Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,21 @@
# Changelog

## Unreleased

- Supports PineForge engine v1.0.0 and codegen 1.0.0; the README builds
against the engine's `v1.0.0` tag and names codegen 1.0.0 as its pair.
- Engine v1.0.0 reports every `strategy.entry` as ENTRY in the pending-order
mirror. An entry with neither a limit nor a stop level is still keyed as a
MARKET intent, so market entries keep their settle-time `MARKET_AT_OPEN`
legs and intent keys. The settled book refuses a MARKET key whose order
the engine prices, rather than sending it at the open.
- With engine v1.0.0, a `process_orders_on_close` stop entry that flips a
position on the bar it is placed fills at that bar's close, as in
TradingView. Its webhook has `id: null` and `identity_resolved: false`, and
the offline execution replay refuses it.
- The README no longer documents the pre-1.0 engine revision `399eead`; it
was not re-tested with these changes.

## 0.1.0 — 2026-09-09 (pre-alpha)

Initial standalone, pre-alpha runtime for PineForge-compiled strategies.
Expand Down
3 changes: 2 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,8 @@ python -m build
python -m twine check --strict dist/*
```

The wheel contains the runtime, metadata, `LICENSE` and `NOTICE`. The source
The wheel contains the `pineforge_live` package (including its maintainer
`verification` modules), metadata, `LICENSE` and `NOTICE`. The source
distribution also includes examples, guides, tests and maintainer scripts.
Keep local build artifacts, journals, credentials and private campaign inputs
out of both distributions. See [release preparation](docs/releasing.md) for
Expand Down
64 changes: 44 additions & 20 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,35 +62,47 @@ python -m pip install -e .

For WebSocket feeds, also run `python -m pip install -e '.[websocket]'`.
JSONL, stdin, HTTP and webhook delivery use the Python standard library.
`pineforge-engine` supplies the compiled strategy; this package's runtime
loads it with `ctypes`.
The compiled strategy is a native library built with the C++
[pineforge-engine](https://github.com/pineforge-4pass/pineforge-engine), which
is not a Python package; this package's runtime loads it with `ctypes`.

To build the public engine and its example strategy corpus:

```sh
git lfs install
git clone https://github.com/pineforge-4pass/pineforge-engine.git ../pineforge-engine
git -C ../pineforge-engine checkout --detach 399eeadaa34cdbae0e30829f0a6c1dbe900cdfa0
git -C ../pineforge-engine checkout --detach v1.0.0
git -C ../pineforge-engine submodule update --init corpus
git -C ../pineforge-engine/corpus lfs pull
export PINEFORGE_ENGINE_ROOT="$(cd ../pineforge-engine && pwd)"
scripts/build_engine.sh
```

Use an ABI-v4 engine build. Two-input probe verification used engine revision
`399eeadaa34cdbae0e30829f0a6c1dbe900cdfa0`. CMake 3.16+, a C++17 compiler and
Git LFS are required; the corpus feed is an LFS object. Initial setup needs network
access for the corpus data and engine build dependencies. The build script
requires `PINEFORGE_ENGINE_ROOT` explicitly and compiles the public corpus,
which can take several minutes. Keep the corpus revision pinned by the engine.
Use engine release v1.0.0 (commit
`5718c5dc05086fc5b66b4cb565617efe837131e3`), which provides ABI v4. All 152
engine-backed tests pass with it and the demo below delivers its actions
(checked on Linux arm64, 2026-09-30). Releases up to v0.13.1 provide ABI v3
or older, and their strategy libraries are refused at load. CMake 3.16+, a
C++17 compiler and Git LFS are required; the corpus feed is a 176 MB LFS
object. Initial setup needs network access for the corpus data and engine
build dependencies. The build script requires `PINEFORGE_ENGINE_ROOT`
explicitly and compiles the public corpus, which can take several minutes.
Keep the corpus revision pinned by the engine.

For your own PineScript source, use
[pineforge-codegen-oss](https://github.com/pineforge-4pass/pineforge-codegen-oss)
to generate C++, then compile it against the ABI-v4 engine. The compiler is
a separate source-available project with commercial-use restrictions; read
the [license summary](#license) before using the compiler or its output in a
product or service. The corpus demo uses already-generated C++ and does not
run the PineScript compiler.
(PyPI package `pineforge-codegen`) to generate C++, then compile it against
the headers and `libpineforge.a` of the same engine build. A codegen 1.x
release is supported only with the engine tag of the same version, so use
codegen 1.0.0 with engine v1.0.0:
`python -m pip install 'pineforge-codegen==1.0.0'`. Its output includes
`pineforge/source/pine_strategy_host.hpp`, which engines before v1.0.0 do not
have. Codegen 1.0.0 output for the corpus SMA and ATR bracket strategies,
compiled this way, delivers the same webhook actions as the corpus libraries.
The compiler is a separate source-available project with commercial-use
restrictions; read the [license summary](#license) before using the compiler
or its output in a product or service. The corpus demo uses already-generated
C++ and does not run the PineScript compiler.

## Run a complete local example

Expand Down Expand Up @@ -276,15 +288,21 @@ tick paths through the same runner: 201 actual HTTP order-action deliveries,
zero duplicate IDs and zero restart deliveries. Each tick path processed
122,092 trade ticks. All probes matched C++ batch on identical reconstructed
input; 27 also matched native chart OHLCV, while 8 had source-data differences.
The report pins the tested code, inputs, reviews and artifact hashes.
This measures live-versus-batch equivalence, not TradingView parity. The
report pins the tested live, engine and codegen commits and the hashes of the
inputs, container image and case artifacts; those artifacts, the image and
the independent review are not public. It was recorded on 2026-09-09 with
the pre-1.0 engine and codegen revisions it names, not with v1.0.0.

