BUG CLASS (doc: BUGCLASS_INDETERMINATE_OUTCOME_20260713.md): an operation with an external
side effect has THREE outcomes — NOT_ATTEMPTED, ATTEMPTED_REFUSED, ATTEMPTED_INDETERMINATE
— and rollback is sound only for the first two. Collapsing the third into 'failed' is what
orphaned 6 live SHORTs: a post-ack TypeError reached rust_backend's 'except Exception ->
synthetic REJECTED -> FSM rollback', which asserted 'no order exists' about an order that
was already filled. Telemetry never had a veto; it hijacked the failure channel.
FIXES (no new seams, no re-architecture):
- venue.py: VenuePostAckError — typed channel meaning THE EFFECT EXISTS. Carries receipt.
- bingx_venue submit/submit_async: point-of-no-return fence. Post-ack bookkeeping failures
raise VenuePostAckError instead of a bare exception.
- rust_backend (BOTH submit paths): catch VenuePostAckError FIRST -> no synthetic REJECT,
no rollback. Slot stays working; E-feed FULL_FILL / reconcile settles the truth.
LOSSLESS TELEMETRY (HJ: 'DITAv2 exists precisely because seams dropped 40% of inputs'):
drop-oldest is data loss and is GONE. Exec path appends O(1) to an unbounded queue and
returns. A SEPARATE spiller thread (which never touches the plane, so a wedged plane cannot
starve it) parks the backlog above HWM into a durable append-only spool; the publisher
replays the spool when the plane recovers.
Proven: wedged-forever plane + 200k records -> 0 dropped, 195903 durable on disk, 4096 in
memory, 7.4 us/call on the exec path. Lossless AND memory-bounded. Healthy plane: 2000/2000.
STILL BROKEN, flagged to codex: the pre-ack branch rolls back on TIMEOUT — but a timeout is
the definition of INDETERMINATE (the order may have filled). Same bug class, older, live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Central finding: TIER-B INVERSION. asex_kernel_executor.py:319 enqueues account/fill
events (execution truth) at priority=4 — the LOWEST tier, BELOW ENTER (P3). Under queue
pressure UV opens a new position before applying the fill that tells it what it already
holds. Tonight's 6 orphans are the proof: tier-G telemetry destroyed tier-B truth, UV
believed it was flat while holding 6 live SHORTs, and no SL/TP/ADVSL can protect a
position the kernel does not know exists. That is why B outranks C and D.
Also catalogued: A-tier sensors (heartbeat/disconnect/seq-gap/halt/stale-book) are not
ranked work at all — only the kill switch is. Missing C (liquidation distance, daily/
session loss, symbol loss, leverage trigger), D (trailing, giveback, stale-exit reprice),
E (self-cross, amend), F (spread/depth gate).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Standing steer (HJ, months): non-blocking behaviour + explicit execution priority.
Telemetry is not on the ladder at all, yet it sat ON the order path, inline and able to
raise — which is how it orphaned 6 live positions.
Exec path now does exactly one thing: pack primitives, append to a bounded ring, return.
No plane write, no snapshot construction, no I/O, no lock, no raise. Snapshot build +
plane publish move to a daemon drain lane. Ring is deque(maxlen=4096): drops OLDEST on
full and counts the drops — telemetry loss is always preferable to exec backpressure,
but it stays observable.
Measured: 1000 exec-path calls against a 2s-BLOCKING plane = 3.65 ms total (3.65 us/call).
Inline, that was 2000 s of stall. Wedged lane + 50k pushes -> ring pinned at 4096,
45903 counted drops, exec path never backpressured. Healthy plane still gets 5/5.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The pre-existing guard covered only publish(). The attribute/coercion block above it
(int()/str()/.metadata.get() on intent+order) was UNGUARDED, and kwarg binding happens
before the body runs at all — so a signature skew sailed straight past a defence that
existed precisely to prevent this, and orphaned 6 live positions.
Everything that can raise now lives inside one try. Failures log loud and are swallowed;
the order path is never affected. Proven against: exploding plane, poisoned intent
coercion (the formerly-unguarded region), and absent plane.
ARCHITECTURAL DEBT (raised by HJ, not fixed here): telemetry has no business being called
inline on the exec path at all. Correct shape = fire-and-forget enqueue drained by the M6
journal lane. This commit makes it harmless, not absent.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Line 154 held mutant debris: KernelControlSnapshot(mode="live", mode="live"") — duplicate
kwarg + unterminated string. Committed since a55501b, it made the ENTIRE dita_v2 suite fail
collection, so nobody has run it. That is why no test caught the bingx_venue telemetry
signature skew that orphaned 6 live positions tonight.
The test was fantasy besides: asserted read.arming == "DARK" (no such field) and
mode == "live" (KernelMode is NORMAL|DEBUG). Rewritten to assert a real invariant —
the second write must flip the buffer and become visible.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
M5 (native_artifact.py + rust_backend build_verified_artifact/verify_artifact hooks)
existed ONLY in the uv/exec-refactor worktree. Canonical never received it, so
vendor_sync.sh downgraded the vendored copy back to a raw 'cargo build' — the same
mechanism by which M1's relock clobbered the bingx_venue telemetry fix and orphaned
6 live positions. Canonical is the source of truth; M5 belongs here.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
M1 re-vendor (89a1f1a) clobbered the T0-DEVIATION fix (20ad493): submit()/submit_async()
pass order_id=/client_order_id= post-ack, the signature dropped them. Every ENTER raised
TypeError AFTER the venue POST returned 200 OK -> rust_backend synthesised REJECTED ->
FSM rollback, while the venue kept the position. Flight-4: 8 bridged promotions, 6 orphan
SHORTs live on VST with a kernel that believes it is flat.
Two fixes:
1. signature accepts order_id/client_order_id again; snapshot prefers them (order is None
on the submit path, so the ack row is the only id source).
2. post-ack telemetry wrapped: observability can never again veto an accepted order.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
CMAESTrainer.train() now accepts workers parameter and passes it to
evaluate_candidate(), enabling parallel episode evaluation during
actual training (not just in tests/benchmarks).
Benchmark result: ProcessPoolExecutor is optimal (4.76x speedup).
Ray is slower (0.36x) due to head init + plasma overhead for 90 scenarios.
1. Vectorized reward path (cwm/core.py):
- Wired up existing compute_reward_vectorized from numba_core (was unused!)
- Eliminates FeatureVector dict allocation + Python dict lookups on hot path
- Numba path used when _HAS_NUMBA=True, Python fallback otherwise
- Bit-identical: same math operations, just via numba JIT
2. Ray-based parallel eval (training/ray_eval.py):
- Industrial multi-core execution via Ray (used by OpenAI/Anyscale)
- ray.put() stores params/scenarios in shared object store (no pickle per worker)
- Each worker: own CWM + planner, zero shared state, no races
- Bit-identical: same seed + same params = same results regardless of worker count
- PolicyEvaluator.evaluate_candidate: new use_ray=True parameter
3. VBT post-analysis (training/vbt_analysis.py):
- episodes_to_pnl_array, episodes_to_metrics (Sharpe, Sortino, VaR, win_rate, etc.)
- cross_asset_comparison, parameter_sensitivity
- format_metrics for human-readable output
- Analysis tool only — runs AFTER engine produces results
4. numba_core.py: added missing 'import math' for compute_reward_vectorized
13 new tests: vectorized reward bit-identity, Ray determinism, Ray result fields,
VBT metrics structure, cross-asset comparison, parameter sensitivity, edge cases.
Total: 1178 tests, 50 files, all green, zero regressions.
Architecture: DuckDB for persistence + full in-memory materialization for reads.
All reads served from Python dicts (sub-microsecond). DuckDB only hit on writes.
Performance evolution (get_asset benchmark):
V0 (raw DuckDB): 876µs per call
V1 (LRU cache): 2.3µs per call (380x)
V2 (in-memory): 0.2µs per call (4380x)
All reads now sub-microsecond:
get_asset: 0.2µs (was 876µs)
query(blockian): 6.6µs (was 2.2ms)
query(sector): 6.6µs (was 3.2ms)
exchange lookup: 12.5µs (was 1.5ms)
full scan: 5.9µs (was 1.8ms)
behavior: 0.4µs
Write path: sync_from_profiles batch-inserts all data, then materializes
into Python dicts. Resync: 76ms (was 210ms, 2.8x faster).
Data integrity: DuckDB WAL provides crash recovery. In-memory dicts are
reconstructed from DB on every sync/close-reopen cycle. Zero data loss.
MAX_HOLD: PARITY (base 250 + 4 modulation branches + bar quantization; fallback
120 loud-only). SL: value PARITY -1.2% (catastrophic-floor override), UV strictly
tighter. TP: NOT AT PARITY — UV 0.35% vs BLUE live 0.20%, no OB modulation
(x1.40/x0.60/x0.75), no TP_FLOOR; UV trailing is a different mechanism. Tie order
divergent (BLUE TP-first, UV SL-first). Price basis+cadence divergent (OBF-mid
per-scan vs BingX-mark 1s). Remediation order proposed, no build without operator.
Real colnames (timestamp/u_prefix_client_id, anomaly_events.ts), query/VST
errors FAIL never PASS (no green-by-error), openOrders wrapper unwrap,
check(d) CH_ALLOWLIST_DBS attribution (BLUE OBF writer no longer flagged).
Maiden live runs by Fable caught all 6; PASS8 fixed same-night.
Formalizes the CEX-010 E-feed account plane (protocol + InMemoryZincPlane +
real plane). This code flew 33h on UV-PRIME flight-1 via the vendored copy
(T0-DEVIATION mid-edit vendoring) but was never committed upstream — the
2026-07-11 clean vendor_sync regressed it and broke the E-feed at boot
(AttributeError publish_account). Committing the flight-proven bytes closes
the vendor-law gap. Authorship: pre-existing WIP in /mnt working tree
(T0-era, likely codex), committed verbatim by Fable for vendor integrity.
- Added parallel_eval.py to package structure tree
- Added Parallel Eval row to completed subsystems table
- Updated CWM row with numba timing (5.3 µs/transition)
- Date updated to 2026-07-11
Read-only auditor for arming-checklist §4 anomalies, the instrument for the
72h-clean finish-line clock. 5 checks against CH + VST (all read-only):
(a) venue order without matching BRIDGE exec_journal row
(b) exec_journal row without venue order
(c) venue order without 'u-' clientOrderId prefix
(d) CH write outside dolphin_uv.* in runner window
(e) tripwire_ok=false occurrences
Authored by cmd-PASS1.2 (PASS8), provenance /mnt/vp-PASS8 bf55777
(agent/oa-violetPASS8). Landed by content (cross-clone fetch hung); files
SHA256-identical to source. Fable verification: 20/20 pass; mutation litmus
RED (inverting the check-(c) prefix guard fails 6 tests incl. PASS8's own
test_c_mutation_* guards — the doctrine's litmus baked into the suite);
read-only confirmed (no writes on any path).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Per Fable #f0fb09ff090feb1f: corrected UTC boundary (gate 08:43:47 CET =
06:43:47 UTC). Re-sliced cached pull by journal_ts. Verified: era A
(incident tail 06:00-06:43:47 UTC) holds 1 of 180 BRIDGE rows (0 pairs,
NET +0.00); era B (clean/certified) holds all 75 paired trades + all 25
bridged-no-venue rows, NET -758.48. Fable's hypothesis (era A carries most
of -758) INVERTED — the full -758.48 is the certified-era number. 0 of 25
no-venue rows are incident-era; they are a clean-era reconciliation gap.
No venue re-fetch. Rollback tag rollback_pre_PASS10_audit_era_20260711190153.