Files
foxhunt/Cargo.toml
jgrusewski 8bb7ffd897 diag(fxt-data-audit): predecoded MBP-10 sidecar audit binary
One-shot diagnostic that loads a .dbn.zst via
load_or_predecode_mbp10 and reports symbol distribution, per-symbol
price stats (min/p1/p50/p99/max for bid_px[0]/ask_px[0]), outlier
counts (zero-price, huge-price >$100k, zero-price-with-size),
and first-record samples per symbol.

Built to investigate the 18% sentinel-laden trade residue in the
ISV stop-controller cluster smokes (97 zero, 85 i32::MAX, 14 weird-
other). The controller path is structurally correct; remaining bad
records hypothesized to originate from source MBP-10 data (mixed
symbols, corrupt records, or unreported instrument families).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 11:19:29 +02:00

827 lines
30 KiB
TOML

[package]
name = "foxhunt"
version.workspace = true
edition.workspace = true
rust-version.workspace = true
authors.workspace = true
license.workspace = true
repository.workspace = true
homepage.workspace = true
documentation.workspace = true
publish.workspace = true
keywords.workspace = true
categories.workspace = true
description = "Foxhunt HFT Trading System - High-frequency trading with ML and comprehensive monitoring"
[dependencies]
# Core dependencies for the root package
tokio.workspace = true
serde = { workspace = true, features = ["derive"] }
serde_json.workspace = true
tracing.workspace = true
tracing-subscriber.workspace = true
# Database dependencies for binaries
redis.workspace = true
sqlx.workspace = true
# gRPC dependencies for service binaries
tonic.workspace = true
tokio-stream.workspace = true
prost.workspace = true
chrono.workspace = true
thiserror.workspace = true
prometheus.workspace = true
lazy_static.workspace = true
axum.workspace = true
rand.workspace = true
# Core trading infrastructure
trading_engine.workspace = true
# Risk management
risk.workspace = true
# Core backtesting and data modules (ML dependencies REMOVED to eliminate cascade)
backtesting.workspace = true
data.workspace = true
# Benchmarking
criterion = { workspace = true }
fastrand = { workspace = true }
async-trait = { workspace = true }
futures = { workspace = true }
uuid = { workspace = true }
bincode = { workspace = true }
flate2 = { workspace = true }
http = { workspace = true }
# ALL ML dependencies removed from root - GPU/ML tests moved to ML training service
anyhow.workspace = true
# Performance benchmarks removed - benchmarks moved to individual crates
# Comprehensive benchmark suite for performance regression detection
# Performance regression testing suite (primary)
[[bench]]
name = "performance_regression"
harness = false
path = "benches/performance_regression.rs"
[[bench]]
name = "trading_latency"
harness = false
path = "benches/comprehensive/trading_latency.rs"
[[bench]]
name = "database_performance"
harness = false
path = "benches/comprehensive/database_performance.rs"
[[bench]]
name = "streaming_throughput"
harness = false
path = "benches/comprehensive/streaming_throughput.rs"
[[bench]]
name = "metrics_overhead"
harness = false
path = "benches/comprehensive/metrics_overhead.rs"
[[bench]]
name = "end_to_end"
harness = false
path = "benches/comprehensive/end_to_end.rs"
[[bench]]
name = "full_trading_cycle"
harness = false
path = "benches/comprehensive/full_trading_cycle.rs"
[workspace]
resolver = "2"
members = [
# Library crates
"crates/trading_engine",
"crates/risk",
"crates/risk-data",
"crates/trading-data",
"crates/ml",
"crates/ml-core",
"crates/ml-ensemble",
"crates/ml-dqn",
"crates/ml-ppo",
"crates/ml-supervised",
"crates/ml-alpha",
"crates/ml-data",
"crates/ml-hyperopt",
"crates/ml-features",
"crates/ml-labeling",
"crates/ml-regime",
"crates/ml-regime-detection",
"crates/ml-checkpoint",
"crates/ml-data-validation",
"crates/ml-validation",
"crates/ml-risk",
"crates/ml-security",
"crates/ml-backtesting",
"crates/ml-asset-selection",
"crates/ml-universe",
"crates/ml-observability",
"crates/ml-stress-testing",
"crates/ml-explainability",
"crates/ml-paper-trading",
"crates/data",
"crates/backtesting",
"crates/common",
"crates/storage",
"crates/model_loader",
"crates/market-data",
"crates/database",
"crates/config",
"crates/ctrader-openapi",
# Training sidecar
"crates/training_uploader",
# CLI binary
"bin/fxt",
"bin/fxt-backtest",
"bin/fxt-data-audit",
# Services
"services/backtesting_service",
"services/broker_gateway_service",
"services/trading_service",
"services/ml_training_service",
"services/data_acquisition_service",
"services/trading_agent_service",
"services/api",
# Testing
"testing/integration",
"testing/e2e",
"testing/load",
"testing/service-load",
"testing/stress",
"testing/service-integration",
"testing/api-load",
]
exclude = [
"testing/vault-integration",
]
[workspace.package]
version = "1.0.0"
edition = "2021"
rust-version = "1.85"
authors = ["Foxhunt HFT Trading System"]
license = "MIT OR Apache-2.0"
repository = "https://github.com/user/foxhunt"
homepage = "https://github.com/user/foxhunt"
documentation = "https://docs.rs/foxhunt"
publish = false
keywords = ["trading", "hft", "ml", "rust", "finance"]
categories = ["finance", "algorithms", "science"]
# Known unfixable duplicates (cargo tree -d), as of 2026-04-30:
#
# Transitive in third-party crates we cannot bump without API breakage or forks:
# - base64 v0.21 (hdrhistogram 7.5 — no newer version released)
# - chacha20 v0.9 (chacha20poly1305 0.10; v0.11 still RC)
# - phf v0.11 (time-tz, transitively via ibapi 1.2 — bumping to ibapi 2.x is a major break)
# - phf v0.12 (chrono-tz 0.10 — both versions held by orthogonal crates)
# - darling v0.14 (vaultrs 0.7 → derive_builder 0.12; vaultrs 0.8 introduces reqwest 0.13 dup, net loss)
# - darling v0.23 (ratatui 0.29 → instability 0.3)
# - itertools v0.10 (criterion 0.5 dev-dep; bumping criterion across 10 bench dirs is high-risk)
# - itertools v0.13 (object_store 0.11; object_store 0.13 has put/get/head/delete API breakage)
# - itertools v0.14 (prost-build 0.14 — already latest)
# - getrandom v0.2/0.3/0.4 (3-way: rand_core 0.6, ahash 0.8, rand 0.10; orthogonal leaves)
# - hashbrown v0.14 (dashmap 6.1 transitive — hashbrown 0.16 in workspace + indexmap)
# - syn v1 / v2 (residual proc-macros pinned to syn 1)
# - thiserror v1 / v2 (some deps still on v1)
#
# Other cargo-tree-d entries are version-suffixes attached to feature splits
# rather than separate compiles (entries with " (*)" markers).
#
# Things we DID dedupe in this pass (2026-04-30):
# - axum 0.7 → 0.8 (workspace + services/api) — dedupes vs tonic 0.14's transitive axum 0.8
# - statrs 0.17 → 0.18 — dedupes nalgebra 0.32 vs 0.33
# - governor 0.6 → 0.10 (services/api + crates/data) — dedupes dashmap 5 vs 6
# - dashmap = workspace (services/api) — same as above
# - hashbrown 0.14 → 0.16 (workspace) — partial dedupe (dashmap 6.1 still pulls 0.14)
[workspace.dependencies]
# Core async and utilities - OPTIMIZED VERSIONS
tokio = { version = "1.40", features = ["rt-multi-thread", "macros", "net", "sync", "time", "fs", "signal", "io-util", "test-util"] }
tokio-util = { version = "0.7", features = ["codec", "io", "rt"] }
tokio-stream = { version = "0.1", features = ["sync"] }
tokio-test = "0.4"
tokio-retry = "0.3"
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
serde_yaml = "0.9"
toml = "0.8"
uuid = { version = "1.10", features = ["v4", "serde", "fast-rng"] }
thiserror = "1.0"
anyhow = "1.0"
futures = { version = "0.3", features = ["std", "alloc", "async-await"] }
futures-util = "0.3"
futures-test = "0.3"
async-trait = "0.1"
once_cell = "1.20"
# Time handling
chrono = { version = "0.4.38", features = ["serde"] }
# Financial and numerical types
rust_decimal = { version = "1.0", features = ["serde", "macros", "maths"] }
rust_decimal_macros = "1.36"
bigdecimal = { version = "0.4", features = ["serde"] }
num-bigint = "0.4"
num-traits = "0.2"
num = "0.4"
# Random number generation
rand = { version = "0.8.5", features = ["small_rng"] }
fastrand = "2.0"
rand_chacha = "0.3.1"
rand_distr = "0.4"
# Logging and tracing
log = "0.4"
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["fmt", "env-filter", "json"] }
tracing-appender = "0.2"
# Serialization
bincode = "1.3"
semver = { version = "1.0", features = ["serde"] }
# High-performance data structures
rustc-hash = "1.1"
ahash = "0.8"
indexmap = { version = "2.0", features = ["serde"] }
crossbeam = "0.8"
crossbeam-queue = "0.3"
crossbeam-channel = "0.5"
crossbeam-utils = "0.8"
parking_lot = { version = "0.12", features = ["deadlock_detection"] }
arrayvec = { version = "0.7", features = ["serde"] }
lazy_static = "1.4"
memmap2 = "0.9"
libc = "0.2"
num_cpus = "1.16"
dashmap = { version = "6.1", features = ["serde"] }
bytes = "1.5"
smallvec = { version = "1.11", features = ["serde", "const_generics"] }
prometheus = "0.14"
questdb-rs = { version = "4", default-features = false }
# MINIMAL numerical libraries only - ALL ML/GPU frameworks REMOVED from workspace
nalgebra = { version = "0.33", features = ["serde", "rand"] }
ndarray = { version = "0.15", features = ["serde"] }
# ALL HEAVY ML/GPU DEPENDENCIES COMPLETELY REMOVED FROM WORKSPACE:
# candle-core, candle-nn, candle-transformers, candle-optimisers - MOVED TO ml_training_service
# ort, wgpu, cudarc - MOVED TO ml_training_service
# tch, torch-sys (PyTorch) - MOVED TO ml_training_service
# linfa, linfa-clustering, linfa-linear - MOVED TO ml_training_service
# smartcore, gymnasium, rerun - MOVED TO ml_training_service
# Network and HTTP
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "gzip"] } # trading_engine needs gzip, data needs json
http = "1.0"
# Security and cryptography
argon2 = "0.5"
sha2 = "0.10"
jsonwebtoken = "9.3"
# Secure secret handling
secrecy = { version = "0.8", features = ["serde"] }
zeroize = { version = "1.8", features = ["std", "zeroize_derive"] }
# HashiCorp Vault integration
vaultrs = "0.7" # 0.8 introduces reqwest 0.13 dup (vs workspace 0.12) — net loss
# Broker connectivity
tokio-tungstenite = { version = "0.24" }
xml-rs = "0.8"
time = { version = "0.3", features = ["serde"] }
ibapi = "1.2"
native-tls = "0.2"
tokio-native-tls = "0.3"
# databento = "0.34.0" # REMOVED - too heavy, use direct data feeds instead
# Configuration and file handling
csv = "1.3"
base64 = "0.22"
regex = "1.0"
url = "2.4"
hex = "0.4"
md5 = "0.7"
# Database
redis = { version = "0.27", features = ["tokio-comp", "json", "connection-manager"] }
sqlx = { version = "0.8.6", default-features = false, features = ["runtime-tokio-rustls", "postgres", "chrono", "uuid", "rust_decimal", "migrate", "derive"] } # derive feature required for compile-time query verification, postgres-only usage with rustls (no MySQL)
# MINIMAL statistics only - ALL HEAVY ML DEPENDENCIES REMOVED FROM WORKSPACE
statrs = "0.18" # Basic statistics only — 0.18 uses nalgebra 0.33 (dedupes vs ml-* crates)
approx = "0.5" # Floating point approximations only
# ALL ML DEPENDENCIES COMPLETELY REMOVED FROM WORKSPACE:
# linfa, linfa-linear, linfa-clustering - MOVED TO ml_training_service
# smartcore - MOVED TO ml_training_service
# candle-core, candle-nn, candle-optimisers, candle-transformers - MOVED TO ml_training_service
# cudarc, tch, torch-sys - MOVED TO ml_training_service
# polars - REMOVED (not used in codebase, replaced with minimal CSV parsing)
# orderbook = "0.1" # REMOVED - unmaintained crate with failure dependency (RUSTSEC-2020-0036)
# Performance and utilities
rayon = "1.0"
wide = { version = "0.7", features = ["serde"] }
bytemuck = { version = "1.14", features = ["derive"] }
autocfg = "1.1"
core_affinity = "0.8"
nix = "0.27"
bumpalo = { version = "3.14", features = ["collections"] }
fs2 = "0.4"
flate2 = "1.0"
# Web framework for monitoring (minimal)
axum = { version = "0.8", features = ["json"] } # 0.8 dedupes with tonic 0.14's transitive axum 0.8
# gRPC and protocol buffers - CONSOLIDATED VERSIONS
# Upgraded to 0.14 for Sync BoxBody support (enables HTTP-layer auth middleware)
# NOTE: 0.14 replaced 'tls' with 'tls-ring'/'tls-aws-lc' + 'tls-native-roots'/'tls-webpki-roots'
# NOTE: 0.14 moved prost build functionality to 'tonic-prost-build' crate
# NOTE: 0.14 requires 'tonic-prost' for generated code runtime
# NOTE: tonic-prost 0.14 requires prost 0.14 (upgraded from 0.13)
tonic = { version = "0.14", features = ["server", "transport", "tls-ring", "tls-webpki-roots"] }
tonic-prost = "0.14"
tonic-prost-build = "0.14"
tonic-reflection = "0.14"
tonic-health = "0.14"
prost = "0.14"
prost-build = "0.14"
prost-types = "0.14"
hyper = { version = "1.0", features = ["server"] } # MINIMAL features only
http-body = "1.0" # Required for generic body types in Tonic 0.14
http-body-util = "0.1" # Required for hyper 1.0 body utilities
hyper-util = { version = "0.1", features = ["tokio", "server"] } # Utilities for hyper 1.0
tower = { version = "0.4", features = ["timeout", "limit", "util"] }
tower-http = { version = "0.5", features = ["trace", "cors"] }
tower-layer = "0.3"
tower-service = "0.3"
# Testing dependencies - MINIMAL ONLY (heavy testing libs removed)
proptest = "1.5" # Restored - needed by many crates
quickcheck = "1.0" # Restored - needed by trading_engine and tests
rstest = "0.22" # Restored - needed by trading_engine
test-case = "3.3" # Restored - needed by config crate
tempfile = "3.12"
serial_test = "3.1"
# REMOVED HEAVY TEST DEPS: wiremock, insta, testcontainers, fake, httpmock, tracing-test, mockall (0 usages in codebase)
# Performance testing - CONSOLIDATED
criterion = { version = "0.5", features = ["html_reports", "async_tokio"] }
hdrhistogram = "7.5"
# Database clients for integration testing
influxdb2 = { version = "0.5", default-features = false, features = ["native-tls"] }
# OpenTelemetry for production monitoring and extensive logging
# NOTE: otel-otlp 0.31 uses tonic 0.14 (matching workspace), fixing the tonic version mismatch
# that prevented with_channel() for explicit plaintext gRPC channels.
tracing-opentelemetry = "0.32"
opentelemetry = { version = "0.31", features = ["trace", "metrics", "logs"] }
opentelemetry-otlp = { version = "0.31", default-features = false, features = ["grpc-tonic", "metrics", "trace", "logs"] }
opentelemetry_sdk = { version = "0.31", features = ["rt-tokio", "metrics", "trace", "logs"] }
# Additional commonly used dependencies - CONSOLIDATED
# Build dependencies already defined above with tonic dependencies
# Async utilities
async-stream = "0.3"
# Data processing and compression
zstd = "0.13"
lz4 = "1.24"
# Object storage for S3 integration
object_store = { version = "0.11", features = ["aws"] } # 0.13 has API breakage (put/get/head/delete moved); skipping
# Parquet/Arrow REQUIRED for market data persistence and replay in backtesting
parquet = { version = "56", default-features = false, features = ["arrow", "snap"] } # Minimal for RecordBatch + SNAPPY compression
arrow = { version = "56", default-features = false, features = [] } # Minimal for arrays/schema only
arrow-array = "56"
arrow-schema = "56"
dbn = "0.42" # Databento Binary format for real market data
hashbrown = "0.16" # 0.16 dedupes with indexmap 2.x's transitive hashbrown
lru = "0.12"
backoff = "0.4"
# Development and configuration - OPTIMIZED
dotenvy = "0.15"
clap = { version = "4.5", features = ["derive", "env"] }
env_logger = "0.11"
color-eyre = "0.6"
# Network and protocols - OPTIMIZED
# Specialized dependencies
metrics = "0.23"
metrics-exporter-prometheus = "0.15"
# Additional test dependencies
arc-swap = "1.6"
# Local workspace crates (for inter-crate dependencies)
trading_engine = { path = "crates/trading_engine" }
data = { path = "crates/data" }
fxt = { path = "bin/fxt" }
risk = { path = "crates/risk" }
risk-data = { path = "crates/risk-data" }
backtesting = { path = "crates/backtesting" }
ml = { path = "crates/ml" }
ml-core = { path = "crates/ml-core" }
ml-ensemble = { path = "crates/ml-ensemble" }
ml-dqn = { path = "crates/ml-dqn" }
ml-ppo = { path = "crates/ml-ppo" }
ml-supervised = { path = "crates/ml-supervised" }
ml-hyperopt = { path = "crates/ml-hyperopt" }
ml-features = { path = "crates/ml-features" }
ml-alpha = { path = "crates/ml-alpha" }
ml-labeling = { path = "crates/ml-labeling" }
ml-regime = { path = "crates/ml-regime" }
ml-regime-detection = { path = "crates/ml-regime-detection" }
ml-checkpoint = { path = "crates/ml-checkpoint" }
ml-data-validation = { path = "crates/ml-data-validation" }
ml-validation = { path = "crates/ml-validation" }
ml-risk = { path = "crates/ml-risk" }
ml-security = { path = "crates/ml-security" }
ml-backtesting = { path = "crates/ml-backtesting" }
ml-asset-selection = { path = "crates/ml-asset-selection" }
ml-universe = { path = "crates/ml-universe" }
ml-observability = { path = "crates/ml-observability" }
ml-stress-testing = { path = "crates/ml-stress-testing" }
ml-explainability = { path = "crates/ml-explainability" }
ml-paper-trading = { path = "crates/ml-paper-trading" }
common = { path = "crates/common" }
storage = { path = "crates/storage" }
market-data = { path = "crates/market-data" }
config = { path = "crates/config" }
database = { path = "crates/database" }
ctrader-openapi = { path = "crates/ctrader-openapi" }
[features]
default = []
cpu-only = []
integration-tests = []
[profile.release]
opt-level = 3
debug = false
debug-assertions = false
overflow-checks = false
lto = "fat"
panic = 'abort'
codegen-units = 1
strip = true
# Fast release builds for CI iteration — skip fat LTO, parallelize codegen.
# Usage: cargo build --profile dev-release -p <crate>
# ~3-5x faster compile than full release, ~10-15% slower runtime.
[profile.dev-release]
inherits = "release"
opt-level = 2
lto = "thin"
codegen-units = 16
strip = true
# HFT production profile — identical to release but preserves frame pointers
# for perf profiling. Used by deploy scripts.
[profile.hft]
inherits = "release"
opt-level = 3
lto = "fat"
codegen-units = 1
strip = false
# Fast release for local GPU testing — parallel codegen, thin LTO.
# Usage: cargo test --profile release-test -p ml --lib -- test_name --ignored
# ~4x faster compile than full release, ~5% slower runtime. Good enough for GPU tests.
[profile.release-test]
inherits = "release"
opt-level = 3
lto = "thin"
codegen-units = 16
strip = true
panic = 'unwind' # Tests need unwinding for panic capture
[profile.bench]
inherits = "release"
debug = false
[profile.test]
opt-level = 0 # Disable optimizations for faster test compilation
debug = 0 # Remove debug info completely for faster linking
debug-assertions = false # Disabled for faster test compilation
overflow-checks = false # Disabled for faster test compilation
lto = false
incremental = true
codegen-units = 256 # Maximum parallelism for test builds
split-debuginfo = "unpacked" # Faster linking on Linux
[profile.dev]
split-debuginfo = "unpacked" # Faster linking for dev builds
# ── Per-package codegen-units overrides ───────────────────────────────────────
# Default for all release builds: codegen-units = 16 → parallel LLVM, faster
# compile. Numerical-sensitive crates (anything whose fp output the DQN
# regression suite depends on bit-for-bit) override back to 1 to preserve the
# exact optimization decisions LLVM makes today.
#
# DO NOT remove an override without running the numerical regression suite.
[profile.release.package."*"]
codegen-units = 16
# Workspace numerical crates — must keep CGU=1 for bit-exact reproducibility
[profile.release.package.ml]
codegen-units = 1
[profile.release.package.ml-core]
codegen-units = 1
[profile.release.package.ml-dqn]
codegen-units = 1
[profile.release.package.ml-ppo]
codegen-units = 1
[profile.release.package.ml-supervised]
codegen-units = 1
[profile.release.package.ml-ensemble]
codegen-units = 1
[profile.release.package.ml-features]
codegen-units = 1
[profile.release.package.ml-labeling]
codegen-units = 1
[profile.release.package.ml-explainability]
codegen-units = 1
[profile.release.package.ml-hyperopt]
codegen-units = 1
[profile.release.package.ml-checkpoint]
codegen-units = 1
[profile.release.package.ml-data]
codegen-units = 1
[profile.release.package.ml-data-validation]
codegen-units = 1
[profile.release.package.ml-validation]
codegen-units = 1
[profile.release.package.ml-asset-selection]
codegen-units = 1
[profile.release.package.ml-backtesting]
codegen-units = 1
[profile.release.package.ml-regime]
codegen-units = 1
[profile.release.package.ml-regime-detection]
codegen-units = 1
[profile.release.package.ml-risk]
codegen-units = 1
[profile.release.package.ml-stress-testing]
codegen-units = 1
[profile.release.package.ml-universe]
codegen-units = 1
[profile.release.package.ml-paper-trading]
codegen-units = 1
[profile.release.package.ml-observability]
codegen-units = 1
[profile.release.package.ml-security]
codegen-units = 1
[profile.release.package.model_loader]
codegen-units = 1
[profile.release.package.training_uploader]
codegen-units = 1
[profile.release.package.risk]
codegen-units = 1
[profile.release.package.trading_engine]
codegen-units = 1
# External numerical/statistical crates
[profile.release.package.ndarray]
codegen-units = 1
[profile.release.package.nalgebra]
codegen-units = 1
[profile.release.package.simba]
codegen-units = 1
[profile.release.package.num-traits]
codegen-units = 1
[profile.release.package.num-complex]
codegen-units = 1
[profile.release.package.libm]
codegen-units = 1
[profile.release.package.statrs]
codegen-units = 1
[profile.release.package.rand_distr]
codegen-units = 1
[profile.release.package.rust_decimal]
codegen-units = 1
[profile.release.package.ordered-float]
codegen-units = 1
[profile.release.package.cudarc]
codegen-units = 1
[dev-dependencies]
anyhow.workspace = true
chrono.workspace = true
common.workspace = true
config.workspace = true
futures.workspace = true
proptest = "1.4"
rust_decimal.workspace = true
rust_decimal_macros.workspace = true
rand_distr.workspace = true
serde_json.workspace = true
sqlx.workspace = true
tempfile = "3.13"
fxt.workspace = true # Required by tests/fixtures/mod.rs
tokio.workspace = true
trading_engine.workspace = true
uuid.workspace = true
# Comprehensive clippy configuration for production-ready HFT system
[workspace.lints.clippy]
# Module structure - allow mod.rs files for complex modules with subdirectories
mod_module_files = "allow"
self_named_module_files = "allow"
# Critical safety lints - KEEP AS DENY (safety-critical for HFT)
panic = "deny"
unimplemented = "deny"
todo = "deny"
out_of_bounds_indexing = "deny"
unchecked_duration_subtraction = "deny"
unreachable = "deny"
exit = "deny"
mem_forget = "deny"
infinite_loop = "deny"
get_unwrap = "deny"
unwrap_in_result = "deny"
use_debug = "deny"
# Safety lints - WARN (fix incrementally, not blocking for HFT compatibility)
unwrap_used = "warn"
expect_used = "warn"
indexing_slicing = "warn"
