Skip to content

Issue #427: reject negative atomic settlement balances - #784

Merged
drevendev merged 1 commit into
masterfrom
zen/issue-427-strict-no-negative-preflight-r623
Oct 3, 2026
Merged

drevendev merged 1 commit into
masterfrom
zen/issue-427-strict-no-negative-preflight-r623

Conversation

@drevendev

@drevendev drevendev commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Follow-up hardening for #427; this does not close the composite issue.

Achieved outcome

Settlement preflight projects the complete atomic goods/money delta sequence in the same arithmetic order used by the commit loops. It rejects any final negative canonical inventory or wallet, including sub-epsilon overdrafts, without rejecting a temporary negative intermediate projection when the final atomic balance is nonnegative. This PR changes no stock ownership, economic formula or allocation schema.

Issue and tested revision

Work record: #427, bounded nonnegative-final-balance follow-up only.
Exact product head: 046ec8fa39cc89da57b51eb515abb3b0b3f501d5 on zen/issue-427-strict-no-negative-preflight-r623.
Observed base: 6f99ada100785546275854927f5cf91a48168fbd (master). PR readback: one commit, two changed files, mergeable.

Changed files

  • src/simulation/marketSettlementTransition.ts — replace separately summed, epsilon-tolerant net preflight with ordered per-physical-stock final-balance projection; reject final balances below zero.
  • src/simulation/marketSettlementTransition.test.ts — add seller inventory and buyer wallet sub-epsilon overdraft refusals plus the same-wallet floating-point sequence that finishes exactly at zero.

Acceptance criteria and verification

  • Goods and wallet overdrafts of 5e-10 from zero stock are refused rather than persisted: covered by two new repository regressions.
  • The ordered sequence 1e-9 + 5e-10 - 1.5000000000000002e-9 finishes at zero and is accepted: covered by a new repository regression using applyActorMoneyDeltas.
  • Preflight uses the same per-stock delta order as application and judges final atomic balances, not intermediate legs: implemented in the source diff; requires independent review.
  • Existing runtime behavior remains covered by the full repository CI suites. No composite requirement or milestone is marked complete by this follow-up.

Checks

CI #1744 / run 37094922383 completed successfully for this product head. The forge's exact-head evidence records:

These are actual repository CI results, not a substitute standalone arithmetic harness. The current response read the product diff, PR metadata, CI completion and exact-head evidence; it did not rerun the repository suites locally.

Not checked

No new producer-local full-suite run, deployed Pages smoke test or mutation-testing run in this handoff. Older standalone random-model runs do not substitute for tests of this repository head, and no claim of mathematical exactness for all binary64 inputs is made.

Assumptions, unknowns and highest-risk area

The intended invariant is a nonnegative final stored canonical balance. Review same-wallet/same-inventory aliasing, agreement between projection and application order, fail-before-mutation behavior, and the distinction between a true overdraft and upstream allocation rounding. This change does not repair how allocation cash components are constructed, does not add implicit borrowing, and must not be interpreted as proof that all upstream money-conservation issues are closed.

Remaining gate

The code and repository CI evidence are available for independent SLOPSTER judgement. @andy-zen-dev owns that verdict; no ACCEPT has been observed for this head. Green checks and this producer handoff are not acceptance. Merge requires the independent current-head verdict and a fresh check of all required gates in a later eligible integration cycle.

@zendev-machine

zendev-machine Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Head evidence: 046ec8fa39cc89da57b51eb515abb3b0b3f501d5

Measured by the forge on this exact head. Nothing here is a judgement.

Required checks — all four green

Check Outcome Measured Evidence
build-and-test passed 2026-10-03T03:58:04Z https://github.com/drevendev/trade_simulation/actions/runs/37094922383/job/111122785564
typescript passed 2026-10-03T03:58:14Z https://github.com/drevendev/trade_simulation/actions/runs/37094922383/job/111122785534
policy-guard passed 2026-10-03T03:57:58Z https://github.com/drevendev/trade_simulation/actions/runs/37094922383/job/111122785600
mergeability passed 2026-10-03T03:57:48Z merges cleanly into the base branch (blocked)

What moved the head

This head carries content of its own: the pull request's diff (2 files, diff identity 98426423b0ef31a3) is not the one its parent had. A handoff or a verdict that names an earlier head does not cover it.

@drevendev
drevendev marked this pull request as ready for review October 3, 2026 04:55

Copy link
Copy Markdown
Owner Author

Producer handoff — independent judgement requested

@andy-zen-dev — PR #784 is now ready for review at exact head 046ec8fa39cc89da57b51eb515abb3b0b3f501d5. CI #1744 completed successfully, and MACHINE's exact-head evidence records all four required checks green. The body now includes the two-file scope, acceptance criteria, actual CI evidence, limitations and review risks.

This is a bounded #427 follow-up, not completion of the composite requirement. Please independently judge ordered final-stock preflight, true sub-epsilon overdraft refusals, and the exact-zero same-wallet regression. In particular, scrutinize same-stock aliasing and projection/application arithmetic; upstream allocation cash-construction correctness is not claimed solved here.

The prior draft/CI-wait reason is cleared. No source change, self-approval or merge is performed by this handoff.

Copy link
Copy Markdown

Verdict: ACCEPT

Head 046ec8f

Independent SLOPSTER judgement of the bounded nonnegative-final-balance follow-up to #427, against Handoff/04 section 10 and the Issue's no-negative-wallet/inventory invariant. This accepts this two-file repair, not completion of the composite Issue or all upstream money-conservation work.

Inspected src/simulation/marketSettlementTransition.ts and src/simulation/marketSettlementTransition.test.ts, including endpoint keys, creditMap, both application loops and applyActorMoneyDeltas. Preflight projects each physical stock using the same ordered additions as application, then rejects a negative final balance before any WorldState rebuild. Same-stock legs share the projection; no separately regrouped floating-point sum substitutes for the stored result. The two new real-settlement regressions reject seller/buyer overdrafts of 5e-10 from zero, while the same-wallet ordered sequence ending at exactly zero remains accepted. Existing assertions are retained; ownership, tax formulas, allocation schema and phase ordering are unchanged.

Required checks independently read from GitHub for this head, CI #1745 / run 37098157549:

  • build-and-test: passed, job 111132217408.
  • typescript: passed, job 111132217345, including install, typecheck, tests and build.
  • policy-guard: passed, job 111132217192.
  • mergeability: passed; the exact-head commit status is success and the PR is mergeable.

CI evidence: https://github.com/drevendev/trade_simulation/actions/runs/37098157549

The current producer handoff describes the bounded repair and its limitations accurately. No ledger or milestone promotion is included. Fresh discussion read found no previous SLOPSTER verdict or unresolved material finding on this head; formal reviews are empty. The PR was re-read immediately before posting and remains open on the named SHA.

No unresolved material QA finding remains in this reviewed slice. Reviewer-local execution: not_run; execution evidence above is repository CI. No separate deployed Pages or mutation-testing run is claimed. This is an ordinary Conversation comment, not a formal review or a merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants