v1.5.0
Pool prices decoded from a float sqrt ratio were wrong, and this fixes them.
The ekubo.sqrt_ratio_float_to_q128 codec reimplemented the SqrtRatio layout
locally and split it at the wrong widths — a 7-bit exponent over an 89-bit
mantissa, shifted by exponent + 2, where the encoding is a 2-bit exponent over
a 94-bit mantissa shifted by 2 + 32 * exponent. The two agree only when
mantissa bits 89..=93 happen to be zero, so a pool that cleared them decoded
correctly and every other one returned a plausible but wrong number instead of
an error. On mainnet, USDC/USDG at tick -165 read as
22775868403039233396916548160160193078693462016 against an on-chain sqrt ratio
of 340254383154770049453632155902269194240. The layout now comes from
ekubo_sdk rather than a second copy of the arithmetic.
A fresh install now keeps every ranked RPC endpoint. default_networks
truncated each network's list to a single URL, so a configuration nobody had
tuned started with no failover: one public provider going down took the whole
network with it until the owner hand-edited the file. Networks are seeded with
the full ranked list from the vendored registry — six endpoints for Ethereum,
seven at most for any default — and an endpoint that cannot be built is now
dropped from the attempt order instead of failing the network outright.
Every address the wallet shows is in EIP-55 checksum case. The Accounts
page, transaction and signature reviews, receipt effects, automation dry-run
rows, and ERC-7730 token labels rendered bare lowercase hex while other screens
were already checksummed, so one account could read two ways in one session.
Agents get the same spelling through MCP — lowercasing a checksummed address is
free, recovering the checksum takes a keccak the agent may not have. Hashed
canonical forms, storage keys, and dapp-facing JSON-RPC payloads deliberately
keep their lowercase bytes, so no stored digest or in-flight approval changes.
Linux owner authentication installs itself. polkit reads action definitions
only from root-owned /usr/share/polkit-1/actions, which an AppImage cannot
write, so on a fresh install every owner operation — signing, key export,
account removal, policy widening — failed with one sentence naming a path to
copy by hand as root. Settings now carries an Owner authentication section
that offers to install the policy through polkit's own pkexec action, with the
definition streamed to install(1) over standard input so nothing depends on a
path root can read. Immutable distributions and NixOS, where that directory is
not writable or not there, are told which file their own tooling has to layer
rather than being handed a command that cannot work. The .deb maps the policy
into the actions directory at package install and needs no setup at all.
Also in this release: the third-party notices are regenerated for the current
dependency graph, and dependencies move up a point release.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.