Skip to content

Resolve multi-outcome Pyth brackets, add data-flow review checklist, and fix security contact - #1662

Merged
hman38705 merged 4 commits into
solutions-plug:mainfrom
rudeus112266:drips/1545-1562-1563-1564
Sep 28, 2026
Merged

hman38705 merged 4 commits into
solutions-plug:mainfrom
rudeus112266:drips/1545-1562-1563-1564

Conversation

@rudeus112266

Copy link
Copy Markdown

Summary

Resolve multi-outcome Pyth brackets, add data-flow review checklist, and fix security contact

What was solved

#1545 — Pyth-based oracle resolution only ever returns a binary outcome (0 or 1)

Fix Pyth-based oracle resolution so it no longer silently collapses multi-outcome markets to a binary 0/1 result. The chosen approach is to extend determine_outcome to support multiple price brackets/strike thresholds for multi-outcome markets, while preserving the existing binary behavior for 2-outcome markets, and to add a test covering a 3-outcome market's interaction with Pyth-based resolution.

Addressed:

  • Changed: contracts/predict-iq/src/modules/oracles.rs
  • Extend oracles::determine_outcome (contracts/predict-iq/src/modules/oracles.rs) to support multi-outcome markets via multiple price brackets/strike thresholds instead of only returning 0 or 1.
  • Preserve existing binary (above/below strike) behavior for markets with 2 options so current resolution semantics are unchanged.
  • Ensure resolve_with_pyth correctly selects outcome indices >= 2 for markets with 3+ options when price data falls in the appropriate bracket.

#1562 — docs/data-flow.md GDPR/privacy compliance doc has no reviewed-by/last-verified date, unlike architecture.md

Add a review/ownership and staleness-control section to docs/data-flow.md so the GDPR/privacy-scoped document gains a last-reviewed date, named owner/team, and a PR checklist (mirroring docs/architecture.md) that triggers updates when new PII-bearing fields, tables, or third-party data sharing are introduced; verify the doc against the current services/api/database/migrations/*.sql schema as part of the change.

Addressed:

  • Changed: docs/data-flow.md
  • docs/data-flow.md must gain a "Last reviewed" date and a named owner/team.
  • docs/data-flow.md must gain a checklist or CI reminder mirroring docs/architecture.md's PR checklist, prompting updates when new PII-bearing fields, tables, or third-party data sharing are introduced.
  • The doc must be verified once against the current services/api/database/migrations/*.sql schema as part of closing the issue.

#1563 — SECURITY.md security@predictiq.io contact address is unverifiable and undocumented elsewhere

Update SECURITY.md to replace the unverifiable security@predictiq.io mailbox with a verifiable contact method (GitHub Security Advisories, which is the standard monitored channel for a GitHub-hosted project), and cross-reference the same contact from CONTRIBUTING.md so the reporting path is documented in more than one place.

Addressed:

  • Changed: SECURITY.md, CONTRIBUTING.md
  • Replace the unverifiable security@predictiq.io email in SECURITY.md with a verified, monitored contact method — GitHub Security Advisories via the repo's /security/advisories/new URL is the only channel confirmable from the repo itself.
  • Update SECURITY.md so the reporting instructions reflect the verified contact method and remove the unverifiable mailbox reference.
  • Cross-reference the verified contact method from CONTRIBUTING.md (or docs/README.md) so the security contact is not a single point of documentation failure.

#1564 — docs/CONTRACT_ERRORS.md has no generation/sync mechanism against contracts/predict-iq/src/errors.rs, unlike API_SPEC.md

Add a sync/verification mechanism so docs/CONTRACT_ERRORS.md cannot drift from contracts/predict-iq/src/errors.rs, mirroring how API_SPEC.md is generated/checked. Implement a lightweight Node script that parses error variants/codes from errors.rs and diffs them against the markdown table in CONTRACT_ERRORS.md, wire it into CI, and document the mechanism at the top of the doc.

Addressed:

  • Changed: docs/CONTRACT_ERRORS.md, contracts/predict-iq/src/errors.rs
  • Add a CI check or lightweight script that diffs contracts/predict-iq/src/errors.rs variants/codes against the table in docs/CONTRACT_ERRORS.md and fails on mismatch
  • Document the chosen sync mechanism at the top of docs/CONTRACT_ERRORS.md (analogous to API_SPEC.md's 'do not edit directly' marker)
  • Keep the existing 61 error variants/table intact — do not renumber, reword, or remove entries

Changes

  • docs/data-flow.md (modify)
  • docs/CONTRACT_ERRORS.md (modify)
  • contracts/predict-iq/src/modules/oracles.rs (modify)
  • CONTRIBUTING.md (modify)
  • SECURITY.md (modify)
  • contracts/predict-iq/src/errors.rs (modify)

Approach

  1. Pyth-based oracle resolution only ever returns a binary outcome (0 or 1) #1545 — Pyth-based oracle resolution only ever returns a binary outcome (0 or 1) (Changed: contracts/predict-iq/src/modules/oracles.rs)
  2. docs/data-flow.md GDPR/privacy compliance doc has no reviewed-by/last-verified date, unlike architecture.md #1562 — docs/data-flow.md GDPR/privacy compliance doc has no reviewed-by/last-verified date, unlike architecture.md (Changed: docs/data-flow.md)
  3. SECURITY.md security@predictiq.io contact address is unverifiable and undocumented elsewhere #1563 — SECURITY.md security@predictiq.io contact address is unverifiable and undocumented elsewhere (Changed: SECURITY.md, CONTRIBUTING.md)
  4. docs/CONTRACT_ERRORS.md has no generation/sync mechanism against contracts/predict-iq/src/errors.rs, unlike API_SPEC.md #1564 — docs/CONTRACT_ERRORS.md has no generation/sync mechanism against contracts/predict-iq/src/errors.rs, unlike API_SPEC.md (Changed: docs/CONTRACT_ERRORS.md, contracts/predict-iq/src/errors.rs)

Issues

Closes #1545
Closes #1562
Closes #1563
Closes #1564

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@rudeus112266 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@hman38705
hman38705 merged commit 54df6f7 into solutions-plug:main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment