Skip to content

fix(execution): a permissions refusal on a bracket leg is definite -- rejected and retried, not state-unknown (#945) - #948

Merged
eaitbrahim merged 2 commits into
mainfrom
fix/945-bracket-refusal-is-definite
Sep 30, 2026
Merged

eaitbrahim merged 2 commits into
mainfrom
fix/945-bracket-refusal-is-definite

Conversation

@eaitbrahim

Copy link
Copy Markdown
Contributor

Closes #945.

What

R5 booked every post-row bracket-leg raise the same way: the pending row stayed, the unbracketed: retry was cleared, and a CRITICAL executor.bracket_state_unknown parked the product's exits on a human -- correct for a timeout, where the venue really may be holding the order. TradeScopeDenied was folded into that bucket on purpose, but a permissions refusal is a DEFINITE answer: the venue did not take the order, nothing rests at the exchange, and there is no unknown to reconcile.

The fix (the review's S-6, R80 in the plan)

A dedicated except TradeScopeDenied ahead of the broad handler:

  • the written row is marked rejected -- the status a broker-rejected placement already takes in _run_order, and what reconcile's own docstring says a broker rejection writes;
  • the unbracketed: retry record is armed (not cleared), so reconcile_unbracketed_positions re-places next cycle and heals the moment the credential trades again -- a rejected row is not a resting one and blocks nothing;
  • a CRITICAL executor.bracket_refused names the position: unprotected, loudly, but not unknown.

Timeouts and every other raise keep R5's state-unknown booking unchanged. _run_order's refutation write (#233) is untouched -- a placement-path refusal is a credential fact; only its row bookkeeping changes. A refusal at the PREVIEW (before any row exists) keeps the pre-row retry path it always had.

Tests

Plan doc: R80 (note: this branch and #944 both append after R77 -- trivial conflict, keep R78/R79 then R80).

… rejected and retried, not state-unknown (#945)

R5 booked every post-row raise as state-unknown: the pending row stayed,
the unbracketed: retry was cleared, and the product's exits waited on a
human to reconcile a row no venue order backed. A TradeScopeDenied is not
ambiguity -- the venue refused the order outright, so nothing rests at the
exchange.

The row now takes rejected (the status a broker-rejected placement already
takes), the retry record is armed, and a CRITICAL executor.bracket_refused
names the position; the next cycle's sweep re-places, and heals the moment
the credential trades again. Timeouts and network raises keep R5's
state-unknown booking. _run_order's refutation write (#233) is untouched.
…al-is-definite

# Conflicts:
#	docs/superpowers/plans/2026-09-28-dca-sleeve-sell-side-build.md
@eaitbrahim
eaitbrahim merged commit 066fd9b into main Sep 30, 2026
4 checks passed
@eaitbrahim
eaitbrahim deleted the fix/945-bracket-refusal-is-definite branch September 30, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A definite TradeScopeDenied on a bracket leg is booked state-unknown, parking exits on a phantom pending row

1 participant