feat(token-2022) PR 2: let Token-2022 orders into the auction - #5003
squadgazzz merged 31 commits into
Conversation
…issing-buy-token-accounts-for-solvers
…issing-buy-token-accounts-for-solvers
Every order the branch would keep costs the winning solver's keypair the rent for an account its owner can close right after the fill, and no engine prices that rent in yet. The expression stays next to the TODO so turning it on is one edit.
"Only the owner's ATA can be created" is a domain rule, but it sat in the blockchain adapter, which had to pull in `domain::Order` to apply it. The adapter is back to handing out classified account states only.
Reinstates the filter 47b4494 removed. The autopilot's cut drops these orders too, but it fails open when its own lookup fails, and then one such order takes down the whole settlement it lands in.
The flag is a per-solve annotation, so carrying it on the domain order forced every constructor and test fixture to set it. The resolution now returns the uids and the DTO builder looks them up.
Every solver engine this driver hosts receives the same auction, so each of them paid for its own getMultipleAccounts round trip in front of the engine call. One shared slot now serves them all, and the engines that arrive while the lookup is in flight wait for its result.
The paragraph on ResolvedSettlement was the only place describing the whole instruction order; it comes back with the buy ATAs among the setup accounts. The DTO TODOs now point at setupCostLamports, which keeps the rent math out of the engines, and the openapi says what happens to an order whose destination cannot be created.
This is the one place the solver keypair pays rent for someone else, and the owner can close the account for the lamports right after the fill, so the cost needs to be countable.
…token-accounts-for-solvers' into solana-autopilot/be-331-let-native-sol-buys-into-the-auction # Conflicts: # crates/autopilot-svm/src/infra/provider.rs
…38-let-token-2022-orders-into-the-auction
…nfidential-only buy accounts
…38-let-token-2022-orders-into-the-auction
… mint and buy account filters
…38-let-token-2022-orders-into-the-auction
|
Claude finished @squadgazzz's task in 3m 3s —— View job PR Review: let Token-2022 orders into the auctionI reviewed the diff against Verdict: this looks solid and well-tested. No correctness or security issues found. The mint-verdict rule, the shared buy-account/mint lookup, the cache lifetimes, and the CoinGecko scaled-UI skip all match the behavior the description promises, and the unit tests cover the interesting cases (per-extension verdicts, cache reuse, missing mints, native-SOL buys, source fallback). A few things I specifically checked that are not problems:
One minor, non-blocking note posted inline: a first-seen mint gets fetched twice per cut (verdict cache + price |
…38-let-token-2022-orders-into-the-auction # Conflicts: # crates/solana-testlib/src/lib.rs
Description
With #5002 the driver settles Token-2022 mints, so the autopilot can let their orders into the auction. It still has to keep out the mints the settlement program can't move. The program pays out with a plain
Transfer, which Token-2022 rejects for any mint with a transfer fee, transfer hook or pausable extension, whatever its settings, and for non-transferable mints. PYUSD is one of them, with a zero fee and no hook program.Today the autopilot parses mints and token accounts with the classic SPL layout only. An order buying a Token-2022 token drops because its buy account doesn't parse. Nothing checks the sell mint, so an order selling PYUSD joins every auction and fails at settlement until it expires.
This PR parses both programs with
StateWithExtensionsand gives each mint a verdict: the token program that moves it, or why the settlement program can't. An order on a mint with a bad verdict drops with aFilteredevent. Verdicts are cached in memory for a minute, since the same mints repeat from one auction to the next. The TTL is short because a freeze authority can flip the default account state. The mints without a cached verdict join the existing buy account lookup, so the check adds no RPC round trip. The rule and its cache live in a newsolana-tokencrate, which the orderbook (#5004) uses at quoting and placement.Parsing extensions has two side effects. xStocks carry the scaled UI amount extension: wallets show the raw balance times an issuer-set multiplier, and CoinGecko prices the shown unit, so these mints skip CoinGecko and the next price source prices them. Nothing is affected today, since every such mint also has an extension that keeps it out. Mints with a permanent delegate pass. Their issuer can move the balance our buffer keeps between settlements, retained fees included, but not a trade in flight. BE-344 tracks that decision.
The PR merges after #5002 is deployed.
Changes
StateWithExtensions, so Token-2022 buy accounts are receivable and mints with extensions get decimalsFilteredevent when its sell or buy mint has a transfer fee, transfer hook or pausable extension (paused or not), is non-transferable, or starts its accounts frozensolana-tokencrate with the mint rule, its cache and the buy account check, for the orderbook to shareunsettleable_mintreason on thefiltered_ordersgauge from solana-autopilot: log why orders are left out of an auction #5000How to test
New unit tests, updated DB test fixture. Needs a barn run before merge: settle a sell and a buy of a plain Token-2022 token, and check that a PYUSD order stays out of auctions with a
Filteredevent.Related issues
BE-338