Skip to main content

2026-09-05 platform audit — status register

The second platform audit (snapshot 2026-09-05 ≈ 14:20–14:32 UTC; source document nexus-platform-audit-2026-09-05.md in the operator workspace) reviewed the live money path — desk output → worker → Solana executor → venues → sleeve ledger → operator surfaces — and the fit of the system to its objective (grow total portfolio value in USDT with BTC/SOL exposure). Its verdict: a functioning autonomous desk whose signing and accounting boundaries are too weak to justify increasing autonomous capital yet.

The owner independently re-verified the platform on 2026-09-05 19:29–19:34 UTC (the same source document, "Current assessment" and "Findings register — current disposition"). That verification supersedes the original findings' status; its verdict: material remediation is deployed and working; the remaining priorities are narrower — enforce Core authorization, finish and activate durable execution, enforce a coherent portfolio budget across concurrent callers, validate the new accounting over time. The portfolio limit gate is observational and the outbox is disabled; neither counts as an active protection because its code and endpoints are deployed. Where a row below carries a qualification in italics, it is quoted from that verification and narrows the engineering claim.

This page is the status register for that audit: one row per finding, maintained by the engineering session, not by the auditor. It supersedes the prose closure tables of the first audit (2026-09-04, archived verbatim in the consolidated report — see the crosswalk) as the readiness view.

Vocabulary​

Every status word means exactly one thing:

StatusMeaning
opennothing landed, or the finding's protection is not active yet (code may exist in a log / off mode — the note says so)
specifiedwritten down (a docs page or design), no code
in progresscode exists locally / on a branch; not on main of the owning repo, or not built
builton main, image built; not rolled out, or rolled out behind a flag that is off
deployedrolled out by Argo (revision given)
live-verifiedchecked against the running cluster after the rollout (date given)
closedthe specific defect is gone and live-verified; residual qualifications stay in the note
partialpart of the finding landed; the rest is named in the note
blockedwaiting on another row

Revisions are git SHAs of the owning repo. Where the owner has decided not to pursue a finding, the row says deferred by owner or declined by owner with the date; the finding stays in the register, it is not closed. A row carries exactly one status; "rolling" is never a status — a revision is either the one running or it is not.

Running revisions at the time of this register (2026-09-05 ≈ 22:05 UTC): nexus-platform fdd7912 (core / worker / telegram, rolled 21:54Z; the chain 7e1adcb 17:50Z → 7d6ed59 ≈ 20:3xZ → fdd7912), nexus-solana a74cc87 (exec, live-verified 17:46Z), nexus-ui f8327f1, nexus-gitops 08ba526, nexus-docs ee2e3ce (before this commit). The re-verification itself ran against platform 7e1adcb / exec a74cc87 / UI 13d3f2a / docs 0301316; where a later revision changed a row, the note says which.

Running revisions as of 2026-09-06 ≈ 10:1x UTC (the tags in nexus-gitops environments/prod/values.yaml at gitops 91232c7 — this is what the rows below are judged against):

RepoRunningLive-verifiedNot yet running
nexus-platform63a2de3 (core / worker / telegram; gitops 2c91751)ee0cd80 2026-09-05 23:4xZ · 2d8eef1 00:1xZ · 63a2de3 figures read back at the 10:09:48Z snapshot—
nexus-solanaea96739 (exec + oracle; gitops 2e9decf)a1eb8f3 2026-09-05 23:33Z · 9c9d19f 2026-09-06 09:3xZ · ea96739 LP read ≈ 2 ms—
nexus-uica1d75e (rolled 2026-09-06 10:19 UTC)Treasury + LP pages, two crash fixes, canonical host — the www 308 live-verified with path and query preservedThe whole chain f8ca034 → 4dca5c0 → 80432d3 → 068ef0f → ad31a86 → 1b078c6 → ca1d75e is in this image
nexus-gitops91232c7aliases route to the UI again—
nexus-docscb328aa (before this commit)——

The 2026-09-05 23:00Z–23:13Z batch that the previous update called "deploying" rolled and was live-verified: platform ee0cd80 at 23:4xZ (budget ledger seeded, version 2, verdict available, anonymous reserve → 401, in-scope NAV 90,981) and exec a1eb8f3 at 23:33Z (auth enforce 14/0/0, not_enforced = 7 checks, accum_intents live with TTL 90 s / retention 7 d, budget_check enabled, outbox off with journal: legacy). Rows below are updated accordingly.

What 2026-09-06 added, in one line each (detail in the rows): nexus-solana 9c9d19f sleeve reconciler false positive that had blocked every new swing buy · 4804e26 rent attribution (a −$1,068 phantom cost) · 7046ba8 one send commitment · 0641ea5 a preflight-rejected send re-arms · ea96739 position cache. nexus-platform fdc6758 lending calls follow the market holding the position · 3ce6c78 a supply cannot breach the float floor · 2553748 … 63a2de3 P&L correctness, window coverage, lending reconciliation, the earning block, LP as legs. nexus-ui f8ca034 / 4dca5c0 / 80432d3 / 068ef0f LP positions, proxy budget, Treasury truthfulness pass, two crash fixes. nexus-gitops 2c8d76a ACCUM_MIN_FLOAT_USDC 2000 · 91232c7 ingress aliases + canonical host.

