The eight Convert cron jobs
Every scheduled job Instant Convert registers, how often it runs, which four keep running while the addon is disabled or unlicensed because they finish work a convert already started, and which four start new work and stop.
All eight are registered in the core scheduler under the category convert
from the first release, and appear on System → System Monitoring →
Scheduled Tasks (/admin/system/cron). They run in the platform's cron
process: with it down, no Send is paid, no fill is booked and no quote expires.
The split
The jobs fall into two kinds, and the difference decides what happens when you switch the addon off or its licence lapses.
- Finishing jobs complete work a convert already started: paying and
confirming a Send, booking a hedge fill the exchange has already made,
following a house movement already submitted. They are flagged
returnsCustomerMoney, they do not check the licence, and they keep running while the addon is disabled or unlicensed. A lapsed licence must never strand a customer's held value, and an unbooked fill would show in the pool-backing reconciliation as drift against customer money. Only thestopEverythingflag on the extension status request stops them. - Start-new jobs begin work. The scheduler itself checks only whether the extension is enabled, so each of these also checks, at the point of work, that the addon is enabled, licensed, and (unless noted) not draining. Every one of those checks fails closed.
| Job | Title on the cron screen | Every | Kind | Runs in drain |
|---|---|---|---|---|
convertQuoteCleanup |
Expire Convert Quotes | 5 minutes | start-new | yes |
convertSendPayout |
Pay Convert & Send Payouts | 30 seconds | finishing | yes |
convertSendConfirm |
Confirm Convert & Send Payouts | 30 seconds | finishing | yes |
convertHedgeCycle |
Convert Hedge Dispatch | 15 seconds | start-new | yes, reducing only |
convertHedgeBook |
Book Convert Hedge Fills | 15 seconds | finishing | yes |
convertRebalanceCycle |
Plan Convert House Movements | 5 minutes | start-new | no |
convertRebalanceVerify |
Verify Convert House Movements | 1 minute | finishing | yes |
convertPnlSweep |
Sweep Convert Profit | 1 hour | start-new | no |
What each one does
convertQuoteCleanup marks open quotes past their expiry as expired (the
execute already refuses them by the clock; this keeps the table and the console
truthful), closes quoting of a currency with unacknowledged pool-backing drift,
and at most every 30 minutes re-registers the house's Ecosystem deposit addresses
with the scanner so on-chain funding keeps being credited. Moves no money.
convertSendPayout pays each due Send from the house's own address,
recording every transaction before it is broadcast, one runner at a time. See
Sends.
convertSendConfirm follows broadcast Sends to finality, books a confirmed
one exactly once, fails a reverted one into its reversal, retries reversals that
have not landed, moves a Send the chain cannot account for to review, and alerts
the admins who can act.
convertHedgeCycle beats every 15 seconds. Every run measures exposure and
writes the snapshot the dashboard, the caps and the disable check read, whatever
the hedge mode. A run plans (in Monitor only mode it records what it would
send; in Automatic mode it dispatches) only when
convertHedgeIntervalSeconds has passed since the last run that planned, a time
kept in Redis; at the default of 15 that is every run.
See Hedging.
convertHedgeBook books each dispatched hedge's fill, with the fee the venue
actually charged, exactly once. It also settles hedges that stall:
- A market order still open after 5 minutes is cancelled and read back; one still open after that goes to review.
- An order the venue cannot be asked about for 30 minutes goes to review, as does one sent to an exchange provider the platform no longer trades on, and one with no exchange order id that cannot be found by its client order id.
- A hedge whose dispatcher stopped before sending the order is marked failed after 2 minutes, because nothing was ordered.
- An order that ended with nothing filled is marked failed and counts toward the currency's failures in a row.
A hedge in review freezes its currency until it is resolved.
convertRebalanceCycle writes the movement plan every run, even while
movements are off, and claims and dispatches only when every switch is open. See
Movements.
convertRebalanceVerify follows submitted movements until the coins have
arrived and been credited, and books their costs. A claim still not dispatched
after 10 minutes is marked failed with its hold restored, since nothing was
sent. So is a movement the exchange refused or cancelled, and a chain →
exchange dispatch that stopped before signing anything. A movement whose outcome
it cannot prove goes to review. Among the cases:
- an exchange → chain dispatch that stopped 30 minutes ago after the exchange may have been asked, when no withdrawal can be adopted;
- an indeterminate withdrawal request still not adopted after 30 minutes;
- a signed hash the chain has not seen 30 minutes after signing;
- a movement sent to an exchange provider the platform no longer trades on;
- anything still unproven after 72 hours.
convertPnlSweep works out realised profit per currency for each finished UTC
day and, when the sweep is on, pays it to the Super Admin, once per day and no
earlier than 00:10 UTC the next day. It runs hourly rather than daily because the
scheduler has periods only and a daily period would land at 00:00, before the
ten-minute settling margin, and sweep each day a full day late. See
Profit & loss.
Single runners
The jobs that do work hold a Redis lease so only one process runs each at a time. The hedge and movement cycles' leases fail closed: without a lease, no new work starts. The Send payout and confirmation leases, and the movement verifier's, fail open, because every row they touch is still claimed one at a time with a conditional update, so two runners can never pay or book the same thing twice, and a Redis blip must not strand a customer's payout.
Stopping the finishing jobs too
When you switch the addon off in the Extension Manager with anything still in
flight, the request is refused with a list of what is outstanding, and the switch
stays on. The Extension Manager has no button to confirm or to stop everything.
Both are fields of the status request itself:
PUT /api/admin/system/extension/<productId>/status, which needs
edit.extension. Send {"status": false, "acknowledgeInFlight": true} to
disable anyway, and the finishing jobs keep running. Add "stopEverything": true
to stop the finishing jobs as well. Use it only when those jobs are themselves
the fault: with them stopped, Sends are neither paid nor reversed and fills are
not booked until you enable the addon again, which clears the stop.