wshy
84bc6cb875
Merge pull request #145 from intfoo/feat/index-support
...
自选/监控/个股分析支持指数(asset_type="index")
2026-07-31 19:19:17 +08:00
wshy
b59be65107
Merge pull request #143 from CJ0Hn/feat/watchlist-screenshot-import
...
fix: 自选截图导入优化
2026-07-31 19:11:12 +08:00
wshy
89bb60bdaf
Merge pull request #133 from dunmin1980-ux/cursor/tickflow-pro-rate-limit-p0
...
TickFlow Pro: process-local 80% RPM safety + Phase 1 probe scaffold
2026-07-31 19:08:11 +08:00
wshy
ceb53735b5
Merge pull request #134 from CJ0Hn/fix/numba-parallel-serialize
...
fix: 串行化 Numba parallel 内核,避免策略页并发崩溃
2026-07-31 19:08:07 +08:00
wshy
16077bb13e
Merge pull request #148 from im47cn/fix/test-time-bomb-live-enriched
...
fix(test): 修复 test_live_enriched_metadata 硬编码日期导致的 time-bomb 失败
2026-07-31 19:04:57 +08:00
shy3130
f8fca96f42
修复停复牌股票实时涨跌停漏算
2026-07-30 13:09:07 +08:00
intfoo
865e75fc8b
fix(index): 修复 PR #46 四个阻断项
...
阻断项1: 前端 TypeScript 类型扩展
- MonitorRule.asset_type 加 'index' (api.ts:517)
- screenerStrategies 参数加 'index' (api.ts:1412)
- klineMinute 响应 asset_type 去重 (api.ts:1296)
阻断项2: 指数监控独立评估
- _evaluate_monitors 股票早期 return 降级为 stock_ready 标志
仅跳过股票轮, ETF/指数轮独立判断数据新鲜度
- 纯指数行情/自选场景下指数规则可正常触发
阻断项3: 核心指数模式不截断分区
- _process_full_market_records 按 index_mode 条件分支:
mode=all (完整 CN_Index) → flush 覆盖; mode=core (部分标的) → merge 不截断
- merge_live_enriched_asset 对 index 正确更新 _index_enriched_cache
阻断项4: Free 档额度分批
- _fetch_watchlist_quotes 用 resolve_limit + chunked 按 capability batch 上限分批
- 失败批次跳过不整轮退出, 已有股票实时刷新不受影响
- 复用进程级共享限速器 sleep_between_batches
测试: +7 测试覆盖 4 个阻断项核心场景
2026-07-28 21:13:10 +08:00
im47cn
5f1c1cf0bb
fix(test): replace hardcoded dates with cn_today() in test_live_enriched_metadata
...
test_history_strategy_monitor_keeps_live_row_with_exclude_st_enabled used
date(2026,7,20) as the "today" value, but MonitorRuleEngine.evaluate()
calls cn_today() internally. The date mismatch caused the basic_filter
+ history filter to produce 0 rows, making the test fail 8 days after
it was written.
Also fixes test_live_enriched_cache_keeps_instrument_metadata_without_persisting_it
which used the same hardcoded date — would break on any future run.
Replace all hardcoded dates with cn_today() / cn_today()-timedelta(days=3)
so the tests are timeless.
2026-07-28 09:46:51 +08:00
intfoo
3e6f9bcfb7
fix(index): 后端分钟K隔离加固与规则资产类型纠正
...
- kline.sync_minute_single 对指数 symbol 显式 400 (防污染 kline_minute)
- kline.sync_minute 全市场 universe 剔除指数 symbol
- kline.get_minute 响应新增 asset_type 字段 (3 处 return)
- monitor_rules._reconcile_index_asset_type 纠正误存为 stock 的指数规则
(应用于 save_rule/list_rules/_sync_engine, 混合池不动)
- 文案资产中立化: "个股信号→信号" "指定股票→指定标的" (options label + 校验报错)
- 测试: reconcile 5 断言 + sync_minute_single 拒指数 400 + 分时报错断言同步
2026-07-26 19:59:10 +08:00
intfoo
ed4355e0ea
feat: 指数(asset_type=index)后端接入 — 数据路由/自选enriched/监控指数轮/隔离防污染
...