Register​

IdFindingSeverityStatus (2026-09-05)RevisionNote
S1Armed signer trusts callers and externally built transaction messagesCriticalclosed — live-verified 2026-09-05 16:27Z, EXEC_AUTH_MODE=enforcenexus-solana 2c0be5a (code, 15:55Z), running in a74cc87 · nexus-gitops 29c983a (solanaExec.auth.mode: enforce, 16:27Z)Live after the flip: {allowed: 32, would_deny: 0, denied: 0}; key-less GET → 401 auth:missing, read-role key on POST → 403 auth:role; worker/telegram clean, 0 restarts. Flipped after 90 min of log mode (165 allowed, 0 caller denials; the only would_deny entries were key-less operator probes). Roles: worker, telegram = execute; core, ui = read; self = the exec's own loops. Keys: Secret nexus-exec-auth (EXEC_API_KEYS) on the exec, per-caller SOLANA_EXEC_API_KEY from nexus-app / nexus-ui; rotation = edit .secrets → bootstrap-secrets.sh → roll. Semantic gate on all signing paths (ALT resolution, signer set, program allowlist, delegate/authority decoding, delta bounds vs a 90 s TxIntent); not_enforced by design (as of a74cc87) = inner CPI programs / Token-2022 balances / LP batch sums / submit_signed relay. Re-verification 19:29Z: original absence resolved; semantic coverage partial — the exclusions above are real limits (LP operations split over several transactions are bounded per transaction, not per batch; a lending-supply intent bounds the outgoing mint but not a minimum receipt-token position); the status showed zero semantic checks since the 17:46Z process start, so no production signing under this exact rollout has been exercised — unit tests are synthetic coverage, not a rehearsal. Live caps observed 25 000 USDC / action, 250 000 / day (configuration, not a recommendation). Receipt bounds deployed 2026-09-05, live-verified 23:33Z (nexus-solana 83bb7d8, in a1eb8f3): the receipt-token gap is closed for the fungible cases — a Kamino supply's cToken leg is a pre-sign receives bound (min = expected × (1 − EXEC_RECEIPT_TOLERANCE_FRAC, default 0.01); an unreadable exchange rate refuses the supply), JitoSOL deposit / withdraw bounds the JitoSOL / SOL received (quote less slippage_bps), LP remove / close bounds the coin + USDC back as receives legs when the set is one transaction; MarginFi (no receipt token) and LP open (position NFT / DLMM account) are verified after the send from the venue read (receipt.verified) — reported, not enforceable. The /v1/status not_enforced list is now seven entries: inner_programs, token2022_balances, lp_batch_sum, lp_open_receipt_presign, lp_collect_receipt, lending_receipt_untokenized, submit_signed. Multi-transaction LP sets stay bounded per transaction. Live-verified 2026-09-05 23:33Z (not_enforced = those seven) and exercised on a real send 2026-09-06 ≈ 09:0x UTC: a 995.55 USDC Kamino supply had its cToken receipt bound enforced pre-sign (min 821,596,315 cTokens, 1 % tolerance) and confirmed — the first production signing under the receipt-bound code, closing the re-verification's "no production signing under this exact rollout" caveat for the fungible lending case. Not yet exercised live: JitoSOL, LP remove / close pre-sign bounds, and the post-state MarginFi / LP-open verifications.
S2nexus-allow-monitoring admitted the monitoring namespace to every Nexus port, so Grafana could reach the signer (:8091)Highlive-verified 2026-09-05 15:2xZ; re-verified 19:3xZnexus-gitops 34f731dNarrowed on 2026-09-05: nexus-allow-monitoring limited to networkPolicy.monitoringPorts ([9100]). Live-verified 15:2x UTC and again by the re-verification (resolved — live verified): Grafana → exec:8091 times out, Grafana → worker:9100 200, worker → exec:8091 200. Docs corrected (Security).
S3Core authorization in log mode, not enforcingHighclosed — enforced since 2026-09-05 22:37Z, live-verifiednexus-platform eb1c464 (Core side of S4, 16:02Z), running in fdd7912Core runs NEXUS_AUTH_MODE=enforce, NEXUS_AUTH_READ=open (gitops c95071e; 24 h of log mode before the flip: 383 decisions — service 131, ui_operator 147, anonymous reads 105 — 0 would_deny; after the roll an anonymous POST → 401 no_key, reads 200, UI up, no caller 401/403). Rollback: core.auth.mode: log. Previously: ui_operator principal observed, would_deny 0 since 16:02Z. Re-verification: open — enforcement pending; authentication code exists, but rejected principals are not generally blocked in this mode. The flip is enforce once the identity binding (S4) has been checked against the real operator / service workflows and would_deny stays at 0 — owner priority 1 under Next.
S4UI proxy does not bind the operator assertion to the verified sessionHighdeployed 2026-09-05 (UI 15:14Z, Core 16:02Z)nexus-ui a2561d9 (running in f8327f1), nexus-platform eb1c464 (running in fdd7912)Live: anonymous /api/nexus|cex|solana → 401; Core classifies the UI key as ui_operator; duplicate/mixed-case identity headers → 400; NEXUS_API_KEY_READ read-only service key. Contract: NEXUS_UI_API_KEY ui-proxy principal carrying session-derived operator identity (never promoted to service), NEXUS_API_KEY service, optional NEXUS_API_KEY_READ, X-Nexus-Proxy-Origin on mutations, all inbound X-Nexus-* stripped. Core side in nexus-platform, proxy side in nexus-ui. Documented under Identity propagation. Re-verification: implementation resolved — deployed and tested; full authenticated browser role testing was not performed; S3 remains separate.
S5Skill-import SSRF guard is lexical, not a resolved-destination policyHighdeployed 2026-09-05 16:02Znexus-platform eb1c464, running in fdd7912fetch_skill_url: resolved-address policy, no automatic redirects (≤ 3 validated hops), pinned resolve, https only, size / content-type caps, optional host allowlist. Re-verification: implementation resolved — deployed and tested; 35 Core tests pass, including the SSRF policy and loopback refusal; no production URL-import mutation was invoked.
S6Signer pod has no explicit securityContextHighlive-verified 2026-09-05 15:2xZ; re-verified 19:3xZnexus-gitops 34f731drunAsNonRoot 1000, RuntimeDefault seccomp, no privilege escalation, drop ALL, read-only rootfs + /tmp emptyDir. Live-verified 15:2x UTC: id = uid 1000, touch /x refused, /tmp writable, /health ok after the rollout. Re-verification: resolved — live verified (UID/GID 1000, seccomp, no escalation, dropped capabilities, read-only rootfs).
S7Runner egress (0.0.0.0/0:443 + DNS) is broader than the "LLM providers only" docs claimedMediumopen (technical gap) — docs corrected 2026-09-05nexus-docs f121c8dIt is a port restriction, not a provider allowlist. Application-layer egress/SSRF control remains open. Re-verification: documentation corrected; technical gap open.
F1Ladder execution is not a durable financial outbox (= C4)Highpartial — phase 2 deployed 2026-09-05 17:46Z behind EXEC_OUTBOX=0 (the durable-consumer protection is not active); the legacy outcome-journal regression is fixed and live-verified 2026-09-05 23:33Z; phase 3 / activation opennexus-solana db421a7 (phase 1, deployed 15:14Z) · 12c9dc3 / a74cc87 (phase 2 + cost capture c483bbd, live-verified 17:46Z) · 918b8fb (legacy journal, 22:49Z) in a1eb8f3 (23:13Z, deploying)Phase 1 (db421a7): 180 s self-call hotfix, submitted_unknown with signature, accum_outbox + serial consumer, record-before-send CAS, boot reconciliation, cancel coordination. Phase 2 (12c9dc3): fill verification from tx meta (confirmed_unverified beyond EXEC_OUTBOX_FILL_TOLERANCE_FRAC 0.01 or after EXEC_OUTBOX_META_MAX_ATTEMPTS 10), finish_tx → maybe_broadcast with the exact last_valid_block_height, lending-recall signatures recorded before send, operator routes GET /v1/ladder/outbox, POST …/{id}/retry / /abandon with an operator_actions[] audit trail, /health always 200 with {status, degraded, reasons, outbox}, GET /v1/health/outbox 503 when stuck / unverified / heartbeat stale, EXEC_OUTBOX_ADOPT_LEGACY=1 boot adoption. Re-verification: partial — new outbox deployed but disabled; /v1/status and /v1/health/outbox return enabled=false; none of the durable ladder-consumer protection is active; a healthy outbox endpoint whose payload says disabled is not a successful outbox health test; legacy outcome journal regression — the active legacy branch no longer writes accum_tranche_queue (its outcome trace is a log line; ladder machine state persists separately but is not a signature / outcome journal). Regression fixed in 918b8fb (live-verified 2026-09-05 23:33Z in a1eb8f3 — GET /v1/ladder/outbox answers {enabled: false, journal: "legacy"} with 0 rows so far; the first legacy fire under it is still to be observed — Known regressions): the flag-off spawn path journals every tranche attempt into accum_outbox as source: "legacy" rows — a pending row under the rung's fire key (attempts: 1, max_attempts: 1) is inserted before the