Known implementation constraints¶
The reviewed revision has material constraints that require a fix, explicit architectural acceptance, or operational control before deployment:
- Perp mark and funding formulas are external inputs.
- Market flags share storage with the cumulative-funding sign; writers must preserve accounting bits.
- Margin is unsigned and has no insolvency waterfall.
- Hard-paused Perp books block ordinary FIFO partial liquidation.
- Route replacement relies on an off-chain drained-book precondition.
- Spot and Perp apply different reserved-bit rules to packed replacement.
- Spot L2 can overstate executable stale depth.
- Spot reserves are aggregate per account/token, and verified books have no unregister path.
- Queue capacity is bounded; exhaustion reverts placement.
- Hook execution is synchronous, fail-open, and may repeat in one action.
- One-click trigger conditions are opaque and keeper-attested; the wallet does not prove that the condition is true.
- Some risk/configuration transitions are incomplete in events and require calldata/getter reconciliation.
This page must be updated whenever a constraint is fixed, accepted, or superseded.