# TIER 3: HFT Requirements - Permanently ALLOW
# These operations are fundamental to trading systems and are NOT safety issues.
# Industry standard: QuantLib, ta-rs, polars, ndarray all allow these operations.
float_arithmetic = "allow" # Required for price * quantity, PnL calculations
default_numeric_fallback = "allow" # Rust idiom, safe type inference (e.g., let x = 0.25;)
as_conversions = "allow" # Performance-critical conversions (f64 ↔ i64)
cast_possible_truncation = "allow" # Controlled by domain constraints (prices, quantities)
cast_precision_loss = "allow" # Acceptable for price normalization
cast_sign_loss = "allow" # Quantity conversions (always positive)
cast_lossless = "allow" # Let Rust infer safe casts
arithmetic_side_effects = "allow" # Core business logic for trading calculations
# High-priority restriction lints for HFT safety
assertions_on_result_states = "deny"
clone_on_ref_ptr = "allow" # Arc::clone() is intentional for shared state
create_dir = "deny"
dbg_macro = "deny"
decimal_literal_representation = "deny"
deref_by_slicing = "deny"
disallowed_script_idents = "deny"
else_if_without_else = "deny"
empty_drop = "deny"
empty_structs_with_brackets = "deny"
error_impl_error = "deny"
filetype_is_file = "deny"
float_cmp_const = "deny"
fn_to_numeric_cast_any = "deny"
format_push_string = "deny"
host_endian_bytes = "deny"
if_then_some_else_none = "deny"
impl_trait_in_params = "deny"
inline_asm_x86_att_syntax = "deny"
inline_asm_x86_intel_syntax = "deny"
integer_division = "warn"
large_include_file = "deny"
let_underscore_must_use = "deny"
lossy_float_literal = "deny"
map_err_ignore = "warn"
missing_enforced_import_renames = "deny"
mixed_read_write_in_expression = "deny"
modulo_arithmetic = "deny"
multiple_inherent_impl = "deny"
multiple_unsafe_ops_per_block = "warn"
mutex_atomic = "deny"
needless_raw_strings = "deny"
non_ascii_literal = "deny"
partial_pub_fields = "deny"
# Observability - TIER 3: Required for CLI, debugging, and error reporting
print_stderr = "allow" # Error reporting before logger initialization
print_stdout = "allow" # CLI output, debugging, benchmarks (criterion)
pub_use = "allow"
rc_buffer = "deny"
rc_mutex = "deny"
rest_pat_in_fully_bound_structs = "deny"
same_name_method = "deny"
semicolon_inside_block = "deny"
shadow_reuse = "deny"
shadow_same = "deny"
shadow_unrelated = "deny"
str_to_string = "deny"
string_add = "deny"
string_slice = "deny"
string_to_string = "deny"
suspicious_xor_used_as_pow = "deny"
tests_outside_test_module = "deny"
try_err = "deny"
undocumented_unsafe_blocks = "warn"
unnecessary_safety_comment = "deny"
unnecessary_safety_doc = "deny"
unseparated_literal_suffix = "deny"
verbose_file_reads = "deny"
wildcard_enum_match_arm = "deny"
# Performance lints for HFT systems
missing_const_for_fn = "warn"
trivially_copy_pass_by_ref = "warn"
large_types_passed_by_value = "warn"
redundant_clone = "warn"
unnecessary_wraps = "warn"
single_char_lifetime_names = "warn"
doc_markdown = "warn"
manual_let_else = "warn"
# Readability and maintainability lints
cognitive_complexity = "warn"
too_many_arguments = "warn"
too_many_lines = "warn"
type_complexity = "warn"
large_enum_variant = "warn"
enum_variant_names = "warn"
module_name_repetitions = "warn"
similar_names = "warn"
single_match_else = "warn"
unnecessary_cast = "warn"
used_underscore_binding = "warn"
wildcard_imports = "warn"
# Pedantic lints that are noise in HFT/ML code — permanently allow
# These are intentional domain patterns, not safety issues
needless_pass_by_value = "allow" # Trait signatures require owned values
