Skip to content

Iteration 41: parent SDK execution and runtime contracts - #14

Draft
cloudQuant wants to merge 1 commit into
devfrom
codex/iteration41-parent-worktree-closure
Draft

cloudQuant wants to merge 1 commit into
devfrom
codex/iteration41-parent-worktree-closure

Conversation

@cloudQuant

Copy link
Copy Markdown
Owner

Scope

This draft records the uncommitted parent SDK work from the original D:\bt_api_py checkout as commit ae6e6150. It adds CTP credential binding and execution approval contracts, a SimNow execution adapter candidate, runtime plugin contracts for managed dispatch/cancellation/reconciliation/recovery, the capability-bundle verifier, and focused offline tests. It also includes the root CTP minimum-version and pytest-asyncio pins plus installer compatibility changes.

The credential binding and adapter code can support managed CTP write operations when their explicit capabilities, owner-bound approvals, active native session, and per-operation verifier are supplied. These changes do not register a runtime adapter by default and do not establish production authorization. No live CTP login, order, cancel, account-wide writer fence, native lifecycle, or SimNow certification PASS is accepted here. Keep real trading writes NO_WRITE / LIVE_NO_GO pending independent cross-package review and QA.

The root version-pin changes overlap parts of draft PR #13. This PR intentionally targets dev as requested; reconcile that overlap before merging either PR.

Verification

  • git diff --cached --check passed before commit.
  • Focused source run with pytest-asyncio 0.23.8 and the checked-out CTP source: 592 passed, 2 skipped, 29 failed.
  • Of the 29 failures, 25 are runtime plugin tests incompatible with the current bt_api_risk PR ci(governance): land iteration 03 governance foundation (M0-M5) #1 API: generic resolution now rejects dispatch-inflight freezes, while the parent candidate still uses generic resolve/reassert paths. Three CTP read-observation cases reject their set1_group1 profile scope, and one gateway case returns UNKNOWN where the test expects RETURNED_UNVERIFIED.
  • Ruff reports one fixable import-order (I001) in test_ctp_entry_approval_arm.py; source was frozen without edits per the current instruction.
  • The combined capability-bundle run did not complete and is not counted as passing.

All test failures are fake/offline integration evidence. They do not authorize or demonstrate real provider writes.

@cloudQuant cloudQuant added the risk:r3 发布/安全/供应链风险 label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk:r3 发布/安全/供应链风险

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants