D12-F03-A05 / Complete engineering topic

Fat-Finger Limit

A production-minded guide to Fat-Finger Limit.

D12 · MATCHING ENGINES AND VENUE LO…
D12-F03-A05Canonical / Tested / Open
D12 / D12-F03

Evaluate three independent pre-trade checks and return every breached dimension.

The decision this tutorial makes visible

A single typo can be dangerous through price, size, or combined notional; one generic threshold hides which risk actually failed.

The precise question is: Does an order stay within configured quantity, notional, and aggressive-price-deviation limits?

An operator needs a deterministic accept, reject, prevent, purge, or trigger decision with its exact reason. A builder needs the same point-in-time policy and order state to reproduce that decision in code, audit data, visuals, and the browser lab.

Intuition before notation

Three rulers inspect the order independently. Reporting all failures is more useful than stopping at the first one.

The result depends on instrument and venue scope, effective policy identity, session ownership, decision-time reference state, equality rules, and exact units. Changing any one of them creates a different control decision even when the output field name is unchanged.

Scope and nearby methods

The canonical gate checks maximum quantity, price-times-quantity notional, and side-aware aggressive deviation from an explicit reference. Thresholds are implementation inputs.

VariantDefinitionBest useMain limitation
Three-axis canonical gateQuantity, notional, and percentage deviationTeaching and gateway baselineOmits credit/position aggregation
Dollar collarAbsolute price distanceLow-priced instrumentsNot percentage comparable
Portfolio risk limitAggregate exposure and GreeksFirm riskDifferent algorithm

What is sourced, selected, synthetic, and derived

RoleMaterial claimEvidenceBoundary
Sourced factEU RTS 7 requires instrument-adapted price collars, maximum order value, and maximum order volume controls; Cboe documents configurable fat-finger and notional port controls.S1, S2, S3Neither source prescribes the repository's synthetic thresholds, combined three-axis policy, reference source, account hierarchy, or override workflow.
Implementation choiceThe canonical gate checks maximum quantity, price-times-quantity notional, and side-aware aggressive deviation from an explicit reference. Thresholds are implementation inputs.Frozen package definitionProduction control hierarchies, exemptions, overrides, and account/venue rules remain outside scope unless explicitly named.
Synthetic teaching inputCanonical orders, prices, thresholds, sessions, and identifiers are repository-authored.datasets/canonical-input.json and scenario-results.jsonThey are not observed participant or venue records.
Author-derived calculationThe synthetic buy is 150 bps above reference, has quantity 4,000, and notional 4.06 billion atom-units. All remain within the configured limits.Formula, canonical fixture, Python/TypeScript parity, and independent arithmeticCorrect arithmetic does not establish compliance, latency, or trading value.

The primary sources support only the named regulatory or venue behavior. They do not certify the synthetic policy IDs, orders, thresholds, sessions, or outputs. Those values are repository-authored, and every displayed result is an author-derived calculation under the selected control contract.

Formula, symbols, and numerical policy

Plain text
accept = (Q≤Qmax) ∧ (pQ≤Nmax) ∧ (aggressive_bps≤Dmax)
SymbolMeaningUnitPolicy
plimit priceatomspositive
p_refreference priceatomspoint-in-time
Qorder quantityunitspositive
Norder notionalatoms×unitspQ
Dside-aware aggressive deviationbpsfloored at zero
  • Notional uses exact integer multiplication.
  • Deviation is reported to six decimal basis points.
  • Equality with a configured maximum passes.

Read the formula in the same order as the algorithm. Validate identity, ordering, units, and supported state first. Apply the selected equality and window rules second. Calculate with unrounded numeric values. Round only at the declared presentation boundary, and preserve null as a diagnostic rather than coercing it to zero.

Build the algorithm

  1. Validate order and configured limits
  2. Compute exact notional
  3. Compute buy-above or sell-below aggressive deviation
  4. Evaluate quantity, notional, and price checks
  5. Return all violations

Production-minded operational checklist

  1. Resolve side and reference source
  2. Load instrument/account limits
  3. Compute every check independently
  4. Return all failures
  5. Route any override through a separately authorized workflow

The checklist is intentionally strict: an explicit rejection is safer than a plausible output built from stale, malformed, or unsupported state.

Worked synthetic example

The canonical fixture is synthetic teaching data, not an observed control event, customer order, or broker execution. Its primary author-derived output, violations, is all three checks pass: quantity 4,000, notional 4.06 billion atom-units, and aggressive deviation 150 bps. The complete input and output are in datasets/canonical-input.json and datasets/expected-output.json.

The synthetic buy is 150 bps above reference, has quantity 4,000, and notional 4.06 billion atom-units. All remain within the configured limits.

Counterfactual checkpoint

Breach two dimensions at once. Tighten maximum quantity and notional while keeping a passive price. The output changes because Each ruler is evaluated independently; a passive price does not excuse excessive size or notional.

The structured result retains state and diagnostics in addition to the primary number. That makes the calculation independently reviewable and prevents a partial, null, rejected, or venue-bounded outcome from being mistaken for an unqualified value.

Boundary and counterexample workbook

The playground computes every scenario at 61 deterministic parameter states. The table uses the declared focus step and states whether that focus reproduces the canonical fixture. The full state ledger and compressed transition segments are in datasets/scenario-results.json.

ScenarioReview focusPurposeStatePrimary outputDiagnosticDecision segments
Canonical size-and-price sweepStep 30 · canonical fixtureMove quantity and price through the combined three-axis acceptance envelope. Synthetic data; the effective policy remains explicit.accepted150.0 aggressive bpswithin-configured-limits3
Maximum-quantity equalityStep 30 · comparison focusSet quantity exactly equal to its configured maximum; equality must pass. Synthetic data; the effective policy remains explicit.accepted0.0 aggressive bpswithin-configured-limits2
Passive sell, notional breachStep 30 · comparison focusKeep sell price nonaggressive while quantity-price notional breaches its limit. Synthetic data; the effective policy remains explicit.rejected0.0 aggressive bpslimit-breached:notional3
Aggressive buy, dual breachStep 30 · comparison focusDrive buy price through both notional and aggressive-deviation limits. Synthetic data; the effective policy remains explicit.rejected400.0 aggressive bpslimit-breached:notional,aggressive_deviation_bps3
Tighter 100-bps policyStep 30 · comparison focusHold the order path constant while tightening only the aggressive-deviation maximum. Synthetic data; the effective policy remains explicit.accepted0.0 aggressive bpswithin-configured-limits3
Sell-side aggressive sweepStep 30 · comparison focusMove a sell below reference and verify side-aware aggressive deviation. Synthetic data; the effective policy remains explicit.accepted150.0 aggressive bpswithin-configured-limits3
Quantity-and-notional failureStep 30 · comparison focusTighten size and notional limits while preserving zero aggressive deviation. Synthetic data; the effective policy remains explicit.rejected0.0 aggressive bpslimit-breached:quantity,notional2

These rows are not backtest observations. They are controlled counterexamples that expose how one driver changes the state, output, or reason code while the rest of the contract stays fixed.

Visualize the boundary

Fat-Finger Limit annotated teaching map

Open this SVG at full size, or use the guided playground to compare the seven topic-specific canonical, boundary, policy, and failure scenarios.

The Mermaid flow answers where the selected calculation sits in the processing sequence. The SVG keeps the formula, output, decision boundary, and invariant visible together. The lab lets the reader step through the same structured states without changing the underlying definition.

Implementation walkthrough

The Python and TypeScript references validate policy identity, price/quantity units, session or remembered state, and the supported mode before applying the control. Both return the decision together with distances, violations, cancellation/prevention events, or trigger state so an operator can reconstruct why the gate acted.

The main implementation branches are:

  • all checks pass — Accept, because Within configured envelope.
  • one or more checks fail — Reject and list all, because Unsafe dimension identified.
  • reference missing/stale — Reject input, because Deviation cannot be reproduced.

Neither reference silently fetches data, mutates caller-owned inputs outside the declared engine behavior, guesses hidden state, or substitutes a provider default. Shared JSON fixtures make value, null, state, and reason-code drift visible across languages.

Testing and validation

Definition tests compare every canonical field, reject malformed state, and exercise the material boundary. Family validation recomputes every playground state from the reference function. Independent arithmetic is recorded beside the fixture rather than inferred only from implementation output.

The audit must preserve these invariants:

  • Notional equals integer price times quantity.
  • Nonaggressive prices have zero aggressive deviation.
  • The combined decision passes only when every check passes.
  • The structured output retains violations, state, policy context, and reason fields.

Passing these checks proves that the deterministic reference matches the selected control contract. It does not certify exchange conformance, regulatory compliance, latency, operational resilience, or the safety of an override.

Failure modes and misuse

  • Passing one control does not imply an order passes every venue, broker, regulatory, credit, position, or market-access check.
  • Reference prices, bands, thresholds, group identifiers, and disconnect ownership must be point-in-time inputs; later values cannot repair an earlier decision.
  • A definition-correct control does not certify production latency, legal compliance, operational resilience, or trading profitability.

Debugging order

When a result looks surprising, inspect the state in this order:

  1. Confirm instrument, venue/product, session, order type, side, and policy ID.
  2. Confirm integer price scale, quantity units, reference or band as-of time, and trigger clock.
  3. Confirm identity/ownership scope, mode, equality rule, threshold ordering, and remembered state.
  4. Recalculate the invariant and the declared scenario focus before changing code.

Evidence and historical boundary

Historical decision: deferred. A named production-control event would require complete point-in-time order, policy-version, reference-data, session, override, acknowledgement, and venue evidence plus redistribution permission. A labeled synthetic fixture is more reproducible and avoids implying a public record proves private control behavior.

The primary sources are Cboe port controls, Cboe U.S. Equities FIX, EU RTS 7. They support the source roles listed in the research ledger, not a redistributable historical observation, a private participant decision, current configuration at an unnamed venue, compliance certification, trading outcome, profitability claim, or prediction claim.

Summary and next topic

You can now diagnose multi-axis pre-trade order risk. The learning flow is: Cancel-on-Disconnect → Fat-Finger Limit → Circuit-Breaker Trigger. Carry the result forward only with its scope, clock, state, and evidence label.

Fat-Finger Limit calculation flow

This flow identifies the selected calculation stages and the structured output.

Rendering system map…

Takeaway: Price, size, and notional are separate failure axes even when they share one accept/reject gate.

ReferencesPrimary sources and evidence notes

Expand the source trail, evidence role, and limitations behind the engineering choices.

S1 — Cboe Titanium U.S. Equities/Options Web Portal Port Controls Specification

S2 — Cboe Titanium U.S. Equities FIX Specification

  • Organization or authors: Cboe Global Markets
  • Source type: Official exchange technical specification
  • Publication or effective date: Current specification accessed 2026-07-30
  • Version: Current online specification
  • URL or DOI: https://www.cboe.com/document/tech-spec/document/technical-specifications/cboe-titanium-u.s.-equities-fix-specification
  • Accessed: 2026-07-30
  • Jurisdiction: Cboe U.S. equities venues
  • Supports: Configurable match-trade-prevention, cancel-on-disconnect variants, purge filters, and fat-finger port attributes.
  • Limitations: Exact availability and behavior depend on venue, port, protocol, capacity, order type, and the current configuration.

S3 — Commission Delegated Regulation (EU) 2017/584

  • Organization or authors: European Commission
  • Source type: Official regulation
  • Publication or effective date: 2016-07-14
  • Version: Consolidated text accessed 2026-07-30
  • URL or DOI: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32017R0584
  • Accessed: 2026-07-30
  • Jurisdiction: European Union trading venues
  • Supports: Instrument-adapted price collars, maximum order value, maximum order volume, monitoring, rejection, and exceptional authorization procedures.
  • Limitations: Does not prescribe the repository's synthetic thresholds or establish compliance outside its scope.

