Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
docs/evidence/phase8b_historical_shadow_campaign_public.json text eol=lf
19 changes: 18 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,18 @@ jobs:
run: python -m unittest discover -s open-core/tests -p "test_phase8b_operator_bootstrap.py" -v
- name: Phase 8B socket-free shadow runtime, account/market matrices, restart, replay, concurrency, crash, boundaries, and evidence
run: python -m unittest discover -s open-core/tests -p "test_phase8b_shadow*.py" -v
- name: Phase 8B historical shadow campaign compact 1,440-event cross-platform verification
if: ${{ matrix.os == 'windows-latest' || matrix.python != '3.12' }}
env:
RUN_SHADOW_CAMPAIGN_COMPACT: "true"
run: python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_campaign*.py" -v
- name: Phase 8B historical shadow campaign full 25,920-event verifier and evidence reproducibility
if: ${{ matrix.os == 'ubuntu-latest' && matrix.python == '3.12' }}
env:
RUN_SHADOW_CAMPAIGN_FULL: "true"
run: |
python -c "import subprocess; from secure_eval_wrapper.live.shadow_campaign_evidence import load_public_historical_shadow_campaign_evidence as load; evidence=load('docs/evidence/phase8b_historical_shadow_campaign_public.json'); sha=evidence['repository_sha']; subprocess.run(['git','merge-base','--is-ancestor',sha,'HEAD'],check=True); changed=subprocess.check_output(['git','diff','--name-only',sha,'HEAD'],text=True).splitlines(); assert changed == ['docs/evidence/phase8b_historical_shadow_campaign_public.json'], changed"
python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_campaign*.py" -v
- name: Compile package and scripts
run: python -m compileall -q open-core/src open-core/scripts
- run: secure-eval-backtest
Expand All @@ -105,6 +117,7 @@ jobs:
- run: secure-eval-live-kill --help
- run: secure-eval-live-bootstrap --help
- run: secure-eval-live-shadow --help
- run: secure-eval-live-shadow-campaign --help

postgres-integration:
name: PostgreSQL 16 integration
Expand Down Expand Up @@ -199,6 +212,10 @@ jobs:
env:
RUN_POSTGRES_INTEGRATION: "true"
run: python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_postgres.py" -v
- name: Phase 8B historical shadow campaign PostgreSQL 2,016-event persistence, replay, resume, gaps, conflicts, corruption, concurrency, and crash recovery
env:
RUN_POSTGRES_INTEGRATION: "true"
run: python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_campaign_postgres.py" -v
- name: Seeded 0023 to 0026 upgrade with existing Phase 5, Phase 6, Phase 7, and Phase 8A rows
run: |
python open-core/scripts/apply_postgres_migrations.py --database secure_eval_upgrade --create-database --through 0009 --seed-phase5
Expand Down Expand Up @@ -234,4 +251,4 @@ jobs:
python-version: "3.12"
- run: python -m pip install -e "./open-core[test]"
- name: No production writes, credentials, arbitrary endpoints, account powers, flattening, FIX, or fixture preflight authority
run: python open-core/src/secure_eval_wrapper/validation.py --skip-tests && python -m unittest discover -s open-core/tests -p "test_phase8_credential_permissions.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8_identity.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8_guarded_live.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8b_authenticated_readonly_preflight.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_boundaries.py" -v
run: python open-core/src/secure_eval_wrapper/validation.py --skip-tests && python -m unittest discover -s open-core/tests -p "test_phase8_credential_permissions.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8_identity.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8_guarded_live.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8b_authenticated_readonly_preflight.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_boundaries.py" -v && python -m unittest discover -s open-core/tests -p "test_phase8b_shadow_campaign_boundaries.py" -v
8 changes: 6 additions & 2 deletions .project/implementation_status.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"repository": "Tcx086/secure-eval-wrapper",
"status_source": "docs/IMPLEMENTATION_STATUS.md",
"schema": ".project/implementation_status.schema.json",
"updated_at_utc": "2026-07-18T18:00:00Z",
"updated_at_utc": "2026-07-26T00:00:00Z",
"current_phase": "phase_8_guarded_live_execution",
"rules": {
"future_functional_prs_must_update_markdown_status": true,
Expand Down Expand Up @@ -412,9 +412,13 @@
"Persist complete fixture, public, and unavailable provenance plus summary hashes inside the authoritative JSONB bundle; apply one canonical SQL, JSON, hash, and safety validator during target verification, replay, load, and inspect; and add committed-row, restart, replay, conflict, and provenance-tamper regressions without migration 0027",
"Upgrade to verifier v4 with seven distinct executable concurrency semantics whose expected and observed classifications, run IDs, hashes, result hashes, and passed flags are rerun and compared exactly",
"Preserve source-issued public read counts across downstream runtime, persistence, replay and conflict, and serialization failures with an immutable public-safe operation carrier and CLI regressions that cannot expose private exception text",
"Independently audit and accept the public-data and synthetic-account Phase 8B shadow-assurance implementation with audit conclusion PASS and 0 blockers: PR #9 candidate head 3e2849f0cc6262b75cb983a9876e19cf7c5356d9 merged as 376aa35e5b8b77d67b24efca5bbc9fffc95137a5; accept docs/evidence/phase8b_shadow_assurance_public.json payload SHA-256 666c0e229c9b002a78ee5b235f11eef42fa3d0403b9169c2528c0ba30c8ae0dd and phase8b-shadow-assurance-verifier-v4 result SHA-256 a90b6730d527d42527be697d498c6e8c0fb0793a94bc0c03f84d0a743ad6542a; final-main Actions run 29865978929 checked out 376aa35e5b8b77d67b24efca5bbc9fffc95137a5 and passed Ubuntu Python 3.11 job 88754184792, Ubuntu Python 3.12 job 88754184786, Ubuntu Python 3.13 job 88754184811, Windows Python 3.12 job 88754184779, PostgreSQL 16 integration job 88754184783, and public/private and runtime boundary job 88754184785; migrations 0001 through 0026 remain immutable with no 0027; no real public-network smoke, operator bootstrap, or authenticated proof was executed, real-proof authorization remains NO, and production submit/cancel remain disabled and unreachable"
"Independently audit and accept the public-data and synthetic-account Phase 8B shadow-assurance implementation with audit conclusion PASS and 0 blockers: PR #9 candidate head 3e2849f0cc6262b75cb983a9876e19cf7c5356d9 merged as 376aa35e5b8b77d67b24efca5bbc9fffc95137a5; accept docs/evidence/phase8b_shadow_assurance_public.json payload SHA-256 666c0e229c9b002a78ee5b235f11eef42fa3d0403b9169c2528c0ba30c8ae0dd and phase8b-shadow-assurance-verifier-v4 result SHA-256 a90b6730d527d42527be697d498c6e8c0fb0793a94bc0c03f84d0a743ad6542a; final-main Actions run 29865978929 checked out 376aa35e5b8b77d67b24efca5bbc9fffc95137a5 and passed Ubuntu Python 3.11 job 88754184792, Ubuntu Python 3.12 job 88754184786, Ubuntu Python 3.13 job 88754184811, Windows Python 3.12 job 88754184779, PostgreSQL 16 integration job 88754184783, and public/private and runtime boundary job 88754184785; migrations 0001 through 0026 remain immutable with no 0027; no real public-network smoke, operator bootstrap, or authenticated proof was executed, real-proof authorization remains NO, and production submit/cancel remain disabled and unreachable",
"Implement the historical shadow campaign candidate as a deterministic streaming orchestration layer over the accepted ShadowAssuranceRuntime, guarded-live configuration, standardized signals, preflight, approval, manifest, risk, reservation, canonical shadow bundle, and PostgreSQL repository contracts; the fixed full profile generates 25,920 five-minute BTC-USDT Spot events across twelve regimes and a deterministic synthetic-account timeline without treating hypothetical intents as fills or account-state changes",
"Add deterministic event, segment, window, account-snapshot, run, decision-chain, and campaign identities; point-in-time anti-lookahead checks; exact replay; earliest-gap resume; mutation lineage; concurrency and crash matrices; the secure-eval-live-shadow-campaign plan, run, resume, inspect, and verify interface; callback-free exact-type and sealed-container boundaries; truthful structured failure stages and progress; strict canonical duplicate-free verifier-derived public evidence; focused tests; and six-job CI wiring without adding a migration or production authority; this records an implementation candidate only and does not claim that independent audit, branch CI, PostgreSQL execution, public-network smoke, operator bootstrap, or authenticated proof has passed or executed",
"Preserve the independently accepted Phase 8B shadow-assurance baseline unchanged; operator bootstrap execution remains unexecuted, authenticated proof remains unexecuted, real-proof authorization remains NO, Phase 8 remains in_progress, Phase 8C remains not_started, Phase 9 remains todo, and production submit and cancel remain disabled and unreachable"
],
"todo": [
"Independently audit the Phase 8B historical shadow campaign implementation and its public evidence before accepting it; until then it remains implemented_pending_independent_audit",
"Prepare a separately and explicitly authorized local secure_eval_phase8b database bootstrap operation; bootstrap authorization and authenticated-proof authorization must remain distinct, and neither bootstrap nor authenticated proof may run automatically",
"Keep real authenticated proof authorization at NO; optionally execute exactly one controlled local authenticated read-only proof with operator-owned environment credentials that are never persisted only after separate exact operator authorization",
"Independently review the resulting redacted proof before accepting the operational Phase 8B checkpoint",
Expand Down
11 changes: 7 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ A public, auditable, and reproducible framework for building crypto trading syst

The project is developed in explicit, auditable phases. Architecture, PostgreSQL foundations, public market data, public alpha, and standardized signals are complete. Deterministic simulated execution and event-driven backtesting are complete after local PostgreSQL 16 and independent GitHub Actions validation.

> **Current status:** Phases 0-7 are completed checkpoints. Phase 8A and the Phase 8B authenticated read-only proof implementation are independently audited and accepted. A public-data/synthetic-account Phase 8B shadow-assurance implementation candidate is pending independent audit; the optional real local authenticated proof has not been executed. Production submit/cancel and external production FIX remain disabled and unreachable.
> **Current status:** Phases 0-7 are completed checkpoints. Phase 8A, the Phase 8B authenticated read-only proof implementation, the dedicated operator bootstrap implementation, and the public-data/synthetic-account shadow-assurance baseline are independently audited and accepted. The Phase 8B historical shadow campaign is an implementation candidate pending independent audit. Operator bootstrap execution and the optional real authenticated proof remain unexecuted, real-proof authorization is `NO`, and production submit/cancel and external production FIX remain disabled and unreachable. Phase 8 remains `in_progress`, Phase 8C remains `not_started`, and Phase 9 remains `todo`.

## Why this project exists

Expand Down Expand Up @@ -73,8 +73,8 @@ Signals are not fills. Phase 5 backtests create order intents, pass them through
| 5 | Simulated Execution and Event-Driven Backtesting | Completed; PostgreSQL and CI validated |
| 6 | Monitoring and strictly simulated FIX 4.4-compatible profile | Completed; first-independent-audit repairs accepted |
| 7 | Paper Trading | Completed through fifth independent audit |
| 8 | Guarded Live Execution | Phase 8A/proof accepted; shadow-assurance candidate pending audit; real proof unexecuted; production writes disabled |
| 9 | Reporting and Public Delivery | Future |
| 8 | Guarded Live Execution | In progress; Phase 8A/proof/bootstrap/shadow-assurance implementations accepted; historical campaign candidate pending audit; bootstrap and real proof unexecuted; production writes disabled; Phase 8C not started |
| 9 | Reporting and Public Delivery | Todo; not started |

The authoritative progress records are:

Expand All @@ -83,6 +83,7 @@ The authoritative progress records are:
- [`docs/IMPLEMENTATION_STATUS.md`](docs/IMPLEMENTATION_STATUS.md)
- [Guarded live execution](docs/GUARDED_LIVE_EXECUTION.md)
- [Phase 8B shadow assurance](docs/PHASE8B_SHADOW_ASSURANCE.md)
- [Phase 8B historical shadow campaign](docs/PHASE8B_HISTORICAL_SHADOW_CAMPAIGN.md)
- [`.project/implementation_status.json`](.project/implementation_status.json)

Completed and planned work must remain synchronized between these two files.
Expand Down Expand Up @@ -340,7 +341,7 @@ The intended principle is simple: **make the infrastructure inspectable without

Phases 3 and 4 are complete and auditable: public alphas produce continuous point-in-time `AlphaValue` records, and standardized signals apply deterministic ranking, thresholding, combination, conflict, and confidence rules with PostgreSQL lineage.