return_self_not_must_use = "allow" # Builder patterns don't need must_use
redundant_closure_for_method_calls = "allow" # Explicit closures preferred for clarity
map_unwrap_or = "allow" # map().unwrap_or() is idiomatic in many contexts
unreadable_literal = "allow" # Large numeric literals in financial code
cloned_instead_of_copied = "allow" # Explicit .cloned() for clarity
unnecessary_literal_bound = "allow" # Literal bounds for API clarity
ignored_unit_patterns = "allow" # Unit patterns in match arms
explicit_iter_loop = "allow" # Explicit .iter() preferred for clarity
unnecessary_debug_formatting = "allow" # Debug formatting in error messages
missing_panics_doc = "allow" # Panics documented at usage site
struct_excessive_bools = "allow" # Boolean flags efficient for HFT state
struct_field_names = "allow" # Domain-specific field naming
redundant_else = "allow" # Explicit else for clarity
assigning_clones = "allow" # Clone assignment patterns
unnested_or_patterns = "allow" # Explicit or-patterns for clarity
manual_string_new = "allow" # String::new() vs String::from("") is stylistic
comparison_chain = "allow" # Explicit comparisons preferred
range_plus_one = "allow" # Explicit range bounds
case_sensitive_file_extension_comparisons = "allow" # File extensions handled correctly
needless_for_each = "allow" # for_each preferred in some contexts
inefficient_to_string = "allow" # ToString implementations
bool_to_int_with_if = "allow" # Explicit bool-to-int conversion
match_wildcard_for_single_variants = "allow" # Explicit wildcard in single-variant matches
semicolon_if_nothing_returned = "allow" # Semicolons for consistency
default_trait_access = "allow" # Default::default() for clarity
needless_continue = "allow" # Explicit continue for control flow clarity
many_single_char_names = "allow" # Math variable names (x, y, z, w, etc.)
missing_errors_doc = "allow" # Internal APIs don't need full error documentation
missing_safety_doc = "allow" # Safety documented at usage site
inline_always = "allow" # Performance-critical inlining hints
unused_async = "allow" # Async needed for trait implementations
unused_self = "allow" # Self parameter needed for trait consistency
must_use_candidate = "allow" # Not all functions need must_use
should_implement_trait = "allow" # Custom method names over std traits
match_same_arms = "allow" # Explicit match arms for clarity
needless_borrows_for_generic_args = "allow" # Explicit borrows for API clarity
manual_clamp = "allow" # Explicit min/max chains for clarity
implicit_hasher = "allow" # HashMap/HashSet in public APIs
no_effect_underscore_binding = "allow" # Underscore bindings for side effects
mixed_attributes_style = "allow" # Mix of inner/outer attributes acceptable
cargo_common_metadata = "allow" # Not all crates need full metadata
multiple_crate_versions = "allow" # Dependency tree allows multiple versions
[workspace.lints.rust]
unsafe_code = "warn"
missing_docs = "allow"
unreachable_pub = "warn"
unused_crate_dependencies = "allow" # Allow in tests/examples where not all deps are used
unused_extern_crates = "allow" # Allow in tests/examples where not all deps are used
unused_import_braces = "warn"
unused_lifetimes = "warn"
unused_qualifications = "allow" # Allow std:: prefixes for clarity
variant_size_differences = "warn"
[patch.crates-io]
# Local cudarc fork: adds load_cubin() without nvrtc feature gate
cudarc = { path = "vendor/cudarc" }