self-call that may spend, then settled from the route's answer (submitted → confirmed with signature, blockhash, last_valid_block_height, quote, fill + costs verified within EXEC_OUTBOX_FILL_TOLERANCE_FRAC; confirmed_unverified; failed; or submitted with worker_note: "submitted_unknown" on a timeout / maybe_broadcast). Unlike the outbox path the signature is recorded after the route returned (the row says so); a failed insert is logged loudly and the fire proceeds unchanged. Behaviour change: a confirmed legacy fire now marks its rung Fired with the realized fill (before, every legacy fire left the rung Firing forever — the reason EXEC_OUTBOX_ADOPT_LEGACY exists); a failed / unknown outcome still leaves it Firing, never re-fired. Off-flag, GET /v1/ladder/outbox lists the journal (enabled: false, journal: true) and the /v1/ladder / /v1/status summary is {enabled: false, journal: "legacy", counts, legacy_rows, submitted_unknown, unreconciled[], rows[], fired[]}; retry / abandon stay 503 (no worker). When the flag flips, boot reconciliation settles journal rows like worker rows (confirmed ⇒ Fired, submitted ⇒ chain verdict, a dead signature ⇒ abandoned, never auto-retried). The pre-fire budget hook (F6) runs before mark_firing on both paths. Since nexus-solana 0641ea5 (2026-09-06, in ea96739) the journal also distinguishes a proven non-broadcast from an ambiguous one: ladder::classify_response reads never_broadcast before maybe_broadcast and settles the row failed instead of submitted + worker_note: "submitted_unknown", so a preflight rejection no longer leaves a phantom unreconciled row. Phase 3 open: in-process prepare / broadcast / confirm split (drop the self-call), crash / timeout / duplicate-submission rehearsal, EXEC_OUTBOX=1 after a dry-run soak, observed durable rows and restart recovery, retire the legacy spawn path. Env reference: apps/nexus-solana-exec/README.md; routes on nexus-solana.
F2Typed approvals are not exactly-onceHighpartial — exec-side idempotency + fencing live-verified 2026-09-05 23:33Z; every platform caller sends intent_id / fence since 2d8eef1, live 00:1xZ; first live confirmed intent 2026-09-06 09:0xZ; no replay, crash or takeover has been observednexus-platform e3d7c4c (H3, deployed 14:54Z) · cf219fa in ee0cd80 (Telegram approvals reserve / claim / consume on accum_budget_ledger, 23:00Z) · nexus-solana 23c083b in a1eb8f3 (accum_intents, live-verified 23:33Z) · nexus-platform 2b5cb1b…2d8eef1 (callers send intents, 23:5xZ)H3 (22-char ids, 6 h TTL, CAS claim, decision hash) deployed 2026-09-05 14:54Z. Re-verification: partial — exactly-once gap remains; a crash between economic action and durable acknowledgement still needs executor idempotency and fenced recovery. Exec side (23c083b, deploying): every mutating route (/v1/swap/execute, /v1/orders/create|cancel, /v1/lending/supply|withdraw|withdraw-all, /v1/stake/deposit|withdraw, /v1/squads/fund-exec, /v1/lp/open|remove|collect|close) accepts intent_id (the caller's durable decision id — approval id, plan id, outbox row id; it also names the semantic TxIntent) and fence (monotonic per intent). One record per id in accum_intents ({_id, kind, params_hash, state: prepared|submitted|confirmed|failed, fence, signature, signatures[], attempts, outcome{status, body}, …}, TTL EXEC_INTENT_RETENTION_SECS 604 800 s; GET /v1/intents/{id}), driven by the three signing choke points — begin, the prepared → submitted CAS with the signature after authorize and before broadcast (a lost CAS drops the signed transaction unsent), settle. A repeat with the same id answers, in order: 409 intent:mismatch (different params hash), 409 intent:stale_fence (fence below the stored one), the stored outcome with replayed: true (confirmed, or failed with a signature — nothing is signed again), 409 intent:in_flight (submitted, or prepared younger than EXEC_INTENT_TTL_SECS 90 s; carries the signature when known), or a re-arm (failed without a signature / stale prepared: nothing was ever signed). withdraw-all binds {intent_id}#{reserve} per leg; an LP batch keeps one claim and appends every signature. /v1/submit-signed and /v1/sleeve/{order}/exit take no fields; requests without intent_id are untouched. Platform side (cf219fa, deploying): a Telegram-approved buy is reserved and claimed on accum_budget_ledger before it is sent (swing_buy:approval:<id>:<n>, lease telegram:<user>, fence token), consumed when the exec accepted it, released otherwise; a settlement with a stale fence — the claim was taken over after the lease died — is refused and counted (nexus_portfolio_fence_rejections_total). Callers wired (2b5cb1b … 2d8eef1, live 2026-09-06 00:1xZ): every Telegram approval step sends approval:<id>:<step> with the H3 claim_generation as fence (bumped on claim, retry and takeover) and all 13 worker exec POST sites send the F6 reservation id + claim fence (or <decision_ts>:<action>:… + sweep-start ms when unbudgeted); the 409 matrix is handled (in_flight poll / skip, stale_fence never retried, mismatch loud) and counted (nexus_exec_intent_replays_total{caller}, nexus_exec_intent_refusals_total{caller,code}). First sweep with intents attached: no refusals, no replays, no errors. First live confirmed intent 2026-09-06 ≈ 09:0xZ — a 995.55 USDC Kamino supply, confirmed, attempts: 1. Correctness fix 2026-09-06 (0641ea5, in ea96739): record-before-send wrote the signature into the record before the broadcast, so a send the node rejected at preflight settled failed with a signature — and the exactly-once rule then replayed that failure for ever, locking the intent out. Two lending supplies were unrecoverable that way on 2026-09-06 (-32002 … Blockhash not found; the underlying commitment mismatch is 7046ba8). Now send::classify returns NeverBroadcast for exactly one shape (SendTransactionPreflightFailure, or bare -32002) — the answer the node gives instead of forwarding — and only then does the record move its signature to unsent_signatures (kept across the re-arm as the audit trail), settle failed without a landed signature, and re-arm. Everything else stays Ambiguous / submitted. LP batch sets keep the replay behaviour from batch 1 on. Still open: the ambiguous submitted state is reconciled by the caller / operator from the signature on GET /v1/intents/{id}, not automatically; no live crash / replay / takeover rehearsal has happened.
F3Blackout gate runs after standing treasury hygieneHighdeployed 2026-09-05 16:02Znexus-platform eb1c464, running in fdd7912Live: gate evaluated once per sweep before hygiene and fallback; 18 actions classified (risk-increasing blocked, risk-reducing blackout_exempt); nexus_accum_actions_gated_total. Before eb1c464 the gate (H12, ACCUM_MAX_DECISION_AGE_SECS=43200) protected the decision pass only; recall/rotate/repark/supply ran before it. Re-verification: original ordering defect resolved — deployed and tested; local gate tests pass; no live stale-feed failure injection performed. Docs: HARVEST §5. The hygiene the gate orders is itself rebuilt as the confirmed, rate-limited sweep of the owner lending policy (2026-09-05 ≈ 20:55Z: keep the JLP reserve, recall only on confirmed stress, rotations rare) — nexus-platform 4fd5c4c + fdd7912, live since 21:54Z (first sweep: no movement, JLP 90.3 %, liquidity 34.7× position); knobs (gitops d5318ad) and desk prompt (3f90adb) live ≈ 21:15Z; recall stays blackout_exempt — HARVEST §5.
F4Order-account disappearance is not a fill proofHighdeployed 2026-09-05 15:55Znexus-solana 2c0be5a, running in a74cc87Fills proven from tx meta (fill_proof: tx_meta, token deltas), reconciliation_required and unknown states preserved, record-before-send (placing), cancel_pending before the cancel tx, stable lot ids. Re-verification: implementation substantially resolved; live lifecycle proof pending — tests cover external cancellation, partial execution, cancel/fill races, missing writes and restart; no new complete live fill/cancel under the revised code was observed. First live fill / cancel under the new path still to be observed (owner priority 4).
F5Sleeve ledger vs wallet: 0.0521 cbBTC in the ledger, ≈ 0.0000479 in EXECHighclosed — repair applied 2026-09-05 16:20Z, live-verified; re-verified 19:3xZ; the reconciler's 2026-09-06 false positive is fixed and live-verified 09:3xZnexus-solana 2c0be5a (reconciler + repair, 15:55Z) · nexus-platform eb1c464 (worker gate) · nexus-solana 9c9d19f + 9a2f3b5 (reconciler correctness, in ea96739, live-verified 2026-09-06 09:3xZ)Repair applied by the operator after a dry-run review (never automatically): orphan sell ENJURa… linked to lot 4HAnsRgd…, lot closed with 0.0001 cbBTC dust (7.66 USDC ≤ the 10 USDC dust threshold). After: inventory ∅, committed_usdc = 10,537 (the open buy escrow only), GET /v1/sleeve/reconcile → all_explained: true, unresolved: false. The explanation matched the wallet to the satoshi (orphan sell −0.052 + 0.1 % Jupiter Trigger output fee −0.0000521). Worker refuses new swing buys while unresolved is set (eb1c464). Re-verification: specific cbBTC mismatch resolved — live verified; this is tolerance-based sleeve reconciliation under this reconciler's reference prices, classifications and tolerances (wallet dust ≈ 0.0000479 cbBTC ≈ 3.58 USDC, under the 10 USDC threshold; the 10-SOL open sell is identified as an orphan / core sell), not a complete financial audit; historical lots still report qty_is_actual=false. 2026-09-06 — the opposite failure, and its fix (9c9d19f, live-verified 09:3xZ). The reconciler reported unresolved: true when nothing was missing, and because the worker refuses new swing buys while that flag is set, every new swing buy was blocked for the morning. Two causes, both the reconciler expecting coin that was never sleeve inventory: a filled core sell (an operator / treasury sell of 10 SOL against an empty SOL ledger) was subtracted unconditionally, and the 10 SOL sitting in the newly opened Orca LP position was invisible to it. Fix: no explanation may release more than the ledger expected to be in the wallet (expected_wallet_qty); what a sell moved beyond that is a new kind core_sell (qty: 0 — it changes no expectation), coin in an LP is held_in_lp per position (releasing at most the inventory it holds, reporting held_qty otherwise), and per-mint held_elsewhere_qty / non_sleeve_allowance_qty (the EXEC gas float on the native-SOL pair, forgiving only a surplus) make the arithmetic legible. unresolved_reasons[] now carry residual_usdc and a one-line summary so the operator sees how far off it is. An unreadable LP scan is unresolved, never a silent zero (top-level lp_unreadable, gating all_explained): an LP position the reconciler cannot see is indistinguishable from coin missing from the wallet. After the roll: unresolved: false, all_explained: true, SOL/USDC explained by core_sell + held_in_lp (8.51 held elsewhere), residual 0 — nexus-solana → Reconciler.
F6No strategy-wide exposure / liquidity caps (= H5)Highbuilt — gate deployed 2026-09-05 17:50Z in log mode (evaluates, reserves and counts, blocks nothing); aggregate CAS ledger + fenced claims + approval / exec coverage deployed and live-verified 2026-09-05 23:33–23:4xZ; the SOL-exposure cap input was understated until 2026-09-06 (LP legs); enforce still waits on the owner decisionnexus-platform 15ebb97 … 7e1adcb (17:50Z); log-mode fix e6ce1af / fda55f4 / 84f29a5 (pushed 19:5xZ, live in fdd7912 21:54Z) · 1e6a080 (ledger) / b900de9 (worker claims) / cf219fa (Core routes + Telegram) in ee0cd80 (23:00Z, deploying) · nexus-solana b0a00f1 (pre-fire hook) in a1eb8f3 (23:13Z, deploying) · nexus-gitops d848adf (worker.budget.mode: log), a33055d (dashboard row + nexus.budget rules, 23:01Z)accum_reservations (kinds ladder_rung | swing_buy | lp_add | lending_supply | repark | stake; held → consumed | released, TTL ACCUM_LIMIT_RESERVATION_TTL_SECS 21 600) + accum_portfolio_limits; GateLedger::check_budget on every risk-increasing site (hygiene rotate / repark, swing buy, lending supply, stake, LP open, fallback DCA clip / proposals); the armed ladder is a standing ladder_rung reservation refreshed each sweep; stale / absent NAV ⇒ budget_unavailable. Defaults: SOL family 0.60, BTC 0.40, protocol kamino 0.70 / others 0.25, LP total 0.15, liquid reserve 5 000 USDC, lending recall haircut 0.10, single action 0.30 of NAV, NAV max age 7 200 s. GET /v1/desk/budget; metrics nexus_accum_actions_gated_total{class="budget",reason} (log mode: would_block:<reason>), nexus_portfolio_*. Dry run on live data 16:57Z: NAV ≈ 91.0k, SOL family 25.6k + standing ladder reservations 37.5k SOL / 12.5k BTC ⇒ SOL exposure 69 % vs the 60 % cap (headroom −8.5k), liquid free 6.1k vs the 5k floor ⇒ every swing buy / LP add would be denied (sol_exposure_cap, liquid_reserve) while the ladder is fully armed (re-verification at 19:12Z: 69.37 %, headroom −8 535 USDT — exposure and commitment are different: the budget projects buy escrows and ladder reservations; NAV exposure treats unfired escrow as stablecoin). A chained push briefly rolled the gate in enforce (d128e17, before 7e1adcb) — blocks-new-exposure-only, safe direction. Incident 18:36 / 19:06Z: a stale-mark NAV snapshot made budget_unavailable bypass log mode and refuse hygiene repark / rotation for two sweeps (recalls unaffected); fixed by e6ce1af (stored snapshot judged with its view → fresh valuation), fda55f4 (log mode never denies — would_block:budget_unavailable), 84f29a5 (oracle re-read ×3 on stale marks). First real verdict 20:36Z: would_block:single_action_cap on the hygiene rotation re-supplying the existing 56 k Kamino float (> 30 % of NAV) — not net new exposure; in enforce it would block routine rotations. Re-verification: partial — budget gate in log mode; not an atomic global budget: (1) scope — exec-plane ladder fires, direct execute-role requests and later Telegram approvals occur outside this worker-only projection; (2) concurrency — check_budget evaluates a sweep-local snapshot and Db::reserve upserts one id; there is no atomic compare / update of the aggregate limit across ids, so two independent sweeps can both reserve the same headroom (a source-level finding, no observed overspend). Aggregate atomicity + fencing (1e6a080 / b900de9, deployed 2026-09-05, live-verified 23:4xZ): accum_budget_ledger (_id: "portfolio") is the one document every reservation is projected against — aggregate totals_usdc plus the request, written back with a compare-and-set on version (+1 per write; a writer that loses the CAS re-reads and re-evaluates, MAX_CAS_TRIES 8, then reservation_error); the first writer seeds it from the live held rows (rebuilt_from_rows_at_ms); accum_reservations stays as the write-through audit trail and no longer supplies headroom. Entries go held → executing → consumed | released: before money moves the call site claims the entry (lease{owner, since_ms, until_ms}, fence += 1; lease claim_lease_secs / ACCUM_LIMIT_CLAIM_LEASE_SECS, default 900 s), consume / release of an executing entry require that fence, a dead lease can be taken over by another executor (the fence moves on) after which the old holder's settlement is refused StaleFence (counted on nexus_portfolio_fence_rejections_total), consuming a never-claimed entry is refused NotClaimed, and a paged proposal hands its claim back (GateLedger::keep_for_later, executing → held, re-claimed with a fresh fence on approval). Metrics nexus_portfolio_ledger_version, nexus_portfolio_reserve_conflicts_total, nexus_portfolio_fence_rejections_total. Scope (cf219fa, b0a00f1, deploying): Telegram-approved buys (swap / create_order with USDC in) reserve + claim + consume on the same ledger (BudgetGate; sells, cancels and digests are not budgeted); Core GET /v1/desk/budget gained verdict (version, available, mode, headroom_usdt{…}, reserved_usdc{…}) and ledger (entries[] with state, lease, fence), plus POST /v1/desk/budget/reserve and /reservations/{id}/claim|consume|release for movements made outside the worker (service keys only under enforce — API reference); the exec consults verdict before a rung fires on both ladder paths (mode: enforce with available: false, or family headroom + the ladder's standing ladder_rung reservation < rung budget ⇒ the rung is held Armed, re-asked every tick, budget: rung S1 HELD digest; log ⇒ log line only; no verdict / Core unreachable / EXEC_BUDGET_CHECK=0 ⇒ proceed with a warning — Core availability never blocks a rung on its own; /v1/status.budget_check). The exec does not reserve again: the rung is already counted by the standing reservation the worker mirrors. Direct execute-role requests to the signer remain outside the ledger. Ledger live-verified 2026-09-05 23:4xZ: accum_budget_ledger seeded on the first sweep (version 2; standing ladder reservations 37.5k SOL / 12.5k BTC), GET /v1/desk/budget.verdict available, mode log, anonymous POST /v1/desk/budget/reserve → 401; the exec's /v1/status.budget_check enabled against http://nexus-core with no verdict effect (log mode). Cap input corrected 2026-09-06 (nexus-platform 72967bd, deployed): an LP position was one NAV component whose asset was the uppercased pool address and whose qty was 0, so the LP's coin leg was excluded from exposure.SOL — and exposure.SOL is the sol_exposure cap input. Emitting one line per leg (venue <protocol>:<pool>, uncollected fees on their own …:fees line) moved exposure.SOL 18.71 % → 19.87 % at the 10:09:48Z snapshot. This was an exposure and cap understatement, never a NAV understatement — the position's value was already counted — but it means every headroom figure computed before that revision was slightly generous. Also 2026-09-06: the exec float floor ACCUM_MIN_FLOAT_USDC went 5 000 → 2 000 by owner decision (nexus-gitops 2c8d76a, worker.reserves.minFloatUsdc; the $5k floor was sized for the retired cbBTC arm, gas floor unchanged at the 0.2 SOL code default), which lowers the liquid_reserve figure the desk sizes against, and nexus-platform 3ce6c78 stops a decision-pass lending_supply sizing itself through that floor. Remaining preconditions for enforce: owner decision (trim deep rungs, raise the SOL cap ≈ 0.75, or accept the sleeve pausing) · exempt same-funds rotations or measure the single-action cap on net new exposure · re-read the headroom against the corrected LP exposure before choosing a number. Flip and watch procedure: Operations → Portfolio budget gate; ledger runbook: Operations → Budget ledger. Detail: HARVEST §5.
F7CEX UI proxy incompatible with the X-Api-Key cutover (C6)Mediumdeployed 2026-09-05 15:14Z; re-verified 19:3xZnexus-ui a2561d9, running in f8327f1nexus-ui: server-side CEX_MANAGER_API_KEY (present in the nexus-ui Secret), read-endpoint allowlist, explicit "unavailable" state on 401/5xx. Re-verification: resolved for supported CEX reads — live verified; the UI's service credential reads Binance and Kucoin /Balances/exchange with 200 and success=true; interactive portfolio rendering was not tested. Documented on nexus-ui. Exchange-key privileges and CEX trading approvals are L3 in the crosswalk.
F8Goal approval semantics: specific drafts auto-approved by clarify_goalsMediumopen (product decision)nexus-platform e3d7c4c (behaviour deployed)Docs state the running behaviour (Goal lifecycle). Product decision pending: ready_for_review state + recorded approver vs an explicitly scoped auto-approval policy. Re-verification: open — product policy unresolved; documentation describes the behaviour, it does not supply an independent human approval.
O1Backups share the production failure domain (= H9)Highdeferred by owner (2026-09-05 16:25Z: "not for now")—Daily on-node mongodump (03:15, 14-day retention, hostpath PVC) stays the only backup — a local backup, not DR. The candidate (encrypted nightly copy to the .98 host + restore drill into isolated infra) is recorded, not scheduled. Finding remains open on the merits. Re-verification: deferred — residual risk remains; backup completed, data and backup PVCs remain hostpath; no off-node copy or restore drill was verified. Recorded as a residual risk, not a pending permission (owner priority 6).
O2Oracle agreement / green health do not establish failoverHighpartial — second RPC configured 2026-09-05 15:5xZ, failover unprovennexus-gitops 208f20aThe exec runs two endpoints since the 15:5xZ gitops batch: the dedicated node plus public=https://api.mainnet-beta.solana.com (SOLANA_RPC_URLS, priority failover in RpcChain; the outbox's second-endpoint unlandable proof reads it). Re-verification: partial — second RPC configured; this closes "only one configured endpoint", not failover / independence / feed-validation proof; no outage was induced. Open: failover exercise, feed-identity (account owner, discriminator, expected feed id, full verification, confidence) and slot-lag checks — L9 in the crosswalk.
O3Release safety not proven (= H7)Mediumpartial — branch protection / PR flow declined by owner (2026-09-05 16:25Z)nexus-platform eb1c464Direct push to main stays the deploy flow for every repo (CI writes the image tag into environments/prod/values.yaml; Argo rolls it). CI lints the worker; mob-host is clippy'd locally only and excluded from the hosted test build (runner disk, 2feff39 / eb1c464); nexus-solana paths-ignore since db421a7. Re-verification: partial — owner delivery policy retained; strict Clippy now includes worker / auth; mob-host remains excluded from hosted tests; artifact / provenance and coverage limits remain. What remains partial is the test / lint coverage and provenance (L12), not a pending decision.
O4Financial observability behind operational observabilityMediumpartial — dashboard + rules deployed 16:27Z; exporter 17:12Z (scrapeable 17:4xZ); cost / outbox signals 17:46Z; P&L gauges + dashboard row ≈ 20:3xZ; budget row + nexus.budget rules deployed 23:01Z; nexus_pnl_cost_anomalies_total added 2026-09-06nexus-gitops 9f6aa48 (operational rules) · 05c3ffd (financial) · a5912c7 (dashboard label) · b5b6079 (P&L row) · a33055d (budget row + rules, deployed 23:01Z) · nexus-platform ac38aa1 (exporter) · 750c5ce / 7d6ed59 (P&L gauges) · ee0cd80 (ledger metrics, 23:00Z, deploying) · nexus-solana a74cc87 (costs, outbox health)Deployed: Grafana Nexus Treasury dashboard (uid nexus-treasury, 30 panels + the row "Where the money comes from") and the nexus.financial group (15 rules: NAV stale / incomplete / drawdown 10 % · 20 % / daily loss 5 %, stablecoin depeg, mark stale, signer unreachable / paused / auth denied / policy denial, daily cap 80 %, sleeve unresolved, outbox stuck, rung firing stuck) alongside nexus.backups / nexus.signer / nexus.auth / nexus.agents. The worker exporter (treasury_signals, 60 s) rolled at 17:12Z and was unscrapeable 17:12–17:4xZ: nexus_nav_component_usdt used a component label that the registry adds globally, Prometheus rejected every worker scrape; renamed nav_component (513a173 / d128e17, dashboard a5912c7). Rule added: never use component / job / instance / pod / namespace as a metric label. Signals live since the exec a74cc87 rollout: /v1/status.costs_today, GET /v1/health/outbox, /v1/ladder.outbox.fired[] costs; the budget gate's nexus_portfolio_* and nexus_accum_actions_gated_total{class="budget"}; the P&L-by-source gauges since worker 7d6ed59 (first rows 21:12Z). Re-verification: improved — operational telemetry live (six Nexus targets up; financial metrics / rules and NAV view exist); fresh alert delivery, restore alerts and incident recovery were not exercised; cost persistence and attribution gaps remain. Budget row + rules (a33055d, deployed 23:01Z): Treasury dashboard row "Portfolio budget (caps, reservations, ledger)" — budget available, ledger version, reserve CAS conflicts, fence rejections, reserved (ladder), SOL cap / liquid reserve headroom, gate verdicts (24 h increase), cap headroom — on the ledger metrics nexus_portfolio_ledger_version / nexus_portfolio_reserve_conflicts_total / nexus_portfolio_fence_rejections_total (worker ee0cd80); group nexus.budget: NexusBudgetUnavailable (nexus_portfolio_budget_available == 0 for 30 m, warning), NexusBudgetFenceRejection (increase(nexus_portfolio_fence_rejections_total[15m]) > 0, critical — a stale executor tried to settle after a takeover: check for a duplicated money movement), NexusSolCapBreachedEnforce (nexus_portfolio_cap_headroom_usdt{cap="sol_exposure"} < 0 for 6 h, info — the F6 owner decision). Cost-anomaly signal (nexus-platform 2553748, deployed 2026-09-06): nexus_pnl_cost_anomalies_total{field} counts every on-chain cost figure the P&L sanity rules refused — ≤ 0, non-finite, above PNL_COST_SANITY_USD (25), or a rent_* field on a native-SOL pair. It exists because the observability stack showed a +1,068 USD cost row and a +1,226 round trip for a day without anything flagging either; the counter is the tripwire for the next mis-parsed figure. It is not alerted on yet, and neither is nexus_pnl_unexplained_usdt (the candidate rule) — see the residual analysis on Measuring success for why a threshold cannot be chosen yet. Still partial: no rule reads costs_today; NexusOutboxStuck is silent while EXEC_OUTBOX=0 (Operations → P&L gauges, Alerting).
