</style>\n" as *u8)
2075 w(fd, "<h2 class='ghead' id='bench'>Measured head-to-head — a receipt, not a claim</h2>\n<div class='meth'><b>" as *u8); wnote(fd, hdr[BR_H_TITLE] as *u8); w(fd, ".</b> " as *u8); wnote(fd, hdr[BR_H_WORKLOAD] as *u8)
2076 w(fd, " Measured on <code>" as *u8); wnote(fd, hdr[BR_H_HOST] as *u8); w(fd, "</code> on " as *u8); w(fd, ymd); w(fd, " (unix " as *u8); wn(fd, hdr[BR_H_ASOF]); w(fd, "), " as *u8); wn(fd, hdr[BR_H_RUNS]); w(fd, " runs per arm, reference arm <span class='bench-ref'>" as *u8); wnote(fd, hdr[BR_H_REF] as *u8)
2077 w(fd, "</span> = 1.00x. Every arm had to print the same checksum or its row is VOID and never ranked; an arm whose toolchain is not declared on the host is UNMEASURABLE, an absence rather than a loss. Written by <code>" as *u8); wnote(fd, hdr[BR_H_WRITER] as *u8); w(fd, "</code>, re-derived here by <code>nx_bench_receipt_lib</code>: reader verdict <span class='bst " as *u8)
2078 if verdict == BR_V_VALID { w(fd, "ok" as *u8) } else { if verdict == BR_V_VOID { w(fd, "void" as *u8) } else { w(fd, "unm" as *u8) } }
2079 w(fd, "'>" as *u8); w(fd, br_verdict_name(verdict)); w(fd, "</span>, writer wrote " as *u8); w(fd, br_verdict_name(written))
2080 if agree == 1 { w(fd, " (writer and reader agree)" as *u8) } else { w(fd, " (<b>WRITER AND READER DISAGREE</b> -- the rows were edited after the receipt was written)" as *u8) }
2081 w(fd, ".</div>\n<div style='overflow-x:auto'><table class='bench-tab'><thead><tr><th>Arm</th><th>Toolchain</th><th>Version</th><th>Median µs</th><th>Min µs</th><th>vs reference</th><th>Checksum</th><th>Status</th><th>Runs</th><th>Source sha256</th><th>Binary</th></tr></thead><tbody>\n" as *u8)
2082 var k: i64 = 0
2083 while k < n {
2084 let b: i64 = k * BR_STRIDE
2085 let st: i64 = arms[b + BR_A_STATUS]
2086 w(fd, "<tr><td><b>" as *u8); wnote(fd, arms[b + BR_A_NAME] as *u8); w(fd, "</b></td><td>" as *u8); wnote(fd, arms[b + BR_A_TOOL] as *u8)
2087 w(fd, "</td><td><code>" as *u8); wnote(fd, arms[b + BR_A_VER] as *u8); w(fd, "</code></td><td class='num'>" as *u8)
2088 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_MED]) } else { w(fd, "-" as *u8) }
2089 w(fd, "</td><td class='num'>" as *u8)
2090 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_MIN]) } else { w(fd, "-" as *u8) }
2091 w(fd, "</td><td class='num'>" as *u8)
2092 br_ratio_text(arms[b + BR_A_RATIO], rt, 0); w(fd, rt)
2093 w(fd, "</td><td class='num'>" as *u8)
2094 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_CHK]) } else { if st == BR_ST_VOID { wn(fd, arms[b + BR_A_CHK]) } else { w(fd, "-" as *u8) } }
2095 w(fd, "</td><td><span class='bst " as *u8); w(fd, bd_status_class(st)); w(fd, "'>" as *u8); w(fd, br_status_name(st)); w(fd, "</span>" as *u8)
2096 if st != BR_ST_VALID { w(fd, "<br><span class='ct'>" as *u8); wnote(fd, arms[b + BR_A_NOTE] as *u8); w(fd, "</span>" as *u8) }
2097 w(fd, "</td><td class='num'>" as *u8); wn(fd, arms[b + BR_A_RUNS])
2098 w(fd, "</td><td><code title='" as *u8); wnote(fd, arms[b + BR_A_SRC] as *u8); w(fd, "'>" as *u8); bd_sha_short(fd, arms[b + BR_A_SRCSHA] as *u8); w(fd, "</code></td><td class='num'><code>" as *u8); bd_sha_short(fd, arms[b + BR_A_BINSHA] as *u8); w(fd, "</code> " as *u8); wn(fd, arms[b + BR_A_BINBYTES]); w(fd, " B</td></tr>\n" as *u8)
2099 k = k + 1
2100 }
2101 w(fd, "</tbody></table></div>\n<p class='foot'>bench arms=" as *u8); wn(fd, n); w(fd, " valid=" as *u8); wn(fd, c_valid); w(fd, " void=" as *u8); wn(fd, c_void); w(fd, " unmeasurable=" as *u8); wn(fd, c_unm); w(fd, " build_fail=" as *u8); wn(fd, c_bf); w(fd, " run_fail=" as *u8); wn(fd, c_rf); w(fd, " unknown=" as *u8); wn(fd, c_unk); w(fd, " (partition sums) verdict=" as *u8); w(fd, br_verdict_name(verdict)); w(fd, "</p>\n" as *u8)
2102 w(fd, "<p class='foot'>reproduce: </p><div class='bench-repro'>" as *u8); wnote(fd, hdr[BR_H_REPRO] as *u8); w(fd, "</div>\n<p class='foot'>receipt: knowledge/compare/" as *u8); w(fd, dom); w(fd, ".bench · a rerun on the same host that changes the ranking is a finding, not noise; a rerun on a different host is a different receipt and says so in its host line.</p>\n" as *u8)
2103 return n
2104 }
2105 return n
2106}
2107
2108// Additive shared dependency projection. Parsed declarations are not verified readiness.
2109// Owned by nx_swcompare_lib; no main, filesystem writes, publication or dispatch.
2110import "nx_sha256.nx"
2111const SGP_FIELDS: i64 = 8
2112const SGP_PATH_CAP: i64 = 600
2113const SGP_I64_MAX: i64 = 9223372036854775807
2114struct SgPlan {
2115 plan: *u8
2116 plan_bytes: i64
2117 plan_sha: *u8
2118 matrix_sha: *u8
2119 matrix_bytes: i64
2120 rank_sha: *u8
2121 rank_bytes: i64
2122 nodes: *i64
2123 count: i64
2124 declared: i64
2125 edges: *i64
2126 edge_count: i64
2127 malformed: i64
2128 duplicate_ids: i64
2129 duplicate_edges: i64
2130 missing_deps: i64
2131 cyclic_nodes: i64
2132 target_rows: i64
2133 role_rows: i64
2134 risk_rows: i64
2135 log_rows: i64
2136 rank_count: i64
2137 rank_mismatches: i64
2138 binding_rows: i64
2139 binding_ok: i64
2140}
2141func sg_len(s: *u8) -> i64 { var i: i64 = 0; while s[i] != (0 as u8) { i = i + 1 } return i }
2142func sg_id(s: *u8, n: i64) -> i64 {
2143 if n <= 0 { return 0 }
2144 var i: i64 = 0
2145 while i < n {
2146 let c: i64 = s[i] as i64
2147 var ok: i64 = 0
2148 if c >= 48 { if c <= 57 { ok = 1 } }
2149 if c >= 65 { if c <= 90 { ok = 1 } }
2150 if c >= 97 { if c <= 122 { ok = 1 } }
2151 if c == 95 { ok = 1 }; if c == 45 { ok = 1 }
2152 if ok == 0 { return 0 }; i = i + 1
2153 }
2154 return 1
2155}
2156// Unlike splitpipe, count every field even when the caller's pointer reserve is full.
2157func sg_split(s: *u8, f: *i64, capacity: i64, delimiter: i64) -> i64 {
2158 var count: i64 = 1; var i: i64 = 0; f[0] = s as i64
2159 while s[i] != (0 as u8) {
2160 if s[i] == (delimiter as u8) { s[i] = 0 as u8; if count < capacity { f[count] = s as i64 + i + 1 }; count = count + 1 }
2161 i = i + 1
2162 }
2163 return count
2164}
2165func sg_decimal(s: *u8) -> i64 {
2166 if s[0] == (0 as u8) { return 0 - 1 }
2167 var v: i64 = 0; var i: i64 = 0
2168 while s[i] != (0 as u8) {
2169 let c: i64 = s[i] as i64; if c < 48 { return 0 - 1 }; if c > 57 { return 0 - 1 }
2170 let d: i64 = c - 48; if v > (SGP_I64_MAX - d) / 10 { return 0 - 1 }
2171 v = v * 10 + d; i = i + 1
2172 }
2173 return v
2174}
2175func sg_sha(b: *u8, n: i64) -> *u8 {
2176 let raw: *u8 = sys_mmap(32); let text: *u8 = sys_mmap(65)
2177 if (raw as i64) <= 0 { return "" as *u8 }; if (text as i64) <= 0 { return "" as *u8 }
2178 sha256_digest(b, n, raw)
2179 let digits: *u8 = "0123456789abcdef" as *u8
2180 var i: i64 = 0
2181 while i < 32 { let c: i64 = raw[i] as i64; text[i*2] = digits[c / 16]; text[i*2+1] = digits[c % 16]; i = i + 1 }
2182 text[64] = 0 as u8; return text
2183}
2184func sg_find(m: *SgPlan, name: *u8, length: i64) -> i64 {
2185 var i: i64 = 0
2186 while i < m.count {
2187 let id: *u8 = m.nodes[i*SGP_FIELDS + 1] as *u8
2188 if sg_len(id) == length {
2189 var j: i64 = 0; var equal: i64 = 1
2190 while j < length { if id[j] != name[j] { equal = 0 }; j = j + 1 }
2191 if equal == 1 { return i }
2192 }
2193 i = i + 1
2194 }
2195 return 0 - 1
2196}
2197func sg_prefix_decimal(s: *u8, key: *u8) -> i64 {
2198 if starts(s, key) == 0 { return 0 - 1 }
2199 return sg_decimal((s as i64 + sg_len(key)) as *u8)
2200}
2201func sg_rank(m: *SgPlan, raw: *u8, n: i64) -> i64 {
2202 m.rank_count = 0 - 1
2203 if n <= 0 { return 0 }
2204 if n == SGP_I64_MAX { m.rank_mismatches = m.rank_mismatches + 1; return 0 }
2205 m.rank_sha = sg_sha(raw, n); m.rank_bytes = n
2206 if sg_len(m.rank_sha) != 64 { m.rank_mismatches = m.rank_mismatches + 1; return 0 }
2207 let b: *u8 = sys_mmap(n + 1); var c: i64 = 0
2208 if (b as i64) <= 0 { m.rank_mismatches = m.rank_mismatches + 1; return 0 }
2209 while c < n { if raw[c] == (0 as u8) { m.rank_mismatches = m.rank_mismatches + 1; return 0 }; b[c] = raw[c]; c = c + 1 }; b[n] = 0 as u8
2210 let f: *i64 = sys_mmap(12 * 8) as *i64
2211 if (f as i64) <= 0 { m.rank_mismatches = m.rank_mismatches + 1; return 0 }
2212 var pos: i64 = 0; var stamps: i64 = 0
2213 while pos < n {
2214 var end: i64 = pos; while end < n { if b[end] == (10 as u8) { break }; end = end + 1 }
2215 b[end] = 0 as u8; if end > pos { if b[end-1] == (13 as u8) { b[end-1] = 0 as u8 } }
2216 let line: *u8 = (b as i64 + pos) as *u8; pos = end + 1
2217 if starts(line, "# inputs_v=" as *u8) == 1 {
2218 m.binding_rows = m.binding_rows + 1
2219 let nf: i64 = sg_split(line, f, 12, 32)
2220 if nf == 6 {
2221 if streq(f[1] as *u8, "inputs_v=1" as *u8) == 1 {
2222 let ps: *u8 = f[2] as *u8; let ms: *u8 = f[4] as *u8
2223 if starts(ps, "plan_sha256=" as *u8) == 1 { if starts(ms, "matrix_sha256=" as *u8) == 1 {
2224 if streq((ps as i64 + 12) as *u8, m.plan_sha) == 1 { if streq((ms as i64 + 14) as *u8, m.matrix_sha) == 1 {
