OPEN→CLOSED
Agent operations · External side effects
ORINX
The order closed. The position did not.
One close appeared complete in the local ledger while the exchange still held the position. I designed ORINX to preserve both records, retry once under a fixed limit, check both sides again, and hand the unresolved position to a person.
Created and operated by Titus Lai.

One close · Two records
The same position had two incompatible endings.
The local close commits, but no matching exchange receipt arrives.

CLOSE / pos_017OPEN→OPEN
exit_not_committed- Lifecycle
- pos_017
- pos_017
- Last confirmed state
- close committed
- position open · no close receipt
- Retry budget
- 0 / 1 available
- not used
The incident that changed the architecture
What happened, what it risked, and what I changed.
- 01Before
OPEN / OPENBoth records described the same open position.
The local lifecycle and the exchange observation shared one position identity.
- 02Failure
CLOSED / OPENOnly the local close completed.
The interface implied that exposure had ended, but the exchange still carried the position.
- 03Decision
PRESERVE BOTHI refused to manufacture agreement.
ORINX kept both timestamped records, classified exit_not_committed, and checked ownership plus kill-switch state.
- 04Permanent fix
RETRY × 1Retry once, read both sides again, then stop.
If the records still disagree, automation latches off and hands a typed evidence packet to a person.
Second engineering case
A watchdog can report healthy after it has gone blind.
Independent heartbeat
No outside observation means unhealthy, even when the local process responds.
One restart
The system may restart once; another failure goes to a person instead of looping.
Notification cooldown
Cooldown reduces duplicate messages. It never changes health or suppresses recovery.
Inspectable evidence, explicit boundary
The public case proves the decisions—not an exchange connection.
Two runnable examples, 50 tests, a bilingual incident account, three diagrams, and fail-closed boundary checks.
The original runtime, strategies, parameters, operating data, identifiers, deployment topology, and exchange connections.