§7USDT NAV, TWR/MWR, attribution, benchmark suite, scenario tests (= M3)—live-verified 2026-09-05 17:25Z (NAV series); P&L by source live since 21:12Z; validation batch live-verified 23:4xZ; the first day's P&L figures were wrong and are corrected 2026-09-06 (63a2de3); validation still immaturenexus-platform ac38aa1 (17:12Z) · 8e1e0cb / 0a58575 / ee0cd80 (validation batch, 23:00Z, deploying) · nexus-ui 13d3f2a / f8327f1 (P&L section) · nexus-gitops 05c3ffd (dashboard + rules), 441291a / 078055c (worker rollout fix), b5b6079 (P&L row) · nexus-solana c483bbd / a74cc87 (costs, 17:46Z) · nexus-platform 3a91236 … 7d6ed59 (P&L by source, ≈ 20:3xZ)First snapshot 17:25 UTC: 91,138 USDT, 0 unknown components, 4 benchmarks frozen at inception; UI /treasury. Deployed: worker job treasury_nav (hourly) → accum_nav_snapshots (per-component known|unknown|stale, USDT numeraire via Coinbase USDT-USD / USDC-USD, chain-linked TWR, HWM / drawdown, MWR 30 d + inception, exposure, attribution), accum_external_flows (operator-recorded), accum_benchmarks + frozen config (cash 4 % APR, hold_btc_sol 50/50, dca_btc_sol weekly/180 d, ladder_passive 0.3 % slippage), accum_costs; Core GET /v1/desk/nav, /history, /flows, POST /v1/desk/nav/flows; metric exporter. Rollout incident: the first treasury-nav job was fetched by the outgoing worker pod under the shared Apalis consumer name and sat in-flight; re-enqueued by hand at 17:25Z, fixed by strategy: Recreate (gitops 441291a) + per-pod consumer nexus-jobs-<POD_NAME> (platform 9063b8d, gitops 078055c) — Operations → Apalis queue. Costs: the exec reports fee_lamports + priority_fee_lamports, rent_lamports, fee_usd (venue fee only) and realized quantities on sleeve rows, fired rungs and /v1/status.costs_today since a74cc87 (17:46Z); the NAV job books them as tx_fee / priority_fee / swap_fee in accum_costs — Measuring success → Costs. P&L by source (owner request 2026-09-05 evening): per period ΔNAV − external flows = Σ sources + unexplained, sources jito_staking / lending:<venue> / lp_fees:<pool> / sleeve_realized:<pair> / sleeve_unrealized:<pair> / market:* / costs:* / unexplained in accum_pnl_sources + accum_pnl_events, own movements in accum_internal_flows; Core GET /v1/desk/pnl*; 8 gauges; dashboard row. First live rows 21:12Z: sleeve +402.26 realized (matches the exec ledger), unrealized +134.57, lending:kamino +0.24 USDT for the hour (≈ 3.7 % annualised vs 11.0 % quoted — one hour, not a verdict), market:SOL −15.64, unexplained −95.61 (the pre-recording 17:37Z rotation gap), ΔNAV −111.92; the identity holds. Re-verification (at the 19:12Z snapshot, before per-source rows existed): measurement implemented and live; validation immature — in-scope NAV 91,106.75 USDT, inception TWR −0.03464 %, 1d/7d/30d windows null, benchmark history starts 17:25Z; the snapshot does not establish sustainable USDT outperformance. Its measurement qualifications (in-scope NAV with 12 CEX entries unvalued, manual flows only, TWR treats flows as period-end, yield was a residual at 19:12Z, cost ingestion incomplete) are recorded on Measuring success → Measurement qualifications. Validation batch (8e1e0cb … ee0cd80, deployed 2026-09-05, live-verified 23:4xZ) — what the re-verification's qualifications now get: (1) flow-timed TWR — the period is split at every external flow and valued on marks interpolated between the bracketing snapshots (holdings repriced, a constant residual rate solved so the chain ends at the observed NAV), labelled in meta.twr.method ∈ no_flows | flow_time_interpolated_marks | flow_time_flat | end_of_period_fallback, with the old figure kept as meta.twr.period_return_end_of_period for comparison; (2) durable costs keyed by signature — accum_costs._id = <kind>:<signature>:<field>, insert-once, so the four feeds (sleeve rows, outbox fills, route answers, costs_today) land on the same rows; the 11 record_route_costs call sites in mob_jobs.rs persist every route answer's costs; costs_today (an aggregate without signatures) is reconciled as meta.costs.exec_today.unbooked_sends_today; the rule: on-chain fees / rent are attributed (costs:tx / costs:venue) but never deducted from NAV — the wallets already paid them; costs_accrued_usd deducts off-portfolio costs only (infra, ai_tokens); (3) in-scope NAV — in_scope_nav_usdt (= nav_usdt), scope: "strategy", out_of_scope{value_usdt_estimate, unpriced_entries, entries[]} with cex-manager's usdValue as an estimate never counted (all 12 CEX dust entries were unpriced when built); (4) residual external-flow detection every snapshot — the on-chain pool (wallet_exec, wallet_vault, sleeve_escrow, lending, lp) vs the previous pool repriced, beyond NAV_FLOW_DETECT_MIN_USDT 50 + NAV_FLOW_DETECT_TOL_FRAC 0.01 × internal activity ⇒ an accum_external_flows row source: detected_unconfirmed (dated at the snapshot, wallet / asset by the largest move), applied to the period and listed on /v1/desk/nav.flows.detected_unconfirmed for the operator to confirm or offset; (5) attribution_method: pnl_ledger everywhere — unexplained explicit, never folded into yield. Exec follow-ups recorded, not built: costs_today.entries[] with signatures; GET /v1/chain/transfers for signature-confirmed detection (source: detected). Not built: the no-AI counterfactual (benchmark 5), historical reconstruction, scenario tests, forecast scoring, cumulative lending interest since deposit (exec exposes supplied_ui / apy only), ladder_realized (never emitted). The sleeve's realized USDC PnL is still not a portfolio return; the series remains too short for any verdict. P&L correctness batch, deployed 2026-09-06 (nexus-platform 2553748 → 72967bd → 4b5a181 → 63a2de3, with the exec side in 4804e26). The first live day produced figures that were wrong, not merely young, and every one of them is now governed by a stated rule — Measuring success: (a) a cost is positive and small — ≤ 0 is dropped, above PNL_COST_SANITY_USD (25) is booked Unattributed and surfaced in notes + costs.unattributed_usdt, rent_* is skipped whole on a native-SOL pair (the sold coin leaves through a wSOL escrow and lands in the exec's rent delta), and every refusal counts on nexus_pnl_cost_anomalies_total{field}; (b) a round trip is the exec's own realized figure when the exec read the confirmed transaction (realized_pnl_usdc + proceeds_source: "tx_meta") — profit_source: "exec_realized" | "derived", with sleeve.profit_source_counts; (c) a repair pass, inline in the hourly treasury_nav job (no separate job), purges the poisoned stored rows over a 30-day lookback, recomputes the sleeve events, rewrites the affected period rows and moves each period's unexplained by the opposite amount so the identity still holds — reported on /v1/desk/pnl.costs.repair; (d) rolling windows cover the series (covered, truncated_to_series, series_starts_at, coverage.note, /v1/desk/nav.returns_coverage) instead of resolving to from == to, 0 periods, delta 0 — which the UI had been drawing as a flat 30 days; (e) lending reconciles (balance_delta_usdt = net_flows_usdt + interest_usdt + unattributed_usdt, contaminated_periods[] when the venue changed or |Δ| exceeded PNL_LENDING_SANITY_MULT (10) × the implied accrual, plus interest_clean_usdt / apr_realized_clean); (f) a window-independent earning block (kind, venue, asset, principal_qty/usdt, rate_reported, earned_window_usdt, earned_inception_usdt, apr_realized_inception, status, since, note) — note is null or an array of sentences, never a bare string, which crashed the UI until nexus-ui 068ef0f; (g) LP as legs (F6 above). Corrected figures after the 10:09:48Z snapshot (nav_1788689388951): NAV 91,611.15 USDT, TWR index 1.005188 (+0.52 % since inception), 0 unknown components; ΔNAV since inception +472.83 = market:SOL +537.96, sleeve_realized:SOL/USDC +159.40 (was +1,226.46), sleeve_unrealized −134.90, unexplained −101.96, market:LP +16.98, market:STABLE −7.22, lending:kamino +3.04, costs:venue −0.47, costs:tx −0.0005 (was +1,067.96); sleeve realized all-time 561.66 (was 1,628.48). earning: Kamino 57,433.72 principal / +3.04 / realised APR 3.63 % / contaminated, JitoSOL 17,165.63 / 0 / earning, LP orca 1,067.27 / 0 / earning. The −101.96 residual is analysed, not fixed: −95.61 is the three NAV periods before the source ledger's first row (2026-09-05T20:12:14.720Z) — no attribution exists for them at all, and the 17:37Z Kamino rotation sits inside; −6.23 is the execution cost of the JitoSOL→SOL unstake and the LP add, i.e. venue slippage on our own conversions, currently booked to no cost source; ≈ −0.12 is rounding. An unattributed_pre_ledger bucket with a ledger_starts_at marker and a costs:slippage source are specified only — verified absent from nexus-platform at 63a2de3 (clean tree, HEAD == origin/main); the P&L source vocabulary is closed and slippage is documented as landing in unexplained (the residual). Honest finding on the measurement itself: Kamino's realised APR over 12 clean hours was ≈ 3.8 % annualised against 11 % advertised, but supplied_ui carries ±$2 of noise on a $56k balance and fell in 2 of 11 hours, and the venue rotation contaminates the series — the sample cannot yet measure the true rate.
§8Documentation repairs (13 items)—done in docs — stale register text removed in this commitnexus-docs f121c8d … this commitRe-verification: improved; register still has stale text — some rows simultaneously said deployed and "Not deployed"; outbox phase 2 is deployed, still disabled. Those fragments (S5, F3, F4, F7, O2 and the outbox "rolling" status) are gone as of this commit; every row now carries one status. For the 19:29–19:34Z snapshot the independently verified disposition in the consolidated report takes precedence over this register. Prompt files: the accum-desk prompts no longer claim forecasts are "Brier-scored" (nexus-gitops 97f01fc, live after the 21:15Z accum-host restart); the scorer itself is still missing (M3).