2225 if sg_prefix_decimal(f[3] as *u8, "plan_bytes=" as *u8) == m.plan_bytes {
2226 if sg_prefix_decimal(f[5] as *u8, "matrix_bytes=" as *u8) == m.matrix_bytes { m.binding_ok = 1 }
2227 }
2228 } }
2229 } }
2230 }
2231 }
2232 } else {
2233 if starts(line, "# asof=" as *u8) == 1 {
2234 stamps = stamps + 1
2235 let nf: i64 = sg_split(line, f, 12, 32)
2236 if nf > 12 { m.rank_mismatches = m.rank_mismatches + 1 } else {
2237 var z: i64 = 0; var found: i64 = 0
2238 while z < nf { if starts(f[z] as *u8, "rungs=" as *u8) == 1 { found = found + 1; m.rank_count = sg_prefix_decimal(f[z] as *u8, "rungs=" as *u8) }; z = z + 1 }
2239 if found != 1 { m.rank_mismatches = m.rank_mismatches + 1 }
2240 }
2241 } else {
2242 if starts(line, "rank|" as *u8) == 1 {
2243 let nf: i64 = sg_split(line, f, 12, 124)
2244 if nf != 10 { m.rank_mismatches = m.rank_mismatches + 1 } else {
2245 let id: *u8 = f[3] as *u8; let idx: i64 = sg_find(m, id, sg_len(id))
2246 if idx < 0 { m.rank_mismatches = m.rank_mismatches + 1 } else {
2247 if streq(f[9] as *u8, m.nodes[idx*SGP_FIELDS+3] as *u8) == 0 { m.rank_mismatches = m.rank_mismatches + 1 }
2248 }
2249 }
2250 }
2251 }
2252 }
2253 }
2254 if stamps != 1 { m.rank_mismatches = m.rank_mismatches + 1 }
2255 if m.binding_rows != 1 { m.binding_ok = 0 }
2256 if m.matrix_bytes <= 0 { m.binding_ok = 0 }
2257 return 0
2258}
2259func sg_parse(raw: *u8, n: i64, rank: *u8, rn: i64, matrix: *u8, mn: i64) -> *SgPlan {
2260 // SgPlan stores 25 pointer/i64 fields, each one native 64-bit word.
2261 let m: *SgPlan = sys_mmap(25 * 8) as *SgPlan
2262 if (m as i64) <= 0 { return 0 as *SgPlan }
2263 m.rank_count = 0 - 1; m.matrix_bytes = mn
2264 m.plan_sha = "" as *u8; m.matrix_sha = "" as *u8; m.rank_sha = "" as *u8
2265 if n <= 0 { m.malformed = 1; return m }
2266 if (raw as i64) <= 0 { m.malformed = 1; return m }
2267 // Reserve arithmetic is bounded by the input byte count, not a policy cutoff.
2268 if n > SGP_I64_MAX / (SGP_FIELDS * 8) - 1 { m.malformed = 1; return m }
2269 if rn < 0 { m.malformed = 1; return m }; if mn < 0 { m.malformed = 1; return m }
2270 if rn > 0 { if (rank as i64) <= 0 { m.malformed = 1; return m } }
2271 if mn > 0 { if (matrix as i64) <= 0 { m.malformed = 1; return m } }
2272 m.plan_bytes = n; m.plan_sha = sg_sha(raw, n)
2273 if sg_len(m.plan_sha) != 64 { m.malformed = 1; return m }
2274 if mn > 0 { m.matrix_sha = sg_sha(matrix, mn); if sg_len(m.matrix_sha) != 64 { m.malformed = 1; return m } }
2275 let b: *u8 = sys_mmap(n + 1); m.plan = b
2276 if (b as i64) <= 0 { m.malformed = 1; return m }
2277 var maxrows: i64 = 1; var maxedges: i64 = 1; var c: i64 = 0
2278 while c < n {
2279 if raw[c] == (0 as u8) { m.malformed = m.malformed + 1 }
2280 if raw[c] == (10 as u8) { maxrows = maxrows + 1; maxedges = maxedges + 1 }
2281 if raw[c] == (44 as u8) { maxedges = maxedges + 1 }
2282 b[c] = raw[c]; c = c + 1
2283 }
2284 b[n] = 0 as u8
2285 m.nodes = sys_mmap(maxrows * SGP_FIELDS * 8) as *i64
2286 m.edges = sys_mmap(maxedges * 2 * 8) as *i64
2287 let f: *i64 = sys_mmap(SGP_FIELDS * 8) as *i64
2288 if (m.nodes as i64) <= 0 { m.malformed = 1; return m }
2289 if (m.edges as i64) <= 0 { m.malformed = 1; return m }
2290 if (f as i64) <= 0 { m.malformed = 1; return m }
2291 var pos: i64 = 0
2292 while pos < n {
2293 var end: i64 = pos; while end < n { if b[end] == (10 as u8) { break }; end = end + 1 }
2294 b[end] = 0 as u8; if end > pos { if b[end-1] == (13 as u8) { b[end-1] = 0 as u8 } }
2295 let line: *u8 = (b as i64 + pos) as *u8; pos = end + 1
2296 if starts(line, "sotatarget|" as *u8) == 1 { m.target_rows = m.target_rows + 1 }
2297 if starts(line, "rungrole|" as *u8) == 1 { m.role_rows = m.role_rows + 1 }
2298 if starts(line, "risk|" as *u8) == 1 { m.risk_rows = m.risk_rows + 1 }
2299 if starts(line, "log|" as *u8) == 1 { m.log_rows = m.log_rows + 1 }
2300 if starts(line, "rung|" as *u8) == 1 {
2301 m.declared = m.declared + 1
2302 let nf: i64 = sg_split(line, f, SGP_FIELDS, 124)
2303 if nf != SGP_FIELDS { m.malformed = m.malformed + 1 } else {
2304 let id: *u8 = f[1] as *u8
2305 if sg_id(id, sg_len(id)) == 0 { m.malformed = m.malformed + 1 } else {
2306 if sg_find(m, id, sg_len(id)) >= 0 { m.duplicate_ids = m.duplicate_ids + 1 } else {
2307 var j: i64 = 0; while j < SGP_FIELDS { m.nodes[m.count*SGP_FIELDS+j] = f[j]; j = j + 1 }
2308 m.count = m.count + 1
2309 }
2310 }
2311 }
2312 }
2313 }
2314 var node: i64 = 0
2315 while node < m.count {
2316 let deps: *u8 = m.nodes[node*SGP_FIELDS+7] as *u8
2317 if streq(deps, "-" as *u8) == 0 {
2318 var start: i64 = 0; var at: i64 = 0; var more: i64 = 1
2319 while more == 1 {
2320 var delimiter: i64 = 0
2321 if deps[at] == (0 as u8) { more = 0; delimiter = 1 }
2322 if deps[at] == (44 as u8) { delimiter = 1 }
2323 if delimiter == 1 {
2324 let length: i64 = at - start
2325 let name: *u8 = (deps as i64 + start) as *u8
2326 if sg_id(name, length) == 0 { m.malformed = m.malformed + 1 } else {
2327 let dep: i64 = sg_find(m, name, length)
2328 if dep < 0 { m.missing_deps = m.missing_deps + 1 } else {
2329 var duplicate: i64 = 0; var e: i64 = 0
2330 while e < m.edge_count { if m.edges[e*2] == dep { if m.edges[e*2+1] == node { duplicate = 1 } }; e = e + 1 }
2331 if duplicate == 1 { m.duplicate_edges = m.duplicate_edges + 1 } else {
2332 m.edges[m.edge_count*2] = dep; m.edges[m.edge_count*2+1] = node; m.edge_count = m.edge_count + 1
2333 }
2334 }
2335 }
2336 start = at + 1
2337 }
2338 at = at + 1
2339 }
2340 }
2341 node = node + 1
2342 }
2343 let degree: *i64 = sys_mmap((m.count+1)*8) as *i64
2344 let visited: *i64 = sys_mmap((m.count+1)*8) as *i64
2345 if (degree as i64) <= 0 { m.malformed = 1; return m }
2346 if (visited as i64) <= 0 { m.malformed = 1; return m }
2347 var e: i64 = 0; while e < m.edge_count { let to: i64 = m.edges[e*2+1]; degree[to] = degree[to] + 1; e = e + 1 }
2348 var removed: i64 = 0; var progress: i64 = 1
2349 while progress == 1 {
2350 progress = 0; var i: i64 = 0
2351 while i < m.count {
2352 if visited[i] == 0 { if degree[i] == 0 {
2353 visited[i] = 1; removed = removed + 1; progress = 1
2354 var j: i64 = 0; while j < m.edge_count { if m.edges[j*2] == i { let to: i64 = m.edges[j*2+1]; degree[to] = degree[to] - 1 }; j = j + 1 }
2355 } }
2356 i = i + 1
2357 }
2358 }
2359 m.cyclic_nodes = m.count - removed
2360 sg_rank(m, rank, rn)
2361 return m
2362}
2363func sg_valid(m: *SgPlan) -> i64 {
2364 if (m as i64) <= 0 { return 0 }
2365 if m.malformed + m.duplicate_ids + m.duplicate_edges + m.missing_deps + m.cyclic_nodes != 0 { return 0 }
2366 return 1
2367}
2368func sg_rank_state(m: *SgPlan) -> *u8 {
2369 if m.rank_bytes <= 0 { return "UNAVAILABLE" as *u8 }
2370 if m.rank_count != m.declared { return "STALE_INCONSISTENT" as *u8 }
2371 if m.rank_mismatches > 0 { return "STALE_INCONSISTENT" as *u8 }
2372 if m.binding_rows > 1 { return "INVALID_BINDING" as *u8 }
2373 if m.binding_rows == 1 { if m.binding_ok == 0 { return "STALE_OR_INVALID_BINDING" as *u8 } }
2374 if m.binding_ok == 1 { return "PLAN_MATRIX_BOUND_ONLY" as *u8 }
2375 return "UNBOUND" as *u8
2376}
2377func sg_load(domain: *u8) -> *SgPlan {
2378 let path: *u8 = sys_mmap(SGP_PATH_CAP)
2379 if (path as i64) <= 0 { return 0 as *SgPlan }
2380 let prefix: *u8 = "knowledge/compare/" as *u8
2381 let dn: i64 = sg_len(domain)
2382 if dn + sg_len(prefix) + sg_len(".matrix") + 1 > SGP_PATH_CAP { return 0 as *SgPlan }
2383 if sg_id(domain, dn) == 0 { return 0 as *SgPlan }
2384 let base: i64 = scopy(path, 0, prefix)
2385 let tail: i64 = scopy(path, base, domain)
2386 let plen: *i64 = sys_mmap(16) as *i64; let rlen: *i64 = sys_mmap(16) as *i64; let mlen: *i64 = sys_mmap(16) as *i64
2387 if (plen as i64) <= 0 { return 0 as *SgPlan }; if (rlen as i64) <= 0 { return 0 as *SgPlan }; if (mlen as i64) <= 0 { return 0 as *SgPlan }
2388 var end: i64 = scopy(path, tail, ".plan" as *u8); path[end] = 0 as u8
2389 let p: *u8 = sys_read_file(path, plen)
2390 if (p as i64) == 0 { return 0 as *SgPlan }
2391 end = scopy(path, tail, ".rank" as *u8); path[end] = 0 as u8
2392 let r: *u8 = sys_read_file(path, rlen)
2393 if (r as i64) == 0 { rlen[0] = 0 }
2394 end = scopy(path, tail, ".matrix" as *u8); path[end] = 0 as u8
2395 let x: *u8 = sys_read_file(path, mlen)
2396 if (x as i64) == 0 { mlen[0] = 0 }
2397 return sg_parse(p, plen[0], r, rlen[0], x, mlen[0])
2398}
2399func sg_json(m: *SgPlan, fd: i64) -> i64 {
2400 w(fd, ",\"ladder\":{\"v\":1,\"availability\":" as *u8)
2401 if (m as i64) == 0 { w(fd, "\"UNAVAILABLE\"}" as *u8); return 0 }
2402 w(fd, "\"CAPTURED\"," as *u8); kv_s(fd, "plan_sha256" as *u8, m.plan_sha); wc(fd, 44); kv_n(fd, "plan_bytes" as *u8, m.plan_bytes)
2403 wc(fd, 44); kv_s(fd, "matrix_sha256" as *u8, m.matrix_sha); wc(fd, 44); kv_n(fd, "matrix_bytes" as *u8, m.matrix_bytes)
2404 wc(fd, 44); kv_s(fd, "rank_sha256" as *u8, m.rank_sha); wc(fd, 44); kv_n(fd, "rank_bytes" as *u8, m.rank_bytes)
2405 wc(fd, 44); kv_s(fd, "rank_binding" as *u8, sg_rank_state(m)); wc(fd, 44); kv_n(fd, "rank_declared_nodes" as *u8, m.rank_count)
2406 wc(fd, 44); kv_n(fd, "rank_symbol_or_shape_errors" as *u8, m.rank_mismatches)
2407 wc(fd, 44); kv_n(fd, "declared_nodes" as *u8, m.declared); wc(fd, 44); kv_n(fd, "parsed_nodes" as *u8, m.count)
2408 wc(fd, 44); kv_n(fd, "declared_graph_valid" as *u8, sg_valid(m))
2409 wc(fd, 44); kv_n(fd, "malformed" as *u8, m.malformed); wc(fd, 44); kv_n(fd, "duplicate_ids" as *u8, m.duplicate_ids)
2410 wc(fd, 44); kv_n(fd, "duplicate_dependencies" as *u8, m.duplicate_edges); wc(fd, 44); kv_n(fd, "missing_dependencies" as *u8, m.missing_deps)
2411 wc(fd, 44); kv_n(fd, "cyclic_or_cycle_dependent_nodes" as *u8, m.cyclic_nodes)
2412 wc(fd, 44); kv_n(fd, "target_rows" as *u8, m.target_rows); wc(fd, 44); kv_n(fd, "role_rows" as *u8, m.role_rows)
2413 wc(fd, 44); kv_n(fd, "unprojected_risk_rows" as *u8, m.risk_rows); wc(fd, 44); kv_n(fd, "worklog_rows" as *u8, m.log_rows)
2414 w(fd, ",\"defaults\":{\"implementation\":\"UNKNOWN\",\"verification\":\"UNVERIFIED\",\"eligibility\":\"UNVERIFIED\",\"target_binding\":\"UNVERIFIED\",\"responsible\":null,\"accountable\":null,\"verifier\":null},\"eligible_now\":[],\"eligible_set_complete\":false,\"recommended\":[],\"recommendation_state\":\"WITHHELD\",\"changed_since_supported\":false,\"next_cursor\":null,\"nodes\":[" as *u8)
2415 if sg_valid(m) == 1 {
2416 var i: i64 = 0
2417 while i < m.count {
2418 if i > 0 { wc(fd, 44) }; wc(fd, 123)
2419 kv_s(fd, "id" as *u8, m.nodes[i*SGP_FIELDS+1] as *u8); wc(fd, 44); kv_s(fd, "title" as *u8, m.nodes[i*SGP_FIELDS+2] as *u8)
2420 wc(fd, 44); kv_s(fd, "contract_symbol" as *u8, m.nodes[i*SGP_FIELDS+3] as *u8)
2421 wc(fd, 44); kv_s(fd, "acceptance_authored" as *u8, m.nodes[i*SGP_FIELDS+4] as *u8)
2422 wc(fd, 44); kv_s(fd, "executor_kind_authored" as *u8, m.nodes[i*SGP_FIELDS+5] as *u8)
2423 wc(fd, 44); kv_s(fd, "effort_authored" as *u8, m.nodes[i*SGP_FIELDS+6] as *u8)
2424 w(fd, ",\"forecast\":false,\"prerequisites\":[" as *u8)
2425 var e: i64 = 0; var shown: i64 = 0
2426 while e < m.edge_count {
2427 if m.edges[e*2+1] == i { if shown > 0 { wc(fd, 44) }; let from: i64 = m.edges[e*2]; wq(fd); wj(fd, m.nodes[from*SGP_FIELDS+1] as *u8); wq(fd); shown = shown + 1 }
2428 e = e + 1
2429 }
2430 w(fd, "]}" as *u8); i = i + 1
2431 }
2432 }
2433 w(fd, "]}" as *u8); return 0
2434}
2435// Literal authored fields use the existing text escaper; citation expansion is not needed here.
2436func sg_text(fd: i64, s: *u8) -> i64 {
2437 let n: i64 = sg_len(s)
2438 if n > (SGP_I64_MAX - IA_SEP_AND_NUL) / IA_MAX_EXPANSION - 1 { w(fd, "[text unavailable]" as *u8); return 0 }
2439 let cap: i64 = (n + 1) * IA_MAX_EXPANSION + IA_SEP_AND_NUL
2440 let out: *u8 = sys_mmap(cap); let cut: *i64 = sys_mmap(8) as *i64
2441 if (out as i64) <= 0 { w(fd, "[text unavailable]" as *u8); return 0 }
2442 if (cut as i64) <= 0 { w(fd, "[text unavailable]" as *u8); return 0 }
2443 let written: i64 = ia_esc_text(out, 0, s, cap, cut)
2444 if cut[0] != 0 { w(fd, "[text unavailable]" as *u8); return 0 }
2445 w(fd, out); return written
2446}
2447func sg_html(m: *SgPlan, fd: i64) -> i64 {
2448 w(fd, "<section class='ladder-model' aria-label='Declared prerequisite paths'><h2>Inspect a rung and its prerequisites</h2>" as *u8)
2449 if (m as i64) == 0 { w(fd, "<p>Plan unavailable; no path or eligibility can be established.</p></section>" as *u8); return 0 }
2450 w(fd, "<p>Declared nodes " as *u8); wn(fd, m.declared); w(fd, ". Rank input binding: <b>" as *u8); w(fd, sg_rank_state(m))
2451 w(fd, "</b>. Dependency order is authored. Implementation, acceptance evidence, authority and resource readiness are unverified. No action is recommended or dispatched here.</p><p>Plan SHA-256 <code>" as *u8); w(fd, m.plan_sha); w(fd, "</code>. Target rows " as *u8); wn(fd, m.target_rows)
2452 w(fd, "; role rows " as *u8); wn(fd, m.role_rows); w(fd, ". Existing risks and release worklog retain their own scope; no node completion is inferred.</p>" as *u8)
2453 if sg_valid(m) == 0 {
2454 w(fd, "<p><b>Invalid declared graph.</b> Malformed rows or IDs " as *u8); wn(fd, m.malformed); w(fd, "; duplicate IDs " as *u8); wn(fd, m.duplicate_ids)
2455 w(fd, "; duplicate prerequisites " as *u8); wn(fd, m.duplicate_edges); w(fd, "; missing prerequisites " as *u8); wn(fd, m.missing_deps)
2456 w(fd, "; cyclic or cycle-dependent nodes " as *u8); wn(fd, m.cyclic_nodes); w(fd, ". Node paths withheld.</p></section>" as *u8); return 0
2457 }
2458 w(fd, "<p>Use Enter or Space on a rung to inspect its contract. Prerequisite links locate another rung in this list; open its summary to inspect it. Estimates are authored effort, not forecasts.</p><ol class='ladder-nodes'>" as *u8)
2459 var i: i64 = 0
2460 while i < m.count {
2461 let id: *u8 = m.nodes[i*SGP_FIELDS+1] as *u8
2462 w(fd, "<li><details id='ladder-node-" as *u8); w(fd, id); w(fd, "'><summary>" as *u8); w(fd, id); w(fd, " — " as *u8); sg_text(fd, m.nodes[i*SGP_FIELDS+2] as *u8)
2463 w(fd, "</summary><p><b>Prerequisites:</b> " as *u8)
2464 var e: i64 = 0; var shown: i64 = 0
2465 while e < m.edge_count {
2466 if m.edges[e*2+1] == i {
2467 let from: i64 = m.edges[e*2]; let dep: *u8 = m.nodes[from*SGP_FIELDS+1] as *u8
2468 if shown > 0 { w(fd, ", " as *u8) }; w(fd, "<a href='#ladder-node-" as *u8); w(fd, dep); w(fd, "'>" as *u8); w(fd, dep); w(fd, "</a> (acceptance unverified)" as *u8); shown = shown + 1
2469 }; e = e + 1
2470 }
2471 if shown == 0 { w(fd, "None declared; this does not establish execution eligibility." as *u8) }
2472 w(fd, "</p><p><b>Contract:</b> <code>" as *u8); sg_text(fd, m.nodes[i*SGP_FIELDS+3] as *u8); w(fd, "</code></p><p><b>Acceptance:</b> " as *u8); sg_text(fd, m.nodes[i*SGP_FIELDS+4] as *u8)
2473 w(fd, "</p><p><b>Authored effort:</b> " as *u8); sg_text(fd, m.nodes[i*SGP_FIELDS+6] as *u8); w(fd, ". <b>Executor kind:</b> " as *u8); sg_text(fd, m.nodes[i*SGP_FIELDS+5] as *u8)
2474 w(fd, ". Responsible, accountable and verifier not established. <a href='#worklog'>Inspect retained worklog</a>.</p></details></li>" as *u8); i = i + 1
2475 }
2476 w(fd, "</ol></section>" as *u8); return 0
2477}
2478func sg_css(fd: i64) -> i64 {
2479 w(fd, ".ladder-model{min-width:0}.ladder-model p{max-width:var(--nx-layout-measure)}.ladder-model code{overflow-wrap:anywhere}.ladder-nodes{display:grid;grid-template-columns:repeat(auto-fill,minmax(min(100%,var(--nx-layout-capmin)),1fr));gap:var(--nx-layout-capgap);padding-inline-start:1.5em}.ladder-nodes li{min-width:0}.ladder-nodes details{display:block}.ladder-nodes summary{display:list-item;cursor:pointer;list-style:revert;font-size:1rem;line-height:1.5}.ladder-nodes summary::after{content:none}.ladder-nodes summary:focus-visible,.ladder-nodes a:focus-visible{outline:3px solid var(--ac);outline-offset:2px}.ladder-nodes details:target{outline:2px solid var(--ac);outline-offset:4px}\n" as *u8)
2480 return 0
2481}