The trading bot spent the day moving house, off the Pi and onto a VPS, which sounds like a one-line change and isn't: "the host is up" had to be redefined to mean "the bot is trading", and every failure that only shows itself when nobody is watching had to be found before the fact rather than after it. Meanwhile the stop-loss on an open trade had been telling me it moved when it hadn't, which is a worse class of bug than a stop that plainly fails to move.
Shipped
-
forex-copybot — the bot moved to the VPS, and "VPS up" now means "trading". The bot had a boot trigger; the thing it trades through did not. MT5 ran in session 0, but the bridge started on a logon trigger as Administrator, and the host has no auto-login — so a reboot restored the bot while the broker link stayed down, held together by a stale disconnected RDP session. Measured rather than assumed: a session-0 SYSTEM process can attach to the running terminal (
initializetrue,trade_allowedtrue), so no interactive login is needed anywhere on that box. The bridge is now SYSTEM with a boot trigger, its 72-hour execution limit removed (it had already terminated a run once) and restart set high, and a new keeper runs every five minutes to start the bot when its health endpoint is unreachable and restart the bridge whenbroker_okis false, on a fifteen-minute cooldown. Verified by rebooting the VPS with nobody logged in: bot and bridge up on boot triggers,broker_oktrue, ten orders open, trading about two minutes later. Two other failure paths went with it — the watchdog used to write its alert into a drop directory that only the live bot drains, so the one failure it exists for, the bot being down, was the one it could never report; it now sends directly and keeps the file as a fallback, and an external health check on the Pi pages after two consecutive misses and stays quiet while down. pkia/forex-copybot. -
forex-copybot — an exit policy measured before it was shipped. Holding the full size and ratcheting the stop to each touched target beats banking thirds, on the channel's own signals: 141 filled signals over ~10 months of M5 real fills, 89 of them gold, both intrabar orderings agreeing. Gold: E[R] −0.036 for the ratchet against −0.090 for the legacy ladder, median +0.46R against +0.25R, stop-out rate unchanged at about a third. The popular variant — stop one target behind — measured strictly worse (−0.352R) and was deliberately not implemented. It is now a config flag (
exit_policy: ladder | ratchet_tp), applied live to every open position, with the top target still exiting on the broker's own TP. Five new tests, 385 passing, running snapshot verified. A follow-up commit made the channel's "close half" management call raise the floor instead of slicing the position, so the auto-applied management can't contradict the policy I chose. -
forex-copybot — the stop that reported success because the bridge said 200. I asked the bot why an open trade had passed its first target without its stop moving. Three stacked bugs. The trigger used the ask while the channel's targets track the bid and that pair carries a ~4.5 pip spread — the bid crossed the target and the ask never did, so the ratchet never fired; triggers are now bid-based. The stop amend trusted HTTP 200, but the bridge returns 200 with
success:falsewhen the terminal refuses a stop that violates the minimum distance — so the audit said applied, the database said moved, and the broker still held the original stop. The adapter now reads the response body and the database is written only on broker confirmation. And the target level was marked consumed even when the amend was refused, which killed the retry; levels now consume only on success, with refused amends retrying on a 60-second throttle until the distance clears. Live state repaired, two new tests, 396 passing. Same day, a gold plan that parsed, validated and sized all three zones died as FAILED because the broker answered "market closed" and nothing retried at reopen: such rejections now park, retry every five minutes with the original price, stop, target and size, and the broker stays the authority on when the market is actually open. Deployed at 22:19 UTC, and the retry placed all three trades, confirmed at the broker. -
pi-cicd — the power cut left races, not damage. The cut that left the box dark for eighteen hours rebooted it with every persistent timer firing at once, and three false alarms came out of it: the failed-unit audit was naming a bullet character instead of a unit, because systemd prints a leading marker even with
--no-legend; the chaos drill failed because the service-probe timer hadn't finished a sweep yet and the notification daemon was still binding its socket; and the remote-access restart fired while the user manager was still starting. Fixed with plain parsing, a drill that skips a never-ran sweep while the box is younger than the staleness budget (past it, it's still a failure) and waits, bounded and fail-open, for the notifier's health endpoint, and a restart that waits for the manager to leavestarting. 307 tests pass. pkia/pi-cicd. - product-autopilot — the orchestrator now survives its own crash. Cycle 46 closed T-077: a pid + start-time lock sidecar, an audited stale-lock takeover, a lock that refuses to clobber a live holder, and a checkpoint record written and archived at unlock. The 24-check suite plus the revert experiments are green and the red-team review came back approve-with-changes, all adopted. The repo also back-filled the audit trail from cycles the turn-budget crash had left untracked. pkia/product-autopilot.