- 数据路由: get_name_map 合并指数维表; get_enriched_latest_asset("index") 缓存+flush/merge 分支; daily-batch 按资产分组
- 自选: watchlist_enriched 指数分支 + 行级 asset_type 标注
- 监控: MonitorRuleEngine 第三轮指数评估 (signal/price); 指数实时焐热复刻 ETF flush; Free档自选实时资产分流; 规则校验 (禁 strategy/market/ladder/分时信号)
- 隔离: _resolve_universe 过滤指数防污染股票日K/分钟K; 指数轮 reset_strategy_results=False; 策略/回测/screener 零改动
- AI 分析: prompt 指数无财务文案
2026-07-26 18:35:31 +08:00
shy3130
b43b177899
feat(monitor): add strategy signal event controls
2026-07-26 16:08:42 +08:00
CJohn
e526d25fd0
fix(ocr): 完善截图导入的安全限制与交互状态
...
- 在 Pillow 完整解码前检查图片像素数,并将 DecompressionBombError
转为明确的参数错误,避免压缩大图在校验前占用过多内存
- 为 OCR 线程任务设置独立的 AnyIO CapacityLimiter(2),最多同时执行
两次图片解码与 Tesseract 识别,其余请求排队等待
- 前端调用 ocr-status 检查 Tesseract 是否可用;不可用时禁用截图导入
入口,并按 Windows、macOS 和 Linux 显示对应安装说明
- 关闭弹窗或重新选择图片时取消旧请求,并通过请求代次校验忽略迟到
的异步结果,防止旧候选回写到新弹窗
- 禁用已存在于自选列表中的候选项,批量添加接口返回实际净新增数量,
成功提示使用后端返回值
- 补充图片类型与大小校验、解压炸弹、OCR 状态、并发限制以及批量添加
数量等测试
2026-07-26 12:19:55 +08:00
CJohn
33921fcc51
fix: 串行化 Numba parallel 内核,避免策略页并发崩溃
...
并发 run_all 会触发 workqueue Concurrent access,导致后端进程中断。
为 matrix parallel 内核加进程锁,前端对 run_all 做 pending 去重。
2026-07-26 11:56:10 +08:00
shy3130
6d7092089c
fix(data-source): harden custom source testing
2026-07-25 22:51:27 +08:00
shy3130
96fcbe4fff
fix(data-source): validate custom request settings
2026-07-25 22:13:38 +08:00
wshy
fffd89fce0
Merge pull request #138 from intfoo/feat/custom-source-timeout-param-ui
...
自定义数据源超时与请求参数名支持前端配置
2026-07-25 22:01:11 +08:00
intfoo
99b0c6cb35
fix(index-quotes): compute change_pct for custom data source
...
Custom data source realtime quotes were missing change_pct because _build_index_quotes only kept pre-existing columns. TickFlow path computes it in _fetch_full_market_quotes, but custom source path bypasses that computation.
- _build_index_quotes computes change_pct/change_amount from last_price/prev_close when not provided by the source
- guards prev_close=0 (Polars produces inf, invalid JSON)
- aligns with TickFlow path and _fallback_index_quotes_from_daily
2026-07-24 11:35:19 +08:00
intfoo
a15d0468cc
feat(data-source): expose custom source timeout & request param names in UI
...
- backend: pass timeout through DatasetConfigIn / _config_to_dict / _sanitize_dataset
(previously a hand-set YAML timeout was silently wiped on UI save, resetting to 30s)
- frontend: add per-dataset timeout input; collapsible 请求参数字段映射 with
symbols/start/end_param (non-realtime) + asset_type/freq_param (minute);
rename 字段映射 -> 响应参数字段映射; chevron at title end; realtime empty-state hint
- test: timeout config round-trip (custom value persists, default 30 not emitted)
- docs: document timeout in custom-data-source.md
2026-07-23 16:22:18 +08:00
shy3130
60fe9e6fa6
修复回测指标数据缺失提示问题
2026-07-22 13:30:02 +08:00
shy3130
2d9fe4a4af
修复策略文件无法删除问题
2026-07-22 11:21:13 +08:00
shy3130
2c14fde788
完善个股点位提醒并发布0.1.87
2026-07-21 22:14:07 +08:00
shy3130
72918fe602
优化策略卡片结果加载性能
2026-07-20 13:01:03 +08:00
shy3130
0635698a08
修复策略监控开启后结果归零
2026-07-20 11:12:19 +08:00
shy3130
e1dbd1cafb
修复监控中心涨跌停信号误报
2026-07-20 10:33:06 +08:00
shy3130
4df3062002
fix: 完善自定义分钟数据源配置与异常处理
...
- 补齐资产类型和周期参数在 API、YAML 与前端编辑器中的保存回读
- 权限判断和分时监控统一复用安全的数据源解析边界
- 增加配置往返及解析异常回归测试
2026-07-19 17:01:33 +08:00
shy3130
b1b2494db9
merge: 合并 PR #128 自定义分钟数据源支持
2026-07-19 16:52:52 +08:00
shy3130
b17c882e27
feat: 完善历史换手率重算入口
...
- 财务数据统计纳入历史股本,并在数据页提供分批重算入口
- 缺少股本历史时阻止重算,并接入现有任务进度
- 财务分析卡片使用更新图标,明确数据拉取语义
2026-07-19 16:42:03 +08:00
intfoo
d9a77a534a
fix(minute): 承接 #122 review 三处阻断问题整改 + resolver 异常边界加固
2026-07-19 16:00:22 +08:00
intfoo
4c85f99633
fix(minute): 自定义分钟数据源用户单股补拉/监控页整改 (承接 #121 review)
2026-07-19 13:35:35 +08:00
intfoo and shy3130
e2ffde99d5
fix(minute,monitoring): 自定义数据源用户单股补拉/监控页打通 ( #121 )
...
承接 #126 : 能力探测已补 KLINE_MINUTE_BATCH, 但两处取数/UI 仍按 TickFlow
档位拦截, 配了自定义分钟/实时源的 None 档用户依旧被挡。
- kline_sync.fetch_minute_single: 与 sync_minute_batch 一致, 先查
preferences.get_minute_data_provider(), 非 tickflow 且自定义源有
minute dataset 时走 custom provider, 避免分时图首次打开(本地无数据)
补拉返回空。
- Monitoring.tsx: None 档但配了自定义实时源时, 后端
is_realtime_allowed(realtime_mode=full_market) 仍返回 True。
以 quoteStatus.realtime_allowed 作为最终判据, 不再用 isNoneTier
一刀切拦截实时监控页。
Co-authored-by: shy3130 <shy3130@users.noreply.github.com >
2026-07-19 13:26:52 +08:00
dunmin1980 and Cursor
431550859f
fix: align Phase 1 probe with TickFlow SDK namespaces
...
Use klines.batch/quotes.get, rename dry-run status to DRY_RUN_OK, document
first-batch burst limits, and cover run_live with a fake client.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-19 10:06:26 +08:00
dunmin1980 and Cursor
6cb7f9f50c
chore: drop probe debug instrumentation and ignore probe artifacts
...
Keep the Phase 1 CLI production-clean; local probe reports and debug NDJSON stay out of git.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-19 09:36:55 +08:00
dunmin1980 and Cursor
cafa03fb52
feat: add TickFlow Pro Phase 1 probe scaffold with off-peak gate
...
Dry-run by default; live calls require a key and wait until 16:00 Asia/Shanghai unless --force, so Stage A off-peak probing stays intentional.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-19 09:36:55 +08:00
dunmin1980 and Cursor
0745fdbb7d
fix: apply process-local 80% TickFlow rpm safety budget
...
Scale resolve_limit rpm by SAFETY_RPM_FACTOR and document that the
in-process slot limiter is not a cross-container account budget.
Keep Stage A isolation via off-peak A-share usage guidance.
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-07-19 09:36:55 +08:00
shy3130
8e4258cf20
feat: support historical price limits and share capital
2026-07-18 23:37:54 +08:00
shy3130
e462c63b45
fix: align AI strategy prompt constraints
2026-07-18 18:31:02 +08:00
shy3130
44ab51e65d
feat: improve strategy scoring and backtest execution
2026-07-18 16:59:53 +08:00
shy3130
a1e8be58db
feat: release v0.1.86
2026-07-18 00:49:28 +08:00
shy3130
34eaba3010
fix: handle uncovered walk-forward folds
2026-07-17 14:00:16 +08:00
shy3130
c763a6970f
fix: restore strategy and data compatibility
2026-07-16 14:34:07 +08:00
lytem28
b6cf0495e1
feat: complete matrix-native backtest engine
...
Unify strategy execution across backtest, screener, and monitoring; isolate backtest workloads in spawn workers; and add shared matrix caching plus valid-bar indicator acceleration.
2026-07-16 12:17:27 +08:00
ChenJunheng
0d6b341945
fix(watchlist): 采纳 #94 审查 — 防大图 OOM、OCR 不阻塞事件循环、收紧图片类型
...
为截图预处理增加像素上限与长边降采样;import-image 将 OCR 放入线程池;
去掉任意 image/* 放行,仅允许白名单 MIME/扩展名。
2026-07-15 23:28:30 +08:00
ChenJunheng
6f084e1b29
feat(watchlist): 支持从券商自选截图批量导入
...