```sh
python -m pip install -e '.[dev]'
python -m pip install -e '.[dev,websocket]'
env -u PINEFORGE_ENGINE_ROOT python -m pytest
PINEFORGE_ENGINE_ROOT=../pineforge-engine python -m pytest
PINEFORGE_ENGINE_ROOT="$(cd ../pineforge-engine && pwd)" python -m pytest
```

Without `PINEFORGE_ENGINE_ROOT`, engine-backed cases skip explicitly. Tests
Without `PINEFORGE_ENGINE_ROOT`, engine-backed cases skip explicitly. Set it
to an absolute path; a relative path fails the tests that write configuration
files to temporary directories. Tests
cover strategy-ledger identity, provisional updates, atomic restart, real
loopback HTTP delivery, HMAC, duplicate delivery, receiver persistence, HTTP
polling and WebSocket frames. The [work ledger](ledger.md) records exact
Expand All @@ -304,8 +322,12 @@ that earlier development track.
| `pineforge_live/sources/` | Normalized stdin/JSONL/HTTP/WebSocket feeds |
| `pineforge_live/config.py` | Strategy, metadata, feed and webhook configuration |
| `pineforge_live/engine/` | PineForge ABI binding and full backtest calls |
| `pineforge_live/bars/` | Bar building, 1m aggregation and session calendars |
| `pineforge_live/adapters/` | `mock-feed` generation, recorded tapes and the offline mock venue |
| `pineforge_live/core/` | Ledger/probe and existing reconciliation research |
| `pineforge_live/execution/`, `pineforge_live/drivers/` | Earlier mock-execution research ([docs/execution.md](docs/execution.md)) |
| `pineforge_live/journal/` | Durable state, STOP marker and writer fencing |
| `pineforge_live/verification/`, `cloudrun/` | Maintainer campaign verification tooling |
| `examples/webhook_receiver.py` | Minimal durable receiver for integration |

PineForge engine/codegen feature support and TradingView parity are separate
Expand All @@ -318,8 +340,10 @@ execution acknowledgments belong to your receiver or broker bridge.
Bug reports, documentation fixes, feed adapters and replay cases are welcome.
Start with [CONTRIBUTING.md](CONTRIBUTING.md) for setup, tests, PR scope and
contribution licensing. The [changelog](CHANGELOG.md) tracks release changes.
Maintainer campaign tooling is separate; cloud access is not required to use
the runtime or submit a contribution.
Maintainer campaign tooling (`cloudrun/`, `pineforge_live/verification/`,
`scripts/export_campaign.mjs`) ships in this repository but needs private
repositories and cloud storage; neither is required to use the runtime or
submit a contribution.

## Security reports

Expand Down
3 changes: 3 additions & 0 deletions cloudrun/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ codegen source arrive through SHA-pinned Git bundles at runtime; the worker must
check out their declared commits, verify trees, and compile them on Cloud Run.
Codegen currently has no third-party runtime dependencies. No arbitrary remote
Git branch or unpinned runtime installation belongs in this path.
This is maintainer tooling: it needs the private `pineforge-lab` and
`pineforge-workflow` repositories and a Google Cloud project with an evidence
bucket. The public runtime and its tests need none of these.

All real-probe backtests, both streaming modes, webhook verification and grading
run inside Cloud Run. Local packaging, pure unit tests and compilation are not
Expand Down
6 changes: 4 additions & 2 deletions docs/core.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,8 @@ is what makes the whole thing testable against a recorded tape
the tests and the harness call their venue `"TAPE"`.

Spec: `pineforge-workflow-live/docs/superpowers/specs/2026-09-07-pineforge-live-design.md`
(§4 is the algorithm, §5.4 the reconciler, §5.5 STOP/RiskGuard, §1 the G-invariants).
(§4 is the algorithm, §5.4 the reconciler, §5.5 STOP/RiskGuard, §1 the G-invariants),
a maintainer design document that is not published.

## The one invariant everything else serves

Expand Down Expand Up @@ -384,4 +385,5 @@ same way (`report["seed"]`, exit 1) rather than dying with a message, and a
recompute that aborts twice ends the run with a written summary instead of a
traceback on the next bar's `LedgerGap`. Recompute times are float milliseconds:
a probe run can be sub-millisecond, and spec §2 sizes `grace` off their p99.
See the README for the commands and the current numbers.
Run `python scripts/l1_harness.py --help` for its options; it needs the
ABI-v4 engine build from the README's Install section.
9 changes: 8 additions & 1 deletion docs/execution.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ or claim an account P&L model.

## Run it

Use the same ABI-v4 engine and derived feed as the README's L1 quickstart.
Use the ABI-v4 engine build and derived feed from the README's Install section.
Each run requires a fresh journal directory; reports preserve their input
library/feed digests and epoch identity.

Expand Down Expand Up @@ -96,6 +96,13 @@ Late ledger receipts, terminal partial residuals and uncertain absent orders
remain explicit unresolved facts. Automatic remainder/chunk submission and
exhaustive NOT_FOUND recovery require further adapter contracts.

An entry without a resolved Pine order id (`?`) is refused before any order
of its decision is placed. A `process_orders_on_close` entry that fills at the
close of the bar that placed it never rests in the settled book, so it has no
id. With engine v1.0.0, each orders-on-close close of the corpus probe
`order-deferred-flip-pooc-cross-bar-01` in bars 2000-2199 comes with such an
entry (a same-bar flip), so its replay stops at the first one.

## STOP recovery

Inspect the journal before an explicit operator clear:
Expand Down
5 changes: 4 additions & 1 deletion docs/plan-b3.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,16 @@
> the runner. Broker adapters, account admission, mirror/dead-man execution
> and production exchange evidence below are not requirements of the public
> signal runtime. The current contract is [webhooks.md](webhooks.md).
> Modules and tests named below that are absent from the tree were never
> implemented.

Status: implementation plan, 2026-09-09. This continues the approved live
design and B2 at `1a3a6fb`; it is not evidence that an exchange integration
has passed admission. Local implementation and fault simulation can proceed.
Do not push or enable a production account as part of this continuation.

Authority: sibling `pineforge-workflow-live/docs/superpowers/specs/2026-09-07-pineforge-live-design.md`,
Authority: sibling `pineforge-workflow-live/docs/superpowers/specs/2026-09-07-pineforge-live-design.md`
(a maintainer design document that is not published),
especially §§2–2a, 4–7; its B2 ledger's post-archive ruling and TODO 8–17;
and this repository's [core design](core.md). The post-archive FLATTEN
exemption supersedes the older spec sentence that budgets that flatten.
Expand Down
3 changes: 2 additions & 1 deletion docs/two-input-verification.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,8 @@ calendar hashes and generation-pinned case artifact receipts.

The selection was frozen from a read-only Postgres campaign export: two probes
per lane/group with seed `20260909`, plus SMA, bracket and orders-on-close
regressions. It covers 35 of the 4,190 recorded probes across nine symbols.
regressions. It covers 35 of the 4,190 probes recorded at the time, across
nine symbols.
Probe IDs, original source/CSV bytes, strategy inputs, engine and compiler
versions remained fixed through the verification attempts.

Expand Down
Loading
Loading