Skip to content

CEX execution: record proven submission and private-report spans - #464

Merged
proerror77 merged 6 commits into
mainfrom
codex/execution-spans-399
Jul 29, 2026
Merged

proerror77 merged 6 commits into
mainfrom
codex/execution-spans-399

Conversation

@proerror77

@proerror77 proerror77 commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Change contract

Record seven separate, proven monotonic execution spans for each strategy intent handoff, optional risk completion, userspace write start/return, decoded and semantically validated Binance Spot WS response, private ACK, and private execution report, while preserving fail-closed handling for ambiguous submission and cancel outcomes.

Issue relationship

Closes #399

Acceptance evidence

  • Each emitted intent carries its own monotonic handoff timestamp through risk review, including duplicate strategy IDs; quote expiry remains anchored to the source market event's local receive time.
  • No-risk paths leave risk completion unavailable instead of fabricating a zero span.
  • hft_execution_span_microseconds{span=...} exposes seven fixed, low-cardinality spans: intent_to_risk, risk_to_userspace_write, userspace_write, write_to_sync_response, write_to_private_ack, write_to_private_report, and intent_to_private_report.
  • Execution-span buckets extend to 1 second so remote-response and private-report tails do not collapse into the first overflow bucket.
  • Binance Spot captures userspace write start/return separately. The decoded matching-response boundary is retained only after semantic validation; malformed, mismatched, timeout, transport-unknown, and inconsistent x/X private reports do not claim authoritative timing.
  • Stable client IDs retain provisional state on unknown outcomes; unknown cancel outcomes latch intake. Successful timelines rekey safely when an adapter returns a different order ID.
  • Counterexamples cover per-intent handoff timing with duplicate IDs, stale quote-age anchoring, absent risk, portfolio batch accumulation with lifecycle preservation, delayed/malformed/mismatched responses, timeout after write, private ACK before/after synchronous response, end-to-private-report timing, ambiguous submission/cancel, and duplicate returned order IDs.

Out of scope

  • Kernel, NIC, or hardware TX timestamping
  • Transport migration, batching, or rate admission
  • USD-M/Futures execution
  • Adapters other than Binance Spot; they report unavailable transport boundaries through the default traced method
  • Live enablement or deployment

Dependency or merge order

PR #446 is merged. This PR targets main and is independently mergeable.

Focused validation

  • cargo test --quiet -p hft-ports -p hft-engine -p hft-execution-adapter-binance -p hft-runtime -p hft-infra-metrics
  • cargo check --quiet --workspace --all-targets
  • cargo clippy --quiet -p hft-ports -p hft-engine -p hft-execution-adapter-binance -p hft-infra-metrics --lib -- -D warnings
  • Duplicate-ID counterexample passed 20 consecutive runs with a bounded 100,000 microsecond lifecycle budget.
  • Spec review: PASS by /root/pr464_spec.
  • Standards review: PASS; atomic exception approved by /root/pr464_standards.

Atomic review-size exception

The final eight-file vertical slice is 1,283 changed lines (+1,130/-153), exceeding the 750-line assessment threshold. Codex Standards reviewer /root/pr464_standards explicitly approved the atomic exception: ports, engine lifecycle/risk propagation, worker correlation, Binance private-report semantics, metrics, and their counterexamples form one execution-timing evidence contract. Splitting them would permit partial timing claims or lifecycle loss and would not be independently safe.

Rollout / rollback impact

Metrics and fail-closed execution-safety change only. Live remains disabled. Roll back by reverting this PR's merge commit; no schema migration or runtime cleanup is required.

@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@proerror77, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 41 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 144920e0-acd4-4eb9-9d81-f7e3f978ec83

📥 Commits

Reviewing files that changed from the base of the PR and between 6bbe89b and 2f4c41f.

📒 Files selected for processing (8)
  • rust_hft/execution-gateway/adapters/adapter-binance/src/lib.rs
  • rust_hft/execution-gateway/adapters/adapter-binance/src/ws_order.rs
  • rust_hft/infra-services/core/metrics/src/lib.rs
  • rust_hft/market-core/engine/src/execution_worker.rs
  • rust_hft/market-core/engine/src/lib.rs
  • rust_hft/market-core/ports/src/events.rs
  • rust_hft/market-core/ports/src/traits.rs
  • rust_hft/market-core/runtime/src/portfolio_manager.rs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4cf7323cec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread rust_hft/market-core/engine/src/lib.rs Outdated
Comment thread rust_hft/execution-gateway/adapters/adapter-binance/src/ws_order.rs Outdated
Comment thread rust_hft/market-core/engine/src/lib.rs Outdated
Comment thread rust_hft/infra-services/core/metrics/src/lib.rs Outdated
Comment thread rust_hft/market-core/engine/src/execution_worker.rs Outdated
Comment thread rust_hft/market-core/engine/src/lib.rs Outdated
Base automatically changed from codex/receive-boundary-396 to main July 29, 2026 13:38
@proerror77
proerror77 merged commit 0d11a01 into main Jul 29, 2026
39 of 42 checks passed
@proerror77
proerror77 deleted the codex/execution-spans-399 branch July 29, 2026 22:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CEX execution: instrument intent-to-write, ACK, and private-report spans

1 participant