Evidence boundary

The sources establish only the current or historical rule and protocol facts named in each source record. They do not verify the repository-authored orders, policy identifiers, reference values, thresholds, session state, override authority, or output.

order-controls.ts
/* Deterministic reference algorithms for D12-F03 Order Controls. */

type Inputs = Record<string, any>;

function integer(name: string, value: unknown, positive = false, nonnegative = false): number {
  if (typeof value !== "number" || !Number.isInteger(value)) throw new Error(`${name} must be an integer`);
  if (positive && value <= 0) throw new Error(`${name} must be positive`);
  if (nonnegative && value < 0) throw new Error(`${name} must be nonnegative`);
  return value;
}

function text(name: string, value: unknown): string {
  if (typeof value !== "string" || !value.trim()) throw new Error(`${name} must be a nonempty string`);
  return value.trim();
}

function booleanValue(name: string, value: unknown): boolean {
  if (typeof value !== "boolean") throw new Error(`${name} must be boolean`);
  return value;
}

export function tickSizeValidation(
  price_atoms: unknown,
  tick_size_atoms: unknown,
  price_scale: unknown,
  effective_policy_id: unknown,
): Record<string, unknown> {
  const price = integer("price_atoms", price_atoms, true);
  const tick = integer("tick_size_atoms", tick_size_atoms, true);
  const scale = integer("price_scale", price_scale, true);
  const policyId = text("effective_policy_id", effective_policy_id);
  if (tick > price) throw new Error("tick_size_atoms cannot exceed price_atoms");
  const quotient = Math.floor(price / tick);
  const remainder = price % tick;
  const lower = quotient * tick;
  const upper = remainder === 0 ? lower : lower + tick;
  const valid = remainder === 0;
  return {
    effective_policy_id: policyId,
    price_atoms: price,
    tick_size_atoms: tick,
    price_scale: scale,
    valid,
    remainder_atoms: remainder,
    lower_valid_price_atoms: lower,
    upper_valid_price_atoms: upper,
    distance_to_lower_atoms: price - lower,
    distance_to_upper_atoms: upper - price,
    reason: valid ? "on-grid" : "off-grid",
    state: valid ? "accepted" : "rejected",
  };
}

export function priceBandValidation(
  side: unknown,
  limit_price_atoms: unknown,
  lower_band_atoms: unknown,
  upper_band_atoms: unknown,
  band_as_of_ns: unknown,
  inclusive: unknown = true,
): Record<string, unknown> {
  const orderSide = text("side", side).toLowerCase();
  if (!["buy", "sell"].includes(orderSide)) throw new Error("side must be buy or sell");
  const price = integer("limit_price_atoms", limit_price_atoms, true);
  const lower = integer("lower_band_atoms", lower_band_atoms, true);
  const upper = integer("upper_band_atoms", upper_band_atoms, true);
  const asOf = integer("band_as_of_ns", band_as_of_ns, false, true);
  const includeEdges = booleanValue("inclusive", inclusive);
  if (lower >= upper) throw new Error("lower_band_atoms must be less than upper_band_atoms");
  const valid = includeEdges ? lower <= price && price <= upper : lower < price && price < upper;
  let reason = "inside-band";
  let violation = 0;
  if (price < lower || (price === lower && !includeEdges)) {
    reason = "below-lower-band"; violation = lower - price;
  } else if (price > upper || (price === upper && !includeEdges)) {
    reason = "above-upper-band"; violation = price - upper;
  }
  return {
    side: orderSide, limit_price_atoms: price, lower_band_atoms: lower, upper_band_atoms: upper,
    band_as_of_ns: asOf, inclusive: includeEdges, valid,
    distance_from_lower_atoms: price - lower, distance_to_upper_atoms: upper - price,
    violation_atoms: violation, reason, state: valid ? "accepted" : "rejected",
  };
}

export function selfTradePrevention(incoming_order: unknown, resting_orders: unknown, mode: unknown): Record<string, unknown> {
  if (!incoming_order || typeof incoming_order !== "object" || Array.isArray(incoming_order)) throw new Error("incoming_order must be an object");
  if (!Array.isArray(resting_orders)) throw new Error("resting_orders must be an array");
  const incoming = incoming_order as Inputs;
  const selectedMode = text("mode", mode).toLowerCase();
  if (!["cancel_newest", "cancel_oldest", "decrement_both"].includes(selectedMode)) throw new Error("unsupported self-trade-prevention mode");
  const incomingId = text("incoming_order.order_id", incoming.order_id);
  const side = text("incoming_order.side", incoming.side).toLowerCase();
  if (!["buy", "sell"].includes(side)) throw new Error("incoming_order.side must be buy or sell");
  const price = integer("incoming_order.price_atoms", incoming.price_atoms, true);
  const quantity = integer("incoming_order.quantity", incoming.quantity, true);
  const participant = text("incoming_order.participant_id", incoming.participant_id);
  const group = text("incoming_order.stp_group", incoming.stp_group);
  const seen = new Set<string>([incomingId]);
  const parsed = resting_orders.map((raw: any, index: number) => {
    if (!raw || typeof raw !== "object" || Array.isArray(raw)) throw new Error(`resting_orders[${index}] must be an object`);
    const orderId = text(`resting_orders[${index}].order_id`, raw.order_id);
    if (seen.has(orderId)) throw new Error("order identifiers must be unique");
    seen.add(orderId);
    const restingSide = text(`resting_orders[${index}].side`, raw.side).toLowerCase();
    if (!["buy", "sell"].includes(restingSide) || restingSide === side) throw new Error("resting orders must be on the contra side");
    return {
      order_id: orderId, side: restingSide,
      price_atoms: integer(`resting_orders[${index}].price_atoms`, raw.price_atoms, true),
      quantity: integer(`resting_orders[${index}].quantity`, raw.quantity, true),
      participant_id: text(`resting_orders[${index}].participant_id`, raw.participant_id),
      stp_group: text(`resting_orders[${index}].stp_group`, raw.stp_group),
      sequence: integer(`resting_orders[${index}].sequence`, raw.sequence, false, true),
    };
  });
  parsed.sort((a, b) => side === "buy" ? a.price_atoms - b.price_atoms || a.sequence - b.sequence : b.price_atoms - a.price_atoms || a.sequence - b.sequence);
  let remaining = quantity;
  let externalExecuted = 0, prevented = 0, canceledIncoming = 0, canceledResting = 0;
  let stopped = false;
  const events: any[] = [], finalBook: any[] = [];
  for (const original of parsed) {
    const resting = { ...original };
    const marketable = side === "buy" ? resting.price_atoms <= price : resting.price_atoms >= price;
    if (stopped || remaining === 0 || !marketable) { finalBook.push(resting); continue; }
    const sameGroup = resting.participant_id === participant && resting.stp_group === group;
    const matchQty = Math.min(remaining, resting.quantity);
    if (sameGroup) {
      if (selectedMode === "cancel_newest") {
        canceledIncoming = remaining; prevented += matchQty;
        events.push({ action: "cancel-incoming", incoming_order_id: incomingId, resting_order_id: resting.order_id, prevented_quantity: matchQty });
        remaining = 0; stopped = true; finalBook.push(resting);
      } else if (selectedMode === "cancel_oldest") {
        canceledResting += resting.quantity; prevented += matchQty;
        events.push({ action: "cancel-resting", incoming_order_id: incomingId, resting_order_id: resting.order_id, prevented_quantity: matchQty });
      } else {
        resting.quantity -= matchQty; remaining -= matchQty; prevented += matchQty;
        events.push({ action: "decrement-both", incoming_order_id: incomingId, resting_order_id: resting.order_id, prevented_quantity: matchQty });
        if (resting.quantity > 0) finalBook.push(resting);
      }
    } else {
      resting.quantity -= matchQty; remaining -= matchQty; externalExecuted += matchQty;
      events.push({ action: "execute-external", incoming_order_id: incomingId, resting_order_id: resting.order_id, quantity: matchQty, price_atoms: resting.price_atoms });
      if (resting.quantity > 0) finalBook.push(resting);
    }
  }
  const state = prevented ? "self-trade-prevented" : remaining === 0 ? "externally-filled" : "resting-or-residual";
  return {
    mode: selectedMode, incoming_order_id: incomingId, original_incoming_quantity: quantity,
    external_executed_quantity: externalExecuted, prevented_self_quantity: prevented,
    canceled_incoming_quantity: canceledIncoming, canceled_resting_quantity: canceledResting,
    remaining_incoming_quantity: remaining, events, resting_orders: finalBook, state,
  };
}

export function cancelOnDisconnect(
  disconnected_session_id: unknown,
  disconnect_type: unknown,
  trigger_disconnect_types: unknown,
  policy: unknown,
  orders: unknown,
): Record<string, unknown> {
  const session = text("disconnected_session_id", disconnected_session_id);
  const eventType = text("disconnect_type", disconnect_type).toLowerCase();
  if (!Array.isArray(trigger_disconnect_types) || !trigger_disconnect_types.length) throw new Error("trigger_disconnect_types must be a nonempty array");
  const triggers = trigger_disconnect_types.map((item) => text("trigger_disconnect_type", item).toLowerCase());
  const selectedPolicy = text("policy", policy).toLowerCase();
  if (!["cancel_all", "cancel_continuous", "keep_gtc"].includes(selectedPolicy)) throw new Error("unsupported cancel-on-disconnect policy");
  if (!Array.isArray(orders)) throw new Error("orders must be an array");
  const seen = new Set<string>();
  const parsed = orders.map((raw: any, index: number) => {
    if (!raw || typeof raw !== "object" || Array.isArray(raw)) throw new Error(`orders[${index}] must be an object`);
    const orderId = text(`orders[${index}].order_id`, raw.order_id);
    if (seen.has(orderId)) throw new Error("order identifiers must be unique");
    seen.add(orderId);
    const book = text(`orders[${index}].book`, raw.book).toLowerCase();
    if (!["continuous", "auction"].includes(book)) throw new Error("book must be continuous or auction");
    return {
      order_id: orderId, session_id: text(`orders[${index}].session_id`, raw.session_id), book,
      time_in_force: text(`orders[${index}].time_in_force`, raw.time_in_force).toUpperCase(),
      quantity: integer(`orders[${index}].quantity`, raw.quantity, true),
    };
  });
  const triggered = triggers.includes(eventType);
  const canceled: string[] = [], retained: Array<{ order_id: string; reason: string }> = [];
  for (const order of parsed) {
    if (order.session_id !== session) { retained.push({ order_id: order.order_id, reason: "different-session" }); continue; }
    if (!triggered) { retained.push({ order_id: order.order_id, reason: "disconnect-type-not-configured" }); continue; }
    const shouldCancel = selectedPolicy === "cancel_all"
      || (selectedPolicy === "cancel_continuous" && order.book === "continuous")
      || (selectedPolicy === "keep_gtc" && order.time_in_force !== "GTC");
    if (shouldCancel) canceled.push(order.order_id);
    else retained.push({ order_id: order.order_id, reason: order.book === "auction" ? "auction-order-retained" : "gtc-retained" });
  }
  return {
    disconnected_session_id: session, disconnect_type: eventType, triggered, policy: selectedPolicy,
    canceled_order_ids: canceled, retained_orders: retained, canceled_count: canceled.length,
    retained_count: retained.length, state: triggered ? "purge-applied" : "no-purge",
  };
}

export function fatFingerLimit(
  side: unknown,
  limit_price_atoms: unknown,
  reference_price_atoms: unknown,
  quantity: unknown,
  max_quantity: unknown,
  max_notional_atoms: unknown,
  max_aggressive_deviation_bps: unknown,
): Record<string, unknown> {
  const orderSide = text("side", side).toLowerCase();
  if (!["buy", "sell"].includes(orderSide)) throw new Error("side must be buy or sell");
  const price = integer("limit_price_atoms", limit_price_atoms, true);
  const reference = integer("reference_price_atoms", reference_price_atoms, true);
  const qty = integer("quantity", quantity, true);
  const maxQty = integer("max_quantity", max_quantity, true);
  const maxNotional = integer("max_notional_atoms", max_notional_atoms, true);
  const maxDeviation = integer("max_aggressive_deviation_bps", max_aggressive_deviation_bps, false, true);
  const notional = price * qty;
  const signed = orderSide === "buy" ? price - reference : reference - price;
  const aggressiveDeviationBps = Math.max(0, Math.round((signed * 10000 / reference) * 1e6) / 1e6);
  const checks = {
    quantity: { value: qty, limit: maxQty, passed: qty <= maxQty },
    notional: { value: notional, limit: maxNotional, passed: notional <= maxNotional },
    aggressive_deviation_bps: { value: aggressiveDeviationBps, limit: maxDeviation, passed: aggressiveDeviationBps <= maxDeviation },
  };
  const violations = Object.entries(checks).filter(([, check]) => !check.passed).map(([name]) => name);
  return {
    side: orderSide, limit_price_atoms: price, reference_price_atoms: reference, quantity: qty,
    order_notional_atoms: notional, aggressive_deviation_bps: aggressiveDeviationBps,
    checks, violations, valid: violations.length === 0,
    reason: violations.length ? `limit-breached:${violations.join(",")}` : "within-configured-limits",
    state: violations.length ? "rejected" : "accepted",
  };
}

export function circuitBreakerTrigger(
  reference_close_atoms: unknown,
  current_index_atoms: unknown,
  level_thresholds_bps: unknown,
  previously_triggered_level: unknown = 0,
): Record<string, unknown> {
  const reference = integer("reference_close_atoms", reference_close_atoms, true);
  const current = integer("current_index_atoms", current_index_atoms, true);
  const previous = integer("previously_triggered_level", previously_triggered_level, false, true);
  if (previous > 3) throw new Error("previously_triggered_level cannot exceed 3");
  if (!Array.isArray(level_thresholds_bps) || level_thresholds_bps.length !== 3) throw new Error("level_thresholds_bps must contain exactly three thresholds");
  const thresholds = level_thresholds_bps.map((value) => integer("threshold_bps", value, true));
  if (new Set(thresholds).size !== 3 || thresholds.some((value, index) => index > 0 && value <= thresholds[index - 1])) throw new Error("thresholds must be strictly increasing");
  const declineBps = Math.max(0, Math.round(((reference - current) * 10000 / reference) * 1e6) / 1e6);
  let reached = 0;
  thresholds.forEach((threshold, index) => { if (declineBps >= threshold) reached = index + 1; });
  const newlyTriggered = reached > previous;
  const triggerLevel = newlyTriggered ? reached : 0;
  const actions = ["continue", "level-1-halt", "level-2-halt", "level-3-close"];
  const nextThreshold = reached < thresholds.length ? thresholds[reached] : null;
  const distance = nextThreshold === null ? null : Math.max(0, Math.round((nextThreshold - declineBps) * 1e6) / 1e6);
  return {
    reference_close_atoms: reference, current_index_atoms: current, decline_bps: declineBps,
    level_thresholds_bps: thresholds, previously_triggered_level: previous,
    reached_level: reached, newly_triggered_level: triggerLevel, newly_triggered: newlyTriggered,
    action: actions[triggerLevel], next_threshold_bps: nextThreshold,
    distance_to_next_threshold_bps: distance,
    state: newlyTriggered ? "triggered" : reached ? "already-triggered" : "normal",
  };
}

export function calculate(topicId: string, inputs: Inputs): Record<string, unknown> {
  if (!inputs || typeof inputs !== "object" || Array.isArray(inputs)) throw new Error("inputs must be an object");
  if (topicId === "D12-F03-A01") return tickSizeValidation(inputs.price_atoms, inputs.tick_size_atoms, inputs.price_scale, inputs.effective_policy_id);
  if (topicId === "D12-F03-A02") return priceBandValidation(inputs.side, inputs.limit_price_atoms, inputs.lower_band_atoms, inputs.upper_band_atoms, inputs.band_as_of_ns, inputs.inclusive);
  if (topicId === "D12-F03-A03") return selfTradePrevention(inputs.incoming_order, inputs.resting_orders, inputs.mode);
  if (topicId === "D12-F03-A04") return cancelOnDisconnect(inputs.disconnected_session_id, inputs.disconnect_type, inputs.trigger_disconnect_types, inputs.policy, inputs.orders);
  if (topicId === "D12-F03-A05") return fatFingerLimit(inputs.side, inputs.limit_price_atoms, inputs.reference_price_atoms, inputs.quantity, inputs.max_quantity, inputs.max_notional_atoms, inputs.max_aggressive_deviation_bps);
  if (topicId === "D12-F03-A06") return circuitBreakerTrigger(inputs.reference_close_atoms, inputs.current_index_atoms, inputs.level_thresholds_bps, inputs.previously_triggered_level);
  throw new Error(`unsupported topic_id: ${topicId}`);
}
Full-height labplaygroundOpen full screen