Skip to content

Harden trading safety and simplify trading architecture - #3

Merged
wraithioner merged 4 commits into
mainfrom
codex/reliability-review
Oct 3, 2026
Merged

wraithioner merged 4 commits into
mainfrom
codex/reliability-review

Conversation

@wraithioner

@wraithioner wraithioner commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Trading failures could repeat a spend, miss a copied event, use a wallet after reset, or report profit against the wrong remaining cost basis. This PR strengthens trading safeguards and gives manual, copied and automated trades shared accounting in focused modules.

Changes

  • Split Telegram trade handlers into focused token, manual trade, funding, automation and copy-setting modules; split copy trading into receipt parsing, intake/recovery, policy, locks and execution modules. Public APIs remain compatible, and the runtime import graph has no cycles.
  • Share confirmed-fill classification, measured buy/sell bookkeeping, uncertain-basis handling and token-delta measurement across manual trades, copied trades, limit orders, DCA and sell-all.
  • Replace source-text safety assertions with observable behavior tests using fake providers and controlled promises. Add shared-accounting and real manual-confirmation integration suites.
  • Pin Biome for consistent formatting and recommended lint checks, enforce them in CI, and typecheck every source and test script. Add contributor instructions.
  • Preserve submission signatures; never blindly rebuild an uncertain spend. Confirmed fills stay claimed even if notification or accounting fails.
  • Validate external builder envelopes before signing: sole wallet signer/payer, quote binding, bounded compute/tip fees, permitted direct transfers/setup, known top-level programs, cleared signatures and a pre-sign recheck.
  • Persist target-scoped copy receipts, retry unreadable RPC receipts, paginate history and pause unknown gaps. Disabling or changing automation revokes authorization through submission.
  • Serialize whole operations through balance checks and bookkeeping. Reset and key deletion cancel queued/built work, drain active bookkeeping and clear all owner sessions. Confirmations require unchanged wallets/settings.
  • Retire measured partial-sale basis, use real decimals and account-wide holdings, withhold uncertain measurements, aggregate all token accounts and sweep non-ATAs. Refuse unknown Token-2022/confidential balances.
  • Preserve strongest concentration evidence and include unsampled supply in a conservative upper bound. Refuse malformed chain facts and pause authorities. Vesting receives no concentration discount.
  • Reconcile only supported attributable swaps, exclude rent/old WSOL refunds, respect per-transaction history boundaries and prevent stale repair writes after reset.
  • Keep error reporting safe when thrown values cannot be serialized or converted to strings.
  • Recover validated wallet/vault backups, preserve keys through passphrase conversion, enforce private-chat access and fix filtered/incomplete P&L displays.
  • Migrate all Jupiter calls to one authenticated, paced, deadline-aware gateway client; validate financial environment settings.
  • Scope Jayson 5.0.0 to web3.js with verified HTTP/RPC compatibility; audit is now 3 high / 0 moderate, down from 9 findings.

Validation

  • Formatting, lint and strict typechecking passed for all source/test scripts; 242 behavioral smoke checks passed.
  • All 15 offline regression suites passed, including the existing builder, copy-event, concurrency, accounting, history and client suites plus 11 shared-accounting, 23 public-behavior and 4 manual-confirmation groups.
  • Five actual unsigned builder responses replay offline. Earlier read-only PumpPortal buy/sell, Jupiter SOL→USDC and two-wallet Jito builds passed without signing or broadcasting.
  • Earlier live netcheck: 24 passed, 2 failed (missing holder data after provider limits/timeouts; Jupiter sell build HTTP 429). The architecture cleanup was verified offline.
  • The final integrated npm run check passed on Node 24.19.0. GitHub Actions passed the full format/lint/typecheck/test pipeline on Node 22 and 24 (run).

Tradeoffs and remaining work

The stricter holder bound and builder checks can refuse otherwise valid trades. Durable copy claims favor avoiding repeat spending; a crash after the claim can miss a copy.

Full CPI swap-intent decoding and a durable per-wallet submission journal remain priorities. An unresolved signed transaction can land after the in-process execution gate releases. PumpPortal's current opaque wrapper remains a trust dependency. Non-ATA sells may require consolidation, execution is process-local, and unfamiliar/composed history remains incomplete. The remaining audit findings derive from one unpatched bigint-buffer advisory.

See DEEP_REVIEW.md for reproductions, primary sources, compatibility evidence and remaining work. No production deployment or live trade was performed.

@wraithioner wraithioner changed the title Prevent duplicate trades and protect wallet recovery Harden trading safety, recovery, and accounting Oct 2, 2026
@wraithioner wraithioner changed the title Harden trading safety, recovery, and accounting Harden trading safety and simplify trading architecture Oct 2, 2026
@wraithioner
wraithioner marked this pull request as ready for review October 3, 2026 00:26
@wraithioner
wraithioner merged commit e511cb1 into main Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant