Summary¶
ev_ladder.py is the EV engine the daily round actually uses (pilot reconciliation, consolidation decision 1). Its receipts are attested by re-execution: ladder-binding.py reruns build_ladder on the recorded snapshot and trades and requires every saved ladder to match. This closes REVIEW.md section 5 item 7 in mechanism; it is live in production once the cron prompt keeps its trade inputs and runs the attester (see below).
Contract¶
| Inputs | round-snapshot-<date>.json (live marks; must carry as_of) and trades-<date>.json (one entry per candidate or book position) |
| Output | ev-ladders-<date>.json — a list, one ladder per trade, in trade order |
| Determinism | Deterministic given a dated snapshot: the only wall-clock read (snapshot_date) fires only when the snapshot has no date. Verified bit-identical on the 2026-09-17 production ladders (5 of 5). |
| Attestation | ladder-binding.py --snapshot S --trades T --ladders L --out <date>.attestation.json — records sha256 of the engine source and all three inputs; exit 0 only on pass |
Scope — What Attestation Does Not Do¶
It proves the saved numbers are what this engine computes from these inputs. It does not apply an EV gate. The wiki computations have Layer 1 (ev_net > 0, Amendment 2026-09-17/01); whether ladders need an analogue is a policy question, because the pilot's long-vol book has EV_RN ≈ 0 at entry by design and its edge lives in the exit path.
Nor does it verify the inputs themselves: a wrong mark in the snapshot is reproduced faithfully. Mark quality is guarded by the engine's own sigma.rn_warning and risk_flags.