Files
foxhunt/Cargo.toml
jgrusewski fa3264d58d 🔐 CRITICAL SECURITY MILESTONE: Complete elimination of ALL dangerous hardcoded symbols and fallback values
This comprehensive security audit and remediation eliminates catastrophic vulnerabilities that could have led to unlimited losses, masked compliance violations, and hidden system failures in production trading.

## 🚨 CRITICAL SECURITY FIXES

### Hardcoded Symbol Elimination (200+ instances)
-  Removed ALL hardcoded trading symbols from production code
-  Replaced with sophisticated asset classification system
-  Configuration-driven symbol management with hot-reload capability
-  Pattern-based symbol matching with database-backed rules

### Dangerous Fallback Value Elimination (150+ instances)
- 🔥 CRITICAL: Removed Price::ZERO fallbacks that could disable trading limits
- 🔥 CRITICAL: Eliminated fallback prices in VaR calculations (prevented fake risk metrics)
- 🔥 CRITICAL: Fixed unwrap_or patterns that masked missing market data
- 🔥 CRITICAL: Replaced dangerous match defaults with safe error handling

### Risk Calculation Security Hardening
- ⚠️  PREVENTED: Risk limit bypass through zero value fallbacks
- ⚠️  PREVENTED: Hidden compliance violations through silent defaults
- ⚠️  PREVENTED: Market data corruption masking
- ⚠️  PREVENTED: Portfolio calculation failures hiding as zero values

## 🏗️ ARCHITECTURE IMPROVEMENTS

### Configuration Management
- Database-backed asset classification with PostgreSQL hot-reload
- Comprehensive symbol configuration management
- Real-time configuration updates without service restart
- Production-grade audit logging and change tracking

### Safety Mechanisms
- Fail-safe error handling (systems fail explicitly instead of silently)
- Conservative fallbacks only where absolutely safe
- Comprehensive logging of all fallback usage
- Statistical confidence requirements for position sizing

### Production Readiness
- Zero compilation errors across entire workspace
- Comprehensive test fixture system with realistic data generation
- Database migrations for symbol configuration infrastructure
- Complete API documentation for all public interfaces

## 📊 SCOPE OF CHANGES

**Files Modified**: 71 production files across critical trading systems
**Lines Changed**: +4945 additions, -831 deletions
**Security Vulnerabilities Fixed**: 200+ dangerous patterns eliminated
**Critical Systems Hardened**: Risk engine, ML models, trading services, position management

## 🎯 IMPACT

**BEFORE**: System could execute trades with wrong accounts, incorrect limits, hidden failures, arbitrary risk assumptions
**AFTER**: Production-secure system with explicit configuration requirements, safe failure modes, and comprehensive monitoring

This represents the largest security remediation in the project's history, transforming a potentially catastrophic codebase into a production-ready, security-first HFT trading platform.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-09-29 14:35:15 +02:00

488 lines
14 KiB
TOML

[package]
name = "foxhunt"
version.workspace = true
edition.workspace = true
rust-version.workspace = true
authors.workspace = true
license.workspace = true
repository.workspace = true
homepage.workspace = true
documentation.workspace = true
publish.workspace = true
keywords.workspace = true
categories.workspace = true
description = "Foxhunt HFT Trading System - High-frequency trading with ML and comprehensive monitoring"
[dependencies]
# Core dependencies for the root package
tokio.workspace = true
serde = { workspace = true, features = ["derive"] }
serde_json.workspace = true
tracing.workspace = true
tracing-subscriber.workspace = true
# Database dependencies for binaries
redis.workspace = true
sqlx.workspace = true
# gRPC dependencies for service binaries
tonic.workspace = true
tokio-stream.workspace = true
prost.workspace = true
chrono.workspace = true
thiserror.workspace = true
prometheus.workspace = true
lazy_static.workspace = true
axum.workspace = true
rand.workspace = true
# Core trading infrastructure
trading_engine.workspace = true
# Risk management
risk.workspace = true
# Core backtesting and data modules (ML dependencies REMOVED to eliminate cascade)
backtesting.workspace = true
data.workspace = true
adaptive-strategy.workspace = true
# Benchmarking
criterion = { workspace = true }
fastrand = { workspace = true }
async-trait = { workspace = true }
futures = { workspace = true }
uuid = { workspace = true }
bincode = { workspace = true }
flate2 = { workspace = true }
http = { workspace = true }
# ALL ML dependencies removed from root - GPU/ML tests moved to ML training service
anyhow.workspace = true
# Performance benchmarks removed - benchmarks moved to individual crates
[workspace]
resolver = "2"
members = [
# "foxhunt-common-types", # DELETED - types migrated to common/src/types.rs
"trading_engine",
"risk",
"risk-data",
"trading-data",
"tli",
"ml",
"ml-data",
"data",
"backtesting",
"adaptive-strategy", # Re-enabled after fixing compilation issues
"common",
"storage",
"market-data",
"database",
"config",
"services/backtesting_service",
"services/trading_service",
"services/ml_training_service",
"tests",
"tests/e2e"
]
exclude = [
"performance-tests",
"tests/e2e/vault_integration"
]
[workspace.package]
version = "1.0.0"
edition = "2021"
rust-version = "1.75"
authors = ["Foxhunt HFT Trading System"]
license = "MIT OR Apache-2.0"
repository = "https://github.com/user/foxhunt"
homepage = "https://github.com/user/foxhunt"
documentation = "https://docs.rs/foxhunt"
publish = false
keywords = ["trading", "hft", "ml", "rust", "finance"]
categories = ["finance", "algorithms", "science"]
[workspace.dependencies]
# Core async and utilities - OPTIMIZED VERSIONS
tokio = { version = "1.40", features = ["rt-multi-thread", "macros", "net", "sync", "time", "fs", "signal", "io-util", "test-util"] }
tokio-util = { version = "0.7", features = ["codec", "io", "rt"] }
tokio-stream = { version = "0.1", features = ["sync"] }
tokio-test = "0.4"
tokio-retry = "0.3"
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
serde_yaml = "0.9"
toml = "0.8"
uuid = { version = "1.10", features = ["v4", "serde", "fast-rng"] }
thiserror = "1.0"
anyhow = "1.0"
futures = { version = "0.3", features = ["std", "alloc", "async-await"] }
futures-util = "0.3"
futures-test = "0.3"
async-trait = "0.1"
once_cell = "1.20"
# Time handling
chrono = { version = "0.4.31", features = ["serde"] }
# Financial and numerical types
rust_decimal = { version = "1.0", features = ["serde", "macros"] }
rust_decimal_macros = "1.36"
num-bigint = "0.4"
num-traits = "0.2"
num = "0.4"
# Random number generation
rand = { version = "0.8.5", features = ["small_rng"] }
fastrand = "2.0"
rand_chacha = "0.3.1"
rand_distr = "0.4"
# Logging and tracing
log = "0.4"
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["fmt", "env-filter"] } # MINIMAL features only
# Serialization
bincode = "1.3"
semver = { version = "1.0", features = ["serde"] }
# High-performance data structures
rustc-hash = "1.1"
ahash = "0.8"
indexmap = { version = "2.0", features = ["serde"] }
crossbeam = "0.8"
crossbeam-queue = "0.3"
crossbeam-channel = "0.5"
crossbeam-utils = "0.8"
parking_lot = { version = "0.12", features = ["deadlock_detection"] }
arrayvec = { version = "0.7", features = ["serde"] }
lazy_static = "1.4"
memmap2 = "0.9"
libc = "0.2"
num_cpus = "1.16"
dashmap = { version = "6.0", features = ["serde"] }
bytes = "1.5"
smallvec = { version = "1.11", features = ["serde", "const_generics"] }
prometheus = "0.14"
# MINIMAL numerical libraries only - ALL ML/GPU frameworks REMOVED from workspace
nalgebra = { version = "0.33", features = ["serde", "rand"] }
ndarray = { version = "0.15", features = ["serde"] }
