CEX execution: record proven submission and private-report spans - #464
Conversation
|
Warning Review limit reached
Next review available in: 41 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4cf7323cec
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…-399 # Conflicts: # rust_hft/market-core/engine/src/execution_worker.rs
Change contract
Record seven separate, proven monotonic execution spans for each strategy intent handoff, optional risk completion, userspace write start/return, decoded and semantically validated Binance Spot WS response, private ACK, and private execution report, while preserving fail-closed handling for ambiguous submission and cancel outcomes.
Issue relationship
Closes #399
Acceptance evidence
hft_execution_span_microseconds{span=...}exposes seven fixed, low-cardinality spans:intent_to_risk,risk_to_userspace_write,userspace_write,write_to_sync_response,write_to_private_ack,write_to_private_report, andintent_to_private_report.x/Xprivate reports do not claim authoritative timing.Out of scope
Dependency or merge order
PR #446 is merged. This PR targets
mainand is independently mergeable.Focused validation
cargo test --quiet -p hft-ports -p hft-engine -p hft-execution-adapter-binance -p hft-runtime -p hft-infra-metricscargo check --quiet --workspace --all-targetscargo clippy --quiet -p hft-ports -p hft-engine -p hft-execution-adapter-binance -p hft-infra-metrics --lib -- -D warnings/root/pr464_spec./root/pr464_standards.Atomic review-size exception
The final eight-file vertical slice is 1,283 changed lines (
+1,130/-153), exceeding the 750-line assessment threshold. Codex Standards reviewer/root/pr464_standardsexplicitly approved the atomic exception: ports, engine lifecycle/risk propagation, worker correlation, Binance private-report semantics, metrics, and their counterexamples form one execution-timing evidence contract. Splitting them would permit partial timing claims or lifecycle loss and would not be independently safe.Rollout / rollback impact
Metrics and fail-closed execution-safety change only. Live remains disabled. Roll back by reverting this PR's merge commit; no schema migration or runtime cleanup is required.