Repository navigation
Leverage-ladder gates require achieved leverage (all_of/greater_than conditions), not needs_attention alone - #197
Merged
seathatflowsinourveins merged 3 commits intoSep 24, 2026
Conversation
… (audit gap #5) The leverage-ladder-1x/2x/4x rows flipped on needs_attention == 0 alone, so a rung could be established by a clean trial whose achieved exposure never exceeded the next-lower rung's cap. - scripts/trading_gates.py: add greater_than (exact Decimal comparison of a JSON number or decimal string) and all_of (non-nested equals / array_contains_id / greater_than members) conditions, with validation. - catalogs/us-equities/gates-20260922.json: each ladder row's flip_condition is now an all_of over a preregistered rung receipt: /needs_attention == 0, /leverage/config_max_leverage and /leverage/next_lower_rung_ceiling equal to the rung, /leverage/peak_achieved_leverage > threshold and /leverage/seconds_above_next_lower_rung_ceiling > 0 (thresholds 0.5, 1, 2). - leverage.py: next_lower_rung_ceiling(1) returns the documented 0.5x minimum exposure (ONE_X_MINIMUM_EXPOSURE) instead of None, so the 1x receipt accumulates time above 0.5x. runner.py is unchanged (the native-fault receipt's engine-source binding still holds). - Tests: a trial that never exceeds the lower cap does not satisfy its rung (tests/test_trading_gates.py LeverageLadderFlipConditionTests and tests/test_adaptive_paper_runner.py AchievedLeverageGateTraceTests). - Rung config notes, README-safety.md, README.md and mover-v3 README updated; source-hashes.json and manifests/evidence.json entries refreshed for the changed files only. Offline unit tests on synthetic receipts and traces only; no paper trial was run and no rung receipt exists. No minimum duration above the threshold is set. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ix mover-v3 step-down text Fix round for audit gap #5 review findings. - scripts/trading_gates.py: new source_matches condition (standalone or as an all_of member). The receipt names an in-tree file by path and sha256; the file's bytes must hash to that value, and each [receipt, source] pointer pair must be equal with the same JSON types. Paths that are absolute, contain '..' or a backslash, or resolve outside the tree are refused. - catalogs/us-equities/gates-20260922.json: each leverage-ladder-1x/2x/4x all_of now also requires /schema_version == 1, /kind == "leverage_ladder_rung_receipt", /rung, /source/certified_run_status == "passed", and a source_matches binding. The binding ties the receipt's /leverage and certified_run_status to the /leverage and /status of the committed paper-output.json it names. The preregistered receipt schema in the notes gains source.{paper_output_path, paper_output_sha256, certified_run_status}. The notes also state a limit: needs_attention is a count across runs, is not bound to the hashed file, and is checked at the manual qualification. - mover-v3 README: the step-down list no longer calls seconds_above_next_lower_rung_ceiling a breach. It names achieved leverage above the ceiling in force as a proposed v3 rule (runner.py has no step-down on it today). seconds_above is described as a promotion input. - README-safety.md: documents the binding and its limits. - Tests: source_matches shape and behaviour. Every ladder rung rejects a receipt whose leverage block or status was edited, whose sha256 is wrong, or whose source is missing, outside the tree or absent. A rung also rejects a receipt that stitches one run's leverage onto another run's passed status, and one whose kind, schema_version or rung is wrong. Trials that never pass the lower cap still fail only on the achievement members. AchievedLeverageGateTraceTests now builds a hashed synthetic source. source-hashes.json and manifests/evidence.json entries are refreshed for the changed files only. Offline unit tests on synthetic receipts and sources only. No paper trial was run, and no rung receipt exists. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Resolve manifests/evidence.json by recomputing the hash of the merged catalogs/us-equities/gates-20260922.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins
deleted the
claude/leverage-flip-conditions-20260924
branch
September 24, 2026 17:24
seathatflowsinourveins
pushed a commit
that referenced
this pull request
Sep 25, 2026
Main moved 150+ commits, including #186 and #194 (the v3 data files and calendar extension) and #197 (leverage-ladder gate wording in the v3 README, which merged cleanly). manifests/evidence.json is main's registry with the stale digests refreshed. The study tree is bound by its own tree hash and pinned copies, and was never registered there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes audit gap from the 2026-09-24 trading wiring audit (native-agent-stack-71).
Audit gap #5 is closed: the leverage-ladder gates no longer flip on needs_attention == 0 alone.
What changed:
greater_thancompares exactly (as Decimal) and accepts a JSON number or a decimal string, because the runner writes Decimal values as strings. It rejects booleans, NaN, Infinity and anything that is not a number.all_oftakes a non-empty list of equals, array_contains_id or greater_than conditions. It cannot be nested and cannot containexists. Every condition pointer must now start with '/'.Each note now sets out the rung receipt format in advance: {schema_version 1, kind leverage_ladder_rung_receipt, rung, needs_attention, leverage}, where
leverageis the run's paper-output.json leverage block copied unchanged. The titles now name the threshold.Limits:
Tests. New tests:
Results:
Validation. All required validators pass (exit 0) on the final tree:
All 48 entries in source-hashes.json match the files on disk (5 refreshed). runner.py, safety.py and transport.py are unchanged, so the hashes bound by the native-fault receipt still hold.
Independent review. Severities: medium, medium, low, low, low, info, info. Fix round
b54ad77c64: fixed 2, rejected 0.🤖 Generated with Claude Code