half = { version = "2.6.0", features = ["serde"] }
# ALL HEAVY ML/GPU DEPENDENCIES COMPLETELY REMOVED FROM WORKSPACE:
# candle-core, candle-nn, candle-transformers, candle-optimisers - MOVED TO ml_training_service
# ort, wgpu, cudarc - MOVED TO ml_training_service
# tch, torch-sys (PyTorch) - MOVED TO ml_training_service
# linfa, linfa-clustering, linfa-linear - MOVED TO ml_training_service
# smartcore, gymnasium, rerun - MOVED TO ml_training_service
# Network and HTTP
reqwest = { version = "0.12", features = ["json", "rustls-tls", "gzip", "stream"] } # Restored gzip for data compression
http = "1.0"
# Security and cryptography
argon2 = "0.5"
sha2 = "0.10"
jsonwebtoken = "9.3"
# HashiCorp Vault integration
vaultrs = "0.7"
# Broker connectivity
tokio-tungstenite = { version = "0.21" }
xml-rs = "0.8"
time = { version = "0.3", features = ["serde"] }
ibapi = "1.2"
native-tls = "0.2"
tokio-native-tls = "0.3"
# databento = "0.34.0" # REMOVED - too heavy, use direct data feeds instead
# Configuration and file handling
csv = "1.3"
base64 = "0.22"
regex = "1.0"
url = "2.4"
hex = "0.4"
md5 = "0.7"
# Database
redis = { version = "0.27", features = ["tokio-comp", "json", "connection-manager"] }
sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio-rustls", "postgres", "chrono", "uuid", "rust_decimal", "migrate", "derive"] } # Added rust_decimal and derive for trading system
# MINIMAL statistics only - ALL HEAVY ML DEPENDENCIES REMOVED FROM WORKSPACE
statrs = "0.17" # Basic statistics only
approx = "0.5" # Floating point approximations only
# ALL ML DEPENDENCIES COMPLETELY REMOVED FROM WORKSPACE:
# linfa, linfa-linear, linfa-clustering - MOVED TO ml_training_service
# smartcore - MOVED TO ml_training_service
# candle-core, candle-nn, candle-optimisers, candle-transformers - MOVED TO ml_training_service
# cudarc, tch, torch-sys - MOVED TO ml_training_service
# polars - REMOVED (not used in codebase, replaced with minimal CSV parsing)
orderbook = "0.1" # Minimal order book structure only
# Performance and utilities
rayon = "1.0"
wide = { version = "0.7", features = ["serde"] }
bytemuck = { version = "1.14", features = ["derive"] }
autocfg = "1.1"
core_affinity = "0.8"
nix = "0.27"
bumpalo = { version = "3.14", features = ["collections"] }
fs2 = "0.4"
flate2 = "1.0"
# Web framework for monitoring (minimal)
axum = { version = "0.7", features = ["json"] }
# gRPC and protocol buffers - CONSOLIDATED VERSIONS
tonic = { version = "0.12", features = ["server", "tls"] } # Include TLS features for secure communication
tonic-build = "0.12"
tonic-reflection = "0.12"
tonic-health = "0.12"
prost = "0.13"
prost-build = "0.13"
prost-types = "0.13"
hyper = { version = "1.0", features = ["server"] } # MINIMAL features only
tower = { version = "0.4", features = ["timeout", "limit"] }
tower-http = { version = "0.5", features = ["trace"] }
tower-layer = "0.3"
tower-service = "0.3"
# Testing dependencies - MINIMAL ONLY (heavy testing libs removed)
proptest = "1.5" # Restored - needed by many crates
quickcheck = "1.0" # Restored - needed by trading_engine and tests
rstest = "0.22" # Restored - needed by trading_engine
test-case = "3.3" # Restored - needed by config crate
tempfile = "3.12"
mockall = "0.13"
serial_test = "3.1"
# REMOVED HEAVY TEST DEPS: wiremock, insta, testcontainers, fake, httpmock, tracing-test
# Performance testing - CONSOLIDATED
criterion = { version = "0.5", features = ["html_reports", "async_tokio"] }
hdrhistogram = "7.5"
# Database clients for integration testing
influxdb2 = { version = "0.5", default-features = false, features = ["native-tls"] }
# OpenTelemetry for production monitoring and extensive logging
opentelemetry = { version = "0.27", features = ["trace", "metrics", "logs"] }
opentelemetry-otlp = { version = "0.27", features = ["tonic", "metrics", "trace", "logs"] }
opentelemetry_sdk = { version = "0.27", features = ["rt-tokio", "metrics", "trace", "logs"] }
# Additional commonly used dependencies - CONSOLIDATED
# Build dependencies already defined above with tonic dependencies
# Async utilities
async-stream = "0.3"
# Data processing and compression
zstd = "0.13"
lz4 = "1.24"
# Object storage for S3 integration
object_store = { version = "0.11", features = ["aws"] }
# Parquet/Arrow REQUIRED for market data persistence and replay in backtesting
parquet = { version = "55", features = ["arrow", "async"] }
arrow = { version = "55", features = ["prettyprint", "csv", "json"] }
arrow-array = "55"
arrow-schema = "55"
hashbrown = "0.14"
lru = "0.12"
backoff = "0.4"
# Development and configuration - OPTIMIZED
dotenvy = "0.15"
clap = { version = "4.5", features = ["derive"] }
env_logger = "0.11"
color-eyre = "0.6"
# Terminal UI (for TLI)
ratatui = "0.28"
