Skip to content

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 04 Sep 17:38
· 3 commits to main since this release

v0.2.1

Breaking Changes

  • A real-chain dexdo seller asks the on-chain ModelRegistry whether the name it is about to list exists, and refuses before it deploys an order book or posts an offer when the registry does not carry it. This runs on the default path: it no longer needs --model-registry-validation, which used to be the only way any catalog question was asked at all. Pass the new --allow-unverified-model to list a name the registry does not confirm, or to go on when the registry cannot be read; it is the same flag provision and deploy-market already carry. The flag does not cover a name the registry holds under a different spelling: that is refused either way, with the registered spelling named.
  • The refusal on a secret file that users other than its owner can read now stands in front of every path that reads one. Newly covered: the note pool named by --pool or DEXDO_PN_POOL, which holds an owner key for every note in it; the note deploy recovery file; and the recovery phrase this client stores during wallet onboarding. The wallet secret file is now checked before it is classified rather than after, so a refusal no longer happens with the secret already in memory. On Unix-like systems any group or other permission bit refuses the command before anything is read; run chmod 600 on the file the message names and repeat the command. Windows exposes no file mode and is unchanged.

New / Improvements

  • Real-chain commands work with nothing configured. With DEXDO_MANIFEST unset the client reads the sole per-user default, $HOME/.dexdo/manifest.json on Linux/macOS or %USERPROFILE%\.dexdo\manifest.json on Windows. Both installers copy the archived mainnet manifest there, verify it is a file, and replace it with a warning on every reinstall so updated pins cannot leave an old default behind. The variable still wins wherever it is set, and a path it names that does not exist is refused rather than falling back. The working directory, executable directory, XDG locations and directory scans are never consulted.
  • market, executable-book, quote, orders and subscription resolve a model name against the on-chain ModelRegistry and no longer require a local models.json. Until now the catalog was the default authority and the chain was consulted only when --model-registry-validation switched it on, so a user with no catalog could not ask what a registered market was; orders had no registry path at all. Where a catalog exists it is still read, as a source of your own nicknames: a name it does not know is taken as the model itself, and where it maps a name elsewhere the registry decides. markets without --market still lists the books of the models in your own catalog -- the only one of these questions a local file can answer -- and its refusal now says that, names the file it wanted, and points at markets address --model for the single-model case that needs no file.
  • market and quote say when nothing has been listed under a name instead of printing an empty table. The line goes to standard error, so --json output is unaffected, and it names the order-book address the ModelRegistry derives for that name so a misspelling is visible.
  • dexdo --version names the build it came from: the package version, then the git short hash and commit date of the tree it was built from, or an explicit (unknown) for a build made outside a checkout. The line still starts with dexdo <version>, so installers and scripts that read the version off the front keep working. -V prints the short form.
  • dexdo doctor now reports checks as they complete, separates skipped checks, ends with the overall verdict, and offers a stable --json health report for automation.
  • The released archive carries models.example.json -- a filled-in shape with placeholders to copy and edit -- in place of the working models.json it used to ship, which named our own provider, model and key variable and stopped resolving when that provider retired the model. Nothing loads the example under that name; the catalog the client reads by default is still models.json, and it is yours to write.
  • The seller's gateway TLS identity is kept in the operating system's secret store where the platform has one that holds a secret until something deletes it: Keychain on macOS, Credential Manager on Windows. Elsewhere, including a headless Linux server, it stays an owner-only file at exactly the path it has always used. An identity written by an earlier version is still found either way, so a restarted seller presents the certificate its buyers already pinned. DEXDO_SECRET_STORE=system or =file picks a branch deliberately. The permission check on that file now runs before the read, and accepts any owner-only mode instead of 0600 alone, so a stricter 0400 is no longer refused.

Fixes

  • Vault-to-Hot funding no longer makes every pending request block every later top-up. The client
    reuses a live request only when its native and currency amounts exactly match the current
    shortfall; a different shortfall creates another request. The owner-only funding journal now
    lists every live request with its UTC creation and expiry timestamps and removes unexecuted
    entries older than one hour when it creates a new request. A transfer that already left the Vault
    remains protected from an identical second submission until the Hot shows its credit, even after
    the original queue deadline; once credited, it no longer blocks a later request of the same size.
  • Every command that reads the note pool finds the pool this client wrote. With no --pool, no --data-dir and no DEXDO_PN_POOL the readers stopped short of the platform data directory that note deploy writes to, so on a default install dexdo note list answered that the instance had deployed no notes while the pool sat on disk minutes after it was created, the picker that offers a note when --note-addr is omitted had nothing to offer, and pool-based recovery found no records. That location is now consulted last -- after the flag, the data directory and the variable, none of which change what they resolve to -- and only when the file is actually there, so an instance with no pool still says so, against the right path.
  • dexdo settlement-receipt no longer reports every live deal as inconsistent. It read four deal fields the deployed contract has not declared since generation 4.0.31, so the decode failed on every real deal, the receipt recorded current_getter_shape_invalid, and both the terminal and withdrawal statuses came back inconsistent whatever the deal had actually done. The deal state now comes from the same strict decoder the rest of the client uses, pinned to the compiled ABI, and a shape refusal names the field that was missing instead of only saying that something was. In the receipt JSON the current.state object reports probe_tick, tokens_final, tokens_pending, probe_time and last_claim_time in place of the removed prepaid, frozen, prepaid_time and last_advance; the terminal-state check requires the two escrow earmarks to be zero and no longer demands that of the cumulative delivery counters, which a settled deal keeps by design.
  • One transient server error no longer ends a command that has already spent. The exact-hash receipt read behind note deploy and the message reads behind the multisig delivery proof went straight to the endpoint, so a single 502 from the edge ended the run after the wallet spend had been submitted and left it to be reconciled by hand. Both now repeat like every other chain read in this client -- up to 5 attempts within 45 seconds, with backoff -- and a failure that is not transient still ends the command at once. These are queries: nothing is submitted, so nothing can be submitted twice.