Skip to content

feat(buy-sol) PR 7: reject a native SOL buy to a wallet the System Program does not own - #4995

Closed
squadgazzz wants to merge 1 commit into
solana-orderbook/be-332-sponsored-native-sol-buysfrom
solana-orderbook/native-buy-wallet-check
Closed

squadgazzz wants to merge 1 commit into
solana-orderbook/be-332-sponsored-native-sol-buysfrom
solana-orderbook/native-buy-wallet-check

Conversation

@squadgazzz

Copy link
Copy Markdown
Contributor

Description

Stacked on #4990.

A token buy proves its payout account can receive through the mandatory buy token account creation in the bundle. A native SOL buy has no such step, so #4990 accepts a native buy to any address. The autopilot (#4989) only lets native buys whose wallet is missing or owned by the System Program into a cut. Lamports paid to a program or a sysvar revert the settlement, and a program-owned account strands them. So an order paying a token account or a PDA passes placement, then gets dropped from every cut. It reads open until it expires, and the user never sees an error.

Placement now looks the wallet up once through the sponsoring RPC and applies the autopilot's rule. A failed lookup answers 500, like the blockhash check next to it.

Changes

  • Sponsored placement rejects a native SOL buy to an account the System Program doesn't own as InvalidNativeBuy

How to test

New API test.

@github-actions

Copy link
Copy Markdown

Reminder: Please consider backward compatibility when modifying the API specification.
If breaking changes are unavoidable, ensure:

  • You explicitly pointed out breaking changes.
  • You communicate the changes to affected teams (at least Frontend team and SAFE team).
  • You provide proper versioning and migration mechanisms.

Caused by:

@squadgazzz squadgazzz closed this Sep 29, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
@squadgazzz
squadgazzz deleted the solana-orderbook/native-buy-wallet-check branch September 29, 2026 11:50
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant