**Status:** ⚠ SUPERSEDED 2026-07-14 by `SPEC_UNIFIED_EXEC_LAYER_20260714.md` (subsumed whole — see its Appendix C for the section map). Kept for provenance; do not build from this document.
## 1. Assets unified (adjudication = sub-task 1, DO FIRST)
| asset | what it is | keep |
|---|---|---|
| PINK `ExecutionRouter` | maker/taker POLICY + hooks; 265 tests; `maker_both` ran production since 2026-06-11 | the policy state machine + test corpus |
| BLUE `alpha_engine/execution/` SmartPlacer | OB-aware PLACEMENT: `fill_simulator` (30s bookDepth), `signal_confidence_adapter` (conviction→placement), `ob_reader`, `smartplacer_constants` | the where-in-book model |
| `BingX_FILL_CHARACTERIZATION_AND_ADVANTAGES.md` | measured venue friction, incl. VST conditional-order sampling (`prod/bingx/characterization.py`) | ground truth to adjudicate BOTH against |
Likely complementary (Router = whether-maker; SmartPlacer = where-maker). The
adjudication verdict decides: Router ∪ SmartPlacer ∪ union — nothing built before
that memo exists.
## 2. Contract
**Input** (from kernel via venue adapter): `KernelIntent` + `guideline_price`
(decision layer's reference — e.g. tick price that triggered the exit) +
`urgency_class` (below). Decision layers NEVER place orders; they hand a
guideline and an urgency. (Resolves the ADVSL-stale-price concern: scan-clock
exits pass their price as guideline; SMART-EXEC executes against live book.)
**Output**: same `VenueEvent`/receipt stream the naive adapter emits today —
plus friction telemetry (§8). The kernel cannot tell SMART-EXEC from naive
MARKET; only the fills get cheaper.
## 3. Urgency ladder (maps to exec-priority doctrine A–G)
| `ACQUIRE` | ENTER (F) | patient maker inside spread per SmartPlacer; abandon (don't chase) if price runs — a missed entry is free, a chased entry is not |
Urgency is assigned by the CALLER (it knows why), never inferred by SMART-EXEC.
## 4. Order-management loop
- Runs on the steel clock (1s now; L2/L3 ladder later — design for cadence
injection, no hardcoded 1s).
- Per working order: state = {placed_px, queue_age, book_state, chases_left, ttl}.
- Reprice rule: only toward urgency (never widen an exit). Max chases per class
(constants from characterization data, not vibes).
- Every transition journaled (§8). Single-writer discipline: one owned dispatch
lane (ASEx pattern, as `uv-exit-dispatch` today); the price/tick lane never
blocks on wire time.
## 5. Execution truth (inherits bdc54fb doctrine wholesale)
- Failure triage on every wire op: NOT_ATTEMPTED / REFUSED → rollback sound;
INDETERMINATE → point-lookup own clientOrderID (bounded, read-only, NOT a
reconcile); unresolved → UNKNOWN, no synthetic REJECT, E-feed FILL settles.
- Cancel is a wire op too: cancel-INDETERMINATE means the order MAY still be
live → do not re-place until truth established (double-fill guard).
- Idempotency: every order carries our clientOrderID; replace = cancel-confirm
→ place, never blind amend.
- Partial fills are normal in maker land: FSM already speaks PARTIAL_FILL;
SMART-EXEC must never hold a partial hostage to policy — remainder follows
the same urgency ladder, fills stream up immediately.