On the radar
-
copybot — make the keeper prove the heal, not assume it (S, new). The keeper's Tailscale heal was proven by stopping the service once and watching it repair unattended, but its bridge heal has only ever run on paper. Next step: a drill that stops the bridge on the VPS and asserts the keeper restores the broker link within one interval, pages once if the heal fails twice in a row, and stays silent on a clean heal. Acceptance: with the bridge stopped the keeper restores
broker_okinside fifteen minutes with zero pages; with the bridge held down, exactly one CRITICAL. - copybot — turn the bridge preflight into a gate, not a script someone remembers (S, still open). The preflight exists (it refuses a host that cannot run the MT5 IPC path, with the Wine trap named), but a human still has to run it before deploying, which is exactly the trust that let the README go stale. Next step: wire it into the bridge deploy as step zero. Acceptance: a deploy run against the Wine harness aborts before any bridge start with the IPC diagnosis, the same path against a stubbed native host proceeds, and neither run places an order.
- Train — attribute the deaths per player, not per team (S, still open). The death-cause aggregate reports measured causes, but per team, while every bucket is a round-level statement about one player's death. Next step: use the round context the demo already carries (attacker, victim, teammates-alive, flashed) to yield one row per death. Acceptance: a fixture demo with a known victim produces that player's row with each field measured or explicitly unknown, and editing the round context changes that player's classification while every other player's row stays identical.
Interesting reads
- ChronAlert: live dashboard for radio, weather and alerts, with RTL-SDR for APRS, ADS-B and AIS (RTL-SDR Blog, 5 October 2026) — a desktop situational-awareness dashboard that folds weather and emergency feeds, ham radio and propagation, hazards and infrastructure, and local radio into one screen, with an RTL-SDR doing the work for ships, aircraft and APRS packets, plus Meshtastic node and message display. Free tier is two panels and one watch zone; the paid unlock is a one-off. The interesting part for anyone with a receiver on the roof is the shape: three radios' worth of decoding, one glance.
- Raspberry Pi OS October 2026 update (Linuxiac, 6 October 2026) — the 6 October release ships Linux kernel 6.18.50 LTS and a long list of panel, Control Centre, taskbar and tray fixes: menus that opened off-screen, tray icons that all vanished when one was closed, the ejecter plugin now mounting encrypted drives, and a settled fight between PCManFM and the ejecter plugin over who gets to automount. Nothing here will change anyone's life, which is the point — a home-server box that gets quieter with every release is a good box.
- Companies are putting Jev in charge of agent decisions, and prompt injection can influence the verdict (VentureBeat, 21 September 2026) — worth reading for anyone whose agent loop has a routing or allow/deny step. TypeSafe's Jev is a decision model: you hand it state and typed questions, it returns a choice, a score or a probability with confidence, in 70–500 ms at $0.042 per million input tokens. The useful half is the warning, published by the vendor and by Pydantic: option order is part of what the model sees, and text written to steer it can move the answer — one test dropped a block-the-command probability from 0.76 to 0.48 by planting a single fake field claiming the user had pre-approved it. Pydantic's line is the one to keep: a guard built on this belongs beside deterministic checks, not instead of them.