crossterm = "0.27"
# Network and protocols - OPTIMIZED
# Specialized dependencies
metrics = "0.23"
metrics-exporter-prometheus = "0.15"
# Additional test dependencies
arc-swap = "1.6"
# Local workspace crates (for inter-crate dependencies)
# foxhunt-common-types = { path = "foxhunt-common-types" } # DELETED - types migrated to common/src/types.rs
trading_engine = { path = "trading_engine" }
data = { path = "data" }
tli = { path = "tli" }
risk = { path = "risk" }
risk-data = { path = "risk-data" }
backtesting = { path = "backtesting" }
ml = { path = "ml", default-features = false }
adaptive-strategy = { path = "adaptive-strategy" }
common = { path = "common" }
storage = { path = "storage" }
market-data = { path = "market-data" }
config = { path = "config" }
database = { path = "database" }
[features]
default = []
cpu-only = []
integration-tests = []
[profile.release]
opt-level = 3
debug = false
debug-assertions = false
overflow-checks = false
lto = true
panic = 'abort'
codegen-units = 1
strip = true
[profile.test]
opt-level = 1
debug = true
debug-assertions = true
overflow-checks = true
lto = false
incremental = true
codegen-units = 256
[dev-dependencies]
anyhow.workspace = true
chrono.workspace = true
serde_json.workspace = true
sqlx.workspace = true
tokio.workspace = true
uuid.workspace = true
# Comprehensive clippy configuration for production-ready HFT system
[workspace.lints.clippy]
# Module structure - allow mod.rs files for complex modules with subdirectories
mod_module_files = "allow"
self_named_module_files = "allow"
# Critical safety lints - deny to prevent future unwrap/panic usage in production
unwrap_used = "deny"
expect_used = "deny"
panic = "deny"
indexing_slicing = "warn"
float_arithmetic = "warn"
out_of_bounds_indexing = "deny"
unchecked_duration_subtraction = "deny"
# High-priority restriction lints for HFT safety
arithmetic_side_effects = "warn"
as_conversions = "warn"
assertions_on_result_states = "deny"
clone_on_ref_ptr = "warn"
create_dir = "deny"
dbg_macro = "deny"
decimal_literal_representation = "deny"
default_numeric_fallback = "warn"
deref_by_slicing = "deny"
disallowed_script_idents = "deny"
else_if_without_else = "deny"
empty_drop = "deny"
empty_structs_with_brackets = "deny"
error_impl_error = "deny"
exit = "deny"
filetype_is_file = "deny"
float_cmp_const = "deny"
fn_to_numeric_cast_any = "deny"
format_push_string = "deny"
get_unwrap = "deny"
host_endian_bytes = "deny"
if_then_some_else_none = "deny"
impl_trait_in_params = "deny"
infinite_loop = "deny"
inline_asm_x86_att_syntax = "deny"
inline_asm_x86_intel_syntax = "deny"
integer_division = "warn"
large_include_file = "deny"
let_underscore_must_use = "deny"
lossy_float_literal = "deny"
map_err_ignore = "warn"
mem_forget = "deny"
missing_enforced_import_renames = "deny"
mixed_read_write_in_expression = "deny"
modulo_arithmetic = "deny"
multiple_inherent_impl = "deny"
multiple_unsafe_ops_per_block = "warn"
mutex_atomic = "deny"
needless_raw_strings = "deny"
non_ascii_literal = "deny"
partial_pub_fields = "deny"
print_stderr = "warn"
print_stdout = "warn"
pub_use = "allow"
rc_buffer = "deny"
rc_mutex = "deny"
rest_pat_in_fully_bound_structs = "deny"
same_name_method = "deny"
semicolon_inside_block = "deny"
shadow_reuse = "deny"
shadow_same = "deny"
shadow_unrelated = "deny"
str_to_string = "deny"
string_add = "deny"
string_slice = "deny"
string_to_string = "deny"
suspicious_xor_used_as_pow = "deny"
tests_outside_test_module = "deny"
todo = "deny"
try_err = "deny"
undocumented_unsafe_blocks = "warn"
unimplemented = "deny"
unnecessary_safety_comment = "deny"
unnecessary_safety_doc = "deny"
unreachable = "deny"
unseparated_literal_suffix = "deny"
unwrap_in_result = "deny"
use_debug = "deny"
verbose_file_reads = "deny"
wildcard_enum_match_arm = "deny"
# Performance lints for HFT systems
missing_const_for_fn = "warn"
trivially_copy_pass_by_ref = "warn"
large_types_passed_by_value = "warn"
redundant_clone = "warn"
unnecessary_wraps = "warn"
single_char_lifetime_names = "warn"
doc_markdown = "warn"
manual_let_else = "warn"
# Readability and maintainability lints
cognitive_complexity = "warn"
too_many_arguments = "warn"
too_many_lines = "warn"
type_complexity = "warn"
large_enum_variant = "warn"
enum_variant_names = "warn"
module_name_repetitions = "warn"
similar_names = "warn"
single_match_else = "warn"
unnecessary_cast = "warn"
used_underscore_binding = "warn"
wildcard_imports = "warn"
[workspace.lints.rust]
unsafe_code = "warn"
missing_docs = "allow"
unreachable_pub = "warn"
unused_crate_dependencies = "warn"
unused_extern_crates = "warn"
unused_import_braces = "warn"
unused_lifetimes = "warn"
unused_qualifications = "warn"
variant_size_differences = "warn"