Architecture Decision Records¶
ADRs record the architecture-level decisions behind the Rust core once they are considered settled (accepted / implemented / proposed); the crate sources remain the last word on what the code actually does today. New ADRs are proposed and reviewed through ergo tasks and committed via their own review flow — a table row is added when the file lands.
Start here¶
The load-bearing decisions behind the two-consumer architecture:
ADR-005: Polars-Inspired Three-Layer Architecture — why a Rust engine with a thin Python driver
ADR-003: BotCore as the state layer, peer to ArbitrageEngine — where all pool/token state lives
ADR-019: In-Process revm as the Sole Simulation Executor; Strategy-vs-Engine Separation — the sole simulation executor + strategy/engine separation
ADR-008: Per-block state machine for the pump’s block clock — the pump’s block clock
ADR-025: The ExecutionAdapter seam — a deep, user-owned execution layer over the thin engine — how user code plugs into execution
Index¶
ADR |
Title |
Status |
|---|---|---|
I/O-Free Pool Architecture |
accepted |
|
Pool Type Registry as Module-Level Singleton |
accepted |
|
BotCore as the state layer, peer to ArbitrageEngine |
accepted |
|
Typed TickMap boundary for CL verifier + liquidity-apply seam |
accepted |
|
Polars-Inspired Three-Layer Architecture |
accepted |
|
Bot as the per-chain orchestrator |
implemented |
|
Pool unregister seam |
accepted |
|
Per-block state machine for the pump’s block clock |
implemented |
|
Single-Source-of-Truth Versioning |
accepted |
|
Alembic Retention Through 0.6.x and Rust Schema Cutover |
accepted |
|
Auto-healed Alembic Retirement (Dump-and-Restore Cutover) |
proposed |
|
Spec-Bound Pool Admission Contract |
accepted |
|
The |
accepted |
|
Pool-State Deepening — Where the Trait Seams Live |
accepted |
|
Solver-Seam Relocation — the Resolve→Solve Boundary |
accepted |
|
ReorgPoolState — Pool-Owned Reorg Rollback |
accepted |
|
Forward-Apply Pool-State Traits |
accepted |
|
Tracked Debt — |
accepted |
|
In-Process revm as the Sole Simulation Executor |
accepted |
|
Tier-3 On-Chain Accuracy Oracle |
accepted |
|
Solver-state accuracy is a fail-fast tripwire |
accepted |
|
Registration verify-lifecycle is core-owned |
accepted |
|
|
accepted |
|
Net-profit order index ( |
accepted |
|
The |
accepted |
|
Retire the “backrun” label — “settlement arbitrage” |
accepted |
|
The block-pump dispatch seam |
accepted |
|
The block-pump |
accepted |
|
The executor command grammar |
accepted |
|
The derivation outcome is a tri-state |
accepted |
|
The executor grammar as a facts-driven Plan walker |
accepted; implemented |
|
|
accepted |
|
The encode funnel’s intake contract |
accepted |
|
ERC6909-vault profit capture wiring |
accepted |
|
Consolidate the AMM math family into |
accepted |
|
Do not re-land the V3/V4 window guards |
accepted |
|
Engine Mutex sharding (RAYPAR) |
accepted |
|
The swap-simulation gate |
accepted |
|
The CL event-routing FSM |
accepted |
|
State-lock — enumerated sim-anchor projection |
pending status |
|
Failure reactions are per-bucket |
accepted |
|
The block-epoch pipeline — one stage machine over a cheap-read data plane |
implemented |
|
One role-switching worker fleet — a bounded, budgeted host for every execution resource |
proposed |
|
The observability standard — four channels, a level rubric, one target taxonomy |
proposed |
|
Fleet intake liveness — BackstopTick + PostureEdge complete the host transition relation |
accepted |
|
The solve cycle as a deep module — ArbEngine regroups into registry + cycle + config |
accepted |
|
StageHandlers stays the pure product seam; PumpControl is the driver-facing control seam |
accepted |
|
Retire the ADR-006 D4 subscriber bus — compile is the guard for retired modules |
accepted |
|
Fleet boot registry — one keyed owner for the pooled roles’ boot facts |
accepted |
|
The engine’s interface is one stage seam — the engine recedes to composition machinery |
accepted |
|
A public |
accepted |
|
The degenbot console is a Rust binary — one command model, an argv passthrough for Python |
accepted |
|
The database upgrades itself at open — Alembic retires in-tree ahead of 0.7 |
accepted |
|
FFI Stub Generation — Retire the Hand-Maintained |
accepted |
|
The strategy plumbing surface — ReplayOutcome, journal extractors, the planning workspace, and anchored discovery are the promoted seams |
accepted |
|
Pending-transaction strategy seams — MarketContext, PendingTxStrategy, SubmissionTarget, V4 substrate closure |
accepted |
|
Retire the gated serving seam — refuted premise, membership to the boot registry |
accepted |
|
The strategy host — one process, many drivers over one operator account |
accepted |
|
The strategy crate split — submission is mechanism, |
accepted |
|
The pool family kernel — one taxonomy, capability tiers, species as data |
accepted |
|
Collapsing the V2 walk dispatch — representation vs interface |
accepted |
|
Pool-state provisioning is a plane capability — pool ingress, sealed seeds, the strategy kit |
accepted |
|
One operator file, four layers — node endpoints, chain id, and database path resolve through the typed config on every entry path |
accepted |
|
The file is portable, the secret is not — |
proposed |
|
The session object registry is the cutover — identity is minted once, and the Python side is an adapter |
accepted |
|
The verdict is the single configuration authority — one load, one frozen projection, provenance in the authority |
accepted |
|
Deterministic Stub Generation — |
accepted |
|
The strategy substrate gets one home — ADR-061’s placement reopens |
accepted |
Numbering note: ADR-037 was assigned twice (engine mutex sharding; swap-simulation gate) — both kept as filed.