基于 Tesseract OCR 识别六位代码并校验证券主数据,前端提供导入确认弹窗;
修复批量添加后 enriched 缓存未刷新导致需手动刷新页面的问题。
2026-07-15 23:25:46 +08:00
shy3130
77876c7ee4
fix(data): avoid destructive enriched rebuild cleanup
2026-07-15 21:34:44 +08:00
shy3130
f317377bef
fix(strategy): apply saved params to builtin screeners
2026-07-15 20:06:11 +08:00
shy3130
89115e6f73
fix(strategy): apply saved parameters during execution
2026-07-15 19:03:48 +08:00
wshy and shy3130
963092384f
fix(capabilities): 自定义分钟数据源补 KLINE_MINUTE_BATCH 能力 ( #126 )
...
issue #121 : 用户配了自定义分钟数据源, 但分时图/自动同步/回测等功能
仍提示"需 Pro+"。根因: 能力探测(detect_capabilities)只探测 TickFlow
API Key 档位, 不感知用户本地配的自定义数据源。
修复:
- capabilities.py: CapabilitySet 加 grant() 方法 (不覆盖已有能力)
- policy.py: detect_capabilities 拆成 _detect_tickflow_caps (原逻辑不动)
+ _augment_custom_sources (探测完检查自定义分钟源, 有的话补能力)
补能力后所有 capset.has(KLINE_MINUTE_BATCH) 检查自动通过; 取数函数
内部仍按 preferences.get_minute_data_provider() 分流到自定义源,
不会错误调用 TickFlow。前端读后端返回的 capabilities, 无需改动。
Co-authored-by: shy3130 <shy3130@users.noreply.github.com >
2026-07-14 22:27:03 +08:00
wshy and shy3130
2f762b3bcc
fix(strategy): import 白名单加 datetime + date 参数处理补进文档 ( #123 )
...
问题: ai_single_yang_unbroken 策略用 from datetime import date 做
date 类型参数转换, 被安全修复的 import 白名单(只允许 polars)拦截,
策略加载失败消失。同时 date 列(Polars Date)与字符串参数直接比较
报 InvalidOperationError 导致 500。
修复:
- ai_generator.py: import 白名单加入 datetime (纯日期运算, 无文件/
网络/进程能力, 安全)。验证 os/sys/subprocess 仍被拦。
- strategy-guide.md: params type 补全(float/int/bool/select/date);
filter_history 要点新增 date 参数必须 fromisoformat 转换的代码示例
- strategy-guide-compact.md: 同步补充 (AI 运行时实际用的文档)
从源头避免 AI 生成的 date 类型参数策略再犯字符串 vs Date 列比较错误。
Co-authored-by: shy3130 <shy3130@users.noreply.github.com >
2026-07-14 21:47:26 +08:00
wshy and shy3130
f470e46f2b
fix(security): 策略代码 RCE 漏洞三层修复 ( #122 )
...
漏洞链 (安全研究员 Aeon 报告):
1. StrategyCodeSaveRequest.strict 由客户端控制, 传 false 完全跳过安全校验
2. AST 名单只拦 ast.Name 直接调用, dunder 遍历可绕过
((lambda:0).__globals__["__builtins__"]["__import__"]("os"))
3. _load_file 用 exec_module 执行策略文件, 执行侧零校验
=> 未认证局域网用户可写入任意代码并立即执行 (RCE)
修复:
- strategy.py: 移除 strict 字段, 安全校验无条件执行 (第1层)
- ai_generator.py: _validate_safety 加固, 拦截 dunder 属性访问
(__globals__/__builtins__/__class__/__subclasses__ 等) 和字符串下标
访问 (第2层)
- engine.py: _load_file 在 exec_module 前读文件内容跑一次 _validate_safety,
防止策略文件被直接篡改绕过 API 校验 (第3层 纵深防御)
前端: api.ts 移除 strict 参数, StrategyBuilderDialog/StrategyPoolDialog
移除 strict:true 传参 (前端本就全部传 true, 行为不变)
验证: PoC 三种攻击 payload 全部拦截, 正常策略(只import polars)无误杀
Co-authored-by: shy3130 <shy3130@users.noreply.github.com >
2026-07-14 21:32:39 +08:00
wshy and shy3130
0fba9eb57b
chore: 版本号升至 0.1.85 ( #119 )
...
Co-authored-by: shy3130 <shy3130@users.noreply.github.com >
2026-07-14 18:54:17 +08:00