aa0996f3c649196dfaf981cbf3e660470c814dbe
Expanding the scanner surface per user directive "all should be addressed". Four distinct root causes for CPU-side violations around GPU-owned data — each with its own scan command, fix hierarchy, and learned-patterns entry. - CPURO: CPU reads of GPU-resident data (sizes, reductions) that force implicit sync. Cache at construction, keep stats on device. - ROMEM: `*(ptr as *mut T)` writes where ptr came from a const / read-only source. CUDA mapped-memory flags matter; cuBLAS/cuDNN workspace casts are benign FFI. - LOCKHOT: Mutex/RwLock on per-step path. High-value hits already visible: Mutex<GpuDropout>, Mutex<Option<DropoutScheduler>> in network.rs (every forward pass), Arc<Mutex<NStepBuffer>> in dqn.rs. Never hold tokio::sync::RwLock across .await. - BORROW: shared-&T promoted to &mut T via unsafe ptr casts or UnsafeCell/RefCell. Real example shipped: gpu_replay_buffer.rs:690 changes CudaSlice<i32> → CudaSlice<u32> through raw-ptr cast. Scoreboard seeded with 10 findings. Top scores: - ROMEM-001 (25.0) - size_pinned mapped write, verify allocation flag - ROMEM-004 (25.0) - cuBLAS workspace casts, likely false-positive bulk - ROMEM-002 (15.0) - init-time pinned mapped writes - LOCKHOT-001/002/003 (8.3) - dropout + nstep_buffer locks on hot path - BORROW-001 (8.3) - CudaSlice element-type aliasing CPURO is seeded with a scan-task (CPURO-000) to populate per-site findings in iter 9 — too many Vec::len() false positives to list upfront.
Foxhunt
Production HFT trading system in Rust.
Architecture
The workspace contains 32 crates organized as follows:
Core Libraries (16)
| Crate | Purpose |
|---|---|
trading_engine |
Order processing, FIX 4.4, IB TWS, SIMD, RDTSC timing |
risk |
VaR, Kelly, circuit breakers, kill switches, compliance |
risk-data |
Risk data types and shared structures |
trading-data |
Trading data types |
ml |
DQN Rainbow, PPO, TFT, Mamba2, ensemble inference |
ml-data |
ML data types and feature definitions |
data |
Market data ingestion and storage |
backtesting |
Replay engine, strategy tester |
adaptive-strategy |
Ensemble execution, microstructure analysis |
common |
Shared types, resilience, error handling |
storage |
S3 and local model storage |
model_loader |
Model serialization and loading |
market-data |
Market data feed handlers |
database |
PostgreSQL access layer (SQLx) |
config |
Configuration management |
tli |
CLI commands and tooling |
Services (8)
| Service | Purpose |
|---|---|
backtesting_service |
gRPC backtesting service |
broker_gateway_service |
FIX routing, broker connectivity |
trading_service |
Core trading operations |
ml_training_service |
Model training orchestration |
data_acquisition_service |
Market data acquisition |
trading_agent_service |
Autonomous trading agents |
api_gateway |
gRPC API gateway with auth |
web-gateway |
Axum REST + WebSocket gateway |
Frontend
web-dashboard/ -- React 19 + TypeScript + Vite + TradingView charts.
Building
# Check compilation (no PostgreSQL required)
SQLX_OFFLINE=true cargo check --workspace
# Run tests for a specific crate
SQLX_OFFLINE=true cargo test -p <crate> --lib
# Clippy
SQLX_OFFLINE=true cargo clippy --workspace
ML Models
Four production model architectures on Candle v0.9.1 with CUDA:
- DQN Rainbow -- Deep Q-Network with prioritized replay, dueling heads, noisy nets
- PPO -- Proximal Policy Optimization with GAE and LSTM policies
- TFT -- Temporal Fusion Transformer for multi-horizon forecasting
- Mamba2 -- State space model for sequence prediction
Each model has a standalone trainer and a UnifiedTrainable adapter for the hyperopt pipeline.
Infrastructure
- Git: Gitea at
git.fxhnt.ai(Tailscale-only), Scaleway DEV1-S - Observability: OpenTelemetry OTLP (env
OTEL_EXPORTER_OTLP_ENDPOINT) - Database: PostgreSQL with SQLx offline mode for CI
License
Proprietary. All rights reserved.
Description
Languages
Rust
88.2%
Cuda
7.7%
Python
1.3%
Shell
1.1%
PLpgSQL
0.8%
Other
0.8%