Skip to content

feat(token-2022) PR 2: let Token-2022 orders into the auction - #5003

Merged
squadgazzz merged 31 commits into
mainfrom
solana-autopilot/be-338-let-token-2022-orders-into-the-auction
Oct 2, 2026
Merged

squadgazzz merged 31 commits into
mainfrom
solana-autopilot/be-338-let-token-2022-orders-into-the-auction

Conversation

@squadgazzz

@squadgazzz squadgazzz commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

With #5002 the driver settles Token-2022 mints, so the autopilot can let their orders into the auction. It still has to keep out the mints the settlement program can't move. The program pays out with a plain Transfer, which Token-2022 rejects for any mint with a transfer fee, transfer hook or pausable extension, whatever its settings, and for non-transferable mints. PYUSD is one of them, with a zero fee and no hook program.

Today the autopilot parses mints and token accounts with the classic SPL layout only. An order buying a Token-2022 token drops because its buy account doesn't parse. Nothing checks the sell mint, so an order selling PYUSD joins every auction and fails at settlement until it expires.

This PR parses both programs with StateWithExtensions and gives each mint a verdict: the token program that moves it, or why the settlement program can't. An order on a mint with a bad verdict drops with a Filtered event. Verdicts are cached in memory for a minute, since the same mints repeat from one auction to the next. The TTL is short because a freeze authority can flip the default account state. The mints without a cached verdict join the existing buy account lookup, so the check adds no RPC round trip. The rule and its cache live in a new solana-token crate, which the orderbook (#5004) uses at quoting and placement.

Parsing extensions has two side effects. xStocks carry the scaled UI amount extension: wallets show the raw balance times an issuer-set multiplier, and CoinGecko prices the shown unit, so these mints skip CoinGecko and the next price source prices them. Nothing is affected today, since every such mint also has an extension that keeps it out. Mints with a permanent delegate pass. Their issuer can move the balance our buffer keeps between settlements, retained fees included, but not a trade in flight. BE-344 tracks that decision.

The PR merges after #5002 is deployed.

Changes

  • Mints and token accounts of both token programs parse with StateWithExtensions, so Token-2022 buy accounts are receivable and mints with extensions get decimals
  • An order drops with a Filtered event when its sell or buy mint has a transfer fee, transfer hook or pausable extension (paused or not), is non-transferable, or starts its accounts frozen
  • A buy account that requires incoming memos or refuses credits outside its confidential balance is unreceivable, since the payout carries no memo and lands in the regular balance
  • Mint verdicts are cached in memory for a minute, so each auction reads only the mints without one
  • Scaled UI amount mints skip CoinGecko
  • New solana-token crate with the mint rule, its cache and the buy account check, for the orderbook to share
  • New unsettleable_mint reason on the filtered_orders gauge from solana-autopilot: log why orders are left out of an auction #5000

How to test

New unit tests, updated DB test fixture. Needs a barn run before merge: settle a sell and a buy of a plain Token-2022 token, and check that a PYUSD order stays out of auctions with a Filtered event.

Related issues

BE-338

tilacog and others added 22 commits September 25, 2026 15:11
Every order the branch would keep costs the winning solver's keypair the
rent for an account its owner can close right after the fill, and no
engine prices that rent in yet. The expression stays next to the TODO so
turning it on is one edit.
"Only the owner's ATA can be created" is a domain rule, but it sat in the
blockchain adapter, which had to pull in `domain::Order` to apply it. The
adapter is back to handing out classified account states only.
Reinstates the filter 47b4494 removed. The autopilot's cut drops these
orders too, but it fails open when its own lookup fails, and then one
such order takes down the whole settlement it lands in.
The flag is a per-solve annotation, so carrying it on the domain order
forced every constructor and test fixture to set it. The resolution now
returns the uids and the DTO builder looks them up.
Every solver engine this driver hosts receives the same auction, so each
of them paid for its own getMultipleAccounts round trip in front of the
engine call. One shared slot now serves them all, and the engines that
arrive while the lookup is in flight wait for its result.
The paragraph on ResolvedSettlement was the only place describing the
whole instruction order; it comes back with the buy ATAs among the setup
accounts. The DTO TODOs now point at setupCostLamports, which keeps the
rent math out of the engines, and the openapi says what happens to an
order whose destination cannot be created.
This is the one place the solver keypair pays rent for someone else, and
the owner can close the account for the lamports right after the fill, so
the cost needs to be countable.
…token-accounts-for-solvers' into solana-autopilot/be-331-let-native-sol-buys-into-the-auction

# Conflicts:
#	crates/autopilot-svm/src/infra/provider.rs
@linear-code

linear-code Bot commented Sep 30, 2026

Copy link
Copy Markdown

BE-338

Base automatically changed from solana-autopilot/be-331-let-native-sol-buys-into-the-auction to main September 30, 2026 18:11
@squadgazzz squadgazzz changed the title solana-autopilot: let Token-2022 orders into the auction feat(token-2022) PR 2: let Token-2022 orders into the auction Oct 1, 2026
@squadgazzz
squadgazzz marked this pull request as ready for review October 1, 2026 17:38
@squadgazzz
squadgazzz requested a review from a team as a code owner October 1, 2026 17:38
@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @squadgazzz's task in 3m 3s —— View job


PR Review: let Token-2022 orders into the auction

I reviewed the diff against origin/main — the new solana-token crate, the autopilot-svm provider.rs/prices.rs changes, and the test/testlib updates.

Verdict: this looks solid and well-tested. No correctness or security issues found. The mint-verdict rule, the shared buy-account/mint lookup, the cache lifetimes, and the CoinGecko scaled-UI skip all match the behavior the description promises, and the unit tests cover the interesting cases (per-extension verdicts, cache reuse, missing mints, native-SOL buys, source fallback).

A few things I specifically checked that are not problems:

  • The combined buy_accounts.chain(lookup.unread()) lookup is safe at any size — SolanaRPC::multiple_accounts already .unique()s and chunks by MAX_MULTIPLE_ACCOUNTS, so duplicates and the 100-account getMultipleAccounts cap are handled.
  • settleable_orders can never miss a verdict: lookup/resolve is built from the same token_mints(order) the filter re-reads, so every mint is present.
  • A failed account lookup fails open (keeps all orders) and try_join_all means no partial cache poisoning.
  • receivable_token_account accepting either token program while requiring state.base.mint == mint is fine — a cross-program account/mint pairing can't exist on chain.

One minor, non-blocking note posted inline: a first-seen mint gets fetched twice per cut (verdict cache + price MintInfo cache). Cheap in steady state and a reasonable cross-crate tradeoff — just flagging for later.
· branch solana-autopilot/be-338-let-token-2022-orders-into-the-auction

Comment thread crates/autopilot-svm/src/infra/provider.rs
…38-let-token-2022-orders-into-the-auction

# Conflicts:
#	crates/solana-testlib/src/lib.rs
@squadgazzz
squadgazzz enabled auto-merge October 2, 2026 18:04
@squadgazzz
squadgazzz added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit e7e2c1b Oct 2, 2026
23 checks passed
@squadgazzz
squadgazzz deleted the solana-autopilot/be-338-let-token-2022-orders-into-the-auction branch October 2, 2026 18:26
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants