nx_swcompare_release_candidate.nx source
↩ module page · 2103 lines · 141288 B
1// AUTO-EXTRACTED shared base (nx_oo_extract). license_tier: ORIGINAL No hw writes (Rule 26).
2// functions: w,wc,wn,wj,wq,kv_s,kv_n,c_read,streq,starts,scopy,splitpipe,wnote,rp_base,rp_publish,rp_json,refs_pass
3import "nx_syscalls.nx"
4import "nx_symdecl_lib.nx"
5import "nx_market_ladder_lib.nx"
6import "nx_brand_tokens.nx" // the estate's design-token SSOT -- sc_theme_pass composes it, never a second parser
7import "nx_lineconf_lib.nx" // line-anchored conf reader, ONE owner -- never a private key=value parser
8import "nx_estate_path.nx" // THE ONE probe order for a status artifact -- a stamp written from the serving root must resolve from CWD=buildroot (gauge_pass, gaps_pass)
9import "nx_imgattr_lib.nx" // the ONE definition of how an attribute value and an img tag are written
10import "nx_evprofile_lib.nx" // THE ONE READER of the /compare evidence stamp -- evj_pass below PROJECTS
11import "nx_bench_receipt_lib.nx" // THE ONE READER of a <dom>.bench benchmark receipt -- bench_pass below RENDERS it (2026-09-01)
12import "nx_barfresh_lib.nx" // THE ONE bar-age ruler (2026-09-06) -- plan_pass renders each sotatarget with its sotabar month and freshness state
13import "nx_ladder_lib.nx" // THE ONE ladder ruler (2026-09-06) -- plan_pass renders the targets, the rung-role table and the NOT DECLARED notice
14import "nx_gauge_lib.nx" // THE ONE gauge-heartbeat ruler (codeeffectiveness CE9, 2026-09-06) -- gauge_pass below RENDERS a <dom>.gauge row with the SAME classifier the writing beat uses, so a stale gauge reads STALE and never zero
15 // it into api.json. Its closure adds NOTHING new to this lib: nx_lineconf_lib
16 // above already imports nx_estate_path, and nx_swcompare_matrix already
17 // imports both this base AND nx_evprofile_lib and compiles, so the two
18 // symbol sets are proven compatible rather than assumed so.
19func w(fd: i64, s: *u8) -> i64 { var n: i64 = 0; while s[n] != (0 as u8) { n = n + 1 } sys_write(fd, s, n); return 0 }
20func wc(fd: i64, code: i64) -> i64 { let t: *u8 = sys_mmap(2); t[0] = code as u8; sys_write(fd, t, 1); return 0 }
21func wn(fd: i64, v: i64) -> i64 {
22 var m: i64 = v; if m < 0 { w(fd, "-" as *u8); m = 0 - m }
23 let t: *u8 = sys_mmap(24); var k: i64 = 0; if m == 0 { t[0] = 48 as u8; k = 1 }
24 while m > 0 { t[k] = (48 + (m % 10)) as u8; m = m / 10; k = k + 1 }
25 let o: *u8 = sys_mmap(24); var i: i64 = 0; while i < k { o[i] = t[k-1-i]; i = i + 1 } sys_write(fd, o, k); return 0
26}
27func wj(fd: i64, s: *u8) -> i64 {
28 var i: i64 = 0
29 while s[i] != (0 as u8) { let c: i64 = s[i] as i64
30 if c == 34 { wc(fd, 92); wc(fd, 34) } else { if c == 92 { wc(fd, 92); wc(fd, 92) } else { if c < 32 { wc(fd, 32) } else { wc(fd, c) } } }
31 i = i + 1 }
32 return 0
33}
34func wq(fd: i64) -> i64 { wc(fd, 34); return 0 }
35func kv_s(fd: i64, key: *u8, val: *u8) -> i64 { wq(fd); w(fd, key); wq(fd); wc(fd, 58); wq(fd); wj(fd, val); wq(fd); return 0 }
36func kv_n(fd: i64, key: *u8, v: i64) -> i64 { wq(fd); w(fd, key); wq(fd); wc(fd, 58); wn(fd, v); return 0 }
37func c_read(path: *u8, buf: *u8, cap: i64) -> i64 {
38 let fd: i64 = sys_openat_rd(path); if fd < 0 { return 0 - 1 }
39 var tot: i64 = 0
40 while tot < cap { let r: i64 = sys_read(fd, (buf as i64 + tot) as *u8, cap - tot); if r <= 0 { break } tot = tot + r }
41 sys_close(fd); return tot
42}
43func streq(a: *u8, b: *u8) -> i64 { var i: i64 = 0; while a[i] != (0 as u8) { if a[i] != b[i] { return 0 } i = i + 1 } if b[i] != (0 as u8) { return 0 } return 1 }
44func starts(s: *u8, pfx: *u8) -> i64 { var i: i64 = 0; while pfx[i] != (0 as u8) { if s[i] != pfx[i] { return 0 } i = i + 1 } return 1 }
45func scopy(dst: *u8, doff: i64, src: *u8) -> i64 { var i: i64 = 0; while src[i] != (0 as u8) { dst[doff+i] = src[i]; i = i + 1 } return doff + i }
46func splitpipe(s: *u8, fld: *i64, maxf: i64) -> i64 {
47 var c: i64 = 1; fld[0] = s as i64; var i: i64 = 0
48 while s[i] != (0 as u8) { if s[i] == (124 as u8) { s[i] = 0 as u8; if c < maxf { fld[c] = (s as i64) + i + 1; c = c + 1 } } i = i + 1 }
49 return c
50}
51func wnote(fd: i64, s: *u8) -> i64 {
52 var i: i64 = 0
53 while s[i] != (0 as u8) {
54 var emitted: i64 = 0
55 if s[i] == (91 as u8) { if s[i+1] == (64 as u8) {
56 var kl: i64 = 0
57 while s[i+2+kl] != (0 as u8) { if s[i+2+kl] == (93 as u8) { break } kl = kl + 1 }
58 if s[i+2+kl] == (93 as u8) { if kl > 0 {
59 w(fd, "<a class='cite' href='" as *u8); wc(fd, 35); w(fd, "ref-" as *u8)
60 var q: i64 = 0
61 while q < kl { wc(fd, s[i+2+q] as i64); q = q + 1 }
62 w(fd, "'>[" as *u8)
63 q = 0
64 while q < kl { wc(fd, s[i+2+q] as i64); q = q + 1 }
65 w(fd, "]</a>" as *u8)
66 i = i + 2 + kl + 1
67 emitted = 1
68 } }
69 } }
70 // ESCAPE THE TAG DELIMITERS, AND DELIBERATELY NOT '&'. Note prose is PROSE, so a '<' in it must
71 // render as TEXT: emitted raw it injects a live element into the published page. MEASURED
72 // 2026-08-26 -- a browser note reading "an <img> is an INLINE_BLOCK" emitted a real empty <img>,
73 // which took that page to a11y-issues=1 and made its whole-page asset claim UNPROVABLE, because
74 // the verifier counted an img tag whose src it could never resolve. One funnel, so both
75 // generators and every domain are fixed at once.
76 // '&' IS LEFT ALONE ON PURPOSE: 48 notes across the fleet (corpus_complete=1) carry intentional
77 // entities such as —, and escaping it would publish those literally on all 48. That is the
78 // imprecision chosen here, named rather than left for the next reader to rediscover.
79 if emitted == 0 {
80 let c: i64 = s[i] as i64
81 if c == 60 { w(fd, "<" as *u8) } else { if c == 62 { w(fd, ">" as *u8) } else { wc(fd, c) } }
82 i = i + 1
83 }
84 }
85 return 0
86}
87// ---- RIVAL-CLAIM PROVENANCE (2026-09-05) ----------------------------------------------------------------
88// Every Yes, Best or Part code in a rival column is a CLAIM about someone else's product, and until this
89// pass those codes were feature-observation reads with nothing behind them: the refs gate proves every
90// declared reference is cited and every mark resolves, but nothing asked whether a row that grades a rival
91// cites anything at all. Measured while evaluating DanceXR against charsim: eleven rows of rival codes typed
92// from a vendor read, zero marks, indistinguishable on the page from a row backed by a pinned mirror.
93// ONE classifier here, read by both generators (the refs_pass precedent), so the split cannot drift:
94// RV_NONE every rival code is 0 -- the row claims nothing about a rival
95// RV_CITED at least one rival code is non-zero AND the note carries a reference mark ( [@key] )
96// RV_UNCITED at least one rival code is non-zero and the note carries no mark: an observation read
97// A mark proves a mirror exists and is pinned (the refs gate's job); it does not prove the mirror SUPPORTS
98// the code -- that residual is stated on the page, never hidden behind the badge.
99const RV_NONE: i64 = 0
100const RV_CITED: i64 = 1
101const RV_UNCITED: i64 = 2
102func rv_code(s: *u8) -> i64 {
103 var v: i64 = 0
104 var any: i64 = 0
105 var i: i64 = 0
106 while s[i] != (0 as u8) { let c: i64 = s[i] as i64; if c >= 48 { if c <= 57 { v = v * 10 + (c - 48); any = 1 } } i = i + 1 }
107 if any == 0 { return 0 }
108 return v
109}
110func rv_note_cited(note: *u8) -> i64 {
111 var i: i64 = 0
112 while note[i] != (0 as u8) { if note[i] == (91 as u8) { if note[i+1] == (64 as u8) { return 1 } } i = i + 1 }
113 return 0
114}
115func rv_class(note: *u8, rf: *i64, rr: i64, stride: i64, ncol: i64) -> i64 {
116 var claims: i64 = 0
117 var cj: i64 = 0
118 while cj < ncol { if rv_code(rf[rr*stride + 4 + cj] as *u8) != 0 { claims = claims + 1 } cj = cj + 1 }
119 if claims == 0 { return RV_NONE }
120 if rv_note_cited(note) == 1 { return RV_CITED }
121 return RV_UNCITED
122}
123// the SOTA dialect grades with letters: B = Best, Y = Yes, ~ = Part are positive claims about a rival; N and blank are not.
124// ONE claim rule per dialect, ONE note rule for both, so the two generators cannot split on what counts as a claim.
125func rv_grade_claims(g: *u8) -> i64 { if g[0] == (66 as u8) { return 1 } if g[0] == (89 as u8) { return 1 } if g[0] == (126 as u8) { return 1 } return 0 }
126func rv_class_grades(note: *u8, rf: *i64, rr: i64, stride: i64, first: i64, count: i64) -> i64 {
127 var claims: i64 = 0
128 var cj: i64 = 0
129 while cj < count { if rv_grade_claims(rf[rr*stride + first + cj] as *u8) == 1 { claims = claims + 1 } cj = cj + 1 }
130 if claims == 0 { return RV_NONE }
131 if rv_note_cited(note) == 1 { return RV_CITED }
132 return RV_UNCITED
133}
134func rv_name(c: i64) -> *u8 {
135 if c == RV_CITED { return "CITED" as *u8 }
136 if c == RV_UNCITED { return "UNCITED" as *u8 }
137 return "NONE" as *u8
138}
139
140func rp_base(p: *u8) -> *u8 {
141 var i: i64 = 0
142 var last: i64 = 0
143 while p[i] != (0 as u8) { if p[i] == (47 as u8) { last = i + 1 } i = i + 1 }
144 return ((p as i64) + last) as *u8
145}
146func rp_publish(mir: *u8, dom: *u8) -> i64 {
147 let src: *u8 = sys_mmap(700)
148 var so: i64 = scopy(src, 0, "../" as *u8)
149 so = scopy(src, so, mir); src[so] = 0 as u8
150 let ln: *i64 = sys_mmap(16) as *i64
151 let body: *u8 = sys_read_file(src, ln)
152 if (body as i64) == 0 { return 0 }
153 if ln[0] <= 0 { return 0 }
154 let dir: *u8 = sys_mmap(700)
155 var dd: i64 = scopy(dir, 0, "../sites/nishifamily/compare/" as *u8)
156 dd = scopy(dir, dd, dom); dd = scopy(dir, dd, "/refs" as *u8); dir[dd] = 0 as u8
157 sys_mkdir(dir, MODE_0755)
158 let fin: *u8 = sys_mmap(700)
159 var fo: i64 = scopy(fin, 0, dir); fo = scopy(fin, fo, "/" as *u8); fo = scopy(fin, fo, rp_base(mir)); fin[fo] = 0 as u8
160 let tmp: *u8 = sys_mmap(700)
161 var to2: i64 = scopy(tmp, 0, fin); to2 = scopy(tmp, to2, ".tmp" as *u8); tmp[to2] = 0 as u8
162 let fd: i64 = sys_openat_wr(tmp, MODE_0644)
163 if fd < 0 { sys_free_file(body, ln[0]); return 0 }
164 let wrote: i64 = sys_write(fd, body, ln[0])
165 sys_close(fd)
166 sys_free_file(body, ln[0])
167 if wrote != ln[0] { return 0 }
168 if sys_renameat(tmp, fin) < 0 { return 0 }
169 return 1
170}
171
172// ---- THE REDISTRIBUTION GATE, ADDED 2026-08-25 ----
173// rp_publish above copies a stored third-party mirror into the PUBLIC docroot, and rp_html then links
174// it as "read in our library". THAT IS REDISTRIBUTION OF SOMEONE ELSE'S WORK, and until today nothing
175// on that path asked whether the licence permits it -- on 80 of the 84 domains carrying a .refs file.
176// The .refs `class` field is a SOURCE-TYPE vocabulary (published-paper, vendor-doc, dataset...), never
177// a rights vocabulary, so it could not have answered the question even in principle.
178//
179// RIGHTS ARE DATA (knowledge/refs_redistribute.conf), never code: clearing a class costs a row edit
180// AFTER someone reads a licence, not a rebuild. The encoding matches nx_licgate_lib and nx_acquire_lib
181// (0 NO / 1 REVIEW / 2 YES) so the three rulers cannot disagree about direction.
182const RP_NO: i64 = 0
183const RP_REVIEW: i64 = 1
184const RP_YES: i64 = 2
185const RP_KEYCAP: i64 = 128
186
187// AN ABSENT ROW IS A REFUSAL, NOT A PERMISSION. lcf_int_of returns LCF_MISS (negative) for a missing
188// key, so a class nobody has adjudicated -- including a brand-new vocabulary word arriving in a future
189// .refs file -- can never show up as an accidental YES. Silence is never permission.
190func rp_may_republish(cls: *u8) -> i64 {
191 let key: *u8 = sys_mmap(RP_KEYCAP)
192 var k: i64 = scopy(key, 0, "class_" as *u8)
193 k = scopy(key, k, cls); key[k] = 0 as u8
194 let v: i64 = lcf_int_of("knowledge/refs_redistribute.conf" as *u8, key)
195 if v < 0 { return RP_NO }
196 if v > RP_YES { return RP_NO }
197 return v
198}
199
200// THE GATE IN FRONT OF THE COPIER.
201// arm=0 (today) is MEASURE-ONLY: behaviour is byte-identical to before, so no published page changes
202// and no link disappears. That is the ONLY way to land this without silently stripping a link from 80
203// domains in a single regen. arm=1 ENFORCES, and flipping it is an OPERATOR decision about a public
204// surface -- the conf says so in its own words.
205// A missing or non-numeric arm row reads LCF_MISS (negative), which is not 1, so a corrupted conf
206// fails toward TODAY'S behaviour rather than toward an unannounced fleet-wide link removal. That is
207// deliberately the opposite default from rp_may_republish: an unreadable POLICY must not silently
208// change a public surface, while an unadjudicated CLASS must never grant a right.
209func rp_publish_gated(mir: *u8, dom: *u8, cls: *u8) -> i64 {
210 let arm: i64 = lcf_int_of("knowledge/refs_redistribute.conf" as *u8, "arm" as *u8)
211 if arm == 1 {
212 if rp_may_republish(cls) != RP_YES { return 0 }
213 }
214 return rp_publish(mir, dom)
215}
216
217func rp_json(fld: *i64, count: i64) -> i64 {
218 if count == 0 { wc(1, 44); wq(1); w(1, "refs" as *u8); wq(1); wc(1, 58); wc(1, 91) } else { wc(1, 44) }
219 wc(1, 123)
220 kv_s(1, "key" as *u8, fld[1] as *u8); wc(1, 44)
221 kv_s(1, "cite" as *u8, fld[2] as *u8); wc(1, 44)
222 kv_s(1, "url" as *u8, fld[3] as *u8); wc(1, 44)
223 kv_s(1, "mirror" as *u8, fld[4] as *u8); wc(1, 44)
224 kv_s(1, "pin" as *u8, fld[5] as *u8); wc(1, 44)
225 kv_s(1, "accessed" as *u8, fld[6] as *u8); wc(1, 44)
226 kv_s(1, "class" as *u8, fld[7] as *u8); wc(1, 44)
227 kv_s(1, "grounds" as *u8, fld[8] as *u8)
228 wc(1, 125)
229 return 0
230}
231// ---- rp_html LIFTED INTO THE BASE 2026-08-23 (lane L). It was a byte-identical copy in BOTH generators
232// while refs_pass here called it as a dangling callback, so nothing else could import this lib (a gate
233// composing watch_pass failed to link on rp_html). One copy now; the only per-generator difference --
234// the section header prose -- travels as the hdr argument. ----
235func rp_html(fld: *i64, count: i64, dom: *u8, hdr: *u8) -> i64 {
236 if count == 0 { w(1, hdr) }
237 w(1, "<li id='ref-" as *u8); w(1, fld[1] as *u8); w(1, "'><span class='rkey'>[" as *u8); w(1, fld[1] as *u8); w(1, "]</span> " as *u8)
238 w(1, fld[2] as *u8)
239 w(1, " <span class='rlinks'><a href='" as *u8); w(1, fld[3] as *u8); w(1, "'>publisher</a>" as *u8)
240 if streq(fld[4] as *u8, "-" as *u8) == 0 {
241 if rp_publish_gated(fld[4] as *u8, dom, fld[7] as *u8) == 1 {
242 w(1, " · <a href='/compare/" as *u8); w(1, dom); w(1, "/refs/" as *u8); w(1, rp_base(fld[4] as *u8)); w(1, "'><b>read in our library</b></a> <code>" as *u8); w(1, fld[4] as *u8); w(1, "</code>" as *u8)
243 } else {
244 w(1, " · mirror <code>" as *u8); w(1, fld[4] as *u8); w(1, "</code>" as *u8)
245 }
246 }
247 if streq(fld[5] as *u8, "-" as *u8) == 0 { w(1, " · pin <code>" as *u8); w(1, fld[5] as *u8); w(1, "</code>" as *u8) }
248 if streq(fld[6] as *u8, "-" as *u8) == 0 { w(1, " · accessed " as *u8); w(1, fld[6] as *u8) }
249 w(1, " · <span class='rgrade'>" as *u8); w(1, fld[7] as *u8); w(1, "</span></span>" as *u8)
250 w(1, "<span class='rg'>Grounds: " as *u8); w(1, fld[8] as *u8); w(1, "</span></li>\n" as *u8)
251 return 0
252}
253func refs_pass(path: *u8, bufz: *u8, capz: i64, mode: i64, dom: *u8, hdr: *u8) -> i64 {
254 // SAME CAP, SAME REMOVAL (2026-08-28, debt 1787937117): the HTML refs render was called with the
255 // 20479-byte plan buffer while the api.json render got a larger one, so on any board whose .refs
256 // exceeds 20479 the page and the JSON disagreed about how many references exist -- 7 of them
257 // measured, aesthetictwin worst at 37446. Size from the file, never from the caller.
258 var fsz: i64 = 0
259 let szfd: i64 = sys_openat_rd(path)
260 if szfd < 0 { return 0 }
261 fsz = sys_lseek(szfd, 0, 2)
262 sys_close(szfd)
263 if fsz <= 0 { return 0 }
264 let buf: *u8 = sys_mmap(fsz + 1)
265 let n: i64 = c_read(path, buf, fsz)
266 if n <= 0 { return 0 }
267 buf[n] = 0 as u8
268 let fld: *i64 = sys_mmap(200) as *i64
269 var count: i64 = 0
270 var p: i64 = 0
271 while p < n {
272 var e: i64 = p
273 while e < n { if buf[e] == (10 as u8) { break } e = e + 1 }
274 buf[e] = 0 as u8
275 let line: *u8 = (buf as i64 + p) as *u8
276 p = e + 1
277 var skip: i64 = 0
278 if line[0] == (0 as u8) { skip = 1 }
279 if line[0] == (35 as u8) { skip = 1 }
280 if skip == 0 {
281 let nf: i64 = splitpipe(line, fld, 12)
282 if streq(fld[0] as *u8, "ref" as *u8) == 1 { if nf >= 9 {
283 if mode == 1 { rp_html(fld, count, dom, hdr) }
284 if mode == 2 { rp_json(fld, count) }
285 count = count + 1
286 } }
287 }
288 }
289 if count > 0 { if mode == 1 { w(1, "</ol>\n" as *u8) } else { if mode == 2 { wc(1, 93) } } }
290 return count
291}
292
293// ---- PLAN RENDERING, LIFTED INTO THE BASE 2026-08-22 (rung DG5) ------------------------------------
294// WHY THIS MOVED. plan_pass lived INSIDE nx_swcompare_matrix, so a domain whose page is emitted by the
295// SOTA generator had its .plan admitted as data and then NEVER RENDERED. Proven with full coverage
296// (matches=0, files=11, corpus_complete=1): the tool plane's own computed build order was invisible on
297// its own page, which is why nx_compare_rank looked like it had nothing to say there.
298// This follows the refs_pass precedent exactly -- ONE renderer in the base, BOTH generators call it --
299// so the two surfaces cannot drift into two different plan dialects. A second copy in the sota generator
300// would have been the duplicate-ruler defect, and it would have drifted on the first row kind either
301// generator added.
302// dstate and wlow come WITH it, not after it: NishiLang resolves identifiers in TEXTUAL ORDER, so a lib
303// function cannot call a helper defined later in the importing program. A partial lift does not compile.
304const SWL_DSTATE_CAP: i64 = 20480 // .debtstate sidecar read buffer. The NUL slot is DERIVED (CAP - 1)
305 // rather than a second hand-counted constant beside it: two numbers
306 // describing one buffer drift silently and the parser then reads the
307 // wrong window while still compiling.
308
309// Print what the DEBT PLANE says about an id: open, eaten, or not filed in this scope at all. The state
310// file is `id<TAB>state` per line, refreshed by the regen before any page is emitted.
311func dstate(fd: i64, id: *u8, ds: *u8, dn: i64) -> i64 {
312 if dn <= 0 { return 0 }
313 var i: i64 = 0
314 while i < dn {
315 var e: i64 = i
316 while e < dn { if ds[e] == (10 as u8) { break } e = e + 1 }
317 var k: i64 = 0
318 var ok: i64 = 1
319 var stop: i64 = 0
320 while stop == 0 {
321 if i + k >= e { stop = 1 } else {
322 let c: i64 = ds[i+k] as i64
323 if c == 9 { stop = 1 } else {
324 let ic: i64 = id[k] as i64
325 if ic == 0 { ok = 0; stop = 1 } else { if ic != c { ok = 0; stop = 1 } else { k = k + 1 } }
326 }
327 }
328 }
329 if ok == 1 { if (id[k] as i64) == 0 {
330 var s: i64 = i + k
331 if s < e { if ds[s] == (9 as u8) { s = s + 1 } }
332 w(fd, "<span class='pstate'>" as *u8)
333 var q: i64 = s
334 while q < e { wc(fd, ds[q] as i64); q = q + 1 }
335 w(fd, "</span>" as *u8)
336 return 1
337 } }
338 i = e + 1
339 }
340 // NOT "not filed". The lookup is scoped to THIS domain, so a debt filed under another scope is
341 // absent here while being perfectly real in the plane. Saying "not filed" publishes a false negative
342 // about a colleague's open work.
343 w(fd, "<span class='pstate note'>not in this scope</span>" as *u8)
344 return 0
345}
346// lowercase into a search-key attribute; single AND double quotes neutralised so they cannot close it.
347// wlow writes a lowercase SEARCH TOKEN into a single-quoted data- attribute. It already neutralised
348// both quote characters, which is why the gallery's data-t survived the caption apostrophe that
349// destroyed its sibling alt on the same tag -- HALF A LAW, APPLIED IN ONE ATTRIBUTE AND NOT THE OTHER.
350// It still passed the three markup-significant bytes through raw, so the same hole stood open for any
351// caption carrying an ampersand or an angle bracket. It now hands its result to the ONE attribute
352// escaper rather than carrying a second, weaker copy of that decision (2026-08-26).
353// The bare character codes are gone with it: they are the IA_ identities now.
354func wlow(fd: i64, s: *u8) -> i64 {
355 let n: i64 = ia_slen(s)
356 let low: *u8 = sys_mmap(n + 1)
357 var i: i64 = 0
358 while i < n {
359 var c: i64 = s[i] as i64
360 if c >= IA_UPPER_A { if c <= IA_UPPER_Z { c = c + IA_CASE_DELTA } }
361 if c == IA_SQ { c = IA_SP }
362 if c == IA_DQ { c = IA_SP }
363 low[i] = c as u8
364 i = i + 1
365 }
366 low[n] = 0 as u8
367 let need: i64 = n * IA_MAX_EXPANSION + IA_SEP_AND_NUL
368 let b: *u8 = sys_mmap(need)
369 let tr: *i64 = sys_mmap(IA_SLOT_BYTES) as *i64
370 ia_esc_attr(b, 0, low, need, tr)
371 w(fd, b)
372 return 0
373}
374// ---- LADDER TO SOTA helpers (2026-09-06), defined BEFORE plan_pass because NishiLang resolves in textual order ----
375// Both take SPANS precomputed before the walk: plan_pass's walk NUL-terminates lines and splitpipe zeroes pipes in place,
376// so a field re-parsed at render time on an already-walked line would read one truncated field. The bytes of the fields
377// themselves are untouched, so a span captured first is still readable when its consumer row arrives later in the file.
378// the month and freshness state of the sotabar row whose id is `id`, printed after the target's "dated by <id>"
379func swl_bar_state(fd: i64, buf: *u8, bidoff: *i64, bidlen: *i64, bym: *i64, bst: *i64, nb: i64, id: *u8) -> i64 {
380 var i: i64 = 0
381 while i < nb {
382 if ld_span_is(buf, bidoff[i], bidlen[i], id) == 1 {
383 w(fd, " = " as *u8)
384 if bym[i] == BF_NONE { w(fd, "MALFORMED MONTH" as *u8) } else {
385 let ymb: *u8 = sys_mmap(12)
386 bf_ym_write(ymb, 0, bym[i])
387 w(fd, ymb)
388 }
389 w(fd, " " as *u8); w(fd, bf_state_name(bst[i]))
390 return 1
391 }
392 i = i + 1
393 }
394 w(fd, " = NO SUCH SOTABAR ROW, UNDATED" as *u8)
395 return 0
396}
397// the deps field of the rung row whose id is `id` (what the rung stands on), or a dash
398func swl_rung_deps(fd: i64, buf: *u8, ridoff: *i64, ridlen: *i64, rdoff: *i64, rdlen: *i64, nr: i64, id: *u8) -> i64 {
399 var i: i64 = 0
400 while i < nr {
401 if ld_span_is(buf, ridoff[i], ridlen[i], id) == 1 {
402 if rdlen[i] > 0 { sys_write(fd, (buf as i64 + rdoff[i]) as *u8, rdlen[i]) } else { w(fd, "-" as *u8) }
403 return 1
404 }
405 i = i + 1
406 }
407 w(fd, "-" as *u8)
408 return 0
409}
410// A release date comes from a complete positive decimal epoch, never filtered digits.
411const SWL_RELEASE_I64_MAX: i64 = 9223372036854775807
412func swl_release_epoch(s: *u8) -> i64 {
413 if (s as i64) == 0 { return 0 }
414 if s[0] == (0 as u8) { return 0 }
415 var v: i64 = 0
416 var i: i64 = 0
417 while s[i] != (0 as u8) {
418 let c: i64 = s[i] as i64
419 if c < 48 { return 0 }
420 if c > 57 { return 0 }
421 let d: i64 = c - 48
422 if v > (SWL_RELEASE_I64_MAX - d) / 10 { return 0 }
423 v = v * 10 + d
424 i = i + 1
425 }
426 return v
427}
428// Equal timestamps preserve append-order corrections; older rows cannot replace newer ones.
429func swl_release_candidate(epoch: *u8, kind: *u8, entry: *u8, current: i64, now: i64) -> i64 {
430 if (kind as i64) == 0 { return 0 }
431 if (entry as i64) == 0 { return 0 }
432 if entry[0] == (0 as u8) { return 0 }
433 if streq(kind, "land" as *u8) != 1 { return 0 }
434 let candidate: i64 = swl_release_epoch(epoch)
435 if candidate <= 0 { return 0 }
436 if candidate < current { return 0 }
437 if candidate > now { return 0 }
438 return candidate
439}
440
441func plan_pass(path: *u8, bufz: *u8, capz: i64, phase: i64) -> i64 {
442 // THE 20479-BYTE CAP IS REMOVED, NOT RAISED (2026-08-28, debt 1787937117). The caller handed us a
443 // guessed buffer whose cap silently short-read every .plan over 20479 bytes -- 8 of 93 measured,
444 // browser worst at 63614 -- publishing a PREFIX whose lost rows are always the NEWEST, announced
445 // nowhere. A ceiling that has to be guessed is a defect generator in both directions, and for a FILE
446 // read there is no guess to make: size the buffer from the file itself (lseek END), like sys_read_file.
447 // bufz/capz are kept only so every existing call site still compiles; they are deliberately unused.
448 var fsz: i64 = 0
449 let szfd: i64 = sys_openat_rd(path)
450 if szfd < 0 { return 0 }
451 fsz = sys_lseek(szfd, 0, 2)
452 sys_close(szfd)
453 if fsz <= 0 { return 0 }
454 let buf: *u8 = sys_mmap(fsz + 1)
455 let n: i64 = c_read(path, buf, fsz)
456 if n <= 0 { return 0 }
457 buf[n] = 0 as u8
458 let fld: *i64 = sys_mmap(200) as *i64
459 // the plane's view of each debt id, refreshed by the regen before this page was emitted.
460 // Derived from the plan path so the two files cannot drift apart by name.
461 let dsbuf: *u8 = sys_mmap(SWL_DSTATE_CAP)
462 var dsn: i64 = 0
463 if phase == 3 {
464 let dsp: *u8 = sys_mmap(600)
465 var dq: i64 = 0
466 while path[dq] != (0 as u8) { dsp[dq] = path[dq]; dq = dq + 1 }
467 var cut: i64 = dq
468 while cut > 0 { if dsp[cut] == (46 as u8) { break } cut = cut - 1 }
469 if cut > 0 { dq = cut }
470 dq = scopy(dsp, dq, ".debtstate" as *u8)
471 dsp[dq] = 0 as u8
472 dsn = c_read(dsp, dsbuf, SWL_DSTATE_CAP - 1)
473 if dsn < 0 { dsn = 0 }
474 }
475 var in_rung: i64 = 0
476 var in_ms: i64 = 0
477 var in_biz: i64 = 0
478 var in_lad: i64 = 0
479 var in_log: i64 = 0
480 var release_epoch: i64 = 0
481 let release_now: i64 = sys_now_realtime_sec()
482 var release_entry: *u8 = 0 as *u8
483 var release_rung: *u8 = 0 as *u8
484 // LADDER TO SOTA (2026-09-06): classify the sotabar/barscan and sotatarget/rungrole rows ONCE, before the walk below
485 // NUL-terminates lines and zeroes pipes in place, and bank the spans the render helpers read (see swl_bar_state).
486 let bfnb: i64 = bf_count_rows(buf, n, BF_BAR_TAG)
487 let bfoff: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
488 let bfym: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
489 let bfst: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
490 let bfseen: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
491 let bfc: *i64 = sys_mmap(BF_C_N * 8) as *i64
492 let bfcur: i64 = bf_now_ym()
493 bf_classify(buf, n, bfcur, bfoff, bfym, bfst, bfseen, bfc)
494 let bidoff: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
495 let bidlen: *i64 = sys_mmap((bfnb + 1) * 8) as *i64
496 let sfo: *i64 = sys_mmap(8) as *i64
497 var sbi: i64 = 0
498 while sbi < bfnb { let sbe: i64 = bf_line_end(buf, n, bfoff[sbi]); bidlen[sbi] = bf_field(buf, bfoff[sbi], sbe, BF_F_BAR_ID, sfo); bidoff[sbi] = sfo[0]; sbi = sbi + 1 }
499 let ldnt: i64 = bf_count_rows(buf, n, LD_TARGET_TAG)
500 let ldnr: i64 = bf_count_rows(buf, n, LD_RUNG_TAG)
501 let ldc: *i64 = sys_mmap(LD_N_COUNT * 8) as *i64
502 let ldtoff: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
503 let ldtcls: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
504 let ldtst: *i64 = sys_mmap((ldnt + 1) * 8) as *i64
505 let ldroff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
506 let ldrrole: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
507 let ldrtgt: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
508 let ldrst: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
509 ld_classify(buf, n, ldtoff, ldtcls, ldtst, ldroff, ldrrole, ldrtgt, ldrst, ldc)
510 let ldv: i64 = ld_verdict(ldc)
511 let ridoff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
512 let ridlen: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
513 let rdoff: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
514 let rdlen: *i64 = sys_mmap((ldnr + 1) * 8) as *i64
515 var sri: i64 = 0
516 while sri < ldnr { let sre: i64 = bf_line_end(buf, n, ldroff[sri]); ridlen[sri] = bf_field(buf, ldroff[sri], sre, LD_F_R_ID, sfo); ridoff[sri] = sfo[0]; rdlen[sri] = bf_field(buf, ldroff[sri], sre, LD_F_R_DEPS, sfo); rdoff[sri] = sfo[0]; sri = sri + 1 }
517 var in_tgt: i64 = 0
518 var in_role: i64 = 0
519 var p: i64 = 0
520 while p < n {
521 var e: i64 = p
522 while e < n { if buf[e] == (10 as u8) { break } e = e + 1 }
523 buf[e] = 0 as u8
524 let line: *u8 = (buf as i64 + p) as *u8
525 p = e + 1
526 var skip: i64 = 0
527 if line[0] == (0 as u8) { skip = 1 }
528 if line[0] == (35 as u8) { skip = 1 }
529 if skip == 0 {
530 let nf: i64 = splitpipe(line, fld, 20)
531 let kind: *u8 = fld[0] as *u8
532 if phase == 1 {
533 if streq(kind, "log" as *u8) == 1 { if nf == 5 {
534 let candidate: i64 = swl_release_candidate(fld[1] as *u8, fld[3] as *u8, fld[4] as *u8, release_epoch, release_now)
535 if candidate > 0 {
536 release_epoch = candidate
537 release_rung = fld[2] as *u8
538 release_entry = fld[4] as *u8
539 }
540 } }
541 if streq(kind, "pos" as *u8) == 1 { if nf >= 2 { w(1, "<p class='lead'><b>Where we are.</b> " as *u8); wnote(1, fld[1] as *u8); w(1, "</p>\n" as *u8) } }
542 if streq(kind, "goal" as *u8) == 1 { if nf >= 2 { w(1, "<p class='lead'><b>Where we need to go.</b> " as *u8); wnote(1, fld[1] as *u8); w(1, "</p>\n" as *u8) } }
543 if streq(kind, "answer" as *u8) == 1 { if nf >= 4 {
544 w(1, "<div class='answer'><b>" as *u8); w(1, fld[1] as *u8); w(1, ": " as *u8); w(1, fld[2] as *u8); w(1, ".</b> " as *u8); wnote(1, fld[3] as *u8); w(1, "</div>\n" as *u8) } }
545 if streq(kind, "bar" as *u8) == 1 { if nf >= 6 {
546 w(1, "<p class='lead'><b>Research bar.</b> <a href='" as *u8); w(1, fld[2] as *u8); w(1, "'>" as *u8); w(1, fld[1] as *u8); w(1, "</a> is measured on " as *u8); w(1, fld[3] as *u8)
547 w(1, ". Theirs: <b>" as *u8); wnote(1, fld[4] as *u8); w(1, "</b>. Ours: " as *u8); wnote(1, fld[5] as *u8); w(1, ".</p>\n" as *u8) } }
548 if streq(kind, "unit" as *u8) == 1 { if nf >= 2 { w(1, "<div class='meth'><b>The unit.</b> " as *u8); w(1, fld[1] as *u8); w(1, "</div>\n" as *u8) } }
549 // biz|axis|position|figures|decision -- the BUSINESS CASE row kind (investment, opportunity
550 // cost, market, competitive position, go-to-market, buy-vs-build). Rendered as one table in
551 // the executive layer; biz rows belong LAST in a plan's phase-1 block so the table closes clean.
552 if streq(kind, "biz" as *u8) == 1 { if nf >= 5 {
553 if in_biz == 0 { w(1, "<h2>Business case</h2>\n<table class='pl'><thead><tr><th>Axis</th><th>Position</th><th>Figures</th><th>Decision</th></tr></thead><tbody>\n" as *u8); in_biz = 1 }
554 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b></td><td>" as *u8); wnote(1, fld[2] as *u8)
555 w(1, "</td><td class='ct'>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
556 // ladder|level|best_in_class|have|grow|verdict -- the MARKET-ENTRY LADDER row kind (2026-08-24): per level
557 // (hobbyist to research leader) what best-in-class looks like from the mirrored record, what the estate measures
558 // today, what must grow, and the ENTER or HOLD or GROW-FIRST verdict. Rendered as one table after the business
559 // case; ladder rows belong LAST in a plan's phase-1 block. The verdict is DATA here; ml_entry_verdict computes it.
560 if streq(kind, "ladder" as *u8) == 1 { if nf >= 6 {
561 if in_biz == 1 { w(1, "</tbody></table>\n" as *u8); in_biz = 0 }
562 if in_lad == 0 { w(1, "<h2>Market-entry ladder</h2>\n<table class='pl'><thead><tr><th>Level</th><th>Best in class (Aug 2026)</th><th>What we have</th><th>What must grow</th><th>Verdict</th></tr></thead><tbody>\n" as *u8); in_lad = 1 }
563 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b></td><td>" as *u8); wnote(1, fld[2] as *u8)
564 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8)
565 w(1, "</td><td class='ct'>" as *u8); wnote(1, fld[5] as *u8)
566 // the COMPUTED verdict beside the authored one (nx_market_ladder_lib, the one ruler the CLI uses)
567 if nf >= 7 { ml_render_computed_html(1, path, fld[6] as *u8) }
568 w(1, "</td></tr>\n" as *u8) } }
569 }
570 if phase == 3 {
571 if streq(kind, "debt" as *u8) == 1 { if nf >= 5 {
572 if in_rung == 0 { w(1, "<h2>Debt register</h2>\n<table class='pl'><thead><tr><th>Id</th><th class='r'>Sev</th><th>What it is</th><th>Unblock</th></tr></thead><tbody>\n" as *u8); in_rung = 1 }
573 w(1, "<tr><td class='ct'>" as *u8); w(1, fld[1] as *u8)
574 // STATE COMES FROM THE PLANE, NEVER FROM THIS ROW. An id the plane does not know is a
575 // page-local note wearing the shape of a filed debt, and saying so is the honest move.
576 dstate(1, fld[1] as *u8, dsbuf, dsn)
577 w(1, "</td><td class='r'>" as *u8); w(1, fld[2] as *u8)
578 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
579 if streq(kind, "risk" as *u8) == 1 { if nf >= 4 {
580 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
581 if in_ms == 0 { w(1, "<h2>Risk register</h2>\n<table class='pl'><thead><tr><th>Risk</th><th>Likelihood x impact</th><th>Mitigation</th></tr></thead><tbody>\n" as *u8); in_ms = 1 }
582 w(1, "<tr><td>" as *u8); wnote(1, fld[1] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[2] as *u8)
583 w(1, "</td><td>" as *u8); wnote(1, fld[3] as *u8); w(1, "</td></tr>\n" as *u8) } }
584 // log|<epoch>|<rung>|<kind>|<text> -- THE WORKED PLAN ON THE BOARD (operator 2026-09-02: a crash must
585 // leave a ledger here, not a transcript to mine). Every leg appends what it measured, landed,
586 // retracted, learned and left queued, per rung; rendered newest-last, each row linking to its rung.
587 if streq(kind, "log" as *u8) == 1 { if nf >= 5 {
588 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
589 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
590 if in_log == 0 { w(1, "<h2 id='worklog'>Release history and work log</h2>\n<div class='meth'><b>The worked plan, on the board.</b> Every leg appends what it measured, landed, retracted, learned and left queued, per rung, so a crash leaves the next seat a ledger here rather than a transcript to mine. Kinds: measure, land, retract, lesson, queue. Newest last.</div>\n<table class='pl'><thead><tr><th>When</th><th>Rung</th><th>Kind</th><th>Entry</th></tr></thead><tbody>\n" as *u8); in_log = 1 }
591 let lep: *u8 = fld[1] as *u8
592 var lv: i64 = 0
593 var li: i64 = 0
594 while lep[li] != (0 as u8) { let lc: i64 = lep[li] as i64; if lc >= 48 { if lc <= 57 { lv = lv*10 + (lc-48) } } li = li + 1 }
595 let ldb: *u8 = sys_mmap(32)
596 let ldn: i64 = bd_ymd(lv, ldb, 0)
597 ldb[ldn] = 0 as u8
598 w(1, "<tr><td class='ct'>" as *u8); w(1, ldb); w(1, "</td><td class='ct'><a href='#" as *u8); wlow(1, fld[2] as *u8); w(1, "'>" as *u8); w(1, fld[2] as *u8)
599 w(1, "</a></td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
600 }
601 if phase == 2 {
602 if streq(kind, "rung" as *u8) == 1 { if nf >= 8 {
603 if in_rung == 0 { w(1, "<table class='pl'><thead><tr><th>Rung</th><th>Closes with</th><th>Definition of done (pre-declared)</th><th>Executor</th><th class='r'>Est.</th></tr></thead><tbody>\n" as *u8); in_rung = 1 }
604 w(1, "<tr id='" as *u8); wlow(1, fld[1] as *u8); w(1, "'><td><b>" as *u8); w(1, fld[2] as *u8); w(1, "</b> (" as *u8); w(1, fld[1] as *u8); w(1, ")" as *u8)
605 if streq(fld[7] as *u8, "-" as *u8) == 0 { w(1, "<br><span class='ct'>after " as *u8); w(1, fld[7] as *u8); w(1, "</span>" as *u8) }
606 w(1, "</td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8)
607 w(1, "</td><td><span class='ex'>" as *u8); w(1, fld[5] as *u8); w(1, "</span></td><td class='r'>" as *u8); w(1, fld[6] as *u8); w(1, " u</td></tr>\n" as *u8) } }
608 // LADDER TO SOTA (2026-09-06): the dated targets, judged by the bar-age ruler, then the rung-role table.
609 // sotatarget and rungrole rows belong AFTER the rung and ms rows in a plan so the ladder renders beneath them.
610 if streq(kind, "sotatarget" as *u8) == 1 { if nf >= 6 {
611 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
612 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
613 if in_tgt == 0 { w(1, "<h2 id='ladder'>Ladder to SOTA</h2>\n<div class='meth'><b>Two dated targets, and every rung's role toward them.</b> Best in class is the proven, deployed leader today; the frontier is the research edge as of its month. Each target is dated by a sotabar row and judged against the current month by the bar-age ruler (FRESH, ATTESTED with the fallback month named, or refused). Each rung is substrate (what the target's own methods consume), an arm (a sovereign arm that triangulates without competing for the number), a contender (its done-rule is a number against the target) or superseded (kept as capability, retired as a claim), and carries the rungs it stands on.</div>\n" as *u8); in_tgt = 1 }
614 w(1, "<div class='answer'><b>" as *u8); w(1, fld[2] as *u8); w(1, " (" as *u8); w(1, fld[1] as *u8); w(1, "), dated by " as *u8); w(1, fld[3] as *u8)
615 swl_bar_state(1, buf, bidoff, bidlen, bfym, bfst, bfnb, fld[3] as *u8)
616 w(1, ".</b> " as *u8); wnote(1, fld[4] as *u8)
617 w(1, " <span class='ct'>ref " as *u8); w(1, fld[5] as *u8); w(1, "</span></div>\n" as *u8) } }
618 if streq(kind, "rungrole" as *u8) == 1 { if nf >= 5 {
619 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
620 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8); in_ms = 0 }
621 if in_tgt == 0 { w(1, "<h2 id='ladder'>Ladder to SOTA</h2>\n" as *u8); in_tgt = 1 }
622 if in_role == 0 { w(1, "<table class='pl'><thead><tr><th>Rung</th><th>Role</th><th>Toward</th><th>Stands on</th><th>Why</th></tr></thead><tbody>\n" as *u8); in_role = 1 }
623 w(1, "<tr><td class='ct'><a href='#" as *u8); wlow(1, fld[1] as *u8); w(1, "'>" as *u8); w(1, fld[1] as *u8); w(1, "</a></td><td class='ct'>" as *u8); w(1, fld[2] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[3] as *u8); w(1, "</td><td class='ct'>" as *u8)
624 swl_rung_deps(1, buf, ridoff, ridlen, rdoff, rdlen, ldnr, fld[1] as *u8)
625 w(1, "</td><td>" as *u8); wnote(1, fld[4] as *u8); w(1, "</td></tr>\n" as *u8) } }
626 if streq(kind, "ms" as *u8) == 1 { if nf >= 5 {
627 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8); in_rung = 0 }
628 if in_ms == 0 { w(1, "<h2>Milestones</h2>\n<table class='pl'><thead><tr><th>Milestone</th><th>Rungs</th><th class='r'>Cumulative</th></tr></thead><tbody>\n" as *u8); in_ms = 1 }
629 w(1, "<tr><td><b>" as *u8); w(1, fld[1] as *u8); w(1, "</b> · " as *u8); w(1, fld[2] as *u8); w(1, "</td><td class='ct'>" as *u8); w(1, fld[4] as *u8)
630 w(1, "</td><td class='r'>" as *u8); w(1, fld[3] as *u8); w(1, " u</td></tr>\n" as *u8) } }
631 }
632 }
633 }
634 if in_rung == 1 { w(1, "</tbody></table>\n" as *u8) }
635 if in_ms == 1 { w(1, "</tbody></table>\n" as *u8) }
636 if in_biz == 1 { w(1, "</tbody></table>\n" as *u8) }
637 if in_lad == 1 { w(1, "</tbody></table>\n" as *u8) }
638 if in_log == 1 { w(1, "</tbody></table>\n" as *u8) }
639 if in_role == 1 { w(1, "</tbody></table>\n" as *u8) }
640 if phase == 1 {
641 w(1, "<section class='meth' id='release-summary'><h2>Latest recorded release</h2>" as *u8)
642 if release_epoch > 0 {
643 let date: *u8 = sys_mmap(32)
644 let date_len: i64 = bd_ymd(release_epoch, date, 0)
645 date[date_len] = 0 as u8
646 w(1, "<p><b>" as *u8); w(1, date); w(1, "</b> · " as *u8)
647 wnote(1, release_rung); w(1, "</p><p>" as *u8); wnote(1, release_entry)
648 w(1, "</p><p><a href='#worklog'>Release history and work log</a></p>" as *u8)
649 } else {
650 w(1, "<p>No valid dated release entry is recorded for this domain.</p>" as *u8)
651 }
652 w(1, "<p>Release entries describe recorded changes; they do not establish that every capability passed evaluation.</p></section>\n" as *u8)
653 }
654 if phase == 2 {
655 // THE TWO VERDICTS, FROM THE RULERS, ON EVERY PAGE WITH A PLAN (2026-09-06). A board that has not declared its
656 // ladder is TOLD so on its own page: an undeclared target is exactly how a seat climbed toward a 2014 bar for a day.
657 w(1, "<div class='meth' id='ladderverdict'><b>Ladder verdict.</b> " as *u8)
658 if ldv == LD_EXIT_NOLADDER {
659 w(1, "<b>NOT DECLARED.</b> This board names no dated best-in-class or frontier target and no rung roles (sotatarget and rungrole rows on its plan); the ranker labels it NO-LADDER until it does, and until then its rungs climb toward a target nobody has written down." as *u8)
660 } else {
661 w(1, "targets " as *u8); wn(1, ldc[LD_N_TARGETS]); w(1, " (best in class " as *u8); wn(1, ldc[LD_N_BIC]); w(1, ", frontier " as *u8); wn(1, ldc[LD_N_FRONTIER]); w(1, ", undated " as *u8); wn(1, ldc[LD_N_UNDATED])
662 w(1, "); rungs " as *u8); wn(1, ldc[LD_N_RUNGS]); w(1, ", placed " as *u8); wn(1, ldc[LD_N_PLACED]); w(1, " (substrate " as *u8); wn(1, ldc[LD_N_SUBSTRATE]); w(1, ", arm " as *u8); wn(1, ldc[LD_N_ARM]); w(1, ", contender " as *u8); wn(1, ldc[LD_N_CONTENDER]); w(1, ", superseded " as *u8); wn(1, ldc[LD_N_SUPERSEDED]); w(1, "), unplaced " as *u8); wn(1, ldc[LD_N_UNPLACED]); w(1, "; verdict <b>" as *u8); w(1, ld_verdict_name(ldv)); w(1, "</b>" as *u8)
663 if ldv == LD_EXIT_PARTIAL { w(1, " -- half-declared: the ranker refuses this board until every target is dated and every rung has a role" as *u8) }
664 }
665 w(1, " Bars: " as *u8); wn(1, bfc[BF_C_BARS]); w(1, " (fresh " as *u8); wn(1, bfc[BF_C_FRESH]); w(1, ", attested " as *u8); wn(1, bfc[BF_C_ATTESTED]); w(1, ", stale " as *u8); wn(1, bfc[BF_C_STALE]); w(1, ", unattested " as *u8); wn(1, bfc[BF_C_UNATTESTED]); w(1, "), verdict <b>" as *u8); w(1, bf_verdict_name(bf_verdict(bfc))); w(1, "</b> against the current month " as *u8)
666 let cymb: *u8 = sys_mmap(12)
667 bf_ym_write(cymb, 0, bfcur)
668 w(1, cymb); w(1, ".</div>\n" as *u8)
669 }
670 return 1
671}
672// ---- WATCH CONTRACTS, MEASURED, FOR EVERY PAGE KIND (2026-08-23, lane L) ----
673// A sota-class page renders <dom>.sota (hand-graded cells) while the ranker reads <dom>.matrix, so a
674// sota domain that also carries a .matrix NEVER FLIPPED on the page when a watch symbol landed
675// (measured on /compare/lang: LN2 landed, the regen republished the page at an IDENTICAL byte size).
676// watch_pass renders the .matrix's symbol rows with their status MEASURED by the one ruler
677// (nx_symdecl_lib sd_declared) -- the same function the matrix generator, the ranker and the regen's
678// comparewatch plane use -- so the page, the plane and the ranker cannot disagree by construction.
679// Writes to fd (a gate captures it through a file), mode 1 = HTML section, mode 2 = JSON array value.
680// An absent .matrix writes NOTHING and returns 0 (a byte-identical emit for every domain without one).
681// Returns the number of symbol rows rendered; the partition it prints must sum to that number.
682const WP_ST_LANDED: i64 = 1
683const WP_ST_WATCHING: i64 = 2
684const WP_ST_PRESENT: i64 = 3
685const WP_ST_MISSING: i64 = 4
686const WP_ST_ABSENT: i64 = 5
687func wp_status_text(st: i64) -> *u8 {
688 if st == WP_ST_LANDED { return "LANDED" as *u8 }
689 if st == WP_ST_WATCHING { return "WATCHING" as *u8 }
690 if st == WP_ST_PRESENT { return "PRESENT" as *u8 }
691 if st == WP_ST_MISSING { return "MISSING" as *u8 }
692 return "ABSENT" as *u8
693}
694func wp_status_class(st: i64) -> *u8 {
695 if st == WP_ST_LANDED { return "me" as *u8 }
696 if st == WP_ST_PRESENT { return "me" as *u8 }
697 if st == WP_ST_WATCHING { return "pa" as *u8 }
698 return "ab" as *u8
699}
700// classify ONE matrix row: organ + symbol field -> status. Measured, never read from the spelling.
701func wp_classify(organ: *u8, sym: *u8, rule_out: *i64) -> i64 {
702 rule_out[0] = 0
703 if streq(sym, "_ABSENT_" as *u8) == 1 { return WP_ST_ABSENT }
704 if starts(sym, "_ABSENT_:" as *u8) == 1 {
705 if sd_present(organ, (sym as i64 + 9) as *u8, rule_out) == 1 { return WP_ST_LANDED }
706 return WP_ST_WATCHING
707 }
708 if sd_present(organ, sym, rule_out) == 1 { return WP_ST_PRESENT }
709 return WP_ST_MISSING
710}
711func watch_pass(mpath: *u8, fd: i64, mode: i64) -> i64 {
712 let ln: *i64 = sys_mmap(16) as *i64
713 let b: *u8 = sys_read_file(mpath, ln)
714 if (b as i64) == 0 { return 0 }
715 let n: i64 = ln[0]
716 if n <= 0 { if mode == 2 { wc(fd, 91); wc(fd, 93) } return 0 }
717 // field capacity derived from the widest row (pipes + 1), never a fixed count
718 var maxf: i64 = 2
719 var pc: i64 = 0
720 var i: i64 = 0
721 while i < n { if b[i] == (124 as u8) { pc = pc + 1 } if b[i] == (10 as u8) { if pc + 1 > maxf { maxf = pc + 1 } pc = 0 } i = i + 1 }
722 if pc + 1 > maxf { maxf = pc + 1 }
723 let fld: *i64 = sys_mmap((maxf + 1) * 8) as *i64
724 let rl: *i64 = sys_mmap(16) as *i64
725 var rows: i64 = 0
726 var c_landed: i64 = 0
727 var c_watching: i64 = 0
728 var c_present: i64 = 0
729 var c_missing: i64 = 0
730 var c_absent: i64 = 0
731 var opened: i64 = 0
732 var p: i64 = 0
733 while p < n {
734 var e: i64 = p
735 while e < n { if b[e] == (10 as u8) { break } e = e + 1 }
736 b[e] = 0 as u8
737 let line: *u8 = (b as i64 + p) as *u8
738 p = e + 1
739 var skip: i64 = 0
740 if line[0] == (0 as u8) { skip = 1 }
741 if line[0] == (35 as u8) { skip = 1 }
742 if line[0] == (64 as u8) { skip = 1 }
743 if skip == 0 {
744 let nf: i64 = splitpipe(line, fld, maxf)
745 if nf >= 4 {
746 let label: *u8 = fld[0] as *u8
747 let organ: *u8 = fld[1] as *u8
748 let sym: *u8 = fld[2] as *u8
749 let note: *u8 = fld[nf - 1] as *u8
750 if sym[0] != (0 as u8) {
751 let st: i64 = wp_classify(organ, sym, rl)
752 if st == WP_ST_LANDED { c_landed = c_landed + 1 }
753 if st == WP_ST_WATCHING { c_watching = c_watching + 1 }
754 if st == WP_ST_PRESENT { c_present = c_present + 1 }
755 if st == WP_ST_MISSING { c_missing = c_missing + 1 }
756 if st == WP_ST_ABSENT { c_absent = c_absent + 1 }
757 var symtext: *u8 = sym
758 if starts(sym, "_ABSENT_:" as *u8) == 1 { symtext = (sym as i64 + 9) as *u8 }
759 if mode == 1 {
760 if opened == 0 {
761 w(fd, "<h2 class='ghead' id='watch'>Watch contracts (measured)</h2>\n<div class='meth'><b>Not a claim, a measurement.</b> Each row names an organ and a symbol; the status is re-measured on every publish by the one ruler the ranker and the hive plane use, and the rule it applied is printed beside it: <b>decl</b> a top-level declaration in a NishiLang organ (a comment or a call site does not count), <b>jsdecl</b> a JS declaration form, <b>exists</b> the organ itself (the symbol is its name), <b>marker</b> a literal the organ carries, <b>data</b> a token in a data file. LANDED / PRESENT = measured present, WATCHING = the named contract is still open, MISSING = the row names something its organ does not carry, ABSENT = no contract named.</div>\n<table class='pl'><thead><tr><th>Axis</th><th>Organ</th><th>Symbol</th><th>Status</th><th>Note</th></tr></thead><tbody>\n" as *u8)
762 opened = 1
763 }
764 w(fd, "<tr><td><b>" as *u8); w(fd, label); w(fd, "</b></td><td class='ct'>" as *u8); w(fd, organ)
765 w(fd, "</td><td class='ct'>" as *u8); w(fd, symtext); w(fd, "</td><td><span class='st " as *u8); w(fd, wp_status_class(st)); w(fd, "'>" as *u8); w(fd, wp_status_text(st))
766 w(fd, "</span>" as *u8)
767 if rl[0] > 0 { w(fd, " <span class='ct'>" as *u8); w(fd, sd_rule_name(rl[0])); w(fd, "</span>" as *u8) }
768 w(fd, "</td><td>" as *u8); wnote(fd, note); w(fd, "</td></tr>\n" as *u8)
769 }
770 if mode == 2 {
771 if opened == 0 { wc(fd, 91); opened = 1 } else { wc(fd, 44) }
772 wc(fd, 123)
773 kv_s(fd, "label" as *u8, label); wc(fd, 44)
774 kv_s(fd, "organ" as *u8, organ); wc(fd, 44)
775 kv_s(fd, "symbol" as *u8, symtext); wc(fd, 44)
776 kv_s(fd, "status" as *u8, wp_status_text(st)); wc(fd, 44)
777 kv_s(fd, "rule" as *u8, sd_rule_name(rl[0])); wc(fd, 44)
778 kv_s(fd, "note" as *u8, note)
779 wc(fd, 125)
780 }
781 rows = rows + 1
782 }
783 }
784 }
785 }
786 if mode == 1 { if opened == 1 {
787 w(fd, "</tbody></table>\n<p class='foot'>watch rows=" as *u8); wn(fd, rows)
788 w(fd, " landed=" as *u8); wn(fd, c_landed); w(fd, " watching=" as *u8); wn(fd, c_watching)
789 w(fd, " present=" as *u8); wn(fd, c_present); w(fd, " missing=" as *u8); wn(fd, c_missing)
790 w(fd, " absent=" as *u8); wn(fd, c_absent); w(fd, " (partition sums)</p>\n" as *u8)
791 } }
792 if mode == 2 { if opened == 1 { wc(fd, 93) } else { wc(fd, 91); wc(fd, 93) } }
793 sys_free_file(b, n)
794 return rows
795}
796
797// ---- PERSON / PRODUCT / PLACE, MEASURED (operator 2026-08-24: "all our compares should have [UI analysis]
798// and august 2026 researched sota ... to tell us how to build a better site than our competitors ... person
799// via privacy and superior cx, product ... design and longevity and features, place ... ease of navigation
800// and ability to accomplish the desired task"). ONE renderer in the base, both generators call it -- the
801// refs_pass / watch_pass precedent. Reads knowledge/compare/<dom>.pppstate, the artefact nx_ppp_probe writes
802// after running ONE ruler on OUR live surface AND on every rival's live front door named in <dom>.ppp:
803// ppp|<col>|<label>|<url>|<json> last line = "# asof=... surfaces=N probed=K ruler=nx_ppp_probe"
804// The page prints per-axis permil AND the raw counts beside it, so the derivation can be argued with, and the
805// direction of the gap per rival is computed HERE from the numbers -- never typed by a seat. A domain with no
806// .pppstate prints a NAMED absence (the worklist: every compare carries this layer; a page not yet measured
807// says so in its own words). Self-contained scoped <style> so it renders in BOTH generators regardless of
808// their page CSS; colours reference the page theme vars with rgb() fallbacks. -1 = unobserved (scores zero
809// for that rule, never acquitted).
810const PL_MAXROWS: i64 = 32
811// first integer value of "<key>": at or after `from`; -999 = key absent (distinct from a real -1 unobserved)
812func pl_jint(buf: *u8, n: i64, from: i64, key: *u8) -> i64 {
813 var klen: i64 = 0
814 while key[klen] != (0 as u8) { klen = klen + 1 }
815 var i: i64 = from
816 var at: i64 = 0 - 1
817 while i + klen <= n {
818 var k: i64 = 0
819 var m: i64 = 1
820 while k < klen { if buf[i + k] != key[k] { m = 0; k = klen } else { k = k + 1 } }
821 if m == 1 { at = i; i = n } else { i = i + 1 }
822 }
823 if at < 0 { return 0 - 999 }
824 var j: i64 = at + klen
825 var neg: i64 = 0
826 if j < n { if buf[j] == (45 as u8) { neg = 1; j = j + 1 } }
827 var v: i64 = 0
828 var got: i64 = 0
829 while j < n {
830 let c: i64 = buf[j] as i64
831 if c >= 48 { if c <= 57 { v = v * 10 + (c - 48); got = 1; j = j + 1 } else { j = n } } else { j = n }
832 }
833 if got == 0 { return 0 - 999 }
834 if neg == 1 { return 0 - v }
835 return v
836}
837// offset of the literal `name` inside buf, or 0 (name is chosen to be unique in the row json)
838func pl_off(buf: *u8, n: i64, name: *u8) -> i64 {
839 var nl: i64 = 0
840 while name[nl] != (0 as u8) { nl = nl + 1 }
841 var i: i64 = 0
842 while i + nl <= n {
843 var k: i64 = 0
844 var m: i64 = 1
845 while k < nl { if buf[i + k] != name[k] { m = 0; k = nl } else { k = k + 1 } }
846 if m == 1 { return i }
847 i = i + 1
848 }
849 return 0
850}
851func pl_cell(fd: i64, v: i64) -> i64 {
852 if v == 0 - 999 { w(fd, "<td class='ct'>-</td>" as *u8); return 0 }
853 if v < 0 { w(fd, "<td class='ct'>unobs</td>" as *u8); return 0 }
854 w(fd, "<td class='r'>" as *u8); wn(fd, v); w(fd, "</td>" as *u8)
855 return 0
856}
857func ppp_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
858 let sp: *u8 = sys_mmap(600)
859 var o: i64 = scopy(sp, 0, "knowledge/compare/" as *u8)
860 o = scopy(sp, o, dom); o = scopy(sp, o, ".pppstate" as *u8); sp[o] = 0 as u8
861 let ln: *i64 = sys_mmap(16) as *i64
862 let b: *u8 = sys_read_file(sp, ln)
863 if (b as i64) == 0 {
864 if mode == 2 { w(fd, "{\"measured\":false}" as *u8); return 0 }
865 w(fd, "<h2 class='ghead' id='ppp'>Person · product · place — not yet measured for this domain</h2>\n<div class='meth'><b>Every compare carries this layer.</b> Declare <code>knowledge/compare/" as *u8); w(fd, dom)
866 w(fd, ".ppp</code> (rows <code>surface|nishi or c1..c4|label|url|connect</code> naming OUR live surface and each rival's front door), run <code>nx_ppp_probe domain " as *u8); w(fd, dom)
867 w(fd, "</code>, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).</div>\n" as *u8)
868 return 0
869 }
870 let n: i64 = ln[0]
871 if n <= 0 { sys_free_file(b, n); if mode == 2 { w(fd, "{\"measured\":false}" as *u8) } return 0 }
872 // the stamp is the LAST non-empty line; capture it BEFORE the parser NUL-splits anything
873 var ls: i64 = n
874 if ls > 0 { if b[ls - 1] == (10 as u8) { ls = ls - 1 } }
875 while ls > 0 { if b[ls - 1] == (10 as u8) { break } ls = ls - 1 }
876 let stamp: i64 = (b as i64) + ls
877 var se: i64 = ls
878 while se < n { if b[se] == (10 as u8) { break } se = se + 1 }
879 b[se] = 0 as u8
880 // collect data-row offsets (lines beginning 'p' = 'ppp|')
881 let roff: *i64 = sys_mmap(PL_MAXROWS * 8) as *i64
882 let rlen: *i64 = sys_mmap(PL_MAXROWS * 8) as *i64
883 var rows: i64 = 0
884 var p: i64 = 0
885 while p < ls {
886 var e: i64 = p
887 while e < ls { if b[e] == (10 as u8) { break } e = e + 1 }
888 if b[p] == (112 as u8) { if rows < PL_MAXROWS { roff[rows] = p; rlen[rows] = e - p; rows = rows + 1 } }
889 p = e + 1
890 }
891 let fld: *i64 = sys_mmap(8 * 8) as *i64
892 if mode == 2 {
893 w(fd, "{\"stamp\":\"" as *u8); wj(fd, stamp as *u8); w(fd, "\",\"surfaces\":[" as *u8)
894 var rj: i64 = 0
895 var emitted: i64 = 0
896 while rj < rows {
897 b[roff[rj] + rlen[rj]] = 0 as u8
898 let line: *u8 = (b as i64 + roff[rj]) as *u8
899 let nf: i64 = splitpipe(line, fld, 5)
900 if nf >= 5 {
901 if emitted > 0 { wc(fd, 44) }
902 w(fd, fld[4] as *u8)
903 emitted = emitted + 1
904 }
905 rj = rj + 1
906 }
907 w(fd, "]}" as *u8)
908 sys_free_file(b, n)
909 return rows
910 }
911 // ---- mode 1: HTML ----
912 w(fd, "<style>.pppsec{overflow-x:auto;margin:6px 0 2px}.pppt{border-collapse:collapse;width:100%;font-size:12.5px;min-width:760px}.pppt th{text-align:left;padding:8px 9px 8px 0;border-bottom:1px solid var(--fg,rgb(26,26,28));color:var(--mut,rgb(120,126,134));font-size:10px;letter-spacing:.06em;text-transform:uppercase;white-space:nowrap}.pppt td{border-bottom:1px solid var(--line,rgb(219,216,208));padding:9px 9px 9px 0;vertical-align:top;line-height:1.4}.pppt td.r{text-align:right;font-variant-numeric:tabular-nums;white-space:nowrap}.pppt td.ct{font-family:var(--mono,ui-monospace,Consolas,monospace);font-size:11px;color:var(--mut,rgb(120,126,134))}.pppt tr.ours td{background:var(--tint,rgba(120,90,220,.06))}.pppt tr.ours td.ni b{color:var(--ac,rgb(88,64,180))}.pppt a{color:var(--ac,rgb(88,64,180));text-decoration:none}</style>\n" as *u8)
913 w(fd, "<h2 class='ghead' id='ppp'>Person · product · place — the same ruler on our live surface and on theirs</h2>\n" as *u8)
914 w(fd, "<div class='meth'><b>Measured on both sides, from the bytes a first visitor receives.</b> <code>nx_ppp_probe</code> fetched every surface below over the sovereign TLS stack and scored three axes by declared rules, each a count against a published Aug-2026 bar. <b>Person</b> (privacy + CX): third-party asset/script hosts, the tracker classes The Markup's Blacklight tests for, consent-banner markers, <code>Set-Cookie</code> on the first consent-less response (the CNIL bar), the OWASP secure headers. <b>Product</b> (design + longevity): design-system hygiene (/12), computed WCAG 2.2 contrast over the page's real colour tokens, the static Core-Web-Vitals predictors (render-blocking css/js, unsized media — the source-visible causes of poor LCP/CLS), script count, dark-mode and reduced-motion queries, canonical URL. <b>Place</b> (findability + task): nav/main/footer landmarks, a skip link, on-site search, breadcrumb, exactly one h1, internal links, lang, viewport, title. Envelope: static HTML plus response headers, no render, no script execution — a client-rendered app is graded on what a no-JS first visitor receives, which is the progressive-enhancement bar itself. <b>unobs</b> = the probe could not see that sub-measure and scored it zero rather than acquit. Stamp: <code>" as *u8)
915 w(fd, stamp as *u8); w(fd, "</code></div>\n" as *u8)
916 w(fd, "<div class='pppsec'><table class='pppt'><thead><tr><th>Surface</th><th class='r'>Person</th><th class='r'>Product</th><th class='r'>Place</th><th class='r'>3p script hosts</th><th class='r'>trackers</th><th class='r'>set-cookie</th><th class='r'>sec hdr /5</th><th class='r'>design /12</th><th class='r'>contrast fails</th><th class='r'>blocking css+js</th><th class='r'>unsized img</th><th class='r'>scripts</th><th class='r'>KB</th><th>nav main skip search crumb</th></tr></thead><tbody>\n" as *u8)
917 var ours_pe: i64 = 0 - 1
918 var ours_pr: i64 = 0 - 1
919 var ours_pl: i64 = 0 - 1
920 var best_pe: i64 = 0 - 1
921 var best_pr: i64 = 0 - 1
922 var best_pl: i64 = 0 - 1
923 var rr: i64 = 0
924 while rr < rows {
925 b[roff[rr] + rlen[rr]] = 0 as u8
926 let line: *u8 = (b as i64 + roff[rr]) as *u8
927 let nf: i64 = splitpipe(line, fld, 5)
928 if nf >= 5 {
929 let col: *u8 = fld[1] as *u8
930 let label: *u8 = fld[2] as *u8
931 let url: *u8 = fld[3] as *u8
932 let js: *u8 = fld[4] as *u8
933 var jn: i64 = 0
934 while js[jn] != (0 as u8) { jn = jn + 1 }
935 var ours: i64 = 0
936 if streq(col, "nishi" as *u8) == 1 { ours = 1 }
937 if ours == 1 { w(fd, "<tr class='ours'><td class='ni'><b>" as *u8) } else { w(fd, "<tr><td><b>" as *u8) }
938 w(fd, label); w(fd, "</b><br><a href='" as *u8); w(fd, url); w(fd, "' rel='nofollow'><span class='ct'>" as *u8); w(fd, url); w(fd, "</span></a></td>" as *u8)
939 let unreach: i64 = pl_jint(js, jn, 0, "\"unreachable\":" as *u8)
940 if unreach != 0 - 999 {
941 w(fd, "<td colspan='13'>UNREACHABLE (probe code " as *u8); wn(fd, unreach); w(fd, ") — no measurement, no score; re-run the probe rather than infer a number</td></tr>\n" as *u8)
942 } else {
943 let sp_pe: i64 = pl_off(js, jn, "\"person\":{" as *u8)
944 let sp_pr: i64 = pl_off(js, jn, "\"product\":{" as *u8)
945 let sp_pl: i64 = pl_off(js, jn, "\"place\":{" as *u8)
946 let pe: i64 = pl_jint(js, jn, sp_pe, "\"score_permil\":" as *u8)
947 let pr: i64 = pl_jint(js, jn, sp_pr, "\"score_permil\":" as *u8)
948 let pl: i64 = pl_jint(js, jn, sp_pl, "\"score_permil\":" as *u8)
949 if ours == 1 {
950 if pe > ours_pe { ours_pe = pe }
951 if pr > ours_pr { ours_pr = pr }
952 if pl > ours_pl { ours_pl = pl }
953 } else {
954 if pe > best_pe { best_pe = pe }
955 if pr > best_pr { best_pr = pr }
956 if pl > best_pl { best_pl = pl }
957 }
958 pl_cell(fd, pe); pl_cell(fd, pr); pl_cell(fd, pl)
959 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"third_party_script_hosts\":" as *u8))
960 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"tracker_hits\":" as *u8))
961 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"set_cookie\":" as *u8))
962 pl_cell(fd, pl_jint(js, jn, sp_pe, "\"sec_headers\":" as *u8))
963 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"design_hygiene\":" as *u8))
964 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"contrast_fails\":" as *u8))
965 let bc: i64 = pl_jint(js, jn, sp_pr, "\"blocking_css\":" as *u8)
966 let bj: i64 = pl_jint(js, jn, sp_pr, "\"blocking_js\":" as *u8)
967 if bc < 0 { pl_cell(fd, bc) } else { if bj < 0 { pl_cell(fd, bj) } else { pl_cell(fd, bc + bj) } }
968 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"unsized_media\":" as *u8))
969 pl_cell(fd, pl_jint(js, jn, sp_pr, "\"script_tags\":" as *u8))
970 let bytes: i64 = pl_jint(js, jn, 0, "\"bytes\":" as *u8)
971 if bytes > 0 { w(fd, "<td class='r'>" as *u8); wn(fd, bytes / 1024); w(fd, "</td>" as *u8) } else { w(fd, "<td class='ct'>-</td>" as *u8) }
972 w(fd, "<td class='r ct'>" as *u8)
973 wn(fd, pl_jint(js, jn, sp_pl, "\"nav\":" as *u8)); wc(fd, 32); wn(fd, pl_jint(js, jn, sp_pl, "\"main\":" as *u8)); wc(fd, 32)
974 wn(fd, pl_jint(js, jn, sp_pl, "\"skip_link\":" as *u8)); wc(fd, 32); wn(fd, pl_jint(js, jn, sp_pl, "\"site_search\":" as *u8)); wc(fd, 32)
975 wn(fd, pl_jint(js, jn, sp_pl, "\"breadcrumb\":" as *u8)); w(fd, "</td></tr>\n" as *u8)
976 }
977 }
978 rr = rr + 1
979 }
980 w(fd, "</tbody></table></div>\n" as *u8)
981 // the direction of the gap, computed from the numbers above
982 w(fd, "<div class='meth'><b>Where to beat them, from the numbers.</b> " as *u8)
983 if ours_pe >= 0 { if best_pe >= 0 {
984 w(fd, "PERSON ours " as *u8); wn(fd, ours_pe); w(fd, " vs best rival " as *u8); wn(fd, best_pe)
985 if ours_pe > best_pe { w(fd, " — we lead; hold it (zero third-party hosts, zero trackers, headers 5/5 is the ceiling). " as *u8) } else { w(fd, " — behind: the higher-scoring rival shows which privacy rule we lose. " as *u8) }
986 } }
987 if ours_pr >= 0 { if best_pr >= 0 {
988 w(fd, "PRODUCT ours " as *u8); wn(fd, ours_pr); w(fd, " vs best rival " as *u8); wn(fd, best_pr)
989 if ours_pr > best_pr { w(fd, " — we lead on measurable hygiene; the perceptual premium is a judged rung, not this ruler. " as *u8) } else { w(fd, " — behind: design/12, contrast, blocking, unsized and scripts name the rule. " as *u8) }
990 } }
991 if ours_pl >= 0 { if best_pl >= 0 {
992 w(fd, "PLACE ours " as *u8); wn(fd, ours_pl); w(fd, " vs best rival " as *u8); wn(fd, best_pl)
993 if ours_pl > best_pl { w(fd, " — we lead on the findability floor; task completion by a real user is the next ruler. " as *u8) } else { w(fd, " — behind: nav main skip search crumb, in that order. " as *u8) }
994 } }
995 w(fd, "Re-measured by the beat; nothing here is typed by a seat.</div>\n" as *u8)
996 sys_free_file(b, n)
997 return rows
998}
999
1000// ============================================================================
1001// SC THEME PASS (2026-08-25) -- ONE palette, emitted from the estate's TOKEN SSOT
1002// (nx_brand_tokens), for BOTH domain generators. It is lifted HERE for the same
1003// reason plan_pass, dstate and wlow were lifted here: this module is the base class
1004// the two generators already share, so a palette that lives here CANNOT drift
1005// between them. Two hand-landed dark blocks in two files is the duplicate-ruler
1006// defect wearing a stylesheet.
1007//
1008// WHY IT EXISTS. Measured 2026-08-25 against the LIVE pages, not inherited:
1009// /compare/search scored theme-aware 0/2 and prefers-color-scheme occurred ZERO
1010// times in 79,499 bytes of matrix source. The dark PALETTE was already authored and
1011// already shipping as html[data-theme='dark'] -- it was simply unreachable from the
1012// operating system's own preference. ***A THEME THAT EXISTS BUT CANNOT BE REACHED
1013// WITHOUT HUNTING FOR A CHIP IS A CAPABILITY THE PAGE IS PAYING FOR AND NOT
1014// DELIVERING.*** Nothing here invents a palette, so no contrast pair moved: the dark
1015// values below are byte-identical to the literal they replace, which makes the dark
1016// rendering unchanged BY CONSTRUCTION rather than by inspection.
1017//
1018// ***THE DARK VALUES ARE DECLARED ONCE AND EMITTED TWICE.*** The same parsed rows go
1019// out under html[data-theme='dark'] (the chip) AND under the media query (the OS
1020// preference). Keeping two copies in step is exactly how a chip theme and an auto
1021// theme drift apart; here a drift is not merely unlikely, it is UNREPRESENTABLE --
1022// there is only one copy of the data, and it is re-SELECTED, never re-PARSED, so the
1023// SSOT keeps its 3-pipe field rule, its bt_ident_safe/bt_value_safe injection screens
1024// and its silent-skip semantics. A second brand parser here would be a second ruler.
1025//
1026// ***THE MEDIA BLOCK IS GUARDED :root:not([data-theme]) AND THAT GUARD IS LOAD-BEARING.***
1027// This page ships a three-way switcher (paper/ink/dark) whose sett() calls
1028// setAttribute('data-theme', n) for ALL THREE values -- paper INCLUDED -- and a boot
1029// script restores the stored choice before first paint. But PAPER IS THE BARE :root
1030// DEFAULT: there is no html[data-theme='paper'] rule to out-rank anything. So an
1031// UNGUARDED @media(prefers-color-scheme:dark){:root{...}} would carry EQUAL
1032// specificity to that default and sit LATER in the cascade, and would therefore
1033// repaint a user who had just explicitly chosen Paper on an OS-dark machine. Every
1034// explicit choice sets the attribute, so :not([data-theme]) makes all three chips win
1035// over the OS preference with ONE selector, while a visitor who has chosen nothing
1036// still gets their system preference. ***A DARK BLOCK ADDED WITHOUT FIRST ASKING
1037// WHETHER THE PAGE ALREADY HAS A THEME SWITCHER SILENTLY OVERRIDES AN EXPLICIT USER
1038// CHOICE -- AND FROM THE USER'S SIDE THAT IS INDISTINGUISHABLE FROM A BROKEN BUTTON.***
1039// nx_brand_tokens' bt_emit_dark_root_buf emits the UNGUARDED selector, which is
1040// CORRECT for a page with no switcher (nx_games_page). The difference is the switcher,
1041// not the SSOT, so the fix belongs at this call site and NOT in the shared emitter.
1042//
1043// BREAKPOINTS ARE THE ESTATE'S ONE LADDER, NOT A THIRD SET. 860/640 are taken from
1044// sites/nishifamily/nishi-ds.css section 5 RESPONSIVE -- the same two numbers
1045// nx_games_page adopted, for the same reason: a third ladder would be a duplicate
1046// ruler wearing a constant and nothing downstream could tell the two apart. They
1047// redefine TOKENS ONLY, never components: a token carries no paint, so a breakpoint
1048// cannot restyle anything the page did not already opt into by reading that token.
1049//
1050// MEMORY: the two scratch buffers are deliberately NOT munmap'd per call -- this is a
1051// one-shot page emitter that exits, and sc_theme_pass is called exactly once per page.
1052// Declared rather than left silent.
1053const SC_TOKCAP: i64 = 16384
1054const SC_BP_MD: i64 = 860
1055const SC_BP_SM: i64 = 640
1056
1057// The compare palette AS DATA. Light rows first, then the dark overrides. A token with
1058// NO dark row is theme-independent by construction -- that is why --nx-font-mono and
1059// the layout tokens carry none: a monospace stack and a wrap width are not chrome.
1060func sc_brand() -> *u8 {
1061 return "token|color|bg|rgb(243,241,236)\ntoken|color|fg|rgb(26,26,28)\ntoken|color|accent|rgb(88,64,180)\ntoken|color|panel|rgb(249,247,243)\ntoken|color|soft|rgb(236,233,226)\ntoken|color|tint|rgb(236,233,226)\ntoken|color|line|rgb(219,216,208)\ntoken|color|mut|rgb(92,96,104)\ntoken|color|faint|rgb(138,141,148)\ntoken|color|gk|rgb(60,64,72)\ntoken|color|goff|rgb(198,195,187)\ntoken|color|ghalf|rgb(122,126,134)\ntoken|color|codebg|rgb(229,226,218)\ntoken|color|ok|rgb(26,127,55)\ntoken|color|part|rgb(178,106,0)\ntoken|color|absent|rgb(179,38,30)\ntoken|color|exceed|rgb(130,80,223)\ntoken|font|mono|ui-monospace,Consolas,monospace\ntoken|layout|wrap|clamp(20rem,95vw,110rem)\ntoken|layout|gutter|clamp(14px,3vw,28px)\ntoken|layout|measure|66ch\ntoken|layout|capmin|27rem\ntoken|layout|capgap|clamp(10px,1.6vw,20px)\ntoken|layout|rail|13rem\ndark|color|bg|rgb(16,18,23)\ndark|color|fg|rgb(226,229,235)\ndark|color|accent|rgb(171,152,238)\ndark|color|panel|rgb(23,26,34)\ndark|color|soft|rgb(30,34,43)\ndark|color|tint|rgb(23,26,34)\ndark|color|line|rgb(43,47,56)\ndark|color|mut|rgb(139,146,158)\ndark|color|faint|rgb(100,107,119)\ndark|color|gk|rgb(168,175,186)\ndark|color|goff|rgb(58,63,73)\ndark|color|ghalf|rgb(120,127,138)\ndark|color|codebg|rgb(35,39,48)\ndark|color|ok|rgb(121,224,167)\ndark|color|part|rgb(255,166,120)\ndark|color|absent|rgb(118,130,154)\ndark|color|exceed|rgb(255,209,122)\n" as *u8
1062}
1063
1064// The SSOT's own dark wrapper, named once so its LENGTH is DERIVED and never
1065// hand-counted beside the literal -- a hand-counted length is a second copy of the
1066// string's shape and the two drift silently.
1067func sc_dark_open() -> *u8 { return "@media(prefers-color-scheme:dark){:root{\n" as *u8 }
1068func sc_dark_close() -> *u8 { return "}}\n" as *u8 }
1069
1070func sc_theme_pass(fd: i64) -> i64 {
1071 let bd: *u8 = sc_brand()
1072 let bn: i64 = bt_len(bd)
1073 let tb: *u8 = sys_mmap(SC_TOKCAP)
1074 // ---- light :root, straight from the SSOT ----
1075 let lw: i64 = bt_emit_root_buf(bd, bn, tb, SC_TOKCAP)
1076 if lw < 0 { w(2, "FATAL sc_theme_pass: brand parsed ZERO light tokens -- refusing to emit a page with no palette\n" as *u8); sys_exit(2); return 2 }
1077 // bt_app SATURATES at cap instead of failing, so an undersized buffer truncates the
1078 // palette mid-block and still returns a POSITIVE count. ***A CAP REACHED IN SILENCE
1079 // BECOMES A MEASUREMENT NOBODY KNOWS IS PARTIAL*** -- refuse at the boundary instead.
1080 if lw >= SC_TOKCAP - 1 { w(2, "FATAL sc_theme_pass: light block reached SC_TOKCAP -- this palette is TRUNCATED, not complete\n" as *u8); sys_exit(2); return 2 }
1081 sys_write(fd, tb, lw)
1082 // ---- page-local ALIASES over the SSOT names: one indirection, so a brand DATA edit
1083 // re-themes the whole page and every rule below keeps reading the short name it
1084 // always read. They are var() REFERENCES, not copies, so they resolve at use time --
1085 // which is why ONE alias block serves paper, ink, dark and the OS preference alike.
1086 w(fd, ":root{--bg:var(--nx-color-bg);--fg:var(--nx-color-fg);--ac:var(--nx-color-accent);--panel:var(--nx-color-panel);--soft:var(--nx-color-soft);--tint:var(--nx-color-tint);--line:var(--nx-color-line);--mut:var(--nx-color-mut);--faint:var(--nx-color-faint);--gk:var(--nx-color-gk);--goff:var(--nx-color-goff);--ghalf:var(--nx-color-ghalf);--codebg:var(--nx-color-codebg);--mono:var(--nx-font-mono);--y:var(--nx-color-ok);--p:var(--nx-color-part);--n:var(--nx-color-absent);--ex:var(--nx-color-exceed)}\n" as *u8)
1087 // ---- dark: ONE parse, TWO selectors ----
1088 let dw: i64 = bt_emit_dark_root_buf(bd, bn, tb, SC_TOKCAP)
1089 // bt_emit_dark_root_buf returns 0 (never negative) when the brand carries no dark
1090 // rows, so this guard is <= 0. A < 0 guard here would be a tooth that CANNOT FIRE.
1091 if dw <= 0 { w(2, "FATAL sc_theme_pass: brand carries NO dark override -- the page would ship theme-blind\n" as *u8); sys_exit(2); return 2 }
1092 if dw >= SC_TOKCAP - 1 { w(2, "FATAL sc_theme_pass: dark block reached SC_TOKCAP -- TRUNCATED, not complete\n" as *u8); sys_exit(2); return 2 }
1093 let op: *u8 = sc_dark_open()
1094 let ol: i64 = bt_len(op)
1095 let cl: i64 = bt_len(sc_dark_close())
1096 // The re-selection is only valid if the SSOT still emits the wrapper we expect. If it
1097 // ever changes, slicing past a stale prefix would emit a CORRUPT block that still
1098 // looks like CSS -- so verify the prefix and refuse loudly rather than guess.
1099 var gi: i64 = 0
1100 while gi < ol { if tb[gi] != op[gi] { w(2, "FATAL sc_theme_pass: nx_brand_tokens changed its dark wrapper -- re-selecting it would corrupt the block\n" as *u8); sys_exit(2); return 2 } gi = gi + 1 }
1101 let rs: i64 = ol
1102 let re: i64 = dw - cl
1103 if re <= rs { w(2, "FATAL sc_theme_pass: dark block carried no rows between its wrapper\n" as *u8); sys_exit(2); return 2 }
1104 let rb: *u8 = sys_mmap(SC_TOKCAP)
1105 var k: i64 = 0
1106 while rs + k < re { rb[k] = tb[rs + k]; k = k + 1 }
1107 w(fd, "html[data-theme='dark']{\n" as *u8)
1108 sys_write(fd, rb, k)
1109 w(fd, "}\n" as *u8)
1110 w(fd, "@media(prefers-color-scheme:dark){:root:not([data-theme]){\n" as *u8)
1111 sys_write(fd, rb, k)
1112 w(fd, "}}\n" as *u8)
1113 // ---- breakpoints: TOKENS ONLY, on the estate's one ladder ----
1114 w(fd, "@media (max-width:" as *u8); wn(fd, SC_BP_MD); w(fd, "px){:root{--nx-layout-gutter:clamp(12px,3.6vw,18px)}}\n" as *u8)
1115 w(fd, "@media (max-width:" as *u8); wn(fd, SC_BP_SM); w(fd, "px){:root{--nx-layout-wrap:100%;--nx-layout-gutter:12px}}\n" as *u8)
1116 return 0
1117}
1118
1119// ---- sc_layout_pass: THE ONE LAYOUT EMITTER FOR EVERY COMPARE PAGE (2026-08-31) ----
1120// WHY THIS EXISTS. The body rule was hand-copied into SEVEN generators and had already drifted to
1121// SIX different page widths (960/980/1000/1040/1080/1180) -- the duplicate-ruler defect living in
1122// emitted CSS, where nothing compares the copies. Worse, the two layout TOKENS the SSOT publishes
1123// (--nx-layout-wrap/--nx-layout-gutter) were DEFINED on every page and REFERENCED by none of the
1124// sota-class ones: they hardcoded max-width:980px and a second clamp() straight over the top.
1125// ***A TOKEN DEFINED AND NEVER READ IS NOT A DESIGN SYSTEM, IT IS DEAD BYTES THAT LOOK LIKE ONE***
1126// -- and the page it governed rendered as one narrow column down the middle of a 1920px display.
1127//
1128// FULL CANVAS WITHOUT UNREADABLE PROSE. These are two different width budgets and the fix is to stop
1129// spending one on the other. The PAGE takes a fluid clamp (95vw, capped) so the LAYOUT uses the
1130// display; PROSE keeps its own measure cap (--nx-layout-measure, 66ch) applied to the text element
1131// itself, never to its container. Surplus width therefore cannot lengthen a line -- it has nowhere
1132// to go except into more capability cards side by side, which is more information on screen rather
1133// than a 200-character sentence.
1134//
1135// WHY SC_CAP_SPLIT IS A CONST AND NOT A TOKEN. Every other layout number here is a --nx-layout-*
1136// token, per rule 11. This one CANNOT be: a CSS container/media query CONDITION does not accept
1137// var(), so the threshold must reach the stylesheet as a literal. A named const emitted through wn()
1138// is the same guarantee by the only mechanism CSS allows -- it is not an exception to the rule, it is
1139// the rule honoured where var() is structurally unavailable. 496px is where a card can seat the
1140// 13rem rail beside a main column still wider than the rail; below it the card stacks.
1141//
1142// CONTAINER QUERY, NOT A BREAKPOINT, FOR THE CARD. The same .cap renders one-per-row on a phone and
1143// three-across on a desktop, so its reflow depends on ITS OWN width, not the window's. @container is
1144// Baseline Widely Available (2025-08-14). The container-name is declared explicitly and queried by
1145// name: an unresolvable container silently falls back to small-viewport units rather than erroring,
1146// so the anonymous form would fail as a confident wrong answer.
1147const SC_CAP_SPLIT: i64 = 496
1148func sc_layout_pass(fd: i64) -> i64 {
1149 // page shell -- reads the SSOT tokens, so a brand DATA edit re-widths every compare page at once
1150 w(fd, "*{box-sizing:border-box}html{scrollbar-gutter:stable}\n" as *u8)
1151 w(fd, "body{background:var(--bg);font-family:-apple-system,Segoe UI,Roboto,sans-serif;max-width:var(--nx-layout-wrap);margin:0 auto;padding:0 var(--nx-layout-gutter) 6vh;color:var(--fg);line-height:1.6;font-size:clamp(15px,0.5vw + 13px,16.5px)}\n" as *u8)
1152 // min-width:0 defeats the min-content floor that grid/flex children carry by default. Without it a
1153 // single wide table forces every ancestor wider than its track and THE PAGE scrolls sideways --
1154 // the overflow lands on the document, which is the one place it must never land.
1155 w(fd, "main{min-width:0}main>*{min-width:0;max-width:100%}table{max-width:100%}\n" as *u8)
1156 // long unbroken identifiers (organ names, hashes, paths) are the only real width bombs on these
1157 // pages; break them where they occur instead of letting them set the table's minimum width
1158 w(fd, ".pl .ct,.ev code,.rlinks code,.watch{overflow-wrap:anywhere}\n" as *u8)
1159 // ---- PROSE MEASURE: ONE cap for the prose blocks BOTH archetypes emit ----
1160 // THE REGRESSION THIS FUNCTION CAUSED, AND WHY THE FIX LANDS HERE. Widening body from a fixed 980px
1161 // to a fluid clamp is right for the LAYOUT and wrong for PROSE unless the prose carries its own cap.
1162 // Matrix learned that on 2026-08-25 and capped .meth/.lead/.answer/.verdict at 72ch. Sota never
1163 // received it: measured over the whole corpus, 72ch occurs 5 times in the estate and ALL FIVE are in
1164 // nx_swcompare_matrix (coverage_complete=1 corpus_complete=1 over 23,407 files). So sota's .meth --
1165 // the ~1,100-character "How this is scored" block, the FIRST prose a reader meets -- went from
1166 // inheriting 980px (~130 characters a line) to inheriting up to 1760px (~240), roughly 3x the WCAG
1167 // 1.4.8 (AAA) 80-character ceiling. ***A FIX THAT LIVES IN ONE ORGAN AND NOT ITS SIBLING IS HALF A
1168 // FIX***, and widening the canvas converted this one from latent to acute.
1169 //
1170 // WHY THE TOKEN AND NOT A SECOND 72ch. --nx-layout-measure is already the SSOT's declared prose
1171 // measure and is already read by .cap-note. Hard-coding 72ch a second time -- in the SHARED lib, no
1172 // less -- is the duplicate-ruler defect this extraction exists to remove, and nothing downstream
1173 // could tell the two copies apart. It does NOT overrule matrix: matrix emits its own .meth/.verdict
1174 // rules AFTER this one at equal specificity, so matrix still renders at 72ch and its emitted bytes
1175 // are unchanged. Only sota, which carried NO cap at all, changes. .lead and .answer are deliberately
1176 // NOT here -- they are matrix-only classes already carrying their own 72ch, so listing them would
1177 // add a second ruler for a page that already has one.
1178 w(fd, ".meth,.verdict{max-width:var(--nx-layout-measure);text-wrap:pretty}\n" as *u8)
1179 // ---- the capability board: a responsive multi-column grid ----
1180 // auto-FILL, never auto-fit: auto-fit collapses the empty tracks and stretches a lone card across
1181 // the whole canvas, which re-creates at component scale the exact single-wide-column defect this
1182 // function exists to remove. min(100%,...) inside minmax is load-bearing: the auto-repeat count is
1183 // computed from the track MINIMUM, so a bare minmax(27rem,1fr) overflows any container narrower
1184 // than 27rem instead of dropping to one column.
1185 w(fd, ".caps{display:grid;grid-template-columns:repeat(auto-fill,minmax(min(100%,var(--nx-layout-capmin)),1fr));gap:var(--nx-layout-capgap);align-items:start;margin:6px 0}\n" as *u8)
1186 // the category headings are emitted INSIDE .caps, so they are grid items too and must span the row
1187 w(fd, ".caps>.ghead{grid-column:1/-1}\n" as *u8)
1188 // THE CARD IS SCOPED .caps>.cap, NOT BARE .cap, FOR THE SAME REASON .ghead ABOVE IS. "cap" is an
1189 // overloaded name in this estate and a bare rule in a SHARED lib claims it globally. Measured over
1190 // the whole corpus (coverage_complete=1 corpus_complete=1, 23,407 files) there are four other
1191 // holders: nx_swcompare_crm:64 and nx_swcompare_sending:65 both emit <td class='cap'> inside a <tr>,
1192 // and _hdl_build/nx_rewards:175 emits <span class='cap'> -- none of them a child of .caps, so the
1193 // child combinator excludes all three BY CONSTRUCTION. That matters because the roadmap is to
1194 // convert those generators onto this emitter, and display:grid landing on a <td> overrides
1195 // display:table-cell and destroys the table. Scoping costs 6 bytes and removes the trap before
1196 // anyone can walk into it.
1197 //
1198 // ***THIS IS NOT A COMPLETE FENCE AND MUST NOT BE READ AS ONE.*** The same census found a FIFTH
1199 // holder that the child combinator does NOT exclude: nx_compare_unified:281 emits
1200 // <div class='caps'> with <span class='cap on'> as its DIRECT CHILDREN, so .caps>.cap matches its
1201 // chip row exactly. It is harmless today -- nx_compare_unified does not call sc_layout_pass (the
1202 // four callers, RE-CENSUSED 2026-08-31 at coverage_complete=1 corpus_complete=1 over 23,407 files,
1203 // are nx_swcompare_sota, nx_swcompare_matrix, nx_swcompare_hub and nx_swcompare_watch_gate -- an
1204 // earlier revision of this comment said THREE and omitted hub. LINE NUMBERS ARE DELIBERATELY NOT
1205 // CITED HERE: hub's call site moved 729 -> 863 while this comment was being written, so a line
1206 // citation would rot faster than the fact it carries -- re-derive it with a grep for the symbol.
1207 // That undercount is load-bearing, not cosmetic: this enumeration IS the whole basis for calling the
1208 // collision harmless, so a fence that miscounts its own callers asserts a gap it never measured) -- but
1209 // whoever converts nx_compare_unified inherits a live collision, and a chip is not a card. Naming
1210 // the residual here rather than in a report nobody re-reads: a count without a worklist is not
1211 // actionable, and a fence published as "done" is worse than one published with its gap.
1212 w(fd, ".caps>.cap{container-type:inline-size;container-name:nxcap;display:grid;grid-template-columns:minmax(0,1fr);gap:6px 18px;padding:14px 16px;border:1px solid var(--line);border-radius:14px;background:var(--panel);align-items:start;min-width:0}\n" as *u8)
1213 w(fd, ".capmain{min-width:0}.cap-note{max-width:var(--nx-layout-measure);text-wrap:pretty}\n" as *u8)
1214 w(fd, ".capside{display:flex;flex-direction:row;flex-wrap:wrap;align-items:center;gap:8px}.rw{max-width:100%}\n" as *u8)
1215 w(fd, "@container nxcap (min-width:" as *u8); wn(fd, SC_CAP_SPLIT); w(fd, "px){.caps>.cap{grid-template-columns:minmax(0,1fr) var(--nx-layout-rail)}.capside{flex-direction:column;align-items:flex-end}.rw{justify-content:flex-end;max-width:var(--nx-layout-rail)}}\n" as *u8)
1216 return 0
1217}
1218
1219// ---- THE EVIDENCE PROFILE AS MACHINE-READABLE DATA (2026-08-31, frontier F1208) -------------------
1220// ONE RENDERER IN THE BASE, BOTH GENERATORS CALL IT -- the refs_pass / plan_pass precedent exactly. The
1221// HTML band (ev_pass, in nx_swcompare_matrix) and this JSON projection read THE SAME stamp through THE
1222// SAME reader, nx_evprofile_lib, so a board page and its api.json cannot disagree about that domain's
1223// gaps: there is one artifact and one parser, and this function only PROJECTS what evp_parse already
1224// read. THE GENERATOR ADDS A READER, NEVER A MEASUREMENT -- every field below is already materialised
1225// verbatim on knowledge/status/evstamp_<domain>.verdict by nx_swcompare_evidence.
1226//
1227// ABSTAIN, NEVER ACQUIT -- AND HERE THE ABSTAIN PATH IS THE COMMON PATH. 92 of the 95 live stamps are
1228// v1 (measured 2026-08-31), so the branch that emits NO NUMBERS is the one nearly every board takes,
1229// and it is therefore the one that has to be right: a v1 stamp carries none of the profile keys,
1230// evp_parse leaves every slot -1, and writing a 0 there would publish a gapless board for a domain
1231// nobody ever measured. AN ALWAYS-ZERO FIELD READS AS EVIDENCE.
1232// The evidence key is emitted on EVERY path, including the abstentions. An ABSENT key is
1233// indistinguishable from an emitter that never shipped, so the abstention is published as a VALUE --
1234// status UNKNOWN / UNSTAMPED / AMBIGUOUS -- and never as a silence.
1235//
1236// NO SCALAR GRADE, DELIBERATELY. Counts WITH their denominators, the partition sums, and the list of
1237// gap classes that FIRE. A stored scalar is a field a seat can edit; a counted partition is not, and
1238// any consumer can recompute whatever ranking it wants from these numbers at read time.
1239//
1240// NO PATH IS BUILT HERE. evp_load composes ep_artifact_path, so this behaves identically whether the
1241// generator was launched from the estate root or -- as nx_compare_regen launches it -- from buildroot,
1242// whose knowledge/status holds ZERO evstamp files. A bare relative read there would confidently render
1243// no-evidence for all 96 domains.
1244func evj_class(fired: i64, name: *u8, n: *i64) -> i64 {
1245 if fired != 1 { return 0 }
1246 if n[0] > 0 { wc(1, 44) }
1247 wq(1); wj(1, name); wq(1)
1248 n[0] = n[0] + 1
1249 return 1
1250}
1251
1252func evj_pass(dom: *u8) -> i64 {
1253 let buf: *u8 = sys_mmap(EVP_STAMP_CAP)
1254 let pathout: *u8 = sys_mmap(EVP_PATH_CAP)
1255 let flags: *i64 = sys_mmap(8 * EVP_NFLAG) as *i64
1256 let n: i64 = evp_load(dom, buf, EVP_STAMP_CAP, pathout, flags)
1257 wc(1, 44); wq(1); w(1, "evidence" as *u8); wq(1); wc(1, 58); wc(1, 123)
1258 kv_s(1, "producer" as *u8, "nx_swcompare_evidence" as *u8); wc(1, 44)
1259 kv_s(1, "reader" as *u8, "nx_evprofile_lib" as *u8); wc(1, 44)
1260 // Two different files answering to one name is REFUSED, not silently decided: ep_open_rd probes the
1261 // caller CWD first on purpose, so a stray copy beside the generator would win, and win silently.
1262 if n == EVP_RC_AMBIGUOUS {
1263 kv_s(1, "evidence_status" as *u8, "AMBIGUOUS" as *u8); wc(1, 44)
1264 kv_s(1, "source" as *u8, pathout); wc(1, 44)
1265 kv_s(1, "note" as *u8, "two different files answer to one stamp name -- one under the generator working directory, one at the estate root, and their bytes differ. No reader may pick one, so no numbers are published." as *u8)
1266 wc(1, 125)
1267 return 0
1268 }
1269 if n < 0 {
1270 kv_s(1, "evidence_status" as *u8, "UNSTAMPED" as *u8); wc(1, 44)
1271 kv_s(1, "note" as *u8, "no evidence stamp exists for this domain yet: run nx_swcompare_evidence on it and this object fills itself on the next beat. Not one numeric field is emitted, deliberately -- a zero-filled profile reads as a board with no gaps, which is the one wrong answer nobody would question." as *u8)
1272 wc(1, 125)
1273 return 0
1274 }
1275 let f: *i64 = sys_mmap(8 * EVP_NF) as *i64
1276 evp_parse(buf, n, f)
1277 kv_s(1, "source" as *u8, pathout); wc(1, 44)
1278 kv_n(1, "stamp_version" as *u8, f[EVP_F_V]); wc(1, 44)
1279 kv_n(1, "stamp_read_capped" as *u8, flags[EVP_FL_BRIM]); wc(1, 44)
1280 // THE VERSION IS DERIVED FROM THE WIRE, NEVER DECLARED ON IT: a v1 stamp simply has no profile keys.
1281 if f[EVP_F_V] < 2 {
1282 kv_s(1, "evidence_status" as *u8, "UNKNOWN" as *u8); wc(1, 44)
1283 kv_s(1, "note" as *u8, "this stamp predates the gap profile and carries none of its keys, so the reader abstains rather than acquit. UNKNOWN IS NOT ZERO. Re-stamp with nx_swcompare_evidence on this domain and the counts below appear." as *u8)
1284 wc(1, 125)
1285 return 0
1286 }
1287 let now: i64 = sys_now_realtime_sec()
1288 let ttl: i64 = evp_ttl_sec()
1289 let stale: i64 = evp_stale(f, now, ttl)
1290 var age: i64 = now - f[EVP_F_EPOCH]
1291 if age < 0 { age = 0 }
1292 kv_s(1, "evidence_status" as *u8, "MEASURED" as *u8); wc(1, 44)
1293 kv_n(1, "ok" as *u8, f[EVP_F_OK]); wc(1, 44)
1294 kv_n(1, "epoch" as *u8, f[EVP_F_EPOCH]); wc(1, 44)
1295 kv_n(1, "age_sec" as *u8, age); wc(1, 44)
1296 kv_n(1, "ttl_sec" as *u8, ttl); wc(1, 44)
1297 kv_n(1, "stale" as *u8, stale); wc(1, 44)
1298 // EVERY COUNT CARRIES ITS DENOMINATOR: a bare grounded=14 is not a fact about a board.
1299 wq(1); w(1, "grounded" as *u8); wq(1); wc(1, 58); wc(1, 123)
1300 kv_n(1, "count" as *u8, f[EVP_F_GROUNDED]); wc(1, 44); kv_n(1, "of" as *u8, f[EVP_F_PRESENT])
1301 wc(1, 125); wc(1, 44)
1302 kv_n(1, "unsupported" as *u8, f[EVP_F_UNGROUND]); wc(1, 44)
1303 wq(1); w(1, "gates" as *u8); wq(1); wc(1, 58); wc(1, 123)
1304 kv_n(1, "green" as *u8, f[EVP_F_GREEN]); wc(1, 44)
1305 kv_n(1, "ran" as *u8, f[EVP_F_RAN]); wc(1, 44)
1306 kv_n(1, "declared" as *u8, f[EVP_F_DECLARED]); wc(1, 44)
1307 kv_n(1, "skipped" as *u8, f[EVP_F_SKIPPED]); wc(1, 44)
1308 kv_n(1, "hashed" as *u8, f[EVP_F_HASHED]); wc(1, 44)
1309 kv_n(1, "redseen" as *u8, f[EVP_F_REDSEEN]); wc(1, 44)
1310 kv_n(1, "vacuous" as *u8, f[EVP_F_VACUOUS])
1311 wc(1, 125); wc(1, 44)
1312 wq(1); w(1, "gaps" as *u8); wq(1); wc(1, 58); wc(1, 123)
1313 kv_n(1, "open" as *u8, f[EVP_F_ABSENT]); wc(1, 44)
1314 kv_n(1, "named" as *u8, f[EVP_F_ABSNAMED]); wc(1, 44)
1315 kv_n(1, "unnamed" as *u8, f[EVP_F_ABSBARE])
1316 wc(1, 125); wc(1, 44)
1317 kv_n(1, "flips_ready" as *u8, f[EVP_F_LANDED]); wc(1, 44)
1318 // A PARTITION IS A CLAIM: PUBLISH THE PARTS AND THE SUM SO A LEAK CANNOT HIDE BEHIND A TOTAL.
1319 // reconciles is THREE-STATE on purpose -- 1 sums, 0 LEAKS, -1 not measurable from this stamp --
1320 // because a partition we could not check and one that failed are different facts.
1321 wq(1); w(1, "partition" as *u8); wq(1); wc(1, 58); wc(1, 123)
1322 kv_n(1, "grounded_plus_unsupported" as *u8, f[EVP_F_GROUNDED] + f[EVP_F_UNGROUND]); wc(1, 44)
1323 kv_n(1, "present_axes" as *u8, f[EVP_F_PRESENT]); wc(1, 44)
1324 kv_n(1, "named_plus_unnamed" as *u8, f[EVP_F_ABSNAMED] + f[EVP_F_ABSBARE]); wc(1, 44)
1325 kv_n(1, "open" as *u8, f[EVP_F_ABSENT]); wc(1, 44)
1326 kv_n(1, "reconciles" as *u8, evp_reconciles(f))
1327 wc(1, 125); wc(1, 44)
1328 // THE FAILING CONJUNCT, NAMED. A bare verdict is a disjunction and the reader always guesses the
1329 // alarming third; GPqN and gPQN are the same word and opposite work. evp_conj_char is the WRITER's
1330 // own function, so these letters cannot drift from the letters the referee stamped.
1331 wq(1); w(1, "conj" as *u8); wq(1); wc(1, 58); wq(1)
1332 wc(1, evp_conj_char(f[EVP_F_CJ_G], 71, 103))
1333 wc(1, evp_conj_char(f[EVP_F_CJ_P], 80, 112))
1334 wc(1, evp_conj_char(f[EVP_F_CJ_Q], 81, 113))
1335 wc(1, evp_conj_char(f[EVP_F_CJ_N], 78, 110))
1336 wq(1); wc(1, 44)
1337 kv_s(1, "first_failing_conjunct" as *u8, evp_conj_name(evp_conj_fail(f))); wc(1, 44)
1338 // WHICH DOCUMENT WAS GRADED. There are two knowledge trees and their copies of a matrix differ, so a
1339 // verdict that cannot name its subject document is not a verdict about the published board.
1340 wq(1); w(1, "graded_document" as *u8); wq(1); wc(1, 58); wc(1, 123)
1341 kv_s(1, "tree" as *u8, evp_tree_name(f[EVP_F_MROOT])); wc(1, 44)
1342 kv_n(1, "bytes" as *u8, f[EVP_F_MBYTES]); wc(1, 44)
1343 kv_n(1, "read_capped" as *u8, f[EVP_F_MCAPPED])
1344 wc(1, 125); wc(1, 44)
1345 kv_s(1, "gates_map_tree" as *u8, evp_tree_name(f[EVP_F_GATESROOT])); wc(1, 44)
1346 // THE GAP CLASSES THAT FIRE -- the machine half of the worklist. SEPARATE, NEVER MERGED: CLAIM-ONLY
1347 // needs a gate WRITTEN and GATE-FAILING needs one FIXED, and a single blended number sends a seat at
1348 // the wrong work. The remedy prose lives on the board page and is deliberately NOT copied here: two
1349 // copies of one sentence is a duplicate ruler that drifts on the first edit.
1350 wq(1); w(1, "classes" as *u8); wq(1); wc(1, 58); wc(1, 91)
1351 let cn: *i64 = sys_mmap(16) as *i64
1352 cn[0] = 0
1353 evj_class(evp_claim_only(f), "CLAIM-ONLY" as *u8, cn)
1354 evj_class(evp_gate_failing(f), "GATE-FAILING" as *u8, cn)
1355 evj_class(evp_fabricated(f), "UNSUPPORTED-CLAIM" as *u8, cn)
1356 evj_class(evp_flip_ready(f), "FLIP-READY" as *u8, cn)
1357 evj_class(evp_unnamed_gap(f), "UNNAMED-GAP" as *u8, cn)
1358 evj_class(evp_vacuous_gate(f), "VACUOUS-GATE" as *u8, cn)
1359 evj_class(stale, "STALE" as *u8, cn)
1360 wc(1, 93); wc(1, 44)
1361 kv_n(1, "classes_fired" as *u8, cn[0])
1362 wc(1, 125)
1363 return cn[0]
1364}
1365
1366// ---- MEASURED HEAD-TO-HEAD RECEIPTS (2026-09-01, lang leg) ---------------------------------------------
1367// OPERATOR: "meet and exceed gcc and rust and all the other languages independently verified with evidence
1368// documented and our /compare properly storing and making the evidence reproducible and visible and have that
1369// be an ecosystem wide capability". A performance number typed into a note is a CLAIM; this section renders a
1370// RECEIPT. knowledge/compare/<dom>.bench is written by a measuring organ (nx_lang_h2h for lang) and carries
1371// the host, every toolchain version, every source and binary sha256, min and median microseconds per arm, the
1372// checksum every arm had to agree on, and the exact command that regenerates it. ONE reader
1373// (nx_bench_receipt_lib) is shared by the writer, this renderer and the gate, and the verdict on the page is
1374// RE-DERIVED from the rows here, never copied from the file's own @verdict line -- the two are printed side by
1375// side and an agreement flag says whether the writer and the reader concur.
1376// ONE renderer in the base, BOTH generators call it (the refs_pass / plan_pass / watch_pass precedent), so a
1377// matrix board and a sota board publish the same bench dialect. A domain with no .bench emits NOTHING in both
1378// modes: every board without a receipt is byte-identical by construction.
1379const BD_SECS_PER_DAY: i64 = 86400
1380const BD_DAYS_TO_CIVIL_SHIFT: i64 = 719468 // days from 0000-03-01 to 1970-01-01 (Hinnant, civil_from_days)
1381const BD_DAYS_PER_ERA: i64 = 146097
1382const BD_DAYS_PER_4Y: i64 = 1460
1383const BD_DAYS_PER_100Y: i64 = 36524
1384const BD_DAYS_PER_ERA_LESS1: i64 = 146096
1385const BD_DAYS_PER_YEAR: i64 = 365
1386const BD_YEARS_PER_ERA: i64 = 400
1387const BD_MONTH_NUM: i64 = 153
1388const BD_MONTH_SHIFT: i64 = 2
1389const BD_MONTH_SCALE: i64 = 5
1390const BD_MARCH: i64 = 3
1391const BD_JAN_FROM_MP: i64 = 9
1392const BD_MP_WRAP: i64 = 10
1393const BD_FEB: i64 = 2
1394const BD_TEN: i64 = 10
1395const BD_SHA_SHOWN: i64 = 12
1396// YYYY-MM-DD from unix seconds (proleptic Gregorian, UTC); a non-positive epoch prints a dash
1397func bd_ymd(epoch: i64, dst: *u8, off: i64) -> i64 {
1398 if epoch <= 0 { return br_cat(dst, off, "-" as *u8) }
1399 let z: i64 = epoch / BD_SECS_PER_DAY + BD_DAYS_TO_CIVIL_SHIFT
1400 let era: i64 = z / BD_DAYS_PER_ERA
1401 let doe: i64 = z - era * BD_DAYS_PER_ERA
1402 let yoe: i64 = (doe - doe / BD_DAYS_PER_4Y + doe / BD_DAYS_PER_100Y - doe / BD_DAYS_PER_ERA_LESS1) / BD_DAYS_PER_YEAR
1403 let doy: i64 = doe - (BD_DAYS_PER_YEAR * yoe + yoe / 4 - yoe / 100)
1404 let mp: i64 = (BD_MONTH_SCALE * doy + BD_MONTH_SHIFT) / BD_MONTH_NUM
1405 let d: i64 = doy - (BD_MONTH_NUM * mp + BD_MONTH_SHIFT) / BD_MONTH_SCALE + 1
1406 var m: i64 = mp + BD_MARCH
1407 if mp >= BD_MP_WRAP { m = mp - BD_JAN_FROM_MP }
1408 var y: i64 = yoe + era * BD_YEARS_PER_ERA
1409 if m <= BD_FEB { y = y + 1 }
1410 var o: i64 = br_catn(dst, off, y)
1411 o = br_put(dst, o, 45)
1412 if m < BD_TEN { o = br_put(dst, o, 48) }
1413 o = br_catn(dst, o, m)
1414 o = br_put(dst, o, 45)
1415 if d < BD_TEN { o = br_put(dst, o, 48) }
1416 o = br_catn(dst, o, d)
1417 return o
1418}
1419// the first BD_SHA_SHOWN hex digits of a digest, or the whole thing when shorter
1420func bd_sha_short(fd: i64, s: *u8) -> i64 {
1421 var i: i64 = 0
1422 while s[i] != (0 as u8) { if i < BD_SHA_SHOWN { wc(fd, s[i] as i64) } i = i + 1 }
1423 return 0
1424}
1425func bd_status_class(st: i64) -> *u8 {
1426 if st == BR_ST_VALID { return "ok" as *u8 }
1427 if st == BR_ST_VOID { return "void" as *u8 }
1428 if st == BR_ST_UNMEASURABLE { return "unm" as *u8 }
1429 return "fail" as *u8
1430}
1431// ---- IM3 (intelmine, 2026-09-05): MINED INTELLIGENCE ON THE BOARD -- knowledge/compare/<dom>.proposed, rendered by the base for both generators ----
1432// nx_intelmine_propose routes review and competitive signals (nx_reviewmine_lib over Steam reviews under the
1433// exceeds / meets / mixed / does-not-meet rubric, the installed-title census) through capability_map.conf and APPENDS
1434// prop|epoch|appid|name|signal|kind|term|domain|rung-title|evidence (PR_NF fields; the writer dedupes on appid+kind+term)
1435// The proposer writes DATA and never a page. This is the ONE renderer, so every domain inherits the band on its next
1436// beat and a one-off report can never be built beside it (the grow-the-emitter law). An ABSENT file emits NOTHING --
1437// no section, no JSON key: an empty band would read as "the field has nothing to say", the one wrong answer nobody
1438// questions. A malformed row is COUNTED beside the rendered ones, never dropped in silence. A proposal is a LEAD, never
1439// a rung: it closes only when a rung with a gate lands, and the page says so in its own words.
1440const PR_READ_CAP: i64 = 65536 // announces when it binds; a .proposed file is rows, not a corpus
1441const PR_PATH_CAP: i64 = 600 // knowledge/compare/<dom>.proposed -- the reserve its sibling passes use
1442const PR_I64_BYTES: i64 = 8
1443const PR_NF: i64 = 10 // fields per prop| row, from the writer's own emit order (ip_emit)
1444const PR_SPLIT: i64 = 16 // field table: PR_NF plus room, so an over-long row is read whole rather than clipped to fit
1445const PR_F_TAG: i64 = 0
1446const PR_F_EPOCH: i64 = 1
1447const PR_F_APPID: i64 = 2
1448const PR_F_NAME: i64 = 3
1449const PR_F_SIGNAL: i64 = 4
1450const PR_F_KIND: i64 = 5
1451const PR_F_TERM: i64 = 6
1452const PR_F_DOMAIN: i64 = 7
1453const PR_F_TITLE: i64 = 8
1454const PR_F_EVIDENCE: i64 = 9
1455const PR_CH_COMMENT: i64 = 35
1456const PR_CH_LF: i64 = 10
1457const PR_CH_COMMA: i64 = 44
1458const PR_CH_COLON: i64 = 58
1459const PR_CH_LBRACE: i64 = 123
1460const PR_CH_RBRACE: i64 = 125
1461const PR_CH_LBRACKET: i64 = 91
1462const PR_CH_RBRACKET: i64 = 93
1463// RENDER-TIME TITLE (intelmine IM23/IM27, 2026-09-05): a row whose name column is its appid was written before any
1464// census or platform-api name existed, and the writer dedupes rows so it never rewrites them. The banked name
1465// (nx_steam_reviews name <appid> -> <appid>.name, one line) is read HERE instead, from the estate root as the mgmt
1466// daemon sees it AND from one directory up as the regen sees it (CWD = buildroot) -- the two-root read, announced
1467// per row as name_src=banked, never a silent guess. Absent in both: the row prints its appid and says so.
1468const PR_NAME_CAP: i64 = 256
1469const PR_NAME_DIR: *u8 = "knowledge/reviews/steam/"
1470const PR_NAME_DIR_UP: *u8 = "../knowledge/reviews/steam/"
1471const PR_NAME_SUFFIX: *u8 = ".name"
1472func pr_name_read(dir: *u8, appid: *u8, out: *u8, cap: i64) -> i64 {
1473 let path: *u8 = sys_mmap(PR_PATH_CAP)
1474 var o: i64 = scopy(path, 0, dir)
1475 o = scopy(path, o, appid); o = scopy(path, o, PR_NAME_SUFFIX); path[o] = 0 as u8
1476 let n: i64 = c_read(path, out, cap - 1)
1477 if n <= 0 { return 0 - 1 }
1478 var e: i64 = 0
1479 while e < n { if out[e] == (PR_CH_LF as u8) { break } e = e + 1 }
1480 out[e] = 0 as u8
1481 if e <= 0 { return 0 - 1 }
1482 return e
1483}
1484func pr_name_lookup(appid: *u8, out: *u8, cap: i64) -> i64 {
1485 let n: i64 = pr_name_read(PR_NAME_DIR, appid, out, cap)
1486 if n > 0 { return n }
1487 return pr_name_read(PR_NAME_DIR_UP, appid, out, cap)
1488}
1489func prop_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1490 let path: *u8 = sys_mmap(PR_PATH_CAP)
1491 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1492 o = scopy(path, o, dom); o = scopy(path, o, ".proposed" as *u8); path[o] = 0 as u8
1493 let buf: *u8 = sys_mmap(PR_READ_CAP)
1494 let n: i64 = c_read(path, buf, PR_READ_CAP - 1)
1495 if n <= 0 { return 0 }
1496 var capped: i64 = 0
1497 if n >= PR_READ_CAP - 1 { capped = 1 }
1498 buf[n] = 0 as u8
1499 let fld: *i64 = sys_mmap(PR_SPLIT * PR_I64_BYTES) as *i64
1500 if mode == 2 {
1501 wc(fd, PR_CH_COMMA); wq(fd); w(fd, "proposed" as *u8); wq(fd); wc(fd, PR_CH_COLON); wc(fd, PR_CH_LBRACE)
1502 kv_s(fd, "file" as *u8, path); wc(fd, PR_CH_COMMA)
1503 kv_s(fd, "writer" as *u8, "nx_intelmine_propose" as *u8); wc(fd, PR_CH_COMMA)
1504 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, PR_CH_COLON); wc(fd, PR_CH_LBRACKET)
1505 }
1506 if mode == 1 {
1507 w(fd, "<h2>Mined from the field — review and competitive intelligence proposed to this board</h2>\n" as *u8)
1508 if capped == 1 { w(fd, "<div class='meth'>proposed artefact READ-CAPPED at " as *u8); wn(fd, PR_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1509 w(fd, "<p class='lead'>Rows written by <code>nx_intelmine_propose</code> from <code>nx_reviewmine_lib</code> signals (Steam reviews under the exceeds / meets / mixed / does-not-meet rubric, the installed-title census) and routed here by <code>capability_map.conf</code>. <b>DEFECT</b> names a rival failing that a rung here answers; <b>DEMANDED</b> a capability buyers ask for and do not get; <b>WE-DO-BETTER</b> an exceed the reviews corroborate; <b>THEY-DO-WELL</b> a bar this board must meet; <b>SHIPS</b> a rival capability to match. <b>A proposal is a lead, never a rung</b> — it closes only when a rung with a gate lands, and nothing in this band changes a measured cell.</p>\n" as *u8)
1510 w(fd, "<table class='pl'><thead><tr><th>Signal</th><th>Kind</th><th>Term</th><th>Title</th><th>Proposed rung</th><th>Evidence</th></tr></thead><tbody>\n" as *u8)
1511 }
1512 var rows: i64 = 0
1513 var malformed: i64 = 0
1514 let nbuf: *u8 = sys_mmap(PR_NAME_CAP)
1515 var p: i64 = 0
1516 while p < n {
1517 var e: i64 = p
1518 while e < n { if buf[e] == (PR_CH_LF as u8) { break } e = e + 1 }
1519 buf[e] = 0 as u8
1520 let line: *u8 = (buf as i64 + p) as *u8
1521 p = e + 1
1522 if line[0] != (PR_CH_COMMENT as u8) { if line[0] != (0 as u8) {
1523 let nf: i64 = splitpipe(line, fld, PR_SPLIT)
1524 var ok: i64 = 0
1525 if nf >= PR_NF { if streq(fld[PR_F_TAG] as *u8, "prop" as *u8) == 1 { ok = 1 } }
1526 if ok == 0 { malformed = malformed + 1 } else {
1527 rows = rows + 1
1528 let name: *u8 = fld[PR_F_NAME] as *u8
1529 let appid: *u8 = fld[PR_F_APPID] as *u8
1530 // the proposer wrote the appid as the name when nothing named the title: try the banked name at render
1531 // time (name_src=banked), and only when that is absent too print the number AND say so (name_src=appid)
1532 var shown: *u8 = name
1533 var nsrc: *u8 = "row" as *u8
1534 if streq(name, appid) == 1 {
1535 nsrc = "appid" as *u8
1536 if pr_name_lookup(appid, nbuf, PR_NAME_CAP) > 0 { shown = nbuf; nsrc = "banked" as *u8 }
1537 }
1538 if mode == 1 {
1539 w(fd, "<tr><td><span class='ex'>" as *u8); wnote(fd, fld[PR_F_SIGNAL] as *u8); w(fd, "</span></td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_KIND] as *u8)
1540 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_TERM] as *u8); w(fd, "</td><td>" as *u8)
1541 if streq(nsrc, "appid" as *u8) == 1 { w(fd, "appid <span class='ct'>" as *u8); wnote(fd, appid); w(fd, "</span> (title unresolved: no census row and no banked name)" as *u8) } else { wnote(fd, shown); w(fd, " <span class='ct'>" as *u8); wnote(fd, appid); w(fd, "</span>" as *u8) }
1542 w(fd, "</td><td><b>" as *u8); wnote(fd, fld[PR_F_TITLE] as *u8); w(fd, "</b></td><td class='ct'>" as *u8); wnote(fd, fld[PR_F_EVIDENCE] as *u8); w(fd, "</td></tr>\n" as *u8)
1543 }
1544 if mode == 2 {
1545 if rows > 1 { wc(fd, PR_CH_COMMA) }
1546 wc(fd, PR_CH_LBRACE)
1547 kv_s(fd, "epoch" as *u8, fld[PR_F_EPOCH] as *u8); wc(fd, PR_CH_COMMA)
1548 kv_s(fd, "appid" as *u8, appid); wc(fd, PR_CH_COMMA)
1549 kv_s(fd, "name" as *u8, shown); wc(fd, PR_CH_COMMA)
1550 kv_s(fd, "name_src" as *u8, nsrc); wc(fd, PR_CH_COMMA)
1551 kv_s(fd, "signal" as *u8, fld[PR_F_SIGNAL] as *u8); wc(fd, PR_CH_COMMA)
1552 kv_s(fd, "kind" as *u8, fld[PR_F_KIND] as *u8); wc(fd, PR_CH_COMMA)
1553 kv_s(fd, "term" as *u8, fld[PR_F_TERM] as *u8); wc(fd, PR_CH_COMMA)
1554 kv_s(fd, "domain" as *u8, fld[PR_F_DOMAIN] as *u8); wc(fd, PR_CH_COMMA)
1555 kv_s(fd, "title" as *u8, fld[PR_F_TITLE] as *u8); wc(fd, PR_CH_COMMA)
1556 kv_s(fd, "evidence" as *u8, fld[PR_F_EVIDENCE] as *u8)
1557 wc(fd, PR_CH_RBRACE)
1558 }
1559 }
1560 } }
1561 }
1562 if mode == 1 {
1563 w(fd, "</tbody></table>\n<p class='stats'>proposals <b>" as *u8); wn(fd, rows); w(fd, "</b><span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed)
1564 w(fd, "</b> (counted, never rendered: a row that is not <code>prop|</code> with " as *u8); wn(fd, PR_NF); w(fd, " fields)<span class='sep'>|</span>read-capped <b>" as *u8); wn(fd, capped); w(fd, "</b></p>\n" as *u8)
1565 }
1566 if mode == 2 {
1567 wc(fd, PR_CH_RBRACKET); wc(fd, PR_CH_COMMA)
1568 kv_n(fd, "count" as *u8, rows); wc(fd, PR_CH_COMMA)
1569 kv_n(fd, "malformed" as *u8, malformed); wc(fd, PR_CH_COMMA)
1570 kv_n(fd, "read_capped" as *u8, capped)
1571 wc(fd, PR_CH_RBRACE)
1572 }
1573 return rows
1574}
1575// THE DISCOVERED FIELD (fieldwatch FW1, 2026-09-05; operator: the six columns "arent a good sample of the industry").
1576// knowledge/compare/<dom>.field is WRITTEN by nx_field_discover from <dom>.seeds -- public lists (Wikipedia wikitext,
1577// GitHub topics, awesome lists) read mechanically -- and rendered here by the ONE reader for both generators. The page
1578// shows the field, then measures the matrix's own @cols as a SUBSET of it: columns_in_field of columns, and how many
1579// discovered rivals have no column at all. A seat's pick is thereby shown for what it is. Absent file = no section.
1580const FI_READ_CAP: i64 = 262144 // announces when it binds: a .field is rows, not a corpus
1581const FI_PATH_CAP: i64 = 600
1582const FI_I64_BYTES: i64 = 8
1583const FI_NF: i64 = 7 // rival|name|seeds_hit|mentions|first_seed|link|kind (nx_field_lib fl_emit)
1584const FI_SPLIT: i64 = 12
1585const FI_F_TAG: i64 = 0
1586const FI_F_NAME: i64 = 1
1587const FI_F_SEEDS: i64 = 2
1588const FI_F_MENTIONS: i64 = 3
1589const FI_F_FIRST: i64 = 4
1590const FI_F_LINK: i64 = 5
1591const FI_F_KIND: i64 = 6
1592const FI_SHOW: i64 = 60 // rows rendered; the rest are COUNTED and the stats line says shown of count
1593const FI_COLS_MAX: i64 = 16
1594const FI_CH_COMMENT: i64 = 35
1595const FI_CH_LF: i64 = 10
1596const FI_CH_PIPE: i64 = 124
1597const FI_CH_COMMA: i64 = 44
1598const FI_CH_COLON: i64 = 58
1599const FI_CH_LBRACE: i64 = 123
1600const FI_CH_RBRACE: i64 = 125
1601const FI_CH_LBRACKET: i64 = 91
1602const FI_CH_RBRACKET: i64 = 93
1603const FI_UPPER_A: i64 = 65
1604const FI_UPPER_Z: i64 = 90
1605const FI_CASE_DELTA: i64 = 32
1606func fi_lc(c: i64) -> i64 { if c >= FI_UPPER_A { if c <= FI_UPPER_Z { return c + FI_CASE_DELTA } } return c }
1607// case-insensitive: does hay contain needle (needle non-empty)?
1608func fi_ci_contains(hay: *u8, needle: *u8) -> i64 {
1609 var nl: i64 = 0
1610 while needle[nl] != (0 as u8) { nl = nl + 1 }
1611 if nl < 1 { return 0 }
1612 var hl: i64 = 0
1613 while hay[hl] != (0 as u8) { hl = hl + 1 }
1614 var i: i64 = 0
1615 while i + nl <= hl {
1616 var m: i64 = 0
1617 var j: i64 = 0
1618 while j < nl { if fi_lc(hay[i + j] as i64) == fi_lc(needle[j] as i64) { m = m + 1 } j = j + 1 }
1619 if m == nl { return 1 }
1620 i = i + 1
1621 }
1622 return 0
1623}
1624// the leading words of a column label (up to the first space) -- "Blender 4.5 plus addons" matches a rival named Blender
1625func fi_head_word(col: *u8, out: *u8, cap: i64) -> i64 {
1626 var i: i64 = 0
1627 while col[i] != (0 as u8) { if col[i] == (32 as u8) { break } if i < cap - 1 { out[i] = col[i] } i = i + 1 }
1628 if i > cap - 1 { i = cap - 1 }
1629 out[i] = 0 as u8
1630 return i
1631}
1632// colv/ncols: the matrix generator's ALREADY-SPLIT @cols vector (one owner of the split); the sota generator passes 0/0.
1633func field_pass(dom: *u8, fd: i64, mode: i64, colv: *i64, ncols_in: i64) -> i64 {
1634 let path: *u8 = sys_mmap(FI_PATH_CAP)
1635 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1636 o = scopy(path, o, dom); o = scopy(path, o, ".field" as *u8); path[o] = 0 as u8
1637 let buf: *u8 = sys_mmap(FI_READ_CAP)
1638 let n: i64 = c_read(path, buf, FI_READ_CAP - 1)
1639 if n <= 0 { return 0 }
1640 var capped: i64 = 0
1641 if n >= FI_READ_CAP - 1 { capped = 1 }
1642 buf[n] = 0 as u8
1643 var ncols: i64 = ncols_in
1644 if ncols > FI_COLS_MAX { ncols = FI_COLS_MAX }
1645 if ncols < 0 { ncols = 0 }
1646 let colhit: *i64 = sys_mmap(FI_COLS_MAX * FI_I64_BYTES) as *i64
1647 let head: *u8 = sys_mmap(FI_PATH_CAP)
1648 let fld: *i64 = sys_mmap(FI_SPLIT * FI_I64_BYTES) as *i64
1649 var summary: *u8 = "" as *u8
1650 var rows: i64 = 0
1651 var shown: i64 = 0
1652 var malformed: i64 = 0
1653 var p: i64 = 0
1654 // pass 1: the summary row and the column coverage (every row, never a prefix)
1655 while p < n {
1656 var e: i64 = p
1657 while e < n { if buf[e] == (FI_CH_LF as u8) { break } e = e + 1 }
1658 buf[e] = 0 as u8
1659 let line: *u8 = (buf as i64 + p) as *u8
1660 p = e + 1
1661 if line[0] != (FI_CH_COMMENT as u8) { if line[0] != (0 as u8) {
1662 if starts(line, "field|" as *u8) == 1 { summary = line } else {
1663 let nf: i64 = splitpipe(line, fld, FI_SPLIT)
1664 var ok: i64 = 0
1665 if nf >= FI_NF { if streq(fld[FI_F_TAG] as *u8, "rival" as *u8) == 1 { ok = 1 } }
1666 if ok == 0 { malformed = malformed + 1 } else {
1667 rows = rows + 1
1668 var c: i64 = 0
1669 while c < ncols {
1670 if colhit[c] == 0 {
1671 fi_head_word(colv[c] as *u8, head, FI_PATH_CAP)
1672 if fi_ci_contains(fld[FI_F_NAME] as *u8, head) == 1 { colhit[c] = 1 }
1673 }
1674 c = c + 1
1675 }
1676 }
1677 }
1678 } }
1679 }
1680 var cols_in: i64 = 0
1681 var c2: i64 = 0
1682 while c2 < ncols { if colhit[c2] == 1 { cols_in = cols_in + 1 } c2 = c2 + 1 }
1683 // pass 2: render (re-read, because splitpipe NUL-terminates in place)
1684 let n2: i64 = c_read(path, buf, FI_READ_CAP - 1)
1685 buf[n2] = 0 as u8
1686 if mode == 2 {
1687 wc(fd, FI_CH_COMMA); wq(fd); w(fd, "field" as *u8); wq(fd); wc(fd, FI_CH_COLON); wc(fd, FI_CH_LBRACE)
1688 kv_s(fd, "file" as *u8, path); wc(fd, FI_CH_COMMA)
1689 kv_s(fd, "writer" as *u8, "nx_field_discover" as *u8); wc(fd, FI_CH_COMMA)
1690 kv_s(fd, "summary" as *u8, summary); wc(fd, FI_CH_COMMA)
1691 kv_n(fd, "columns" as *u8, ncols); wc(fd, FI_CH_COMMA)
1692 kv_n(fd, "columns_in_field" as *u8, cols_in); wc(fd, FI_CH_COMMA)
1693 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, FI_CH_COLON); wc(fd, FI_CH_LBRACKET)
1694 }
1695 if mode == 1 {
1696 w(fd, "<h2 id='field'>The field — discovered, not chosen</h2>\n" as *u8)
1697 if capped == 1 { w(fd, "<div class='meth'>field artefact READ-CAPPED at " as *u8); wn(fd, FI_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1698 w(fd, "<p class='lead'>Rows written by <code>nx_field_discover</code> from <code>" as *u8); wnote(fd, dom); w(fd, ".seeds</code>: the industry's own lists (Wikipedia wikitext, GitHub topics, awesome lists) read mechanically, every candidate counted across seeds. The matrix columns above are a SEAT'S pick; this band is the population they were picked from, and the stats line measures one against the other. A rival here is a lead, never a verdict — it earns a column when its capabilities are read and pinned.</p>\n" as *u8)
1699 w(fd, "<div class='meth'><code>" as *u8); wnote(fd, summary); w(fd, "</code></div>\n" as *u8)
1700 w(fd, "<table class='pl'><thead><tr><th>Rank</th><th>Rival</th><th>Seeds</th><th>Mentions</th><th>First seed</th><th>Kind</th><th>Link</th></tr></thead><tbody>\n" as *u8)
1701 }
1702 var p2: i64 = 0
1703 var rank: i64 = 0
1704 while p2 < n2 {
1705 var e: i64 = p2
1706 while e < n2 { if buf[e] == (FI_CH_LF as u8) { break } e = e + 1 }
1707 buf[e] = 0 as u8
1708 let line: *u8 = (buf as i64 + p2) as *u8
1709 p2 = e + 1
1710 if line[0] != (FI_CH_COMMENT as u8) { if line[0] != (0 as u8) { if starts(line, "rival|" as *u8) == 1 {
1711 let nf: i64 = splitpipe(line, fld, FI_SPLIT)
1712 if nf >= FI_NF { if shown < FI_SHOW {
1713 rank = rank + 1
1714 shown = shown + 1
1715 if mode == 1 {
1716 w(fd, "<tr><td class='ct'>" as *u8); wn(fd, rank); w(fd, "</td><td><b>" as *u8); wnote(fd, fld[FI_F_NAME] as *u8)
1717 w(fd, "</b></td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_SEEDS] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_MENTIONS] as *u8)
1718 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_FIRST] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_KIND] as *u8)
1719 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[FI_F_LINK] as *u8); w(fd, "</td></tr>\n" as *u8)
1720 }
1721 if mode == 2 {
1722 if shown > 1 { wc(fd, FI_CH_COMMA) }
1723 wc(fd, FI_CH_LBRACE)
1724 kv_s(fd, "name" as *u8, fld[FI_F_NAME] as *u8); wc(fd, FI_CH_COMMA)
1725 kv_s(fd, "seeds" as *u8, fld[FI_F_SEEDS] as *u8); wc(fd, FI_CH_COMMA)
1726 kv_s(fd, "mentions" as *u8, fld[FI_F_MENTIONS] as *u8); wc(fd, FI_CH_COMMA)
1727 kv_s(fd, "first_seed" as *u8, fld[FI_F_FIRST] as *u8); wc(fd, FI_CH_COMMA)
1728 kv_s(fd, "link" as *u8, fld[FI_F_LINK] as *u8); wc(fd, FI_CH_COMMA)
1729 kv_s(fd, "kind" as *u8, fld[FI_F_KIND] as *u8)
1730 wc(fd, FI_CH_RBRACE)
1731 }
1732 } }
1733 } } }
1734 }
1735 if mode == 1 {
1736 w(fd, "</tbody></table>\n<p class='stats'>field candidates <b>" as *u8); wn(fd, rows); w(fd, "</b><span class='sep'>|</span>shown <b>" as *u8); wn(fd, shown)
1737 w(fd, "</b> of " as *u8); wn(fd, rows); w(fd, "<span class='sep'>|</span>matrix columns in the field <b>" as *u8); wn(fd, cols_in); w(fd, "</b> of " as *u8); wn(fd, ncols)
1738 w(fd, "<span class='sep'>|</span>discovered rivals with no column <b>" as *u8); wn(fd, rows - cols_in); w(fd, "</b><span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed)
1739 w(fd, "</b> (counted, never rendered)<span class='sep'>|</span>read-capped <b>" as *u8); wn(fd, capped); w(fd, "</b></p>\n" as *u8)
1740 }
1741 if mode == 2 {
1742 wc(fd, FI_CH_RBRACKET); wc(fd, FI_CH_COMMA)
1743 kv_n(fd, "count" as *u8, rows); wc(fd, FI_CH_COMMA)
1744 kv_n(fd, "shown" as *u8, shown); wc(fd, FI_CH_COMMA)
1745 kv_n(fd, "no_column" as *u8, rows - cols_in); wc(fd, FI_CH_COMMA)
1746 kv_n(fd, "malformed" as *u8, malformed); wc(fd, FI_CH_COMMA)
1747 kv_n(fd, "read_capped" as *u8, capped)
1748 wc(fd, FI_CH_RBRACE)
1749 }
1750 return rows
1751}
1752// ---- GAUGE HEARTBEATS (codeeffectiveness CE9, 2026-09-06): A GAUGE CELL THAT READS STALE, NEVER ZERO ----
1753// <dom>.gauge rows: gauge|<label>|<stamp-path>|<cadence_s>|<note> (cadence_s 0 = take it from the stamp)
1754// WHY THIS IS IN THE BASE. The estate paid once for its effectiveness gauge going dark for 28 days and reading as
1755// "no movement": a number with no heartbeat is a claim with an expiry date nobody recorded. Every gauge row here is
1756// re-judged on every publish by THE ONE ruler the writing beat also uses (nx_gauge_lib.ga_judge), so the page and the
1757// beat cannot disagree: FRESH shows the value, STALE withholds it (age beyond two beats), BLIND withholds it (an axis
1758// abstained), ABSENT means nothing has measured. In api.json the "gauge" value key exists ONLY on a FRESH row -- a
1759// consumer that reads a missing key as zero is the defect this pass exists to make impossible on the page.
1760const GP_PATH_CAP: i64 = 600
1761const GP_READ_CAP: i64 = 65536
1762const GP_SPLIT: i64 = 8
1763const GP_NF: i64 = 5
1764const GP_F_LABEL: i64 = 1
1765const GP_F_PATH: i64 = 2
1766const GP_F_CAD: i64 = 3
1767const GP_F_NOTE: i64 = 4
1768const GP_ROW_CAP: i64 = 1024
1769const GP_CH_NL: i64 = 10
1770const GP_CH_HASH: i64 = 35
1771const GP_CH_COMMA: i64 = 44
1772const GP_CH_COLON: i64 = 58
1773const GP_CH_LBRACKET: i64 = 91
1774const GP_CH_RBRACKET: i64 = 93
1775const GP_CH_LBRACE: i64 = 123
1776const GP_CH_RBRACE: i64 = 125
1777func gauge_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1778 let path: *u8 = sys_mmap(GP_PATH_CAP)
1779 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
1780 o = scopy(path, o, dom); o = scopy(path, o, ".gauge" as *u8); path[o] = 0 as u8
1781 let buf: *u8 = sys_mmap(GP_READ_CAP)
1782 let n: i64 = c_read(path, buf, GP_READ_CAP - 1)
1783 if n <= 0 { return 0 }
1784 var capped: i64 = 0
1785 if n >= GP_READ_CAP - 1 { capped = 1 }
1786 let now: i64 = sys_now_realtime_sec()
1787 let fld: *i64 = sys_mmap(GP_SPLIT * GA_WORD) as *i64
1788 let f: *i64 = sys_mmap(GA_F_SLOTS * GA_WORD) as *i64
1789 let rb: *u8 = sys_mmap(GP_ROW_CAP)
1790 var rows: i64 = 0
1791 var malformed: i64 = 0
1792 var c_fresh: i64 = 0
1793 var c_stale: i64 = 0
1794 var c_blind: i64 = 0
1795 var c_absent: i64 = 0
1796 if mode == 2 {
1797 wc(fd, GP_CH_COMMA); wq(fd); w(fd, "gauge" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACE)
1798 kv_s(fd, "file" as *u8, path); wc(fd, GP_CH_COMMA)
1799 kv_s(fd, "reader" as *u8, "nx_gauge_lib" as *u8); wc(fd, GP_CH_COMMA)
1800 kv_n(fd, "now" as *u8, now); wc(fd, GP_CH_COMMA)
1801 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACKET)
1802 }
1803 if mode == 1 {
1804 w(fd, "<h2 id='gauge'>Gauges — a heartbeat, never a bare number</h2>\n" as *u8)
1805 if capped == 1 { w(fd, "<div class='meth'>gauge artefact READ-CAPPED at " as *u8); wn(fd, GP_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1806 w(fd, "<p class='lead'>Each row names a gauge stamp written by its measuring beat. This page re-judges the stamp on every publish with the same ruler the beat uses (<code>nx_gauge_lib</code>): <b>FRESH</b> shows the value; <b>STALE</b> withholds it (older than two beats); <b>BLIND</b> withholds it (an axis abstained); <b>ABSENT</b> means nothing has measured. A stale gauge never reads as zero.</p>\n" as *u8)
1807 w(fd, "<table class='gauge-tab'><thead><tr><th>gauge</th><th>state</th><th>reading</th><th>note</th></tr></thead><tbody>\n" as *u8)
1808 }
1809 var p: i64 = 0
1810 while p < n {
1811 var e: i64 = p
1812 while e < n { if buf[e] == (GP_CH_NL as u8) { break } e = e + 1 }
1813 buf[e] = 0 as u8
1814 let line: *u8 = (buf as i64 + p) as *u8
1815 p = e + 1
1816 if line[0] != (GP_CH_HASH as u8) { if line[0] != (0 as u8) { if starts(line, "gauge|" as *u8) == 1 {
1817 let nf: i64 = splitpipe(line, fld, GP_SPLIT)
1818 if nf < GP_NF { malformed = malformed + 1 } else {
1819 let cs: *u8 = fld[GP_F_CAD] as *u8
1820 let cad: i64 = sj_atoi_span(cs, 0, sj_vlen(cs))
1821 // RESOLVE BEFORE JUDGING (2026-09-06): the regen runs with CWD=buildroot while every beat stamps from the serving root, so a
1822 // bare stamp path read ABSENT on the page for a stamp FRESH on disk (measured: knowledge/status/stepsolve.stamp 66 B at the
1823 // root, absent under buildroot). ep_artifact_path is the ONE probe order; an absent stamp still judges ABSENT through the same ruler.
1824 let gpath: *u8 = sys_mmap(GP_PATH_CAP)
1825 if ep_artifact_path(gpath, fld[GP_F_PATH] as *u8) == 0 { let go: i64 = scopy(gpath, 0, fld[GP_F_PATH] as *u8); gpath[go] = 0 as u8 }
1826 let st: i64 = ga_judge(gpath, now, cad, f)
1827 var age: i64 = 0 - 1
1828 if f[GA_F_TS] > 0 { age = now - f[GA_F_TS] }
1829 var mcad: i64 = cad
1830 if mcad <= 0 { mcad = f[GA_F_CADENCE] }
1831 let rl: i64 = ga_render(rb, 0, st, age, ga_max_age(mcad), f[GA_F_GAUGE], f[GA_F_KNOWN], f[GA_F_TOTAL])
1832 rb[rl] = 0 as u8
1833 if st == GA_FRESH { c_fresh = c_fresh + 1 }
1834 if st == GA_STALE { c_stale = c_stale + 1 }
1835 if st == GA_BLIND { c_blind = c_blind + 1 }
1836 if st == GA_ABSENT { c_absent = c_absent + 1 }
1837 if mode == 1 {
1838 w(fd, "<tr><td><b>" as *u8); wnote(fd, fld[GP_F_LABEL] as *u8); w(fd, "</b></td><td class='ct'>" as *u8); w(fd, ga_state_name(st))
1839 w(fd, "</td><td class='ct'>" as *u8); wnote(fd, rb); w(fd, "</td><td>" as *u8); wnote(fd, fld[GP_F_NOTE] as *u8); w(fd, "</td></tr>\n" as *u8)
1840 }
1841 if mode == 2 {
1842 if rows > 0 { wc(fd, GP_CH_COMMA) }
1843 wc(fd, GP_CH_LBRACE)
1844 kv_s(fd, "label" as *u8, fld[GP_F_LABEL] as *u8); wc(fd, GP_CH_COMMA)
1845 kv_s(fd, "stamp" as *u8, fld[GP_F_PATH] as *u8); wc(fd, GP_CH_COMMA)
1846 kv_s(fd, "state" as *u8, ga_state_name(st)); wc(fd, GP_CH_COMMA)
1847 kv_n(fd, "age_s" as *u8, age); wc(fd, GP_CH_COMMA)
1848 kv_n(fd, "max_age_s" as *u8, ga_max_age(mcad)); wc(fd, GP_CH_COMMA)
1849 kv_n(fd, "axes_known" as *u8, f[GA_F_KNOWN]); wc(fd, GP_CH_COMMA)
1850 kv_n(fd, "axes_total" as *u8, f[GA_F_TOTAL]); wc(fd, GP_CH_COMMA)
1851 if st == GA_FRESH { kv_n(fd, "gauge" as *u8, f[GA_F_GAUGE]); wc(fd, GP_CH_COMMA) }
1852 kv_s(fd, "reading" as *u8, rb); wc(fd, GP_CH_COMMA)
1853 kv_s(fd, "note" as *u8, fld[GP_F_NOTE] as *u8)
1854 wc(fd, GP_CH_RBRACE)
1855 }
1856 rows = rows + 1
1857 }
1858 } } }
1859 }
1860 if mode == 2 {
1861 wc(fd, GP_CH_RBRACKET); wc(fd, GP_CH_COMMA)
1862 kv_n(fd, "count" as *u8, rows); wc(fd, GP_CH_COMMA)
1863 kv_n(fd, "fresh" as *u8, c_fresh); wc(fd, GP_CH_COMMA)
1864 kv_n(fd, "stale" as *u8, c_stale); wc(fd, GP_CH_COMMA)
1865 kv_n(fd, "blind" as *u8, c_blind); wc(fd, GP_CH_COMMA)
1866 kv_n(fd, "absent" as *u8, c_absent); wc(fd, GP_CH_COMMA)
1867 kv_n(fd, "malformed" as *u8, malformed); wc(fd, GP_CH_COMMA)
1868 kv_n(fd, "read_capped" as *u8, capped)
1869 wc(fd, GP_CH_RBRACE)
1870 }
1871 if mode == 1 {
1872 w(fd, "</tbody></table>\n<p class='stats'>gauges <b>" as *u8); wn(fd, rows)
1873 w(fd, "</b><span class='sep'>|</span>fresh <b>" as *u8); wn(fd, c_fresh); w(fd, "</b><span class='sep'>|</span>stale <b>" as *u8); wn(fd, c_stale)
1874 w(fd, "</b><span class='sep'>|</span>blind <b>" as *u8); wn(fd, c_blind); w(fd, "</b><span class='sep'>|</span>absent <b>" as *u8); wn(fd, c_absent)
1875 w(fd, "</b> (partition sums)<span class='sep'>|</span>malformed rows <b>" as *u8); wn(fd, malformed); w(fd, "</b> (counted, never rendered)</p>\n" as *u8)
1876 }
1877 return rows
1878}
1879// ---- GAPS FROM THE RECORD (ecosystem EC38, 2026-09-06) ------------------------------------------------------
1880// Renders the record census (nx_goalmap record): organs the estate invokes and directives its own plan queue rows
1881// name that NO board row carries. The feed is the plane's own bytes written beside the conf by the same run
1882// (knowledge/recordgaps.conf.rows), resolved through ep_artifact_path like every status artifact, and its freshness
1883// is judged from the sibling stamp with the ONE gauge ruler: a stale census renders its rows under a STALE state
1884// and a BLIND one says how many declared sources are still unread; neither ever reads as "no gaps".
1885// Per board: this board's own directive rows (board == dom) always; the estate-wide UNASSIGNED organs in full on
1886// the ecosystem hub and as a COUNT everywhere else (hundreds of rows on every page would be the site saying one
1887// thing a hundred times). mode 1 = HTML section, mode 2 = api.json object. Absent feed = no section, returns 0.
1888const GX_FEED: *u8 = "knowledge/recordgaps.conf.rows"
1889const GX_STAMP: *u8 = "knowledge/recordgaps.conf.stamp"
1890const GX_READ_CAP: i64 = 4194304
1891const GX_NF: i64 = 5
1892const GX_F_KIND: i64 = 0
1893const GX_F_NAME: i64 = 1
1894const GX_F_BOARD: i64 = 2
1895const GX_F_SRC: i64 = 3
1896const GX_F_EV: i64 = 4
1897const GX_HUB: *u8 = "ecosystem"
1898const GX_UNASSIGNED: *u8 = "UNASSIGNED"
1899func gaps_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1900 let path: *u8 = sys_mmap(GP_PATH_CAP)
1901 if ep_artifact_path(path, GX_FEED) == 0 { return 0 }
1902 let buf: *u8 = sys_mmap(GX_READ_CAP)
1903 let n: i64 = c_read(path, buf, GX_READ_CAP - 1)
1904 if n <= 0 { return 0 }
1905 var capped: i64 = 0
1906 if n >= GX_READ_CAP - 1 { capped = 1 }
1907 let now: i64 = sys_now_realtime_sec()
1908 let spath: *u8 = sys_mmap(GP_PATH_CAP)
1909 if ep_artifact_path(spath, GX_STAMP) == 0 { let so: i64 = scopy(spath, 0, GX_STAMP); spath[so] = 0 as u8 }
1910 let f: *i64 = sys_mmap(GA_F_SLOTS * GA_WORD) as *i64
1911 var st: i64 = ga_judge(spath, now, 0, f)
1912 if f[GA_F_CADENCE] > 0 { st = ga_judge(spath, now, f[GA_F_CADENCE], f) }
1913 var age: i64 = 0 - 1
1914 if f[GA_F_TS] > 0 { age = now - f[GA_F_TS] }
1915 let fld: *i64 = sys_mmap(GP_SPLIT * GA_WORD) as *i64
1916 var hub: i64 = 0
1917 if streq(dom, GX_HUB) == 1 { hub = 1 }
1918 var total: i64 = 0
1919 var own: i64 = 0
1920 var unassigned: i64 = 0
1921 var malformed: i64 = 0
1922 var shown: i64 = 0
1923 if mode == 2 {
1924 wc(fd, GP_CH_COMMA); wq(fd); w(fd, "gaps" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACE)
1925 kv_s(fd, "feed" as *u8, path); wc(fd, GP_CH_COMMA)
1926 kv_s(fd, "stamp" as *u8, spath); wc(fd, GP_CH_COMMA)
1927 kv_s(fd, "state" as *u8, ga_state_name(st)); wc(fd, GP_CH_COMMA)
1928 kv_n(fd, "age_s" as *u8, age); wc(fd, GP_CH_COMMA)
1929 kv_n(fd, "sources_read" as *u8, f[GA_F_KNOWN]); wc(fd, GP_CH_COMMA)
1930 kv_n(fd, "sources_declared" as *u8, f[GA_F_TOTAL]); wc(fd, GP_CH_COMMA)
1931 kv_n(fd, "hub" as *u8, hub); wc(fd, GP_CH_COMMA)
1932 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, GP_CH_COLON); wc(fd, GP_CH_LBRACKET)
1933 }
1934 if mode == 1 {
1935 w(fd, "<h2 id='gaps'>Gaps from the record — what the estate does that no board carries</h2>\n" as *u8)
1936 w(fd, "<p class='lead'>The record census (<code>nx_goalmap record</code>) reads the invoked-tool population and every plan queue row and files each organ or directive that NO matrix, plan or gates row names. A row here is a callout the boards missed: adjudicate it onto a board or declare it infrastructure. Census state <b>" as *u8)
1937 w(fd, ga_state_name(st)); w(fd, "</b>" as *u8)
1938 if age >= 0 { w(fd, " (age " as *u8); wn(fd, age); w(fd, " s)" as *u8) }
1939 w(fd, ", sources read <b>" as *u8); wn(fd, f[GA_F_KNOWN]); w(fd, "</b> of <b>" as *u8); wn(fd, f[GA_F_TOTAL])
1940 w(fd, "</b> declared — a BLIND census is a FLOOR: unread sources can only add rows.</p>\n" as *u8)
1941 if capped == 1 { w(fd, "<div class='meth'>feed READ-CAPPED at " as *u8); wn(fd, GX_READ_CAP); w(fd, " bytes — the rows below are a PREFIX of the file</div>\n" as *u8) }
1942 w(fd, "<table class='gaps-tab'><thead><tr><th>kind</th><th>name</th><th>board</th><th>source</th><th>evidence</th></tr></thead><tbody>\n" as *u8)
1943 }
1944 var p: i64 = 0
1945 while p < n {
1946 var e: i64 = p
1947 while e < n { if buf[e] == (GP_CH_NL as u8) { break } e = e + 1 }
1948 buf[e] = 0 as u8
1949 let line: *u8 = (buf as i64 + p) as *u8
1950 p = e + 1
1951 if line[0] != (GP_CH_HASH as u8) { if line[0] != (0 as u8) {
1952 let nf: i64 = splitpipe(line, fld, GP_SPLIT)
1953 if nf < GX_NF { malformed = malformed + 1 } else {
1954 total = total + 1
1955 var render: i64 = 0
1956 if streq(fld[GX_F_BOARD] as *u8, dom) == 1 { own = own + 1; render = 1 }
1957 if streq(fld[GX_F_BOARD] as *u8, GX_UNASSIGNED) == 1 { unassigned = unassigned + 1; if hub == 1 { render = 1 } }
1958 if render == 1 {
1959 if mode == 1 {
1960 w(fd, "<tr><td class='ct'>" as *u8); wnote(fd, fld[GX_F_KIND] as *u8); w(fd, "</td><td><code>" as *u8); wnote(fd, fld[GX_F_NAME] as *u8)
1961 w(fd, "</code></td><td class='ct'>" as *u8); wnote(fd, fld[GX_F_BOARD] as *u8); w(fd, "</td><td class='ct'>" as *u8); wnote(fd, fld[GX_F_SRC] as *u8)
1962 w(fd, "</td><td>" as *u8); wnote(fd, fld[GX_F_EV] as *u8); w(fd, "</td></tr>\n" as *u8)
1963 }
1964 if mode == 2 {
1965 if shown > 0 { wc(fd, GP_CH_COMMA) }
1966 wc(fd, GP_CH_LBRACE)
1967 kv_s(fd, "kind" as *u8, fld[GX_F_KIND] as *u8); wc(fd, GP_CH_COMMA)
1968 kv_s(fd, "name" as *u8, fld[GX_F_NAME] as *u8); wc(fd, GP_CH_COMMA)
1969 kv_s(fd, "board" as *u8, fld[GX_F_BOARD] as *u8); wc(fd, GP_CH_COMMA)
1970 kv_s(fd, "source" as *u8, fld[GX_F_SRC] as *u8); wc(fd, GP_CH_COMMA)
1971 kv_s(fd, "evidence" as *u8, fld[GX_F_EV] as *u8)
1972 wc(fd, GP_CH_RBRACE)
1973 }
1974 shown = shown + 1
1975 }
1976 }
1977 } }
1978 }
1979 if mode == 2 {
1980 wc(fd, GP_CH_RBRACKET); wc(fd, GP_CH_COMMA)
1981 kv_n(fd, "shown" as *u8, shown); wc(fd, GP_CH_COMMA)
1982 kv_n(fd, "own" as *u8, own); wc(fd, GP_CH_COMMA)
1983 kv_n(fd, "estate_unassigned" as *u8, unassigned); wc(fd, GP_CH_COMMA)
1984 kv_n(fd, "total" as *u8, total); wc(fd, GP_CH_COMMA)
1985 kv_n(fd, "malformed" as *u8, malformed); wc(fd, GP_CH_COMMA)
1986 kv_n(fd, "read_capped" as *u8, capped)
1987 wc(fd, GP_CH_RBRACE)
1988 }
1989 if mode == 1 {
1990 w(fd, "</tbody></table>\n<p class='stats'>rows shown <b>" as *u8); wn(fd, shown)
1991 w(fd, "</b><span class='sep'>|</span>this board's directives <b>" as *u8); wn(fd, own)
1992 w(fd, "</b><span class='sep'>|</span>estate-wide un-boarded organs <b>" as *u8); wn(fd, unassigned)
1993 if hub == 0 { w(fd, "</b> (listed in full on <a href='/compare/ecosystem'>/compare/ecosystem</a>)<span class='sep'>|</span>census rows <b>" as *u8) } else { w(fd, "</b><span class='sep'>|</span>census rows <b>" as *u8) }
1994 wn(fd, total); w(fd, "</b><span class='sep'>|</span>malformed <b>" as *u8); wn(fd, malformed); w(fd, "</b> (counted, never rendered)</p>\n" as *u8)
1995 }
1996 return shown
1997}
1998func bench_pass(dom: *u8, fd: i64, mode: i64) -> i64 {
1999 let path: *u8 = sys_mmap(600)
2000 var o: i64 = scopy(path, 0, "knowledge/compare/" as *u8)
2001 o = scopy(path, o, dom); o = scopy(path, o, ".bench" as *u8); path[o] = 0 as u8
2002 let hdr: *i64 = sys_mmap(BR_H_N * 8) as *i64
2003 let arms: *i64 = sys_mmap(BR_MAXARMS * BR_STRIDE * 8) as *i64
2004 let n: i64 = br_load(path, hdr, arms)
2005 if n < 0 { return 0 }
2006 let verdict: i64 = br_verdict(hdr, arms, n)
2007 let written: i64 = hdr[BR_H_WRITTEN_VERDICT]
2008 var agree: i64 = 0
2009 if written == verdict { agree = 1 }
2010 var c_valid: i64 = 0; var c_void: i64 = 0; var c_unm: i64 = 0; var c_bf: i64 = 0; var c_rf: i64 = 0; var c_unk: i64 = 0
2011 var i: i64 = 0
2012 while i < n {
2013 let st: i64 = arms[i * BR_STRIDE + BR_A_STATUS]
2014 if st == BR_ST_VALID { c_valid = c_valid + 1 } else { if st == BR_ST_VOID { c_void = c_void + 1 } else {
2015 if st == BR_ST_UNMEASURABLE { c_unm = c_unm + 1 } else { if st == BR_ST_BUILDFAIL { c_bf = c_bf + 1 } else {
2016 if st == BR_ST_RUNFAIL { c_rf = c_rf + 1 } else { c_unk = c_unk + 1 } } } } }
2017 i = i + 1
2018 }
2019 let ymd: *u8 = sys_mmap(32)
2020 bd_ymd(hdr[BR_H_ASOF], ymd, 0)
2021 let rt: *u8 = sys_mmap(32)
2022 if mode == 2 {
2023 wc(fd, 44); wq(fd); w(fd, "bench" as *u8); wq(fd); wc(fd, 58); wc(fd, 123)
2024 kv_s(fd, "file" as *u8, path); wc(fd, 44)
2025 kv_s(fd, "reader" as *u8, "nx_bench_receipt_lib" as *u8); wc(fd, 44)
2026 kv_s(fd, "writer" as *u8, hdr[BR_H_WRITER] as *u8); wc(fd, 44)
2027 kv_s(fd, "title" as *u8, hdr[BR_H_TITLE] as *u8); wc(fd, 44)
2028 kv_s(fd, "workload" as *u8, hdr[BR_H_WORKLOAD] as *u8); wc(fd, 44)
2029 kv_s(fd, "host" as *u8, hdr[BR_H_HOST] as *u8); wc(fd, 44)
2030 kv_n(fd, "runs" as *u8, hdr[BR_H_RUNS]); wc(fd, 44)
2031 kv_s(fd, "ref" as *u8, hdr[BR_H_REF] as *u8); wc(fd, 44)
2032 kv_n(fd, "asof" as *u8, hdr[BR_H_ASOF]); wc(fd, 44)
2033 kv_s(fd, "asof_ymd" as *u8, ymd); wc(fd, 44)
2034 kv_s(fd, "repro" as *u8, hdr[BR_H_REPRO] as *u8); wc(fd, 44)
2035 kv_s(fd, "verdict" as *u8, br_verdict_name(verdict)); wc(fd, 44)
2036 kv_s(fd, "written_verdict" as *u8, br_verdict_name(written)); wc(fd, 44)
2037 kv_n(fd, "writer_reader_agree" as *u8, agree); wc(fd, 44)
2038 kv_n(fd, "arms" as *u8, n); wc(fd, 44)
2039 kv_n(fd, "valid" as *u8, c_valid); wc(fd, 44); kv_n(fd, "void" as *u8, c_void); wc(fd, 44)
2040 kv_n(fd, "unmeasurable" as *u8, c_unm); wc(fd, 44); kv_n(fd, "build_fail" as *u8, c_bf); wc(fd, 44)
2041 kv_n(fd, "run_fail" as *u8, c_rf); wc(fd, 44); kv_n(fd, "unknown" as *u8, c_unk); wc(fd, 44)
2042 wq(fd); w(fd, "rows" as *u8); wq(fd); wc(fd, 58); wc(fd, 91)
2043 var j: i64 = 0
2044 while j < n {
2045 let b: i64 = j * BR_STRIDE
2046 if j > 0 { wc(fd, 44) }
2047 wc(fd, 123)
2048 kv_s(fd, "arm" as *u8, arms[b + BR_A_NAME] as *u8); wc(fd, 44)
2049 kv_s(fd, "toolchain" as *u8, arms[b + BR_A_TOOL] as *u8); wc(fd, 44)
2050 kv_s(fd, "version" as *u8, arms[b + BR_A_VER] as *u8); wc(fd, 44)
2051 kv_s(fd, "source" as *u8, arms[b + BR_A_SRC] as *u8); wc(fd, 44)
2052 kv_s(fd, "source_sha256" as *u8, arms[b + BR_A_SRCSHA] as *u8); wc(fd, 44)
2053 kv_n(fd, "bin_bytes" as *u8, arms[b + BR_A_BINBYTES]); wc(fd, 44)
2054 kv_s(fd, "bin_sha256" as *u8, arms[b + BR_A_BINSHA] as *u8); wc(fd, 44)
2055 kv_n(fd, "runs" as *u8, arms[b + BR_A_RUNS]); wc(fd, 44)
2056 kv_n(fd, "min_us" as *u8, arms[b + BR_A_MIN]); wc(fd, 44)
2057 kv_n(fd, "median_us" as *u8, arms[b + BR_A_MED]); wc(fd, 44)
2058 kv_n(fd, "checksum" as *u8, arms[b + BR_A_CHK]); wc(fd, 44)
2059 kv_s(fd, "status" as *u8, br_status_name(arms[b + BR_A_STATUS])); wc(fd, 44)
2060 kv_n(fd, "ratio_permil" as *u8, arms[b + BR_A_RATIO]); wc(fd, 44)
2061 kv_s(fd, "note" as *u8, arms[b + BR_A_NOTE] as *u8)
2062 wc(fd, 125)
2063 j = j + 1
2064 }
2065 wc(fd, 93)
2066 wc(fd, 125)
2067 return n
2068 }
2069 if mode == 1 {
2070 // scoped style so the section renders identically under both generators' sheets; theme vars with fallbacks
2071 w(fd, "<style>.bench-tab{width:100%;border-collapse:collapse;font-size:.84rem}.bench-tab th,.bench-tab td{text-align:left;padding:6px 8px;border-bottom:1px solid var(--line,rgb(60,64,72));vertical-align:top}.bench-tab th{font-size:.7rem;letter-spacing:.08em;text-transform:uppercase;color:var(--mut,rgb(150,162,186))}.bench-tab td.num{font-variant-numeric:tabular-nums;text-align:right;white-space:nowrap}.bench-tab code{font-family:ui-monospace,Consolas,monospace;font-size:.78rem}.bst{font-size:.66rem;letter-spacing:.08em;text-transform:uppercase;font-weight:650;padding:2px 8px;border-radius:8px;display:inline-block;white-space:nowrap;border:1px solid var(--line,rgb(60,64,72))}.bst.ok{color:var(--nx-color-ok,rgb(26,127,55))}.bst.void{color:var(--nx-color-absent,rgb(179,38,30))}.bst.unm{color:var(--mut,rgb(150,162,186))}.bst.fail{color:var(--nx-color-part,rgb(178,106,0))}.bench-repro{font-family:ui-monospace,Consolas,monospace;font-size:.78rem;background:var(--soft,rgb(40,46,64));padding:8px 10px;border-radius:8px;overflow-x:auto;white-space:pre}.bench-ref{font-weight:600}</style>\n" as *u8)
2072 w(fd, "<h2 class='ghead' id='bench'>Measured head-to-head — a receipt, not a claim</h2>\n<div class='meth'><b>" as *u8); wnote(fd, hdr[BR_H_TITLE] as *u8); w(fd, ".</b> " as *u8); wnote(fd, hdr[BR_H_WORKLOAD] as *u8)
2073 w(fd, " Measured on <code>" as *u8); wnote(fd, hdr[BR_H_HOST] as *u8); w(fd, "</code> on " as *u8); w(fd, ymd); w(fd, " (unix " as *u8); wn(fd, hdr[BR_H_ASOF]); w(fd, "), " as *u8); wn(fd, hdr[BR_H_RUNS]); w(fd, " runs per arm, reference arm <span class='bench-ref'>" as *u8); wnote(fd, hdr[BR_H_REF] as *u8)
2074 w(fd, "</span> = 1.00x. Every arm had to print the same checksum or its row is VOID and never ranked; an arm whose toolchain is not declared on the host is UNMEASURABLE, an absence rather than a loss. Written by <code>" as *u8); wnote(fd, hdr[BR_H_WRITER] as *u8); w(fd, "</code>, re-derived here by <code>nx_bench_receipt_lib</code>: reader verdict <span class='bst " as *u8)
2075 if verdict == BR_V_VALID { w(fd, "ok" as *u8) } else { if verdict == BR_V_VOID { w(fd, "void" as *u8) } else { w(fd, "unm" as *u8) } }
2076 w(fd, "'>" as *u8); w(fd, br_verdict_name(verdict)); w(fd, "</span>, writer wrote " as *u8); w(fd, br_verdict_name(written))
2077 if agree == 1 { w(fd, " (writer and reader agree)" as *u8) } else { w(fd, " (<b>WRITER AND READER DISAGREE</b> -- the rows were edited after the receipt was written)" as *u8) }
2078 w(fd, ".</div>\n<div style='overflow-x:auto'><table class='bench-tab'><thead><tr><th>Arm</th><th>Toolchain</th><th>Version</th><th>Median µs</th><th>Min µs</th><th>vs reference</th><th>Checksum</th><th>Status</th><th>Runs</th><th>Source sha256</th><th>Binary</th></tr></thead><tbody>\n" as *u8)
2079 var k: i64 = 0
2080 while k < n {
2081 let b: i64 = k * BR_STRIDE
2082 let st: i64 = arms[b + BR_A_STATUS]
2083 w(fd, "<tr><td><b>" as *u8); wnote(fd, arms[b + BR_A_NAME] as *u8); w(fd, "</b></td><td>" as *u8); wnote(fd, arms[b + BR_A_TOOL] as *u8)
2084 w(fd, "</td><td><code>" as *u8); wnote(fd, arms[b + BR_A_VER] as *u8); w(fd, "</code></td><td class='num'>" as *u8)
2085 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_MED]) } else { w(fd, "-" as *u8) }
2086 w(fd, "</td><td class='num'>" as *u8)
2087 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_MIN]) } else { w(fd, "-" as *u8) }
2088 w(fd, "</td><td class='num'>" as *u8)
2089 br_ratio_text(arms[b + BR_A_RATIO], rt, 0); w(fd, rt)
2090 w(fd, "</td><td class='num'>" as *u8)
2091 if st == BR_ST_VALID { wn(fd, arms[b + BR_A_CHK]) } else { if st == BR_ST_VOID { wn(fd, arms[b + BR_A_CHK]) } else { w(fd, "-" as *u8) } }
2092 w(fd, "</td><td><span class='bst " as *u8); w(fd, bd_status_class(st)); w(fd, "'>" as *u8); w(fd, br_status_name(st)); w(fd, "</span>" as *u8)
2093 if st != BR_ST_VALID { w(fd, "<br><span class='ct'>" as *u8); wnote(fd, arms[b + BR_A_NOTE] as *u8); w(fd, "</span>" as *u8) }
2094 w(fd, "</td><td class='num'>" as *u8); wn(fd, arms[b + BR_A_RUNS])
2095 w(fd, "</td><td><code title='" as *u8); wnote(fd, arms[b + BR_A_SRC] as *u8); w(fd, "'>" as *u8); bd_sha_short(fd, arms[b + BR_A_SRCSHA] as *u8); w(fd, "</code></td><td class='num'><code>" as *u8); bd_sha_short(fd, arms[b + BR_A_BINSHA] as *u8); w(fd, "</code> " as *u8); wn(fd, arms[b + BR_A_BINBYTES]); w(fd, " B</td></tr>\n" as *u8)
2096 k = k + 1
2097 }
2098 w(fd, "</tbody></table></div>\n<p class='foot'>bench arms=" as *u8); wn(fd, n); w(fd, " valid=" as *u8); wn(fd, c_valid); w(fd, " void=" as *u8); wn(fd, c_void); w(fd, " unmeasurable=" as *u8); wn(fd, c_unm); w(fd, " build_fail=" as *u8); wn(fd, c_bf); w(fd, " run_fail=" as *u8); wn(fd, c_rf); w(fd, " unknown=" as *u8); wn(fd, c_unk); w(fd, " (partition sums) verdict=" as *u8); w(fd, br_verdict_name(verdict)); w(fd, "</p>\n" as *u8)
2099 w(fd, "<p class='foot'>reproduce: </p><div class='bench-repro'>" as *u8); wnote(fd, hdr[BR_H_REPRO] as *u8); w(fd, "</div>\n<p class='foot'>receipt: knowledge/compare/" as *u8); w(fd, dom); w(fd, ".bench · a rerun on the same host that changes the ranking is a finding, not noise; a rerun on a different host is a different receipt and says so in its host line.</p>\n" as *u8)
2100 return n
2101 }
2102 return n
2103}