Skip to content

openport 0.2.1

Choose a tag to compare

@38st 38st released this 27 Sep 07:59

openport 0.2.1

Built from a03ece0.

Install

  • Docker (amd64 and arm64): docker run --rm -p 127.0.0.1:8080:8080 -v openport:/var/lib/openport ghcr.io/38st/openport:0.2.1, then open the link it prints, which carries its write token; or docker build -t openport . from this tag.
  • Linux archives (amd64 and arm64): need OpenSSL 3, zlib and zstd (apt install libssl3t64 zlib1g libzstd1 on Ubuntu 24.04). Unpack one and run bin/openportd.
  • macOS archive (Apple silicon): needs nothing installed. Unpack it with tar -xzf and run bin/openportd. Unpacked in Finder, macOS may refuse to run it as from an unidentified developer; xattr -dr com.apple.quarantine on the folder allows it.

Then open http://127.0.0.1:8080. openportd --help lists every option. SHA256SUMS covers every archive.

What's new since 0.2.0

The account keeps trading

  • No more stale-quote lockouts. Cboe resends only quotes that changed, so a held option whose quote sat still for a minute went stale and blocked every order, closes included. Each snapshot poll now ends with a mark that keeps unchanged quotes current. An underlying whose source runs a minute or two behind the others stays tradable within the stall tolerance. A far wing with no bid (0.00 / 0.05) is marked halfway to its ask and valued at its ask IV instead of blocking the account. After an overnight gap the account waits for the day's first complete snapshot. Holding an iron condor through a demo day, 0.2.0 refused 81 of 125 probe orders as stale; this release refused none of 265, and its marks stayed current throughout.
  • A reduce-only kill switch. A daily-loss or manual trip leaves the account able to close: closing orders, Flatten, bracket exits and the system's closes keep working, while orders that open or add exposure reject.
  • 0DTE stays selected in the chain until its auto-close, with a countdown.

Trading and risk

  • Plan-locked limits and personal guardrails. During an evaluation a limit can be tightened at once, and loosened only from the next day. Optional guardrails: a soft floor, a daily trade cap, a cooldown after a stop-out, and a daily profit lock.
  • Order preview. POST /api/orders/preview, and the tickets, show buying power, the change in Greeks and the maximum loss against the floor, with "Size to floor".
  • Strategy templates: verticals, iron condors and butterflies, strangles, straddles, calendars and diagonals, chosen by delta, points or expected move. Probability of profit now includes the skew term.
  • Good-till-cancelled orders, tags and notes on orders, and brackets on spreads.
  • Chain liquidity: session volume, spreads as a share of the mid, and liquidity warnings on tickets.

Review and practice

  • Trade review: the market and account at every fill, MAE and MFE, R-multiples, day notes, and CSV exports of trades and fills.
  • Replay: 14 scenario days with fresh seeds, drills that start at a chosen time, replay accounts kept in their own journals, and openportd --verify-run to check that a run reproduces exactly.
  • Playbooks: versioned setups that stage orders through the preview, run automatically in replays, and track adherence and pass odds.
  • Brief: one page to read before the bell.

Data and analytics

  • Volatility: model-free implied volatility by the VIX method, skew, realized volatility, implied moves, IV rank and percentile, and the variance risk premium, with a local history (--series-dir, --backfill-series).
  • Tradier and tastytrade market data. These are market-data-only adapters, not yet run live with an account; reports are welcome.
  • An OpenAPI contract, a Python client and an MCP server, with named tokens scoped to read, trade, replay or admin, and the actor recorded on every journal transaction.

Security and reliability

  • DNS rebinding blocked. Every request must address the server by an IP address, localhost, or a name you allow with --allowed-host.
  • Docker trades out of the box. The container keeps a write token in its volume and prints a link that saves it in your browser tab. CI now checks that the image fills an order.
  • Durable journal. On macOS it uses the full sync that survives a power loss. It stops before a full disk can tear it, openportd --repair-journals cuts off a torn last line and keeps the original, and transactions that change nothing are no longer written.
  • HTTP: API keys are not sent on redirects to other hosts, and a timed-out request is not retried. Cboe's timeout is 15 seconds, so one slow symbol no longer stalls the rest.
  • ThetaData snapshots are stamped with their data's time instead of the wall clock.
  • CI now runs the tests under AddressSanitizer and UndefinedBehaviorSanitizer with leak detection, and checks the Python client and the API contract.
  • The macOS archive runs without Homebrew.

Every commit since v0.2.0

  • Docker: give the web type check the shared template parity fixture
  • Build: include where pass odds throw, and brace a test loop's assertion
  • Tests: wait for the account's view of the seeded quotes before a preview purity check
  • Playbooks: versioned setups, staged and replay-automatic orders, adherence and pass odds
  • API: a checked OpenAPI contract, a Python client and MCP server, scoped tokens and actors
  • Brief: one page to read before the bell
  • Build: include for std::exchange, and read JSON values explicitly
  • Volatility: a local history, IV rank and percentile, and the ex-post variance risk premium
  • Replay: a thread-free desk, reproducible runs, --verify-run and stepping
  • Chain: session volume, spreads and liquidity warnings
  • Tests: brace an assertion GCC flags as a dangling else
  • Providers: Tradier and tastytrade market data
  • Build: unhide MetricsSource's account overload in two subclasses
  • Floor: plan-locked limits, personal guardrails, order preview, breach risk and intraday equity
  • Replay: a speed chosen while paused applies when play resumes
  • Journal: trade review with context at every fill, excursions, CSV and day notes
  • Replay: a scenario library, fresh seeds, drills from a start time, and kept journals
  • Orders: good-till-cancelled, tags on orders, and exits on spreads
  • Volatility: model-free IV, skew, realized volatility and implied moves
  • CI: silence GCC's false bounds warnings in sanitizer builds
  • Launch kit: a landing page, and a guide to writing a provider adapter
  • Tickets: probability of profit with skew, and strategy templates
  • Version 0.2.1
  • Trust fixes: a reduce-only kill switch, 0DTE until its auto-close, sanitizers in CI
  • Docs: count 532 C++ tests
  • Journal: survive power loss and a full disk, and repair a torn line
  • Docs: count 530 C++ and 295 web tests
  • ThetaData: stamp a snapshot with its data's time, not the wall clock
  • Journal: a transaction that changed nothing leaves no record
  • Docker: trade from the link the container prints
  • HTTP: keep keys on their origin, and give up on a slow response sooner
  • Web: refuse requests addressed by a DNS-rebinding name
  • Tests: rename a lambda's local that GCC flags as shadowing its parameter
  • Tools: a demo-day soak test for fills and freshness
  • Docs: count 524 C++ tests
  • Marks: a wing nobody bids for no longer blocks the account
  • Docs and Rules page: say what the simulator does
  • Freshness: a complete snapshot keeps unchanged quotes current
  • macOS: a release archive that runs without Homebrew
  • README: the roadmap lists 0.2.0's slippage, portfolio margin, cash dividends, IWM and DIA, and Cboe's new host
  • Analytics: an underlying waits for its first price instead of the wall clock