> For the complete documentation index, see [llms.txt](https://nytshift.gitbook.io/nytshift-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/release-checklist.md).

# Release checklist

## Source package

* [ ] `AGENTS.md` and `START_HERE.md` are present at repository root.
* [ ] `.env.example` contains placeholders/defaults only.
* [ ] Authenticated releases provide private PostgreSQL `DATABASE_URL` and minimum-32-byte `CUSTOMER_ACCOUNT_DIGEST_KEY` secrets; `pnpm db:status`, `pnpm db:migrate` and `pnpm db:verify` accept the exact ordered migration history, Compose has not preloaded unregistered SQL, and `/api/health` reports `customerDatabaseState=ready` plus `customerAccountDigestState=configured` before verified account binding is promoted.
* [ ] No root or web-app `.openai/hosting.json` or Wrangler configuration exists; Cloudflare Workers/Pages and OpenAI Sites are not deployment targets.
* [ ] A public promotion, if separately approved, uses the exact reviewed commit/artifact on the operator-owned `nytshift.xyz` VPS behind the unchanged systemd, Nginx and TLS boundary; localhost checks alone do not authorize it.
* [ ] The artifact was built in a clean detached Linux x64 worktree with Node 24 and pnpm 11.7.0 using `pnpm release:public:build`; the command ran full `handoff:verify`, emitted the exact commit build ID, deterministic GNU-tar/gzip artifact, complete content manifest, SHA-256 sidecar and strict receipt outside the repository.
* [ ] `pnpm release:public:verify` passes before and after transfer, recomputes the complete extracted tree and exact archive hash, and reports the accepted commit. `RELEASE_SHA256` was written only from that verified receipt after extraction.
* [ ] `.env`, `node_modules`, `.next`, `dist`, local stores, caches and virtual environments are excluded.
* [ ] The ZIP opens cleanly and contains a single `hyperliquid-ai-terminal/` root.
* [ ] `docs/release-manifest.md` matches the delivered package.
* [ ] Public `/api/health` reports `releaseState=verified`, the exact accepted 40-character commit and the exact uploaded standalone-archive SHA-256; a partial, malformed or directory-mismatched marker pair returns 503 without exposing paths.
* [ ] Public `/api/health`, `/nightshift#release` and the terminal build-trust drawer agree on coarse release-filesystem capacity, 2 GiB operating reserve and 512 MiB deploy allowance; constrained headroom stays visible, a breached reserve returns 503, no path is exposed, and no retention apply runs implicitly.
* [ ] `/nightshift` visibly matches that exact release pair, reports read-only execution and the actual RHC/venue readiness classes separately, clears the proof during an invalid-health rehearsal, and remains contained at 390 pixels with no console/page errors.
* [ ] `/terminal` top-bar build trust, `B` shortcut and command-palette action open one focus-contained drawer that shows the same exact release pair and separate readiness facts; a failed, timed-out, oversized or malformed health read removes prior identity and visibly reports `DEPLOYMENT_PROOF_UNAVAILABLE`.
* [ ] `pnpm activation:audit --origin https://nytshift.xyz --require-public-ready` validates the exact release foundation, production Privy plus NS-430 rehearsal, licensed v32 chart tree plus NS-431 exact-release/tree rehearsal, and fresh redundant RHC HTTP/archive/WSS topology without cookies or redirects; anonymous evidence always leaves capital trading unproven.

## Safety

* [ ] `EXECUTION_MODE=disabled` and `ALLOW_MAINNET=false` remain the defaults.
* [ ] No private key, bearer token, seed phrase, auth cookie or provider credential is present.
* [ ] The customer database contains only opaque customer/account digests, strict preferences, PAPER snapshots and normalized trading projections. It contains no raw Privy DID/email/token, wallet signature, private key, mnemonic, signer path or signer authority; signer SQLite recovery remains separate.
* [ ] Authenticated PAPER create/save/reload/reset proves optimistic revision conflicts, archived reset history, normalized orders/fills, append-only position/PnL/risk projections and bounded divergent-local recovery. Guest PAPER remains explicitly browser-local.
* [ ] Same-origin account binding requires matching Privy access/identity tokens and an exact provider wallet; one venue/network account cannot be claimed by two customers, and neither success/failure bodies nor PostgreSQL contain the raw address.
* [ ] One strict Hyperliquid testnet lifecycle persists exact order/fill/notional/fee/builder-fee/closed-PnL rows, and its matching configured-account generation persists coverage-labeled equity/margin/exposure, position/mark/liquidation/leverage/margin/funding and funding-event rows. Exact replay creates no duplicate or revision, conflicting/regressing evidence fails closed, bounded evidence remains partial, and unavailable domains write nothing.
* [ ] `pnpm contracts:check` exactly reproduces the eight committed Draft 2020-12/OpenAPI 3.1.1 artifacts; every existing v1 definition and operation request/parameter/security/response boundary is immutable, all references resolve locally, the public-market, public-account, public-RHC-readiness and public-RHC-data servers are loopback-only and anonymous, the agent document has only proposal GET/POST bearer operations, and no credential value or public signer bind is present.
* [ ] Every market catalog/candle/book/trade/funding/liquidation/health body passes its strict runtime response schema before serialization, carries the exact public-market contract version, exposes only normalized fields, and fails closed without returning or logging producer data.
* [ ] Hyperliquid discovery and execution review use the shared strict metadata parser; primary/HIP-3 IDs retain the official sparse DEX index, size/price precision follows current venue rules, a malformed named DEX fails the whole catalog, and additive schema drift is aggregate-only and blocks execution review.
* [ ] AEGIS rejects reduce-only reviews for a flat account, wrong closing side or normalized quantity above the fresh open position; only a valid reduction bypasses entry-only breakers, every dynamic policy passes strict validation, and new BTC/ETH/SOL/HYPE exposure remains inside the reviewed 20% correlated cap as well as symbol/gross limits.
* [ ] Every Arcus/Lighter/Hyperliquid account body passes its strict runtime response schema before serialization, carries the exact public-account contract version, exposes only bounded normalized fields, and fails closed without returning producer data or logging the requested address/validation detail.
* [ ] Every Robinhood Chain connectivity/provider/incident/activity-health body passes its strict runtime response schema before serialization, carries the exact public-RHC contract version, excludes endpoint/path/wallet material, and cannot promote the public RPC to production readiness.
* [ ] Managed Robinhood Chain archive readiness requires fresh endpoint-bound HTTPS historical-state and WSS-head evidence; automatic refresh cannot bootstrap or attest rotated endpoints, concurrent refreshes serialize, failed probes preserve prior evidence, expiry remains visible, and the timer receives no wallet/signer/execution authority.
* [ ] Every Robinhood Chain price/portfolio/activity/radar body passes its strict runtime response schema before serialization, carries the exact public-RHC contract version, preserves canonical/oracle/coverage invariants, and fails closed without logging an address, symbol, payload, endpoint or validation detail.
* [ ] Mock mode is visibly and structurally distinct from live mode.
* [ ] Robinhood Chain adapter exposes no submit/sign method.
* [ ] Stock Token eligibility and transaction surfaces remain blocked.
* [ ] The one canonical contract registry carries its exact official source/review time; every contract-bearing venue asset derives from it; the live drift audit reports 27/27 with no missing, unexpected, mismatched or duplicate rows.
* [ ] The independent Chainlink Robinhood oracle registry reports 21/21 reviewed canonical feeds from the exact official address page; proxy, secondary proxy, heartbeat and decimals match; `BE`, `USAR`, `SGOV` and `CUSO` remain identity-only unless a new reviewed source change is accepted.
* [ ] Arcus order and deposit submission remain blocked without a registered user API wallet, funded USDG, production bridge-contract attestation, and explicit canary approval.
* [ ] The Arcus testnet funding planner revalidates the exact official Markdown parameters, chain 46630, deployed USDG/proxy code, token metadata and public wallet state; it creates only exact wallet-owned calldata and cannot sign, send, approve or claim venue credit.
* [ ] Arcus preflight accepts only same-origin bounded JSON, re-reads official live market/book/account/position/compliance state, rate-limits by opaque account key, uses exact decimal ticks/quantums, and can return no signer header, signature, canonical signed payload, confirmation token or submit capability.
* [ ] Arcus public order/fill REST rows normalize strictly and omit the inspected address; pooled `orders`/`userFills` subscriptions require the exact address, request snapshots and contain no signing fields.
* [ ] Duplicate/out-of-order account events cannot double-apply; an order sequence gap freezes the reducer, forces resubscription and remains degraded until a new order snapshot arrives. REST refresh alone cannot clear it.
* [ ] Missing Arcus `maxOrderSize`, limit-oracle threshold and cancel-on-disconnect remain explicit execution gates rather than guessed values or hidden readiness; live portfolio daily PnL/drawdown must be present and inside policy.
* [ ] Arcus cancel-all is available only with the server kill switch active, exact signer account scope and a non-empty bounded live open-order review; its ten-second token is one-use, the signer sends one exact scheme-2 request, and only reconciled zero open orders complete the stop.
* [ ] Every Arcus place review binds literal one-cancel reconciliation authority; the signer persists scope before place, unknown reconciliation claims at most one cancel-by-client-ID attempt, active incidents lock ordinary entry across restart, ACK/open/partial/failed cancel cannot clear the latch, and only `FILLED`/`CANCELED`/`REJECTED` resolve it.
* [ ] Arcus order failures and reconciliation transitions enter the signer-owned durable outbox without account/order identity; stable HMAC delivery survives restart, failure/overflow blocks ordinary execution, and emergency cancel-all remains independently available.
* [ ] The signer execution database carries the NIGHTSHIFT application ID and exact schema-v8 history; migrations preserve schema-v6 scopes/revenue/lifecycle/leverage/bracket rows, add bounded account/network-bound dead-man switch/action/CLOID tables, bind rehearsal proof to the exact account while clearing unbound legacy timestamps, label legacy protective scopes as stop-loss, permit only exact take-profit/stop-loss bracket-leg identity, and commit atomically only after schema and SQLite integrity checks. Future, foreign, malformed, non-current, non-WAL, or integrity-failed stores block both ordinary and emergency authority without exposing a path.
* [ ] Signer backups require a stopped runtime, use SQLite point-in-time copying, contain exactly one portable database plus a private schema/fingerprint/SHA-256 manifest, retain only verified snapshots within bounds, and preserve the replaced database/WAL/SHM set before guarded restore. The signer and maintenance commands hold one race-free operation lock.
* [ ] Approved and rejected normalized Arcus review verdicts enter the signer audit before any approval token leaves the BFF; authenticated reads require the exact signer/eligibility account, request only Arcus events, cap/validate every row, and never forward signer detail JSON, account, price, quantity, policy metrics, signature, token, or database path.
* [ ] Every protected Arcus/Hyperliquid boundary emits a fresh server-owned span; review creates a durable execution-flow root that is signed into the one-use confirmation ticket, forwarded to the signer and recovered only from the exact CLOID/client-ID audit for later cancel/reconciliation. Browser-supplied lineage is ignored, exact-venue projections show both UUIDs, and telemetry discloses no account/order/body/URL/credential data.
* [ ] Hyperliquid and Arcus signer prices, quantities, increments and notionals are bounded non-exponent decimal strings; TypeScript and Python require the same nine request models, reject extras/JSON numbers, and check exact products before Hyperliquid converts at the final official-SDK adapter.
* [ ] Enabled Hyperliquid execution has an exact BFF/signer builder address and 1..100 tenths-bps fee match; live `userFees`, `maxBuilderFee`, builder `clearinghouseState` and `userAbstraction` are checked before confirmation; less than 100 USDC perps value, any mode other than explicit Standard (`disabled`), insufficient/revoked approval or unavailable evidence yields no token; only immutable `/v2/orders` or additive `/v4/orders` can submit user-confirmed orders; the native builder object reaches every order in a batch; unfilled orders earn no NIGHTSHIFT fee.
* [ ] V4 Hyperliquid brackets accept only an opening parent plus complete profitable-side TP and complete protective SL, require three distinct CLOIDs, emit one official-SDK `normalTpsl` batch with reduce-only limit-trigger children, verify exactly three venue statuses and retain exact take-profit/stop-loss leg scope before I/O. V2 parent-plus-SL remains unchanged; automation V3 rejects brackets; fixed-size/gap risk is disclosed and no sibling-cancel or dynamic-resize guarantee is claimed.
* [ ] Every fee-bound Hyperliquid parent/protective CLOID and exact bracket-leg identity is retained before submission; revenue reconciliation resolves the exact venue order, queries unaggregated account fills, accepts only matching positive `builderFee` evidence, deduplicates globally by `tid`, sums exact decimals per fee token and reports bounded-partial coverage instead of treating ACK, cancellation or incomplete history as earned revenue.
* [ ] The commercial statement scans only retained positive builder-fee fills with exact token/month arithmetic, crosses the signer/BFF boundary without account/order/trade/builder identity, requires an operator session, marks coverage bounded-local, claim state unreconciled and builder archive not ingested, and never converts metered Agent Pro usage or a signed license into recognized revenue without payment-provider evidence.
* [ ] The separate venue reward statement requires an operator session, resolves every official referral token index through strict spot metadata, preserves exact decimals and token-zero parity, removes builder/referrer/account identity, labels claimed/unclaimed balances as combined and not ledger-reconciled, refuses unpublished archive columns and exposes no claim execution capability.
* [ ] Hyperliquid reconciliation uses one strict signer v2 call and atomic transaction to retain the reviewed official venue status, exact original/remaining/filled quantity and every matching fill/fee/PnL row. OID changes, older statuses, final-state reversals, unknown status values and conflicting `tid` evidence fail closed; the terminal never prints raw venue JSON and only filled/canceled/rejected are final.
* [ ] Hyperliquid Time Machine and Trade Autopsy require an operator session and the configured signer account, read only retained reconciled lifecycles without venue I/O, reject browser account overrides and malformed/cross-account evidence, expose exact PnL/fees/builder revenue plus ordered flow/span lineage, and label the 10,000-fill upstream plus 1,000-event local bounds without persisting arbitrary public account inspections.
* [ ] Hyperliquid bracket Trade Autopsy reconstructs only synchronized retained parent/TP/SL evidence, makes zero venue calls, attributes every lineage event to an exact leg and fails closed for standalone, missing, differently timed or corrupt groups; exact `siblingFilledCanceled` remains the sole sibling-cancellation proof.
* [ ] Control-plane schema v3 preserves exact schema-v1/v2 spans, makes each legacy span its own root, emits only fixed-code SLO open/recovery incidents after the minimum sample, and keeps pending outbox rows durable; exact-body HMAC, stable IDs, expiring leases, redirect rejection and bounded retry expose no receiver/secret/body. Disabled or degraded delivery blocks Hyperliquid mainnet but not testnet, and correlation or aggregate recovery never establishes order finality.
* [ ] TradeProposal import is strict, authenticated, CSRF-protected and bounded; persistence contains only normalized identity/hash/fixed lifecycle fields; neutral/abstain cannot attach; directional symbol/side binding is exact; reservations are one-intent; consumption precedes signer I/O; invalid/consumed proposals cannot be reused; and every attached order still receives fresh AEGIS review.
* [ ] Agent credentials are displayed once, expire within 24 hours, persist only as server-keyed HMAC digests, authenticate only from an exact Bearer header over loopback HTTP or HTTPS, and fail immediately on expiry, individual revoke or atomic revoke-all. Invalid authentication is throttled without logging/reflection.
* [ ] New Agent Pro credentials require a strict active Ed25519-signed license whose public-key-only runtime verifier enforces activation, expiry, credential capacity and shared UTC-month attempts. Missing entitlement locks issuance, malformed or partial configuration makes health unsafe, rotation invalidates licensed credentials, and no issuer private key enters config, web, backup or browser scope.
* [ ] Proposal-only `nsl_v1` licenses cannot create automation policies or submit orders. Additive `nsl_v2` terms bind the monthly automation allowance; each new DPoP-authenticated request ID and its authorization/rejection meter atomically, exact replay is not counted twice, status is unmetered, and overage is durably rejected before signer I/O.
* [ ] Agent proposals are capped, strict and charged against a durable rolling attempt quota before exact symbol/stance/notional/validity mandate checks; accepted analysis enters only the single-use operator ledger and every response remains proposal-only/operator-required.
* [ ] The v1 agent bearer cannot list private proposals, create an execution review, confirm, submit, retry, cancel, fund, reconcile or call either signer. The separate v2 DPoP surface is Hyperliquid-testnet-only, policy/AEGIS bound, at-most-once before reconcile and loopback-only in the delivered profile; it exposes submit/status but no cancel, funding, policy mutation, wallet or signer endpoint. Remote and mainnet automation remain unsupported.
* [ ] Every manual Hyperliquid review requires a canonical 1-30 bps slippage ceiling before provider I/O; the tighter operator/platform/automation value binds entry and protective limit prices into the one-use ticket, survives fresh submit review and remains labeled as a price bound rather than a fill guarantee.
* [ ] Every manual Hyperliquid review requires canonical market-position and portfolio-gross USD ceilings with market not exceeding portfolio before provider I/O. One fresh complete all-DEX configured-account generation supplies equity, positions and gross exposure; operator values can only tighten AEGIS percentage limits, selected-asset capacity remains independent, both values survive the one-use ticket and fresh submit review, and valid side/size-bounded reduce-only exits are never trapped by an existing breach.
* [ ] The Agent Pro client accepts exact IPv4 loopback HTTP only, rejects redirects/cookies/referrers, binds fresh P-256 DPoP to the token/method/URI, validates and bounds request/response data, maps failures to fixed codes, and offers only submit/status. Its CLI reads the token only from `NIGHTSHIFT_AGENT_TOKEN`, requires absolute non-symlink private/request files, creates key files only outside the repository and has no token or cancel flag.
* [ ] The Arcus signer supervisor refuses mainnet, Hyperliquid execution, public binds, relative/repository key paths and weak tokens; its doctor is zero-network and its state/log contain no address, key path or token.
* [ ] The Hyperliquid signer supervisor accepts only testnet or explicitly enabled mainnet, refuses Arcus execution, mismatched mainnet flags, mainnet without an explicit cap, mainnet caps above $12, mainnet symbol scope other than exact BTC, mainnet leverage other than 1x, inline/master-wallet keys, public binds, symlink/relative/repository key paths and weak tokens; its doctor and health-only startup are zero-network through lazy SDK construction, exact authenticated health binds network plus symbol digest/count, leverage cap, schema-v8/WAL/eligibility/dead-man state, the shared store lock excludes maintenance/another signer, and state/log contain only fingerprints plus process metadata.
* [ ] Arcus mainnet rehearsal gates contain no environment override: the same-account signer audit must show a testnet acknowledgement followed by `FILLED`/`CANCELED`, plus acknowledged account-wide cancel-all followed by exactly zero open orders, all within 30 days. Partial, stale, cross-account, malformed or acknowledgement-only evidence fails closed.
* [ ] `ARCUS_PUBLIC_API_URL` resolves only to the official HTTPS Arcus origin.
* [ ] `HL_PUBLIC_API_URL` resolves only to the official mainnet Hyperliquid `/info` endpoint.
* [ ] Public venue response-byte, concurrency, circuit and account-rate bounds pass preflight; health contains no URL, body, credential or wallet.
* [ ] Arcus, Lighter and Hyperliquid public market/trade/candle consumers share one socket per venue; Lighter tape/candle subscriptions require exact live-discovered market IDs; pooling, unsubscribe/replay, heartbeat, stale close and conservative connection/message budgets pass tests.
* [ ] Hyperliquid `allMids` remains midpoint-only and cannot update a mark. `allDexsAssetCtxs` maps every primary/HIP-3 market by exact DEX and metadata index; malformed, missing, stale or more-than-25%-moved uncorroborated contexts retain the last accepted mark/time, degrade visibly and remove chart, order-review and unattended paper authority. REST recovery cannot bypass the hold.
* [ ] Every retained held perpetual mark projects to `livePrice: null`; exact-source alert collection omits it, all three PAPER panels receive zero mark/time, chart risk receives no mark/time, order shortcuts disable, watchlists show `-- / MARK HELD`, and palette/brief/book/evidence surfaces never call it current or public live.
* [ ] Lighter public account inspection rejects malformed and zero/system addresses, returns only exact-address type-0 accounts, caps and validates positions/assets, never returns counterparty IDs, and labels authenticated orders/fills/funding plus Robinhood Chain funding unavailable.
* [ ] Every rendered page rotates its CSP nonce; all framework scripts carry it; `script-src` excludes `unsafe-inline`; fonts are same-origin; browser CSP violations are zero.
* [ ] Every modal dialog contains forward/reverse Tab focus, restores the initiating control, transfers focus safely between dialog identities, and ignores Escape while an order/cancel mutation is in flight.
* [ ] Injected-wallet discovery validates and caps EIP-6963 announcements, treats names as self-attested, falls back safely to EIP-1193, observes account/chain/disconnect changes, and exposes no sign, send, approval, permission or persisted-address path.
* [ ] Operator login rejects missing/placeholder secrets, wrong Origin, malformed/oversized JSON and repeated guesses; the cookie is HttpOnly/SameSite-Strict/path-scoped and rotates per login.
* [ ] The optional Fastify development API defaults disabled, refuses non-`127.0.0.1` binds and weak/missing bearer tokens, caps bodies/sockets, ignores forwarded client addresses, and labels paper/evaluation responses non-executable.
* [ ] Watchlist storage rejects malformed, oversized, unsafe and over-cap input; favorites remain isolated by venue and never authorize a subscription, wallet, order or execution path.
* [ ] Command-palette query/result bounds, ID deduplication, live-discovery gating and keyboard/modal guards pass; canonical assets are not called listings and no command can review, submit, cancel, sign or fund.
* [ ] Price-alert storage rejects malformed, oversized, unsafe, duplicate and over-cap input; only fresh matching venue observations trigger once, and the UI never claims background delivery.
* [ ] Workspace-layout storage rejects malformed, oversized, unknown-field, unsafe-name, duplicate and over-cap input; saved views carry presentation preferences only.
* [ ] Candle history rejects malformed/future/impossible values, caps retained bars, uses calendar-aware monthly continuity, discards cross-context responses and never erases rendered history when a REST repair fails.
* [ ] Successful live candle pages write only validated provider bars to the migrated atomic history store; configured retention/series/candle caps, unsupported-market exclusion, explicit aged persisted fallback, health and backup validation pass.
* [ ] Robinhood Chain activity preserves the 27-contract log index while enabling native ETH only for an Alchemy primary endpoint; inbound/outbound external transfers use exact raw wei, bounded pages and separate checkpoints, while missing/internal/malformed/truncated coverage stays explicit.
* [ ] Chart preferences reject malformed, oversized, unknown-field and invalid-period input; fast/slow relationships stay ordered; live last-bar updates do not recreate series; corrections, backfills and context changes retain the full-render fallback.
* [ ] All five Advanced Charts UDF routes validate strict versioned responses, return only live-discovered canonical tickers and verified provider history, preserve seconds/session/timezone/precision, reject stale persisted fallback and expose no demo/iframe feed. The custom Datafeed converts history to milliseconds, uses pooled supervised venue streams, resolves exact Lighter market IDs, repairs gaps/reconnects and unsubscribes cleanly. Native tools activate only from the owner-supplied official v32 package after license attestation, exact file/tree hashes, SRI, nonce/CSP, health and desktop/mobile browser review; otherwise the visible custom fallback and access state remain truthful.
* [ ] The custom chart opens with drawing/history overlays collapsed on desktop and mobile, exposes an unambiguous accessible `TOOLS +` / `TOOLS -` control, preserves an explicit browser-local choice, keeps the risk drawer independent and renders chart-only muted copy through the reviewed terminal contrast palette.
* [ ] The `/nightshift` command deck cannot derive production readiness from a public-RPC block alone; its label and provider gates match the sanitized `/api/rhc/providers` topology.
* [ ] The `/nightshift` coverage matrix starts from all canonical contracts, accepts only live Arcus/Lighter/Hyperliquid discovery, prioritizes Arcus, distinguishes `$0` activity from unavailable, keeps current session state unknown without a holiday calendar, and never labels a listing execution-ready.
* [ ] Every canonical matrix row opens the correct accessible asset dossier; reviewed oracle and identity-only assets stay distinct; canonical ERC-8056 current/pending multiplier and pause state survive a sequencer-configuration price lock; mismatched/crossed/stale books fail closed; and displayed depth is never called total liquidity or execution-ready.
* [ ] Paper compiler, replay and fixture-league routes return generic 404 responses from the production build before parsing request bodies.

## Quality gates

* [ ] `pnpm preflight`
* [ ] `pnpm audit:rhc-registry` while preparing a connected release.
* [ ] `pnpm audit:rhc-bridges` matches all six official route rows and 16 bridge-related mainnet contract rows without additions, removals, mismatches or duplicates.
* [ ] `pnpm audit:rhc-oracles` while preparing a connected release.
* [ ] `pnpm audit:arcus-funding` while preparing a connected release.
* [ ] `pnpm verify`
* [ ] `pnpm build`
* [ ] `pnpm smoke:web`
* [ ] `pnpm handoff:check`
* [ ] `pnpm test:py` when Python 3.10–3.12 dependencies are available.
* [ ] `pnpm lint:py` when the project virtual environment is available.
* [ ] `pnpm test:signer` proves real testnet-only child health, unexpected-child recovery, clean stop and secret-free state/logs with an ephemeral key and no venue request.
* [ ] `pnpm test:hl-signer` proves testnet and hard-capped mainnet Hyperliquid offline doctors, authenticated network-bound health, shared-store exclusion, lazy zero-network startup, testnet unexpected-child recovery, clean stop and secret-free state/logs with ephemeral API-wallet keys.

## Local production lifecycle

* [ ] `pnpm local:start` reaches healthy state on loopback.
* [ ] `pnpm local:restart` changes the child process and returns to healthy state.
* [ ] `pnpm soak:verify` accepts a complete 24-hour, at-least-99%-valid hash chain with scheduled coverage, a changed supervised child generation and full post-restart convergence within 60 seconds; any unsafe runtime, tamper, diagnostic-only Robinhood topology, missing managed fallback/WSS/archive, short duration or oversized gap remains non-qualified.
* [ ] Unexpected child termination is automatically recovered.
* [ ] `pnpm local:stop` leaves no supervised child running.
* [ ] Persistent config survives a restart and cannot enable execution.
* [ ] `pnpm backup:create` and `pnpm backup:verify -- <backup-id>` succeed without copying config, endpoints or secrets.
* [ ] Control-plane backup validation accepts migrated schema-v3 span/root lineage, rejects malformed or non-canonical UUIDs and preserves existing SLO incident/delivery state.
* [ ] Proposal lifecycle backup/restore rejects undeclared, secret-bearing, inconsistent, duplicate, out-of-order, future-schema and oversized state while preserving valid reservations/consumption evidence.
* [ ] Agent-access backup/restore accepts strict schema-v1 migration and schema-v2 entitlement/usage state, rejects plaintext tokens, license material, undeclared fields, invalid HMAC digests/mandates, broken references, duplicate or arithmetically inconsistent usage, inconsistent order and oversized state while preserving revocation/quota/audit evidence.
* [ ] Agent-automation backup/restore accepts strict schema-v1/v2 history and schema-v3 total-fee policy state, revokes migrated policies without inventing historical authority or usage, and rejects license/token/private-key/order material plus invalid fee ceilings, digests, references and aggregate periods.
* [ ] Portfolio reconciliation exact replay is idempotent; boot/reconnect convergence, stale/future/out-of-sequence refusal, missing-open-order unknown state, complete-position replacement, partial-coverage preservation, checkpoint corruption, concurrent persistence and opaque backup/restore all pass.
* [ ] The configured Hyperliquid signer account reconciles every discovered perp DEX, exact missing live orders and bounded unaggregated fill/funding pages before review/submit/automation. Each DEX must match its `allPerpMetas.collateralToken`; Standard, Unified and Portfolio Margin capital plus HIP-3 fees/PnL/funding must use strict `spotMeta` identity and reserve-oracle conversion. Fresh review must match the venue-active leverage and remain within `activeAssetData` maximum size and available capacity. Partial DEX state, schema drift, stale time, unknown order state, unsafe spot debt/holds, missing oracle/token identity or active-capacity mismatch locks without advancing accepted remote time or exposing the account.
* [ ] A Hyperliquid leverage mismatch returns no order ticket and opens only a short-lived explicit leverage review. Confirmation preserves current cross/isolated mode, rechecks venue maximum and fresh state, reaches the official SDK at most once through the distinct signer contract/schema-v8 idempotency table, and reports applied only from matching `activeAssetData`. Unknown is never retried, automation has no leverage authority, and any later order requires a fresh full review.
* [ ] Hyperliquid mainnet entry requires a fresh same-account testnet dead-man rehearsal and a currently armed venue-native `scheduleCancel` deadline. Arm/disarm use one-use operator confirmations; mounted-session heartbeats are monotonic and re-read every discovered perp DEX before extending the fixed 30-second deadline; pre-sign failures prove `not-attempted`; post-sign ambiguity stops heartbeats and is never retried; disarm requires zero open orders; ACK never proves cancellation; real rehearsal requires zero post-deadline open orders plus exact retained CLOID status `scheduledCancel` and separate user authorization.
* [ ] `pnpm hyperliquid:readiness -- --origin http://127.0.0.1:3000 --expected-network <testnet|mainnet> --expected-symbols BTC --max-canary-notional-usd 12 --max-leverage 1 --require-zero-open-orders --require-ready` authenticates only against loopback, reports redacted customer-database/signer/eligibility/builder/portfolio/dead-man and campaign-scope gates, proves the BFF/signer symbol digest plus leverage ceiling agree, performs no capital mutation and revokes its temporary operator session. Mainnet also adds `--require-dead-man-rehearsal`. The complete GTC/cancel, IOC/fill/PnL, reduce-only, TP/SL, ambiguous-outcome, dead-man, restart and backup matrix in `docs/runbooks/hyperliquid-go-live-validation.md` has separate action-time approvals and retained testnet evidence before mainnet.
* [ ] Final testnet or mainnet campaign evidence is generated from a private out-of-repository checklist and passes `pnpm hyperliquid:evidence -- verify --evidence <absolute-private-evidence.json>`. It proves all required cases, authorization no more than five minutes before each mutation, pre/post/final readiness, $12/1x scope, customer-database reconciliation, final flat/zero-order/kill-switch/signer/backup state and redaction. The verifier makes no network request; the separately retained digest is hash evidence, not a reviewer signature.
* [ ] Hyperliquid bracket reconciliation reads the retained parent and every protective child as one strict group, reuses one bounded fill window, accepts only shared intent/account/symbol/builder/time scope and reports sibling cancellation as confirmed only for exact venue `siblingFilledCanceled`. Missing/malformed evidence, bounded coverage, both exits filled, failed protection, a non-terminal retained leg after an exit fill or an unconfirmed sibling stays unavailable or `attention-required`; accepted/closed requires every leg terminal.
* [ ] Restore is refused while the supervisor runs; an offline restore preserves displaced checkpoints and returns to healthy state.
* [ ] Alert delivery is disabled when URL/secret are absent and fails configuration closed when only one is present.
* [ ] A configured receiver verifies timestamp/HMAC and deduplicates `x-nightshift-delivery-id` before returning 2xx.
* [ ] The control-plane receiver independently verifies timestamp, exact raw-body HMAC and stable delivery ID; timeout/5xx retry, restart lease recovery, duplicate acceptance and recovery-marker rehearsal preserve pending evidence and secret-free health.
* [ ] The Arcus signer alert receiver independently verifies timestamp/HMAC and deduplicates stable delivery IDs; timeout/5xx retry, restart lease recovery, outbox overflow and recovery-marker rehearsal preserve fail-closed health without exposing secrets.
* [ ] `/api/market/health` recovers from an isolated circuit rehearsal while `/api/health` remains safe and execution disabled.
