First code of the Unified Execution Layer (SPEC_UNIFIED_EXEC_LAYER_20260714.md). Pure
policy, stdlib+Decimal only, zero I/O, zero venue knowledge, zero importers elsewhere —
adopting it breaks nothing (freeze-safe; operator unparked the build 2026-07-14).
- contract.py: ExecutionRequest input surface (§2.1) + V-TYPES (Side, UrgencyClass,
ProtectiveSpec, ExecutionAdvice), frozen, validated-at-construction, illegal states
unrepresentable. 'an asset, a size, and a prayer'.
- router.py: decide(request) -> RoutingDecision — total pure map of the §6 urgency
ladder. Encodes A1 adjudication verdict in the architecture: Router=whether-maker,
SmartPlacer=where-in-book via the wants_placement/pre_submit seam. Complementary.
- _constants.py: policy magnitudes with provenance; PROVISIONAL ones flagged for
L8/L10 calibration (never vibes, never a hardcoded cadence).
- test_exec_unified.py: 26 behaviour + mutation-litmus tests. Verified RED under
CATASTROPHIC->MAKER and ACQUIRE cross_on_expiry->True mutations.
Not yet wired: PINK drive-loop port (§7), venue dialect (§11), telemetry (§12).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
omp's raw VST capture is correct (2.00 bps = exactly BingX 0.02% published maker rate).
Sign was inverted: BingX reports commission negative for a DEBIT, so -0.001291 USDT is a
fee PAID, not a rebate. Refutes SPEC §0 '1 bp maker' assumption (real = 2 bp); maker-both
RT ~4 bp vs taker ~10 bp — savings case survives, no rebate. Adds EXEC_NAVIGATION_MAP_FOR_OMP.md
to bound omp's searches to prod/bingx/ (was grepping Nautilus framework internals).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Operator's live bluff-check caught it: final grep stage without --line-buffered
block-buffers wakes silently. Verified fixed via EARTEST injection (same-second fire).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Operator-approved. Apostrophe dropped (ASCII identifier law: import daat, DaatQuery,
dolphin_daat.*, no Unicode in any symbol/path/table). The acronym earns its letters:
D=direction (cosine retrieve), A=anchored (magnitude envelope gate), A=ambiguity
(the state we refuse to collapse), T=triage (KNOWN/MARGINAL/OUT_OF_DISTRIBUTION).
'Triage' is deliberate — the house already triages NOT_ATTEMPTED/REFUSED/INDETERMINATE
at the venue. Same verb, same law, now the names say so. Da'at (knowledge, the hidden
sefirah that sits above Malkhut and feeds it) survives in the etymology, where it costs
nothing. YESOD considered and set aside: it names the conduit, not the knowing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Operator's cosine proposal: ADOPTED as stage 1 of 3, never alone.
- Stage 1 RETRIEVE: cosine on DIRECTION = matmul = the reflex (fast, exact, deterministic)
- Stage 2 GATE: magnitude envelope + support + Mahalanobis -> OUT_OF_DISTRIBUTION
- Stage 3 MODEL: local tangent-space/GP -> prediction + VARIANCE (the real extrapolation)
THE DANGER: crises preserve direction and explode magnitude. Cosine returns
similarity 1.0 for a same-shape-10x-size state — max confidence at the exact moment
it is most wrong. Cosine CANNOT produce the OOD verdict; storing direction+magnitude
separately is the entire crash-safety story.
Same law, third coat: INDETERMINATE (venue) / stale-price (exit) / OOD (manifold).
Unknown is not flat, not 'best guess'.
TOPOLOGY (operator's IFF): cyclic (sin,cos) encoding = free + REQUIRED for the
streak-phase grail study; component detection = cheap; persistent homology = EARN IT
(offline Mode-1 diagnostic that shapes the gate, never a per-tick op).
GENERALIZATION: three-stage discipline (not one metric) is a shared kernel — market
fingerprint (scalar_hash is a hash reaching for this; conflict_level is latent OOD),
trade-path/ADVSL, exit-decision, asset transfer (= how full-universe becomes
affordable), counterparty simplex, ops/incident prefiguration, streak-wave phase.
One guard defends all: confident interpolation into unexplored magnitude is the
universal failure mode. Proposed name: DA'AT.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Two modes (operator): EXPLORE (synthetics, ecology-dominant, billions of combos,
emits a MANIFOLD) -> RECOMMEND (live OBF as query, localize + extrapolate, OOD
verdict falls back to doctrinal). Ecology stays: actuals calibrate, ecology plays.
Findings verified live tonight:
- FEE BUG CONFIRMED: trade_execution_quality says 5.016 bps taker; code says 0.5
(asset_classification.py:154/164/174/384). Every CMA-ES number is void until re-baselined.
- BOOK GAP: obf_universe (15.3B rows) is L1+aggregates, NOT a ladder. Three options,
must declare which; book_source provenance tag on every artifact.
- LATENCY: p50 49.9ms / p95 597ms / p99 10.8s / max 450s. Constant-100ms is fiction.
- REGIME MISMATCH: MARAS emits 5 regimes; MALKHUT selector invented 9. RegimeBridge needed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A BingX read-timeout/reset/5xx after send means the answer was lost, not that
the order failed. Classify every submit failure by what it PROVES:
NOT_ATTEMPTED / REFUSED -> rollback sound; INDETERMINATE -> point-lookup our
own clientOrderId (read-only, bounded, never a reconcile); unresolved stays
UNKNOWN — no synthetic REJECT, no slot rollback, E-feed FILL settles truth.
- prod/bingx/http.py: BingxHttpError.effect + order_may_exist, 9 raise sites tagged
- adapters/bingx_direct.py: _lookup_own_order_by_client_id (never POSTs)
- dita_v2/venue.py: VenueIndeterminateError(VenuePostAckError) — existing fences catch it
- dita_v2/bingx_venue.py: both submit paths escalate INDETERMINATE receipts
- 14 tests incl. kernel no-rollback invariant + genuine-REFUSED contrast
Suite: 3416 passed, 19 skipped, 3 xfailed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
BUG CLASS (doc: BUGCLASS_INDETERMINATE_OUTCOME_20260713.md): an operation with an external
side effect has THREE outcomes — NOT_ATTEMPTED, ATTEMPTED_REFUSED, ATTEMPTED_INDETERMINATE
— and rollback is sound only for the first two. Collapsing the third into 'failed' is what
orphaned 6 live SHORTs: a post-ack TypeError reached rust_backend's 'except Exception ->
synthetic REJECTED -> FSM rollback', which asserted 'no order exists' about an order that
was already filled. Telemetry never had a veto; it hijacked the failure channel.
FIXES (no new seams, no re-architecture):
- venue.py: VenuePostAckError — typed channel meaning THE EFFECT EXISTS. Carries receipt.
- bingx_venue submit/submit_async: point-of-no-return fence. Post-ack bookkeeping failures
raise VenuePostAckError instead of a bare exception.
- rust_backend (BOTH submit paths): catch VenuePostAckError FIRST -> no synthetic REJECT,
no rollback. Slot stays working; E-feed FULL_FILL / reconcile settles the truth.
LOSSLESS TELEMETRY (HJ: 'DITAv2 exists precisely because seams dropped 40% of inputs'):
drop-oldest is data loss and is GONE. Exec path appends O(1) to an unbounded queue and
returns. A SEPARATE spiller thread (which never touches the plane, so a wedged plane cannot
starve it) parks the backlog above HWM into a durable append-only spool; the publisher
replays the spool when the plane recovers.
Proven: wedged-forever plane + 200k records -> 0 dropped, 195903 durable on disk, 4096 in
memory, 7.4 us/call on the exec path. Lossless AND memory-bounded. Healthy plane: 2000/2000.
STILL BROKEN, flagged to codex: the pre-ack branch rolls back on TIMEOUT — but a timeout is
the definition of INDETERMINATE (the order may have filled). Same bug class, older, live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Central finding: TIER-B INVERSION. asex_kernel_executor.py:319 enqueues account/fill
events (execution truth) at priority=4 — the LOWEST tier, BELOW ENTER (P3). Under queue
pressure UV opens a new position before applying the fill that tells it what it already
holds. Tonight's 6 orphans are the proof: tier-G telemetry destroyed tier-B truth, UV
believed it was flat while holding 6 live SHORTs, and no SL/TP/ADVSL can protect a
position the kernel does not know exists. That is why B outranks C and D.
Also catalogued: A-tier sensors (heartbeat/disconnect/seq-gap/halt/stale-book) are not
ranked work at all — only the kill switch is. Missing C (liquidation distance, daily/
session loss, symbol loss, leverage trigger), D (trailing, giveback, stale-exit reprice),
E (self-cross, amend), F (spread/depth gate).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Standing steer (HJ, months): non-blocking behaviour + explicit execution priority.
Telemetry is not on the ladder at all, yet it sat ON the order path, inline and able to
raise — which is how it orphaned 6 live positions.
Exec path now does exactly one thing: pack primitives, append to a bounded ring, return.
No plane write, no snapshot construction, no I/O, no lock, no raise. Snapshot build +
plane publish move to a daemon drain lane. Ring is deque(maxlen=4096): drops OLDEST on
full and counts the drops — telemetry loss is always preferable to exec backpressure,
but it stays observable.
Measured: 1000 exec-path calls against a 2s-BLOCKING plane = 3.65 ms total (3.65 us/call).
Inline, that was 2000 s of stall. Wedged lane + 50k pushes -> ring pinned at 4096,
45903 counted drops, exec path never backpressured. Healthy plane still gets 5/5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The pre-existing guard covered only publish(). The attribute/coercion block above it
(int()/str()/.metadata.get() on intent+order) was UNGUARDED, and kwarg binding happens
before the body runs at all — so a signature skew sailed straight past a defence that
existed precisely to prevent this, and orphaned 6 live positions.
Everything that can raise now lives inside one try. Failures log loud and are swallowed;
the order path is never affected. Proven against: exploding plane, poisoned intent
coercion (the formerly-unguarded region), and absent plane.
ARCHITECTURAL DEBT (raised by HJ, not fixed here): telemetry has no business being called
inline on the exec path at all. Correct shape = fire-and-forget enqueue drained by the M6
journal lane. This commit makes it harmless, not absent.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Line 154 held mutant debris: KernelControlSnapshot(mode="live", mode="live"") — duplicate
kwarg + unterminated string. Committed since a55501b, it made the ENTIRE dita_v2 suite fail
collection, so nobody has run it. That is why no test caught the bingx_venue telemetry
signature skew that orphaned 6 live positions tonight.
The test was fantasy besides: asserted read.arming == "DARK" (no such field) and
mode == "live" (KernelMode is NORMAL|DEBUG). Rewritten to assert a real invariant —
the second write must flip the buffer and become visible.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
M5 (native_artifact.py + rust_backend build_verified_artifact/verify_artifact hooks)
existed ONLY in the uv/exec-refactor worktree. Canonical never received it, so
vendor_sync.sh downgraded the vendored copy back to a raw 'cargo build' — the same
mechanism by which M1's relock clobbered the bingx_venue telemetry fix and orphaned
6 live positions. Canonical is the source of truth; M5 belongs here.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
M1 re-vendor (89a1f1a) clobbered the T0-DEVIATION fix (20ad493): submit()/submit_async()
pass order_id=/client_order_id= post-ack, the signature dropped them. Every ENTER raised
TypeError AFTER the venue POST returned 200 OK -> rust_backend synthesised REJECTED ->
FSM rollback, while the venue kept the position. Flight-4: 8 bridged promotions, 6 orphan
SHORTs live on VST with a kernel that believes it is flat.
Two fixes:
1. signature accepts order_id/client_order_id again; snapshot prefers them (order is None
on the submit path, so the ack row is the only id source).
2. post-ack telemetry wrapped: observability can never again veto an accepted order.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Architecture: DuckDB for persistence + full in-memory materialization for reads.
All reads served from Python dicts (sub-microsecond). DuckDB only hit on writes.
Performance evolution (get_asset benchmark):
V0 (raw DuckDB): 876µs per call
V1 (LRU cache): 2.3µs per call (380x)
V2 (in-memory): 0.2µs per call (4380x)
All reads now sub-microsecond:
get_asset: 0.2µs (was 876µs)
query(blockian): 6.6µs (was 2.2ms)
query(sector): 6.6µs (was 3.2ms)
exchange lookup: 12.5µs (was 1.5ms)
full scan: 5.9µs (was 1.8ms)
behavior: 0.4µs
Write path: sync_from_profiles batch-inserts all data, then materializes
into Python dicts. Resync: 76ms (was 210ms, 2.8x faster).
Data integrity: DuckDB WAL provides crash recovery. In-memory dicts are
reconstructed from DB on every sync/close-reopen cycle. Zero data loss.
MAX_HOLD: PARITY (base 250 + 4 modulation branches + bar quantization; fallback
120 loud-only). SL: value PARITY -1.2% (catastrophic-floor override), UV strictly
tighter. TP: NOT AT PARITY — UV 0.35% vs BLUE live 0.20%, no OB modulation
(x1.40/x0.60/x0.75), no TP_FLOOR; UV trailing is a different mechanism. Tie order
divergent (BLUE TP-first, UV SL-first). Price basis+cadence divergent (OBF-mid
per-scan vs BingX-mark 1s). Remediation order proposed, no build without operator.
Real colnames (timestamp/u_prefix_client_id, anomaly_events.ts), query/VST
errors FAIL never PASS (no green-by-error), openOrders wrapper unwrap,
check(d) CH_ALLOWLIST_DBS attribution (BLUE OBF writer no longer flagged).
Maiden live runs by Fable caught all 6; PASS8 fixed same-night.