Counts (2026-09-06 ≈ 10:1x UTC, from the rows above, one per id): 21 rows — 6 live-verified (S1, S2, S3, S6, F5, §7; S1, S3 and F5 closed) · 5 deployed (S4, S5, F3, F4, F7) · 1 built (F6) · 5 partial (F1, F2, O2, O3, O4) · 1 open (F8) · 1 deferred by owner (O1) · 2 docs-only (S7 open on the merits, §8). The counts are unchanged from 2026-09-05 23:2xZ — what changed is the evidence under them. The 23:00Z–23:13Z batch that was "deploying" is now deployed and live-verified, and the 2026-09-06 work corrected defects inside rows that were already at their status rather than moving any row:

  • "Built" for F6 still means the deployed gate evaluates, reserves and counts but blocks nothing until worker.budget.mode: enforce — now with the aggregate CAS ledger running and its SOL-exposure input corrected (18.71 % → 19.87 %), so the owner's cap decision should be re-read against the new figure.
  • "Partial" for F1 still means the outbox is EXEC_OUTBOX=0; the legacy journal is live and now settles a proven non-broadcast as failed, but no legacy fire has been journaled yet.
  • "Partial" for F2 no longer means "no caller sends an intent_id" — every caller does, and one live intent has confirmed. It now means: no replay, crash or takeover has been exercised live, and an ambiguous submitted is still settled by hand.
  • §7 stays live-verified, but its figures were wrong for a day and are corrected in 63a2de3; the residual is analysed and two of its three parts have no code yet.
  • F5 stays closed on the original cbBTC mismatch; the reconciler's own 2026-09-06 false positive — which blocked every new swing buy for a morning — is fixed and live-verified.

Next — the owner's updated priorities (re-verification 2026-09-05)​

Quoted from the consolidated report's "Updated priorities"; the register rows they drive are in brackets.

  1. Complete Core enforcement after the already-deployed identity binding is checked against actual operator / service workflows. Core remains log-only today. [S3, S4]
  2. Complete outbox activation and recovery verification, including the flag-off outcome-journal issue. Do not equate deployed phase-2 code with active durability. [F1 — journal fix live-verified 2026-09-05 23:33Z with 0 rows so far; activation still open]
  3. Resolve the budget-policy conflict and enforce it across execution paths. Choosing a higher cap, a smaller ladder or paused marginal allocations is an owner strategy decision; the review changes none of them. Add aggregate atomicity before calling reservations globally safe. [F6 — atomicity + fencing + approval / exec coverage live-verified 2026-09-05 23:33–23:4xZ; the SOL-exposure input was corrected on 2026-09-06 (LP legs, 18.71 % → 19.87 %), so re-read the headroom before choosing a cap; the decision is still the owner's]
  4. Close approval replay / fencing gaps and observe a full fill / cancel / recovery lifecycle under the new signer / sleeve implementation. [F2 — exec side live-verified 23:33Z and every caller now wired (2d8eef1), one live confirmed intent 2026-09-06 09:0xZ, no replay / crash / takeover observed; a preflight-rejected send now re-arms instead of replaying (0641ea5); F4 — still no complete live fill / cancel; S1 — a receipt bound fired pre-sign on a live supply 2026-09-06 09:0xZ]
  5. Validate the new NAV and cost / flow series, label its scope and attribution honestly, then evaluate benchmarks over meaningful history. [§7, O4 — flow-timed TWR, signature-keyed costs, in-scope labelling and residual flow detection live-verified 2026-09-05 23:4xZ; the P&L correctness batch (63a2de3) then found and repaired the first day's figures on 2026-09-06 — the residual is analysed and two of its three parts have no code; history is still a day long — Measuring success]
  6. Keep the explicitly deferred off-node backup work and the declined mandatory PR policy recorded as residual risks. Do not reopen those as assumed pending permissions; neither choice was changed. [O1, O3]

Known regressions​

  • Legacy ladder branch has no durable per-tranche outcome journal while EXEC_OUTBOX=0 (re-verification F1 caveat, nexus-solana a74cc87) — resolved: nexus-solana 918b8fb (in a1eb8f3), deployed and live-verified 2026-09-05 23:33Z — GET /v1/ladder/outbox answers {enabled: false, journal: "legacy"} with 0 rows so far. The first legacy fire under it has not happened yet, so the journal is verified and the journalling of a real fire is not. With that revision running, the flag-off path writes a source: "legacy" row into accum_outbox before the self-call and settles it from the route's answer (signature, fill, costs; submitted_unknown on ambiguity), and a confirmed fire marks the rung Fired — the F1 row has the detail. What to verify after the roll: GET /v1/ladder/outbox answers {enabled: false, journal: true}, the next fired rung has a legacy row with its signature and ends Fired, /v1/status.outbox.unreconciled[] is empty. The original text, kept for the record: Outbox phase 2 deleted the accum_tranche_queue writer (the outbox rows were meant to replace it) but the flag is off, so the branch that actually fires rungs today logs per-tranche outcomes only; ladder machine state (accum_ladder_state) still persists but is not a signature / outcome journal. Until the outbox is activated and verified, a crash between broadcast and the log line leaves no durable trace of that tranche's signature. The fix restores a durable legacy outcome write (above); activating the outbox is still priority 2. Reader side: accum_tranche_queue remains read-only for EXEC_OUTBOX_ADOPT_LEGACY (HARVEST §11).

What the first audit's rows mean now​

The 2026-09-04 implementation audit (ids C1–C7, H1–H13, M1–M4) is now preserved verbatim, including its remediation appendix, inside the operator workspace's nexus-platform-audit-2026-09-05.md. That report's Legacy finding crosswalk maps all 24 IDs and retains additional controls and qualifications; the old standalone file is no longer required. The dated independent verification in the consolidated report supersedes older closure claims. Historically deployed and live-verified on 2026-09-05 from that list: C1, C5, C6, H6, H10 (infra); C7 fail-closed Telegram allowlist; H2, H8, H13 and C3 (nexus-solana 0913342); H1 policy gate (0913342, live-verified via /v1/status.policy); H3, H4, H11 (log mode), H12 (nexus-platform e3d7c4c). Its rows that this register carries forward: C2 → S1, C4 → F1, H5 → F6, H7 → O3, H9 → O1, M3 → §7, H11 → S3/S4.

The C/H/M ids stay valid as aliases of the rows above — they are not extra findings to add to the S/F/O counts. Where an original finding had controls that no S/F/O row carries, the consolidated report keeps them as carried-forward controls L1–L12; their residual acceptance criteria are listed here so the docs carry them too (one line each; the full text is in the report).

LOriginalResidual acceptance criterion (what still has to be shown)
L1C1 cluster authorizationBeyond the can-i spot checks: no non-privileged pod identity can read the signing Secret, exec into protected pods, create privilege-escalating RBAC bindings or privileged workloads; positive tests for the Argo / monitoring / worker rights kept alongside the denials.
L2C5 Mongo auth, encryption, recoveryA credentialed URI is not TLS: encrypted transport, least-privilege roles, secret rotation and network restriction are separate verifiable controls; replication / off-node recovery stay under O1 (deferred).
L3C6 / M4 CEX security vs functionalityExchange keys shown to lack withdrawal / transfer rights, loans / futures / admin routes disabled or role-restricted, scoped credential per caller (Keycloak client-credentials planned, not implemented); CEX order proposals are still not a typed approval / execution path — implement it with reconciliation + idempotency or label CEX actions informational. A working CEX portfolio page must not imply automated CEX trading.
L4C7 Telegram allowlistConfiguration / rotation and negative-user checks stay in the acceptance set; a healthy bot is not financial authorization.
L5H2 automatic paired exitsThe basis × (1 + 0.006 + 0.002) exit is a code-approved automatic sell, so "every sell is human-approved" stays false; keep edge / basis checks for partial fills and replacements and ensure execute-role routes cannot bypass the sell policy.
L6H4 / H1 typed decision and reserve policySchema validity never authorizes a financial action; signer-side amounts, liabilities, freshness and portfolio limits stay independent of model fields; verify effective reserve floors survive a restart — as of 2026-09-06 they are gas 0.2 SOL (code default; the desk asks 0.5 and is clamped up) and float 2 000 USDC (owner decision, nexus-gitops 2c8d76a, worker.reserves.minFloatUsdc; the code default is still 5 000), and since nexus-platform 3ce6c78 a decision-pass lending_supply can no longer size itself through the float floor; swing action cooldown, deep-bottom freeze, yield-tier / hot-wallet limits and SOL↔JitoSOL clip coverage remain explicit residual checks (HARVEST §12 items 3, 11).
L7H5 LP governanceObservational fraction caps (F6) are only part of it: allowed-pool / protocol validation, fee return measured net of impermanent loss vs hold, range-health alarms, inventory drift, deterministic unwind and incident exits; per-transaction bounds do not bound a multi-transaction LP operation; no open LP today validates nothing about the entry / exit paths (HARVEST §7).
L8H6 NATS auth, ACL, transportShared nexus + restricted runner identities are not per-service isolation: TLS, per-service publish / subscribe permissions and denial of runner JetStream administration are separate criteria; keep the async_nats::connect(url) lesson (285021f, ≈ 8 min bus outage).
L9H8 oracle integrityBeyond failover and freshness (O2): account owner, discriminator, expected feed id, full verification, confidence and slot-lag checks; a second endpoint or an ok price agreement proves none of them (HARVEST §12 item 18).
L10H10 fleet incidents and configuration recoveryCarry forward unmanaged Helm-release drift, reproducible Mongo member configuration, secret-bootstrap key-loss prevention, alert delivery / ingestion tests and meaningful Solana-node / LLM / board-sync metrics; six scrape targets up does not validate those surfaces.
L11H13 fallback allocation migrationCancel-before-activation is proven for the simple path only; a transactional budget migration across ladder state, approval state and DCA scheduling (crash / partial failure, racing rung, duplicate approval) stays under F1 / F2 / F6; no shadow-period acceptance gate has been completed.
L12M1 dependencies and release evidenceDependabot + RustSec workflows exist but do not gate deployment; the recorded advisory counts are historical, not today's inventory; remaining: scan the exact deployed lockfiles / images, assess reachability, SBOM / provenance, and an explicit choice of which checks gate delivery (independent of the direct-main decision under O3).