Phase 5 simulated execution and backtesting is complete through its fourth independent audit. Phase 6 monitoring and the strictly simulated FIX API are complete. Phase 7 safe paper trading is complete through its fifth independent audit. Phase 8A is an accepted PostgreSQL-authoritative guarded-live dry-run/read-only foundation. The Phase 8B explicit authenticated read-only proof implementation is independently audited and accepted, while its optional real local authenticated proof has not yet been executed; production order and cancellation transport remains unconditionally disabled.
Phase 5 simulated execution and backtesting is complete through its fourth independent audit. Phase 6 monitoring and the strictly simulated FIX API are complete. Phase 7 safe paper trading is complete through its fifth independent audit. Phase 8A is an accepted PostgreSQL-authoritative guarded-live dry-run/read-only foundation. The Phase 8B authenticated read-only proof, operator bootstrap, and public-data shadow-assurance implementations are accepted baselines. The historical shadow campaign is a separate implementation candidate pending independent audit; neither operator bootstrap execution nor the optional real authenticated proof has occurred, real-proof authorization remains `NO`, and production order/cancellation transport remains unconditionally disabled.

## Disclaimer

Expand All @@ -359,3 +360,5 @@ The public framework includes deterministic point-in-time monitoring and a stric
`secure-eval-live-dry-run`, `secure-eval-live-status`, `secure-eval-live-reconcile`, and `secure-eval-live-kill` remain safe, write-free commands. `secure-eval-live-preflight` is socket-free without its explicit Phase 8B network flag; with every reviewed configuration, identity, fingerprint, credential-source, PostgreSQL, and CI gate satisfied, it can issue only the exact six catalogued OKX GETs and persist a public-safe proof. No Phase 8 command calls production submit or cancel. See [Guarded Live Execution](docs/GUARDED_LIVE_EXECUTION.md).

`secure-eval-live-shadow` is a separate, permanently hypothetical assurance path. Its default fixture mode evaluates deterministic synthetic accounts and replayable public-market fixtures through the shared guarded-live preflight, approval, manifest, risk, reservation, and PostgreSQL audit contracts. Public-network mode is explicit, bounded, unauthenticated, and limited to exactly two OKX BTC-USDT Spot public GETs. The production source always constructs its own sealed `UrlLibHttpTransport`; offline fake transports remain confined to a `fixture_protocol_test` request-contract harness and cannot create public-network authority. Source-instance-bound provenance is persisted inside the decision/summary hash chain. One canonical validator rechecks every existing, replayed, loaded, or inspected bundle and fails closed on committed-row tampering without repair. Verifier v4 executes the seven distinct concurrency semantics rather than repeating one idempotency pattern. Persistent runs accept only literal loopback and disposable `secure_eval_phase8b_shadow_<suffix>` PostgreSQL 16 targets, with libpq-managed authentication and no password CLI argument. The checked public artifact reports both PostgreSQL verification and public smoke as not executed and remains pending independent audit. The shadow dependency graph has no production broker, submit, cancel, credentials, authenticated endpoints, or operator-database authority. See [Phase 8B Shadow Assurance](docs/PHASE8B_SHADOW_ASSURANCE.md).

`secure-eval-live-shadow-campaign` extends that accepted shadow-assurance baseline with a deterministic, streaming 90-day-equivalent historical campaign over 25,920 generated five-minute BTC-USDT Spot events, twelve fixed regimes, and a deterministic synthetic-account timeline. `plan` is socket-free and database-free; `run`, `resume`, `inspect`, and `verify` accept only literal loopback PostgreSQL 16 targets named `secure_eval_phase8b_shadow_campaign_<safe_suffix>`, delegate authentication to libpq, and expose no password argument. Completion is reconstructed from canonical validated per-event shadow bundles in `audit.run_manifests`; no migration `0027` or campaign-complete authority row is introduced. The candidate enforces point-in-time decision inputs, deterministic IDs and hash chains, exact replay, earliest-gap resume, mutation lineage, and bounded public-safe output. It is pending independent audit and does not authorize authenticated proof or production writes. See [Phase 8B Historical Shadow Campaign](docs/PHASE8B_HISTORICAL_SHADOW_CAMPAIGN.md).
Loading
Loading