# Wallet cache, tutorial and position-flow review

Codex Astra reviewed the My Wallet historical cache, inline borrowing tutorial, and position-specific Borrow/Repay/Roll review flows on 2026-09-14. Applied both sink/source and skip-token tracing after reading the repository review guide and lessons. No remaining concrete blocker was found in the reviewed read-only implementation. This does not approve transaction signing or future live wiring.

## Finding resolved

The first roll validator required both source and destination to be open. `ThetaCattlePair.rollTo` does not prohibit a stopped source; its remaining assets and debt can still be rolled. The validator now accepts a verified source with either known boolean trading status while requiring an open, unexpired, unstarted destination. A regression test covers stopped-source acceptance and unknown-status refusal. The borrow preview's unsupported closed-position restriction was also removed after checking `approveCreditDelegation` in the contract source.

## Independent evidence

- Ran the existing model, portfolio-cache, wallet and position-flow test files successfully.
- Exercised the actual portfolio consumer with the real cache codec in a local DOM/dependency harness: a cache hit still starts discovery; cached cards never invoke risk reads or order presentation; address changes and wallet checking/wrong-chain transitions clear historical cards and invalidate old work; late completions cannot save or repaint; failed refreshes retain historical-only cards without renewing storage; explicit retry and a successful empty portfolio heal the cache.
- Exercised the actual position-dialog consumer in a local DOM/dependency harness: an old delayed close event cannot cancel a reopened dialog; an old timeout aborts only its captured controller; a stale discovery cannot initiate risk reads; amount/asset and destination edits clear reviewed results; account/revision invalidation aborts late risk work without repainting.
- Independently checked debt review with 0.25 base at $2,400 plus 600 quote, distinct 80%/90% liquidation thresholds and 70%/80% LTV limits. Adding 0.125 base of debt changes debt from $300 to $600 and HF from 3.4 to 1.7, with collateral fixed at $1,200 and capacity fixed at $900. Full quote-debt repayment produces no finite HF without changing supplied holdings.

## Cache and async invariants

Cache schema/config versions and scope keys include wallet, chain, contract generation, pool, deployment anchor and account scale. Snapshot block/hash/timestamp are historical data, not discovery watermarks. Successful complete live snapshots alone can be saved; omitted account readings remain absent. The age stamp and data are written together. Reads never renew age, duplicate scopes become misses, and forged higher cached blocks cannot prevent fresh replacement. Seven-day, five-wallet and byte limits only govern historical display/storage.

Portfolio revisions, captured owner/mode eligibility and final context checks guard storage and DOM writes. `lastIdentity` deduplicates wallet-state handling, not successful discovery; explicit refresh resets it. Discovery/request and risk work have abort deadlines, and RPC deadlines extend through body reads. Existing discovery/index anchors remain separate from the wallet cache. Seen sets or partial failures cannot produce a cacheable complete snapshot after an unsuccessful position read.

Wallet bridge/connect single-flight state is bounded and released on failure; generations and provider/read revisions reject obsolete completions. Saved connector labels never certify account identity. Cached `source` is explicitly consumed before risk, orders or action links; cached positions remain unverified and omit live-capability fields.

Dialog operation versions, captured portfolio revision/account/network and operation-local controllers are rechecked after asynchronous discovery and reserve reads and before local review. Delayed close events are ignored while a newly opened dialog is active. Field edits invalidate their displayed review immediately. No review button sends a transaction.

## Tutorial and flow semantics

The inline tutorial values collateral/debt at its separate example market price, not the strike. Its 75% LTV, 80% liquidation threshold and $1 quote assumptions are disclosed. Borrowed proceeds leave the position; legacy examples remain readable; saving uses immutable reviewed inputs. Example-ID deduplication happens after validation, and storage denial is reported distinctly.

Borrow/Repay account review uses current supplied holdings and each reserve's LT/LTV; it does not substitute the hedge-rebalanced chart account. Roll validation checks authenticated source/destination, owner, distinct address, matching factory/pool/assets, destination expiry/open status and zero destination notional. The UI identifies the remaining transfer/simulation/activation steps and keeps wallet signing unavailable. Collateral-based borrowing capacity is not a guarantee of executable borrowing.

No browser, RPC, signing or transaction operation was performed by this review. This evidence file is the only file written for the combined review; runtime code was not edited.
