LP clients and deposits are bound to one machine, but liquidity is fleet-wide #45
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found while scoping the cassette-sync work (aiolabs/bitspire#105 / ADR-004), asking whether a confirmed LP deposit should update a machine's cassette count. It should not — but the reason exposed a mismatch worth recording.
The mismatch
An LP's deposited cash can be drawn from any machine in the fleet. The balance calculation already reflects that:
get_client_balancesums confirmed deposits and completed payments byclient_idonly, with no machine dimension (crud.py:1275-1295).But the schema binds both clients and deposits to a single machine:
dca_clients.machine_id TEXT NOT NULL, withUNIQUE (machine_id, user_id)(migrations.py:112,:121)dca_deposits.machine_id TEXT NOT NULL(migrations.py:160)So one LP operating across two machines is two client rows with two separate balances, and a deposit is recorded against whichever machine the cash happened to arrive at.
Why it is not simply removable
The binding is load-bearing in two places, so this is not dead weight:
_deposit_owned_by(views_api.py:610-617) resolves deposit → machine →operator_user_idto decide whether the caller may touch it. Same pattern for clients atviews_api.py:592. Remove the column and there is no path from a deposit to its operator.machine = await get_machine(client.machine_id); currency = machine.fiat_code(crud.py:1297-1299). Clients inherit their machine's currency.api_create_depositalso enforces thatclient.machine_id == data.machine_id(views_api.py:625-630), so the two bindings must agree.Why it matters later, not now
With one machine per operator the mismatch is invisible. It starts to bite as a fleet grows:
Options, not yet chosen
operator_user_idso authorization no longer travels through a machine, and makemachine_idnullable provenance. Currency then belongs to the operator or the client, not the machine.No action needed for the current fleet. Filing so the next person to touch LP balances knows the binding is authorization and currency, not scope.