Tasks: YU17-otc-rates
-
T-OTC01: Write the headline proof first;
scripts/proofs/yu17-swap-netting.sh; and let its external contract drive the design: the route, the response shape, the artifact filename, the announcement fields. -
T-OTC02: Add
TYPE_SWAP_BOOK = 12toInputEventwith its slot map and the packed date pair, copied forward from the operative YU03 layer. -
T-OTC03: Add
SwapConventions; the compile-time convention table, append-only by index, with a knowing refusal for an index this build does not have. -
T-OTC04: Add
BlpRiskState.decideSwapBookingon the YU14 operative layer: measure the notional, drop the four checks that read state a swap does not have, accrue on acceptance. -
T-OTC05: Add the contract store,
T_CONTRACT,MAX_CONTRACTSandonSwapBooktoMatchingEngineClusteredService; dispatch before the engine soMatchingEngineis untouched. -
T-OTC06: Move
SNAPSHOT_FORMAT4 → 5, holdMIN_READABLE_SNAPSHOT_FORMATat 3, and write and restore contracts in booking order with fail-closed id checks. -
T-OTC07: Add the cut's
#contractssection at cut schema 2, emitted even when empty, with the count declared in the header and ascending ids asserted at render. -
T-OTC08: Stop
RiskExtractCsvat the section marker, leaving CSV schema 3 and every column unchanged. -
T-OTC09: Add
SwapContractCsv; the per-trade artifact, terms only, with a preamble that states the absence of valuation rather than leaving it to be inferred. -
T-OTC10: Render, write and announce both artifacts from one cut under one stamp in
RiskExtractMain; deliver both in one call on the GCS sink; add the optional fourth--rebuildargument. -
T-OTC11: Add
POST /swapsto the gateway, refusing every unrepresentable term before sequencing, andKIND_SWAP_BOOKEDcorrelation on egress. -
T-OTC12: Carry the two changed call sites forward into this layer;
RiskExtractTest(cut render signature, and the position-section filter) andRiskExtractGcsSinkLiveProofTest(sink signature, plus an assertion that the second object lands). A test that cannot compile is not a test that is passing. -
T-OTC13: Add
SwapBookingTest: the netting headline, the netted extract's immunity, snapshot round-trip, format-4 restore, truncation, an unknown convention index, idempotent retry, key-less distinctness, the packed date range, and the notional-not-quantity×rate assertion. -
T-OTC14: Verify the new tests actually executed (
tests="16",skipped="0"in the JUnit XML) and that the headline goes RED when contract netting is spliced into the apply path. -
T-OTC15: Register the state in all five pipeline places; the generate/render pair, the catalog, the runtime-harness installer (both cases), the CI-assets allow-list, and the start/stop/status/test wrapper scripts.
-
T-OTC16: Author the spec pack: README, spec, plan, research, data-model, quickstart, the two requirement deltas, the contract delta, the architecture model (generated to
architecture.md), runtime topology, messaging subject map, and ADR-062/063/064. -
T-OTC17: Run
bash pipeline/generate-state.sh YU17-otc-ratesfrom clean and confirm the exit code is 0; not merely that the[summary]block printed, since a later install stage can fail after it. -
T-OTC18: Build the cluster image from the composed tree, roll the kind rig forward onto the existing epoch behind a snapshot barrier, and confirm every member reports the target image and Ready before any traffic. Verified: applied 23390 preserved across the roll, a format-4 snapshot restored on the format-5 build, no PVC wipe.
-
T-OTC19: Run
scripts/proofs/yu17-swap-netting.shagainst the rolled rig, including its negative controls. -
T-OTC21: Prove the rebuild-from-empty-disk arm live; now step 10 of the proof: the victim's PVC is deleted, not just its pod, and the rebuilt member must re-render the identical cut with the same contract count.
-
T-OTC20: Run the inherited suite against this build. 23 passed, 0 skipped, 3 failed, and all three failures were then run individually and resolved:
yu13-otel-trace-joinpasses once the rig's driftedOTEL_SAMPLE_MASKis restored to the manifest's0, andyu13-cancel-ingress/yu13-stp-and-replacecannot roll a pre-YU16 gateway image at all because the probes moved to port 18111; diagnosed to the kubelet event and written up inissues/resolved/HANDOFF-issue-historical-gateway-images-fail-the-probe-port.md. Neither is a property of this state.
Phase 2; swaptions
- T-OTC44: Add the exercise-style table beside the convention table, under the same index-addressed, append-only, knowing-refusal rule.
- T-OTC45: Add
TYPE_SWAPTION_BOOK(13) and the option-terms word onsecurityId. A distinct command type, so the product is never "is a field set". - T-OTC46: Grow the contract record 8 -> 11 columns and
SNAPSHOT_FORMAT5 -> 6, readingT_CONTRACTat the width the RESTORED format declares; the record carries no length. - T-OTC47: Widen the cut's contracts section (schema 3) and the contracts artifact (schema 2);
a swap carries
SWAPwith both option columns empty. - T-OTC48: Add
POST /swaptionsbehind one shared validator withPOST /swaps, refusing an unknown style and an expiry after the underlying's effective date before sequencing. - T-OTC49: Extend
SwapBookingTest; the European/Bermudan headline, the underlying's terms, the empty wrapper on a swap, one artifact two products, an unknown style, the terms word, and a format-5 snapshot restoring as swaps. - T-OTC50: Add
bothArtifactsAreUsAsciiEncodable. Artifacts are written withUS_ASCII, so one non-ASCII character aborts the EOD batch after the cut is hashed; and every other test renders to a String without ever encoding it. Found live, by an em-dash in a preamble. - T-OTC51: Write
scripts/proofs/yu17-swaption-terms.shand register it in the suite runner. - T-OTC52: Prove the format-5 forward roll LIVE: book a swap on the phase-1 build, take a
snapshot barrier so a format-5
T_CONTRACTexists on disk, roll to phase 2, and confirm the contract returns with its terms intact andproductTypeSWAP. - T-OTC53: Read the applied sequence only when all three members agree (
quiesced_seq); a single-member read races with catch-up and turns replication lag into a sequencing verdict.
Still open
Nothing in this state's own scope. Two cross-cutting items surfaced while proving it and are
carried in issues/:
issues/resolved/HANDOFF-issue-historical-gateway-images-fail-the-probe-port.md; until the historical gateway tags are rebuilt (or the two proofs pin the probe port),yu13-cancel-ingressandyu13-stp-and-replacecannot run on any state from YU16 onward.RiskExtractGcsSinkLiveProofTestis gated onRISK_EXTRACT_GCS_HMAC_KEY_IDand skips without credentials, so the contracts artifact's delivery to the GCS sink is asserted but unverified.