Nishi FamilyCompare › Nishi Dependency Design vs Reference Architectures -- MEASURED with the field's instruments

Nishi Compare · measured, not asserted

Nishi Dependency Design vs Reference Architectures -- MEASURED with the field's instruments

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

Answering "is nx_syscalls supposed to have this design?" with data (nx_eco_graph_arch, 0.24s over 16,222 organs / 42,088 edges): ONE 2-organ cycle in the whole ecosystem, propagation cost 0.5% (Linux 5-18%, Mozilla ~17% on the same MacCormack instrument), nx_syscalls 81% direct fan-in = the libc stable-base pattern, 61% of organs one hop off the base. Verdict: the shape is SOUND (libc-pattern base + periphery-dominated coupling); the honest gaps are the guardrails that KEEP it sound.

Overview

The purpose, declared position and evidence coverage of this domain. Source presence and completed acceptance are different measures.

Where we are. The dependency shape is SOUND and measured with the field's own instruments in 0.24 s over 16,222 organs: propagation cost 0.5 percent (Linux 5-18 on the same MacCormack instrument), one 2-organ cycle in the whole ecosystem (exceed), a libc-pattern universal base at 81 percent fan-in, a living self-graph only the Google monorepo compares to, self-review with field instruments (exceed), mechanical liveness classification and a gate-per-organ validation culture. The honest gaps are the GUARDRAILS that keep it sound: no sworn base-change contract, no cycle gate in the build lane, no import visibility policy, no drift ratchet -- today the shape is habit, not enforcement.

Where we need to go. Turn four measured virtues into four enforced invariants: a base that cannot break its consumers without a gate saying so, a build lane that refuses a new cycle, a visibility policy that says who may import what, and a ratchet that makes erosion of propagation cost or acyclicity a RED -- each by construction in the door every build already passes.

The unit. 1 u = one measured session-leg (estate calibration: graphics R21 in one leg 2026-08-15). Local evidence: the arch instrument (nx_eco_graph_arch, PC plus ADP plus fan-in) landed in one leg; estimates are relative to that.
Where we are: 4 open rungs. Shape sound and self-measured; enforcement absent. Counts measured at emit below this line.
Cost to by-construction acyclicity: 1 u. ED1 the cycle gate on the build door -- the cheapest rung and the one that converts a 99.99 percent habit into 100 percent law.
Cost to a sworn base: 3 u. ED2 the base-change stability contract over nx_syscalls and nx_tier with a consumer-breakage witness.
Cost to policy and ratchet: 3 u. ED3 import visibility rules, ED4 the drift ratchet over PC and cycle count on the beat.

Research bar. Linux no-regressions rule is measured on never break userspace: the base ABI contract. Theirs: the sworn-base bar. Ours: ED2 measured on this page.

Research bar. Bazel visibility is measured on who MAY depend on what, enforced at build. Theirs: the boundary-policy bar. Ours: ED1 and ED3.

Research bar. MacCormack et al. 2006 is measured on propagation cost as the architecture-health instrument. Theirs: the instrument we already run. Ours: ED4 ratchets it.

Latest recorded release

No valid dated release entry is recorded for this domain.

Release entries describe recorded changes; they do not establish that every capability passed evaluation.

9 of 18 capabilities measured|3 of them measured exceeds|9 open|coverage 500/1000|adoption 7 full / 2 partial

Evidence profile — what the gaps on this board actually are

Measured by nx_swcompare_evidence, read back by nx_evprofile_lib. Every figure is a count with its denominator — there is deliberately no score, no grade and no percentage anywhere in this band, because a stored scalar is a field a seat can edit and a counted partition is not.

evidence|grounded 9/9|unsupported 0|gates green 1/1|proven able to fail 1/1|never bitten 0|green at 0/0 1|open gaps 9|of them unnamed 0|of them proof withheld 0|flips ready 0

proven able to fail counts the gates that have a RECORDED RED — nx_gate_bite mutated the gate subject, rebuilt it, watched the gate go red, and that record is inside the shared TTL. never bitten is its complement over the same denominator: those gates ran and were green, and nothing has ever shown them able to detect anything, so their green is a statement about this run and not about the gate. green at 0/0 is a separate and much weaker observation — the gate printed GREEN on a zero denominator, so its own tooth counter says it examined nothing. A gate can be green, non-zero, and still never bitten; that is the common case and it is now visible instead of implied.

partition: grounded + unsupported = 9 vs present 9 · named + unnamed + withheld = 9 vs open 9 · both reconcile

liar-kill conj=GPQN · all four conjuncts held

graded document: BUILDROOT tree, 9284 bytes · gates map: PRIMARY · stamped 0d 1h ago · source ../knowledge/status/evstamp_ecosysdesign.verdict

Gap classWhat it is, and the work it names
VACUOUS-GATEA gate reported GREEN on a ZERO denominator. A gate with real teeth and a broken counter, and a gate with no teeth at all, are indistinguishable from outside; that indistinguishability is the finding, so it is reported here and never convicted.
This band reports the referee counts. The per-axis worklist rows — which axis is unsupported, which watch is ready to flip, which gap is unnamed — are printed by nx_swcompare_evidence ecosysdesign itself and are not carried on the stamp, so this page names the classes and the producer names the rows. That split is stated rather than hidden: a count without a worklist is not actionable, and this band is honest about which half of that it is.

Production map

Follow the dependencies, declared acceptance criteria and recorded priorities. Inspect source binding before treating a rank as executable work.

Ranking source binding: PLAN_MATRIX_BOUND_ONLY. Recorded priorities require current acceptance evidence and resource checks before execution.

Ranking matches the captured plan and matrix only. Latest execution outcome, research freshness, accepted delivery and investment return are unverified.

Recorded priority estimates

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: listed before new work by this heuristic. Priority is not measured delivery cost or execution readiness. Stamp: # asof=1789541553 domain=ecosysdesign target_version=0.1 rungs=11 done=2 open=9 finish=0 ranker=nx_dr_ocm

#StageRungPriorityDerivation
#10.1Cycle gate in the build lane (ED1) icg_cycle_refuse800v=4 m=2 c=10
#2laterOne matrix SSOT not two (ED7) da_tree_reconcile800v=4 m=1 c=5
#3laterImport visibility policy (ED3) ip_visibility_check666v=10 m=1 c=15
#4laterBase-change stability contract (ED2) vf_base_contract600v=9 m=2 c=30
#5laterAdmission forks C4 to C6 (ED6) da_c4_bite_fork428v=3 m=1 c=7
#6laterArchitecture drift ratchet (ED4) ar_ratchet_check400v=3 m=2 c=15
#7laterClock desired-plane read verb (ED9) cj_list200v=1 m=1 c=5
#8laterPer-loop seat-free grading (ED5) na_loop_grade50v=1 m=1 c=20
#9laterCompare admission without a seat (ED8) ca_admit_domain33v=1 m=1 c=30

Declared roadmap — contract, acceptance, executor, effort

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Architecture self-review instrument (EG0)mainPC, ADP and fan-in concentration measured in 0.24 s -- LANDEDOrgan0 u
Living dependency graph (EG1)eg_loadThe sovereign self-graph serving atlas, cards, explorer and arch-review -- LANDEDOrgan0 u
Cycle gate in the build lane (ED1)
after EG1
icg_cycle_refuseThe build door walks the import closure of the target and REFUSES when a new cycle appears that the banked one-cycle baseline does not contain; gate proves a planted two-file cycle is refused with both files named and the known nx_qed_freek pair still builds until the janitor clears itOrgan1 u
Base-change stability contract (ED2)
after EG1
vf_base_contractA sworn interface list for nx_syscalls and nx_tier (names plus arity plus types) and a witness that rebuilds the direct-consumer set on any change to them, refusing a change that breaks a consumer; gate proves a renamed sys_ function is refused naming the first broken importer and an additive function passesOrgan3 u
Import visibility policy (ED3)
after ED1
ip_visibility_checkA data file declaring which directories may import which (hdl_build may import runtime; kernel may not import hub), enforced on the build door with the offending edge named; gate proves a forbidden edge is refused and every current edge passes the declared policy (the policy is DERIVED from the measured graph first, then tightened)Organ1.5 u
Architecture drift ratchet (ED4)
after EG0,ED1
ar_ratchet_checkOn the beat, re-measure PC, cycle count and base fan-in; RED when any worsens past its locked floor, floors ratchet tighter when they improve; gate proves a planted cycle and a planted PC rise both read RED and the current tree reads GREENOrgan1.5 u
One matrix SSOT not two (ED7)da_tree_reconcileMEASURED 2026-08-20: the admission gate reads knowledge/compare while the generator reads buildroot/knowledge/compare, and the two were already 204 bytes apart while both reported rows=12. The gate and the generator must read the SAME tree, or a reconciler must prove them byte-identical before either runs; gate proves a planted one-byte divergence is refused with BOTH hashes named and identical trees passOrgan1 u
Clock desired-plane read verb (ED9)cj_listMEASURED 2026-08-20: nx_clockjob exposes only put, and a row written to the clockjobs plane could not be read back through either the MCP verb or the CLI lane, so a beat registration is unfalsifiable. Add a list verb so a beat can be confirmed by someone other than its writer; gate proves a row written by put is read back by list and that an absent row reads ABSENT rather than empty-planeOrgan0.5 u
Per-loop seat-free grading (ED5)na_loop_gradeGrade each LOOP of a capability on the native axes (entry, callable, routed, beat, toothed, plane, published, documented, seat-free) and return the WEAKEST LINK, with UNOBSERVABLE as a real third state; gate proves a seat-bound loop cannot be graded native just because the same capability has a beat elsewhere, and that a missing ledger reads UNOBSERVABLE rather than zeroOrgan2 u
Admission forks C4 to C6 (ED6)
after ED7
da_c4_bite_forknx_domain_admit currently PRINTS UNVERIFIED for C4 fresh-kill, C5 second-method and C6 stamp-agreement, and its --all sweep collapses to C1 alone. Fork nx_gate_bite, the evclass row read and nx_swcompare_evidence for real, and report every clause in the sweep; gate proves a domain with no fresh kill is refused NAMING C4 and a fully-evidenced domain admitsOrgan1.5 u
Compare admission without a seat (ED8)
after ED6,ED7
ca_admit_domainA write path that admits a domain and appends a row or a ref under the house grammar, enforcing the refs schema and matrix grammar SERVER-SIDE by composing the existing rulers rather than a second parser, under content-CAS; gate proves a malformed row is refused NAMING the failing field AND that a well-formed admission SUCCEEDS -- the positive control, because a guard that refuses everything passes every negative testOrgan3 u

Milestones

MilestoneRungsCumulative
M1 · Acyclic by constructionED11 u
M2 · Sworn baseED24 u
M3 · Policy and ratchetED3,ED47 u
Ladder verdict. NOT DECLARED. This board names no dated best-in-class or frontier target and no rung roles (sotatarget and rungrole rows on its plan); the ranker labels it NO-LADDER until it does, and until then its rungs climb toward a target nobody has written down. Bars: 0 (fresh 0, attested 0, stale 0, unattested 0), verdict NO-BAR against the current month 2026-09.

Inspect a rung and its prerequisites

Declared nodes 11. Rank input binding: PLAN_MATRIX_BOUND_ONLY. Dependency order is authored. Implementation, acceptance evidence, authority and resource readiness are unverified. No action is recommended or dispatched here.

Plan SHA-256 250e3351b274201a15c78596d8ce9548b891ca1a58e88a4c87821c9b4a167ac5. Target rows 0; role rows 0. Existing risks and release worklog retain their own scope; no node completion is inferred.

Use Enter or Space on a rung to inspect its contract. Prerequisite links locate another rung in this list; open its summary to inspect it. Estimates are authored effort, not forecasts.

  1. EG0 — Architecture self-review instrument

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: main

    Acceptance: PC, ADP and fan-in concentration measured in 0.24 s -- LANDED

    Authored effort: 0. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  2. EG1 — Living dependency graph

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: eg_load

    Acceptance: The sovereign self-graph serving atlas, cards, explorer and arch-review -- LANDED

    Authored effort: 0. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  3. ED1 — Cycle gate in the build lane

    Prerequisites: EG1 (acceptance unverified)

    Contract: icg_cycle_refuse

    Acceptance: The build door walks the import closure of the target and REFUSES when a new cycle appears that the banked one-cycle baseline does not contain; gate proves a planted two-file cycle is refused with both files named and the known nx_qed_freek pair still builds until the janitor clears it

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  4. ED2 — Base-change stability contract

    Prerequisites: EG1 (acceptance unverified)

    Contract: vf_base_contract

    Acceptance: A sworn interface list for nx_syscalls and nx_tier (names plus arity plus types) and a witness that rebuilds the direct-consumer set on any change to them, refusing a change that breaks a consumer; gate proves a renamed sys_ function is refused naming the first broken importer and an additive function passes

    Authored effort: 3. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  5. ED3 — Import visibility policy

    Prerequisites: ED1 (acceptance unverified)

    Contract: ip_visibility_check

    Acceptance: A data file declaring which directories may import which (hdl_build may import runtime; kernel may not import hub), enforced on the build door with the offending edge named; gate proves a forbidden edge is refused and every current edge passes the declared policy (the policy is DERIVED from the measured graph first, then tightened)

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  6. ED4 — Architecture drift ratchet

    Prerequisites: EG0 (acceptance unverified), ED1 (acceptance unverified)

    Contract: ar_ratchet_check

    Acceptance: On the beat, re-measure PC, cycle count and base fan-in; RED when any worsens past its locked floor, floors ratchet tighter when they improve; gate proves a planted cycle and a planted PC rise both read RED and the current tree reads GREEN

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  7. ED7 — One matrix SSOT not two

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: da_tree_reconcile

    Acceptance: MEASURED 2026-08-20: the admission gate reads knowledge/compare while the generator reads buildroot/knowledge/compare, and the two were already 204 bytes apart while both reported rows=12. The gate and the generator must read the SAME tree, or a reconciler must prove them byte-identical before either runs; gate proves a planted one-byte divergence is refused with BOTH hashes named and identical trees pass

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  8. ED9 — Clock desired-plane read verb

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: cj_list

    Acceptance: MEASURED 2026-08-20: nx_clockjob exposes only put, and a row written to the clockjobs plane could not be read back through either the MCP verb or the CLI lane, so a beat registration is unfalsifiable. Add a list verb so a beat can be confirmed by someone other than its writer; gate proves a row written by put is read back by list and that an absent row reads ABSENT rather than empty-plane

    Authored effort: 0.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  9. ED5 — Per-loop seat-free grading

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: na_loop_grade

    Acceptance: Grade each LOOP of a capability on the native axes (entry, callable, routed, beat, toothed, plane, published, documented, seat-free) and return the WEAKEST LINK, with UNOBSERVABLE as a real third state; gate proves a seat-bound loop cannot be graded native just because the same capability has a beat elsewhere, and that a missing ledger reads UNOBSERVABLE rather than zero

    Authored effort: 2. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  10. ED6 — Admission forks C4 to C6

    Prerequisites: ED7 (acceptance unverified)

    Contract: da_c4_bite_fork

    Acceptance: nx_domain_admit currently PRINTS UNVERIFIED for C4 fresh-kill, C5 second-method and C6 stamp-agreement, and its --all sweep collapses to C1 alone. Fork nx_gate_bite, the evclass row read and nx_swcompare_evidence for real, and report every clause in the sweep; gate proves a domain with no fresh kill is refused NAMING C4 and a fully-evidenced domain admits

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  11. ED8 — Compare admission without a seat

    Prerequisites: ED6 (acceptance unverified), ED7 (acceptance unverified)

    Contract: ca_admit_domain

    Acceptance: A write path that admits a domain and appends a row or a ref under the house grammar, enforcing the refs schema and matrix grammar SERVER-SIDE by composing the existing rulers rather than a second parser, under content-CAS; gate proves a malformed row is refused NAMING the failing field AND that a well-formed admission SUCCEEDS -- the positive control, because a guard that refuses everything passes every negative test

    Authored effort: 3. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

Learning and practice paths

No structured learning path is declared for this plan. Existing research, roadmap and worklog remain available above.

Capability comparisons

Compare the field, search individual capabilities and open their source and adoption evidence. Documented presence does not establish comparative quality.

Position map — centrality and distinctiveness

The four-quadrant map the field uses for brand strategy (Dawar and Bagga, HBR June 2015), re-derived from this matrix on every publish. Centrality is the share of the category's feature mass a player covers, each feature weighted by how many hold it; distinctiveness is the average lead over each rival on the rows the player holds; breadth is the depth-weighted share of the whole matrix (the bubble); depth is how deeply the rows held are held; momentum is the day-over-day move off the spine (green rising, red falling, grey until day two); the dashed path runs first day → previous day → today. Dividers are the category means. Axes are fitted to the field of play, so read the tick numerals, not the frame. Rival marks are documented presence, so a rival's position reads the record, never its quality. The picture grades its own readability below; the table beside it is the same data for a screen reader or a second method.

Views. 2D cut: centrality, distinctiveness · 3D cube: centrality, distinctiveness, breadth · axes registered: centrality, distinctiveness, breadth, depth, momentum · a board picks its own in knowledge/compare/ecosysdesign.cdmap (cut|x|y, cube|x|y|z); absent = the HBR defaults
Position map, two-dimensional cutOne bubble per player. Bubble area is breadth, the ring colour is momentum, the dashed lines are the category means, and both axes are fitted to the field of play with their tick numerals shown. Every value is repeated in the table that follows. 550 600 650 700 750 800 850 100 200 300 400 500 600 centrality (permil, fitted 550–850) distinctiveness (permil, fitted 100–600) mean 690 mean 319 Unconventional Aspirational Peripheral Mainstream Nishi, centrality 681, distinctiveness 425, breadth 388, depth 777, momentum 0 Linux, centrality 681, distinctiveness 178, breadth 240, depth 619, momentum 0 seL4, centrality 681, distinctiveness 333, breadth 333, depth 857, momentum 0 Plan9, centrality 590, distinctiveness 166, breadth 222, depth 666, momentum 0 Google-monorepo, centrality 818, distinctiveness 494, breadth 574, depth 688, momentum 0 Nishi Linux seL4 Plan9 Google-monorepo

bubble area = breadth · ring = momentum (green rising, red falling, grey until day two) · dashed = category means · axes fitted to the field of play: centrality 550–850, distinctiveness 100–600 of 0–1000 permil (the full range put every player in one corner)
readability of the 2D cut, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 0 (a fact of the data: two players that close are that close) · data spread 707 permil of the plot · quadrant words unseated 0
text contrast, measured with wcag2-ratio (floors from contrast.conf), light theme: labels 16.24 (floor 4.50) · notes 16.24 (floor 4.50) · quadrant words 5.89 (floor 4.50) · tick numerals 5.89 (floor 4.50) · axis titles 5.59 (floor 4.50) · dark theme: labels 13.78 (floor 4.50) · quadrant words 5.55 (floor 4.50) · axis titles 5.97 (floor 4.50) · dark classes under their floor 0 (one figure serves both themes: a dark shortfall is a token to fix, never a class to hide) · classes refused under their floor 0 (a refused class is not drawn; the scale classes are measured, never hidden) · export: SVG PNG (receipt, rendered by the estate's own rasteriser from this page)
Position map, three-dimensional cubeThe same players in an isometric cube. Each axis is fitted to its own field of play and carries numerals on the floor grid and the vertical axis; each bubble drops a dotted line to its floor shadow so height reads as height. Values are in the table that follows. 550 600 650 700 750 800 850 100 200 300 400 500 600 100 200 300 400 500 600 700 centrality distinctiveness breadth Plan9: centrality 590, distinctiveness 166, breadth 222 Linux: centrality 681, distinctiveness 178, breadth 240 seL4: centrality 681, distinctiveness 333, breadth 333 Nishi: centrality 681, distinctiveness 425, breadth 388 Google-monorepo: centrality 818, distinctiveness 494, breadth 574 Nishi Linux seL4 Plan9 Google-monorepo
axes fitted: centrality 550–850 · distinctiveness 100–600 · breadth 100–700 permil · farther bubbles are painted first, nearer ones over them · the floor shadow is each bubble's (x, y) at height 0
readability of the 3D cube, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 0 (a fact of the data: two players that close are that close) · data spread 155 permil of the plot
Position map, small multiplesEvery pair of registered axes as one small cut. Each panel fits both axes to the field of play, the dashed lines are the category means, bubble area is breadth and the ring colour is momentum; the legend below names the colours. 550 850 100 600 distinctiveness vs centrality Nishi: centrality 681, distinctiveness 425 Linux: centrality 681, distinctiveness 178 seL4: centrality 681, distinctiveness 333 Plan9: centrality 590, distinctiveness 166 Google-monorepo: centrality 818, distinctiveness 494 550 850 100 700 breadth vs centrality Nishi: centrality 681, breadth 388 Linux: centrality 681, breadth 240 seL4: centrality 681, breadth 333 Plan9: centrality 590, breadth 222 Google-monorepo: centrality 818, breadth 574 550 850 550 900 depth vs centrality Nishi: centrality 681, depth 777 Linux: centrality 681, depth 619 seL4: centrality 681, depth 857 Plan9: centrality 590, depth 666 Google-monorepo: centrality 818, depth 688 550 850 480 520 momentum vs centrality Nishi: centrality 681, momentum 500 Linux: centrality 681, momentum 500 seL4: centrality 681, momentum 500 Plan9: centrality 590, momentum 500 Google-monorepo: centrality 818, momentum 500 100 600 100 700 breadth vs distinctiveness Nishi: distinctiveness 425, breadth 388 Linux: distinctiveness 178, breadth 240 seL4: distinctiveness 333, breadth 333 Plan9: distinctiveness 166, breadth 222 Google-monorepo: distinctiveness 494, breadth 574 100 600 550 900 depth vs distinctiveness Nishi: distinctiveness 425, depth 777 Linux: distinctiveness 178, depth 619 seL4: distinctiveness 333, depth 857 Plan9: distinctiveness 166, depth 666 Google-monorepo: distinctiveness 494, depth 688 100 600 480 520 momentum vs distinctiveness Nishi: distinctiveness 425, momentum 500 Linux: distinctiveness 178, momentum 500 seL4: distinctiveness 333, momentum 500 Plan9: distinctiveness 166, momentum 500 Google-monorepo: distinctiveness 494, momentum 500 100 700 550 900 depth vs breadth Nishi: breadth 388, depth 777 Linux: breadth 240, depth 619 seL4: breadth 333, depth 857 Plan9: breadth 222, depth 666 Google-monorepo: breadth 574, depth 688 100 700 480 520 momentum vs breadth Nishi: breadth 388, momentum 500 Linux: breadth 240, momentum 500 seL4: breadth 333, momentum 500 Plan9: breadth 222, momentum 500 Google-monorepo: breadth 574, momentum 500 550 900 480 520 momentum vs depth Nishi: depth 777, momentum 500 Linux: depth 619, momentum 500 seL4: depth 857, momentum 500 Plan9: depth 666, momentum 500 Google-monorepo: depth 688, momentum 500
Nishi Linux seL4 Plan9 Google-monorepo
10 panels over 5 registered axes, every pair once (the lower axis on x, the higher on y) · each panel fitted to its own field of play, first and last tick numerals shown · no labels in a small cut, the legend names the colours; the grade below reports the mark terms only (MM summed over the panels, spread averaged)
readability of the small multiples, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 6 (a fact of the data: two players that close are that close) · data spread 537 permil of the plot
PlayerQuadrantcentralitydistinctivenessbreadthdepthmomentumRows heldDays on spineFirst seen
NishiUnconventional6814253887770 since 2026-09-15922026-09-15
LinuxPeripheral6811782406190 since 2026-09-15722026-09-15
seL4Unconventional6813333338570 since 2026-09-15722026-09-15
Plan9Peripheral5901662226660 since 2026-09-15622026-09-15
Google-monorepoAspirational8184945746880 since 2026-09-151522026-09-15
DayMatrix rows reviewedPlayers recorded
2026-09-15185
2026-09-16185

players 5|matrix rows 18|feature mass 44|centrality mean 690|distinctiveness mean 319|axes 5|spine days 2 (shown 2)|rows written today 0|readability defects 2D 0 cube 0|spine knowledge/status/cdmap/ecosysdesign.spine

How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. A dark tag means the organ file EXISTS but does not declare the contracted symbol: something shipped there under another name, and until the contract is repointed to the real entry point (the plan rung and this row) or the function is renamed, that capability is invisible to this board — a build lost to darkness, named so it is not. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1789497476, gate census asof 1789498715 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiLinuxseL4Plan9Google-monorepo
Measured propagation cost (0.5%)Measured: eg_descendants exists in runtime/nx_eco_graph.nx, verified at emit. MEASURED 0.5% avg change-reach vs Linux published 5-18% on the same instrument [maccormack06] -- an order of magnitude more periphery-dominated [baldwin14]; seL4 gets low coupling by tiny scale, we hold it at 16k organs (caveat: file-granularity flatters PC vs Linux module-granularity -- named, not hidden) Adoption: LIB-WIRED importers=37 nonval=30 — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; ahead of Linux, Google-monorepo; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Near-perfect acyclicity (1x2-cycle/16k)Measured exceed: eg_has_cycle in runtime/nx_eco_graph.nx, verified at emit. Linux tolerates within-subsystem cycles; monorepos fight them with tooling; ours is 99.99% acyclic BY CONSTRUCTION (import=source-relative DAG habit) -- one named violation (nx_qed_freek<->nx_group) queued to the janitor rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: LIB-WIRED importers=37 nonval=30 — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of Linux, Plan9, Google-monorepo; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Stable universal base (libc pattern)Measured: sys_write exists in runtime/nx_syscalls.nx, verified at emit. nx_syscalls 81% direct fan-in mirrors libc/kernel-ABI universality [plan9-pike]; Linux's syscall ABI stability discipline ("never break userspace") is Best-in-class [linux-no-regressions] -- ours has the shape, not yet the sworn contract Adoption: LIB-WIRED importers=16142 nonval=9616 — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; fully adopted on the estate ladderCons behind Linux (leads)
Explicit hardware root layerMeasured: nx_tier exists in runtime/nx_tier.nx, verified at emit. seL4's minimal verified TCB is Best [sel4-verification]; nx_tier as the single gen-0 hardware anchor (96% blast radius) is clean layering but unverified Adoption: LIB-WIRED importers=2884 nonval=2504 — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; ahead of Google-monorepo; fully adopted on the estate ladderCons behind seL4 (leads)
Self-knowledge: living dependency graphMeasured: eg_load exists in runtime/nx_eco_graph.nx, verified at emit. Google's monorepo build graph (Bazel/Blaze) [google-monorepo16] is the only comparable queryable whole-ecosystem graph; Linux/Plan9 have no first-class self-graph; ours is sovereign + serves atlas/cards/explorer/arch-review from ONE store Adoption: LIB-WIRED importers=37 nonval=30 — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; ahead of Linux, seL4, Plan9; fully adopted on the estate ladderCons behind Google-monorepo (leads)
Self-review with field instrumentsMeasured exceed: main in runtime/_hdl_build/nx_eco_graph_arch.nx, verified at emit. We measure OURSELVES with MacCormack PC [maccormack06] + ADP + fan-in concentration in 0.24s on demand; the references get measured by external researchers, not by themselves Adoption: RUN-BY:fork:nx_arch_board — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of Linux, seL4, Plan9, Google-monorepo; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Mechanical liveness classificationMeasured: nstatus exists in runtime/_hdl_build/nx_eco_graph_card.nx, verified at emit. trunk/shipped/validation/tested-only/orphan computed from graph+filesystem evidence (living tree=21.8%); monorepos approximate via build-graph queries; kernels carry dead code for years rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on disk; ahead of Linux, seL4, Plan9, Google-monorepoCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Validation-per-organ cultureMeasured: is_test exists in runtime/_hdl_build/nx_eco_graph_card.nx, verified at emit. 6,604 test/gate artifacts (40.7% of nodes); seL4's proof-per-component is Best [sel4-verification]; ours is gate-per-organ breadth without formal proof Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on disk; ahead of Plan9Cons behind seL4 (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Base-change stability contractDARK — runtime/nx_verify.nx EXISTS but does not declare vf_base_contract: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Linux "never break userspace" [linux-no-regressions] + seL4 proofs [sel4-verification] are Best; our nx_tier/nx_syscalls churn can rebuild 96% with no sworn interface gate -- THE top guardrail gap
watching vf_base_contract
Pros none measured yetCons behind Linux (leads), seL4 (leads), Plan9, Google-monorepo; open contract, nothing on disk yet
Cycle-prevention gate in build laneOpen — watching runtime/nx_import_cycle_gate.nx : icg_cycle_refuse, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Monorepo tooling (Bazel visibility+deps checks [bazel-visibility]) prevents cycles at commit time; our acyclicity is habit not enforcement -- one gate away from by-construction
watching icg_cycle_refuse
Pros none measured yetCons behind Google-monorepo (leads); open contract, nothing on disk yet
Import visibility/boundary policyOpen — watching runtime/nx_import_policy.nx : ip_visibility_check, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Google visibility rules are Best [bazel-visibility] (who MAY depend on what, enforced); we have no boundary policy -- any organ may import anything
watching ip_visibility_check
Pros none measured yetCons behind Linux, seL4, Plan9, Google-monorepo (leads); open contract, nothing on disk yet
Architecture drift ratchet (PC/cycles over time)Open — watching runtime/nx_arch_ratchet.nx : ar_ratchet_check, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Monorepos track dep-graph health in CI [google-monorepo16]; our 0.5%/1-cycle snapshot has no ratchet keeping it there -- erosion is silent until re-measured
watching ar_ratchet_check
Pros none measured yetCons behind Google-monorepo; open contract, nothing on disk yet
Capability autonomy meter callable and ledger liveMeasured exceed: am_axis in runtime/_hdl_build/nx_autonomy_meter.nx, verified at emit. MEASURED 2026-08-20: four seat-free axes (judged-DONE share, emitter-authored share, daemon-run share, hands-off-heal share); it averages ONLY scorable axes and refuses INSTRUMENT-BLIND rather than publish a fabricated zero. It was PROMOTED-UNREGISTERED (a real binary nobody could call) behind a 12-day-stale ledger; registered and re-run this session, the rollup flag went from STALE to live autonomy = 705 permil -- the grade did not move, its LIVENESS did. Google SRE production-readiness review is the nearest external analogue; Linux, seL4 and Plan9 carry no self-measured autonomy instrument rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: RUN-BY:clock — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of Linux, seL4, Plan9, Google-monorepo; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Per-loop seat-free grading (not per-capability)Open — watching runtime/nx_native_axes.nx : na_loop_grade, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. THE LAW THIS ROW ENCODES: a capability is not one loop -- grade each loop separately or the seat-free half launders the seat-bound half. MEASURED on /compare 2026-08-20: 7 loops split 3 NATIVE (publish, verify, measure) + 3 SEAT-BOUND (admit, author, evidence) + 1 ABSENT (adjudicate), and the partition sums. A whole-capability grade would have published /compare as NATIVE because it has a live beat, its own SSOT plane and a GREEN published surface. No reference architecture grades autonomy per loop
watching na_loop_grade
Pros none measured yetCons open contract, nothing on disk yet
Domain admission enforces all six standard checksDARK — runtime/_hdl_build/nx_domain_admit.nx EXISTS but does not declare da_c4_bite_fork: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. knowledge/compare/ADMISSION_STANDARD.txt specifies SIX mechanical checks and its enforcement rung names the organ that must compose them. MEASURED 2026-08-20: CORRECTED after calling it: the single-domain path DOES report C1 to C6 and refuses honestly (ecosysdesign 2026-08-20 -- C1 grounded=8 absent=4 ungrounded=0; C2 REFUSE with reason no barcheck row and no UNPINNED declaration so the comparison is silently unfalsifiable; C3 gates file=1; and C4 fresh-kill, C5 second-method, C6 stamp-board each print UNVERIFIED rather than acquitting, which is the abstain-never-acquit third state working correctly). The REAL gap is that C4 to C6 are never forked and the --all sweep collapses to C1 alone: domains=45 faulty=3 faults=10 VERDICT=REFUSE. Bazel enforced visibility and monorepo readiness review are Best here rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching da_c4_bite_fork
Pros none measured yetCons behind Google-monorepo (leads); open contract, nothing on disk yet
Compare admission without a seat (write API)Open — watching runtime/nx_compare_admit.nx : ca_admit_domain, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-20 across the full 1165-tool registered corpus via nx_capsearch: NO write-side organ exists -- only a read-only admission gate and a generic plane appender. Admitting a domain is a hand-authored three-file ritual plus a compare-and-swap append to regen.list, so /compare publishes itself with no seat yet cannot GROW without one. Monorepo tooling accepts machine-authored changes through a reviewed pipeline rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching ca_admit_domain
Pros none measured yetCons behind Google-monorepo; open contract, nothing on disk yet
Clock desired-state plane has a read verbDARK — runtime/nx_clockjob.nx EXISTS but does not declare cj_list: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. MEASURED 2026-08-20: nx_clockjob exposes only put. A row written to the clockjobs plane could not be confirmed through either the MCP verb or the CLI lane, both reading plane EMPTY, so a beat registration is a claim rather than a fact. A write-only control plane cannot be audited and every row in it is unfalsifiable. nx_cron_watch is the working reader for the LIVE plane and proved compare-beat fresh at age 2419s of max_age 46800s. PARTLY SHIPPED 2026-08-20: nx_clockjob gained list, live and dupes (promoted, live sha 3f245139) and cj_err now writes stdout as well as stderr so a refusal is no longer delivered as silence. It falsified a claim of mine within one call -- the beat row I had reported as written was simply absent, rows=128 -- and on first sight it found 82 duplicate pairings over 20 names plus a NAMELESS row that put itself was written to refuse. THIS ROW STAYS A WATCH: no gate organ asserts these verbs, get <name> is not built, and DUPES counts PAIRINGS not surplus rows rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching cj_list
Pros none measured yetCons behind Google-monorepo; open contract, nothing on disk yet
Compare matrix SSOT is ONE tree not twoDARK — runtime/_hdl_build/nx_domain_admit.nx EXISTS but does not declare da_tree_reconcile: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. MEASURED 2026-08-20 and this one is LIVE: the generator reads buildroot/knowledge/compare while the admission gate reads the nishihost twin knowledge/compare. Both trees hashed BEFORE any edit of mine -- buildroot 4242 B sha daa90176 versus nishihost 4038 B sha 4d79c355, a 204-byte divergence -- and yet BOTH report rows=12, so the row count hides the split. AN ADMISSION GATE THAT AUDITS A DIFFERENT COPY THAN THE PUBLISHER READS CANNOT REFUSE WHAT ACTUALLY PUBLISHES. Monorepos enforce a single source of truth by construction and that is Best here. PARTLY SHIPPED 2026-08-20: nx_domain_admit was REPOINTED to the publishing tree (one DA_CDIR/DA_CDIRS pair replacing three call sites) and promoted, live sha 84f099c5; the sweep moved from domains=45 faulty=3 faults=10 to domains=61 faulty=54 faults=342, auditing devmgmt and 15 other domains for the first time ever. THIS ROW STAYS A WATCH because the second half is not built: nothing yet REFUSES on divergence, so the two trees can still drift apart silently and the control that caught this was a hand-run diff rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching da_tree_reconcile
Pros none measured yetCons behind Google-monorepo (leads); open contract, nothing on disk yet
Rival-claim provenance. Every Yes, Best or Part mark in a rival column is a claim about someone else's product. rows with rival marks 17 · cited 10 · uncited 7. A cited row carries a reference mark that resolves to a pinned mirror (the refs gate measures that); an uncited row is an observation read and is badged in its evidence until a reference lands. The badge is the receipt, never the proof: a mark proves a mirror exists, not that the mirror supports the code.

Delivery and evidence

Inspect risks, technical debt, rendered observations, experiments and references. Read scope and limitations alongside every result.

Risk register

RiskLikelihood x impactMitigation
A cycle gate that fires on the one known cycle blocks every build until the janitor lane landscertain x mediumED1 bakes the banked baseline as the floor; only NEW cycles refuse.
A visibility policy written from taste refuses half the tree on day onepossible x highED3 derives the initial policy from the measured graph (zero refusals at birth) and tightens by declaration.
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/ecosysdesign.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain ecosysdesign, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

The field — discovered, not chosen

Rows written by nx_field_discover from ecosysdesign.seeds: the industry's own lists (Wikipedia wikitext, GitHub topics, awesome lists) read mechanically, every candidate counted across seeds. The matrix columns above are a SEAT'S pick; this band is the population they were picked from, and the stats line measures one against the other. A rival here is a lead, never a verdict — it earns a column when its capabilities are read and pinned.

field|seeds=2|scanned=1|fetched=1|reused=0|failed=1|named=2|candidates=2|mentions=2|capped=0 rival|seL4|1|1|col1-sel4|https://sel4.systems/Verification/|named rival|Google-monorepo|1|1|col3-google|https://research.google/pubs/why-google-stores-billions-of-lines-of-code-in-a-single-repository/|named
RankRivalSeedsMentionsFirst seedKindLink
1seL411col1-sel4namedhttps://sel4.systems/Verification/
2Google-monorepo11col3-googlenamedhttps://research.google/pubs/why-google-stores-billions-of-lines-of-code-in-a-single-repository/

field candidates 2|shown 2 of 2|matrix columns in the field 2 of 4|discovered rivals with no column 0|malformed rows 0 (counted, never rendered)|read-capped 0

Gaps from the record — what the estate does that no board carries

The record census (nx_goalmap record) reads the invoked-tool population and every plan queue row and files each organ or directive that NO matrix, plan or gates row names. A row here is a callout the boards missed: adjudicate it onto a board or declare it infrastructure. Census state BLIND (age 74401 s), sources read 4 of 7 declared — a BLIND census is a FLOOR: unread sources can only add rows.

kindnameboardsourceevidence

rows shown 0|this board's directives 0|estate-wide un-boarded organs 492 (listed in full on /compare/ecosystem)|census rows 611|malformed 0 (counted, never rendered)

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [maccormack06] MacCormack, Rusnak, Baldwin. Exploring the Structure of Complex Software Designs: An Empirical Study of Open Source and Proprietary Code. Management Science 52(7), 2006, pp. 1015-1030 (DOI 10.1287/mnsc.1060.0552; RePEc record mirrored). publisher · read in our library knowledge/fetched/cmp_ecosysdesign_maccormack06.html · pin h062f67cb94c633679138a4ef38c546184afd1736b64ab174851f5464f2bf3b9b · accessed 2026-08-18 · published-paperGrounds: The "Measured propagation cost (0.5%)" row and the "Self-review with field instruments" row: the DSM propagation-cost metric and the Linux-vs-Mozilla comparison are this paper's; nx_eco_graph_arch runs the same instrument over 16,222 organs and the Linux 5-18 percent and Mozilla ~17 percent figures quoted on the page are its published comparators.
  2. [baldwin14] Baldwin, MacCormack, Rusnak. Hidden Structure: Using Network Methods to Map System Architecture. Research Policy 43(8), October 2014, pp. 1381-1397. publisher · accessed 2026-08-18 · published-paperGrounds: The @sub verdict language "periphery-dominated coupling" and "core-periphery": this paper defines the core-periphery / multi-core / hierarchical architectural patterns from directed dependency graphs (1,286 releases, 17 applications) that the ecosysdesign self-review classifies our graph against. Publisher page is 403 to the sovereign fetcher and the DASH mirror sits behind a bot challenge, so no library mirror is declared.
  3. [sel4-verification] seL4 Foundation. Verification -- the seL4 microkernel's machine-checked functional-correctness proof from abstract specification to C (and binary), following Klein et al., seL4: Formal Verification of an OS Kernel, SOSP 2009. publisher · accessed 2026-08-18 · vendor-docGrounds: The seL4 column: the "Explicit hardware root layer" row (seL4's minimal verified TCB is Best) and "Validation-per-organ culture" row (proof-per-component is Best); nx_tier is clean layering but unverified. sel4.systems negotiates a TLS suite the sovereign fetcher does not carry, so the mirror is honestly absent (page verified by a second reader).
  4. [linux-no-regressions] The Linux Kernel documentation: Handling regressions -- the no-regressions rule ("if the kernel used to work for you, the rule is that it continues to work for you") governing the userspace ABI. publisher · read in our library knowledge/fetched/cmp_ecosysdesign_linux-no-regressions.html · pin h62a1e0e6b3a4562e31a5adaede5e5a3c61365d7ef95a9e899b557ebe63e7a1b5 · accessed 2026-08-18 · vendor-docGrounds: The Linux column on "Stable universal base (libc pattern)" (2, Best) and "Base-change stability contract" (2): the never-break-userspace discipline the rows name as the sworn contract nx_syscalls has the SHAPE of but not yet the gate for -- THE top guardrail gap.
  5. [plan9-pike] Pike, Presotto, Dorward, Flandrena, Thompson, Trickey, Winterbottom. Plan 9 from Bell Labs. Bell Labs technical paper (Plan 9 4th edition documents; cat-v mirror of the 9p.io original). publisher · read in our library knowledge/fetched/cmp_ecosysdesign_plan9-pike.html · pin h98ba3b3d52e0cbf752bd4a515f8c05b2c011c2f9e7ec8d8b56286be1a98bdc97 · accessed 2026-08-18 · published-paperGrounds: The Plan9 column across the base-layer rows: the everything-is-a-file-server design whose small uniform base is the comparator for our libc-pattern nx_syscalls fan-in; the 9p.io original negotiates a TLS suite the sovereign fetcher lacks, so the cat-v copy is the mirrored URL.
  6. [google-monorepo16] Potvin, Levenberg. Why Google Stores Billions of Lines of Code in a Single Repository. Communications of the ACM 59(7), 2016, pp. 78-87. publisher · read in our library knowledge/fetched/cmp_ecosysdesign_google-monorepo16.html · pin h5f954f0099567b0eac70623edc055dbc93fab5054c067bfc41f8e654e0efe4d9 · accessed 2026-08-18 · published-paperGrounds: The Google-monorepo column: "Self-knowledge: living dependency graph" (Best -- the Blaze build graph is the one comparable queryable whole-ecosystem graph) and "Architecture drift ratchet" (monorepos track dep-graph health in CI); this paper is the published account of that repository and its tooling.
  7. [bazel-visibility] Bazel documentation: Visibility -- target and load visibility rules that declare which packages may depend on a target, enforced at build time. publisher · read in our library knowledge/fetched/cmp_ecosysdesign_bazel-visibility.html · pin habc305d4030202566b6231746d7b359b216dda72111d67c75bc85a918590504c · accessed 2026-08-18 · vendor-docGrounds: The "Import visibility/boundary policy" row (Google visibility rules are Best, Nishi _ABSENT_) and the "Cycle-prevention gate in build lane" row (Bazel visibility+deps checks at commit time): this is the enforced who-may-depend-on-what mechanism our tree lacks -- any organ may import anything today.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/ecosysdesign.matrix · source checks show implementation presence; runtime and user-outcome evidence are reported separately · JavaScript supports page controls