* [ ] A forced public-stream close visibly falls back/reconnects, replays active subscriptions, and returns to live without opening one socket per consumer.
* [ ] Landing, command deck, terminal and 404 render under strict nonce CSP with no console errors or blocked required resources.
* [ ] With `prefers-reduced-motion: reduce`, ticker/status/loading animation and transitions are effectively disabled, CSS scroll behavior is immediate, scripted navigation respects the preference, and keyboard focus remains visibly outlined.
* [ ] No-wallet, connected chain-4663, wrong-chain switch/add, account-change, rejection and 390 × 844 wallet-inspector states pass with manual public-address fallback and zero console errors.
* [ ] Privy production and development apps are separate; Google and wallet login are enabled; exact HTTPS origins are allowlisted; production HttpOnly cookies and DNS are verified; no secret appears in source, client bundles, logs or `config.json`; anonymous, expired, cross-app, conflicting-token, linked-wallet, embedded-wallet and chain-4663 switch states pass on desktop/mobile. Login alone must leave operator, execution, transfer, withdrawal and Agent Pro authority locked.
* [ ] `pnpm identity:evidence -- create|verify` retains a private exact-app production rehearsal with all required checks and a future expiry no more than 30 days away. Health reports `identityProductionEvidenceState=verified` without a path, app hash, token, DID, email or wallet; missing/expired/app-rotated evidence clears readiness and malformed evidence makes health unsafe.
* [ ] User-owned Arcus withdrawal submission remains independently disabled unless exact-app Privy rehearsal evidence, production RHC topology, current withdrawal-document/vault/account/compliance/collateral evidence, a healthy private lifecycle store, a private confirmation secret and explicit owner/security/legal approval all exist. The exact connected provider wallet on chain 4663 alone signs the displayed EIP-712 request; the BFF submits at most once; HTTP 202 remains pending; ambiguity is no-retry; and only an exact matching terminal transfer update closes the retained ID. Health and backup corruption rehearsals fail closed without exposing address, DID, signature, key or token.
* [ ] `pnpm charts:evidence -- create|verify` retains a private exact-release/tree production rehearsal with drawing rail, required studies/resolutions, provider-only history/live repair, zoom/pan/pinch, saved layout, fallback and desktop/mobile checks plus a future expiry no more than 30 days away. Health reports `advancedChartsProductionEvidenceState=verified` without a path, checklist, credential or proprietary asset; missing/expired/release-rotated/tree-rotated evidence clears readiness and malformed evidence makes health unsafe.
* [ ] `/api/profile` requires valid access and identity tokens for the same Privy DID, labels its provider projection `identity-token-bounded`, keeps currently connected browser wallets separate from provider-linked wallets, returns private/no-store responses and fails closed for absent, malformed, ambiguous, cross-user or unavailable evidence.
* [ ] Profile PATCH requires exact same-origin evidence, bounded strict JSON, the current optimistic revision and the per-session mutation budget. Persistence uses only an opaque customer digest plus display preferences, contains no raw DID/email/wallet/token/key, reports aggregate-only health, and survives strict verified backup/restore without granting portfolio, funding, withdrawal, execution or commercial authority.
* [ ] Locked execution status is redacted; all review/submit/cancel/reconcile/audit routes reject absent, tampered, expired or revoked sessions; forwarded-header changes do not bypass the session budget.
* [ ] Authenticated Terminal settings can issue a credential once, copy it, show only redacted retained state, revoke one and revoke all on desktop and 390 x 844 without root overflow, secret persistence, console failure or an execution control.
* [ ] Without a license, Terminal visibly locks Agent Pro issuance while ordinary terminal functions remain available. With an ephemeral valid license, it shows redacted signed state, exact current-month usage and active capacity; authenticated usage export reconciles with attempted proposals and exposes no agent token, proposal body, wallet or key.
* [ ] With a proposal-only license, Terminal visibly locks automation policy creation while preserving stop/revoke controls. With an ephemeral `nsl_v2` license, it shows aggregate automation attempts/limit and exports an authenticated private usage statement without an order, account, token, key or license value.
* [ ] Authenticated Terminal Commercial control renders exact earned-fill token totals or an explicit signer-unavailable state, shows proposal/automation attempts as unpriced, reports payment collection unconfigured, copies only the strict aggregate statement and remains contained at 390 x 844 with no console/CSP failure.
* [ ] Starting `@terminal/api` without explicit enablement fails; an enabled live-process check accepts only its separate bearer capability on loopback and returns no secret-bearing logs or payload reflections.
* [ ] Arcus, Lighter, Hyperliquid and Robinhood Chain favorites, All/Watch modes, `F`/`W` shortcuts, typing suppression, mobile star access and selected instrument restore survive a production-browser reload without console, CSP or failed-response errors.
* [ ] `Ctrl/Command K` cross-venue selection, Arrow/Home/End/Enter/Escape control, safe action execution, focused typing, modal overlap prevention, forced-feed exclusion and 390 × 844 containment pass production-browser verification.
* [ ] Price-alert creation/rejection, `A` shortcut, reload persistence, triggered evidence, deletion/clear, forced-feed lockout and 390 × 844 containment pass production-browser verification.
* [ ] Full desk, Chart focus, Research, Execution and a named custom view pass computed-pane, reload, delete, `L` focus-guard and 390 × 844 containment checks.
* [ ] Paginated chart history remains above the latest-page size after a scheduled refresh; forced candle REST failure preserves bars with `REST REPAIR DEGRADED`, recovery clears the state, continuity telemetry is truthful, and 390 × 844 has no horizontal overflow.
* [ ] A rapid venue/symbol/interval switch with the destination history response deliberately held immediately shows the destination identity with zero retained bars, a hidden chart canvas, no price/study axes and no risk overlays; only an exact-identity response may restore the chart. Desktop and 390 × 844 have no overflow, console warning, console error or page error.
* [ ] After a successful live candle read and process restart, a forced venue outage returns the same verified page as `historySource=persisted` with age/reason/header evidence; provider recovery returns `historySource=provider` and clears the degraded UI notice.
* [ ] Chart style, study toggles and a changed study period survive reload; streaming selects the incremental renderer; UTC crosshair shows exact T/O/H/L/C/V; the 12-field study panel stays within 390 × 844 and remains editable without console errors.
* [ ] The selected perpetual chart shows mark plus oracle/index only from a fresh live market observation; an inspected position attaches only by exact venue/symbol and exact Lighter market ID; multiple matches remain ambiguous; missing venue entry/liquidation values remain missing; and stale/degraded market or account evidence removes affected price lines. Desktop and 390 × 844 remain contained with zero console/CSP failures.
* [ ] The selected perpetual chart shows only fresh exact-scope venue account authority: Hyperliquid uses the selected primary/deployer DEX, Arcus margin totals require complete position evidence and Lighter totals require complete type-0 account evidence. Venue-labeled equity, available collateral, margin used, utilization, capital buffer, position leverage/mode/notional and unrealized PnL remain partial or unavailable instead of inferred; stale evidence clears the account rail. Desktop and 390 x 844 remain contained with zero console/CSP failures.
* [ ] The selected perpetual chart binds realized performance and funding only to the exact venue market: Hyperliquid and Arcus recent closed PnL retain their bounded 2,000/1,000-fill window labels, missing or incomplete fill coverage produces no sum, and cumulative funding requires one exact position; Lighter requires one exact symbol/market-ID position for realized PnL and funding paid. Performance availability remains independent from capital, stale evidence clears it, and desktop plus 390 x 844 remain contained with zero console/CSP failures.
* [ ] The selected perpetual chart binds historical funding only to the exact venue/symbol and labels point count, observed window, latest/mean/range and sign counts without summed carry or annualization. Lighter liquidation context uses only the documented `type` tag inside the retained 100-execution window; Hyperliquid and Arcus visibly report the public classifier as not documented. A venue/symbol switch cannot retain prior context, degraded cached evidence is partial, and desktop plus 390 x 844 remain contained with zero console/CSP failures.
* [ ] With the default public endpoint, `/nightshift` says `RHC DIAGNOSTIC`, reports fallback/WSS/archive not ready, and never says `Production RPC observed` or `Systems production ready`.
* [ ] Live `/nightshift` shows the current canonical total plus Arcus/Lighter/Hyperliquid listing counts, an Arcus row opens the exact market in `/terminal`, forced Arcus loss removes Arcus matches behind a degraded reason, and 390 × 844 contains the horizontally scrollable matrix without page overflow.
* [ ] On desktop and 390 × 844, one reviewed-oracle and one identity-only dossier render canonical identity, oracle/multiplier state, schedule, bounded book and execution reason without root overflow, failed response, console error or CSP violation; refresh retains the selected asset and re-reads scoped evidence.
* [ ] Lighter terminal selection, search, watchlist, alert, supported intervals, chart/tape streams, public-account state and read-only access proof pass on desktop and 390 × 844 with zero CSP/console failures and no order action.
* [ ] Arcus `PREFLIGHT` renders current tick/step/minimum/session margin, stays disabled without a registered inspected account, reports exact ticks/quantums and blockers from the server boundary, and remains contained at 390 x 844 with no submit or signing control.
* [ ] Arcus account inspection shows REST snapshot versus live WebSocket lifecycle evidence, reconciled open/recent-closed/fill counts and the HTTP-ACK warning; desktop and 390 x 844 have no root overflow or console failure.
* [ ] Each selected perp venue shows a fresh two-sided order book with `WS LIVE` and age on the pooled socket; forced stale/reconnect state switches to explicit `REST SNAPSHOT`, and a deterministic Lighter nonce gap preserves accepted state, resubscribes, repairs from REST and never appears live during the gap.
* [ ] Arcus `Signer audit` shows review/submission/cancel/emergency/reconciliation evidence only after operator unlock and exact-account inspection; locked, mismatch, unavailable and empty states remain distinct, and public funding/transfer rows never substitute for missing signer evidence.
* [ ] Arcus testnet funding plan shows matched official parameters, live chain/contracts/wallet state, exact required calls, simulation/prerequisite state, fee completeness, mainnet lock and credit reconciliation on desktop and 390 x 844, with no wallet prompt, send control, CSP violation or root overflow.
* [ ] Robinhood Chain history labels canonical ERC-20 versus external native-ETH events, exposes Alchemy/provider and independent gap state, retains token events during a forced native-provider failure, and remains contained at 390 x 844 with zero console or CSP errors.

## Codex upload

* [ ] Archive or publish the reviewed NIGHTSHIFT release artifact.
* [ ] Ask Codex to read `AGENTS.md` and `START_HERE.md` first.
* [ ] Assign one ticket, beginning with `RHC-101`.
* [ ] Require exact test commands and unresolved-check disclosure in the completion report.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/release-checklist.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
