Skip to content

Instructions

Every handler in #[program]. Marked πŸ” = permissionless crank (any signer may advance it); πŸ”’ = authority-gated; πŸ“– = read-only.

Instruction Args Signer Semantics Errors
health β€” caller Liveness probe; emits HealthChecked{version:1}. β€”
initialize_pause β€” authority One-time init of AccordState singleton; caller becomes pause authority. β€”
πŸ”’ pause β€” authority Instant freeze; clears any pending unpause. NotPauseAuthority, AlreadyPaused
πŸ”’ propose_unpause β€” authority Arms unpause at slot + UNPAUSE_TIMELOCK_SLOTS. NotPauseAuthority, NotPaused, ArithmeticOverflow
πŸ” execute_unpause β€” caller Lands unpause once notice slot passes; no authority check. NoPendingUnpause, UnpauseTimelockNotElapsed
create_subaccord domain_ref, evidence_spec, staking_token, fee_token, min_stake, min_jury_size, alpha_bps, review_window, commit_window, reveal_window, appeal_window, max_appeals, aggregation, coherence_tol_bps, reveal_threshold_bps, shortfall_policy, max_draw_attempts, fee_per_juror, authority, evidence_operator, juror_credential, juror_schema creator Permissionless pool init. domain_ref != [0;32]. max_appeals <= MAX_APPEALS. appeal_window >= MIN_APPEAL_WINDOW_SECS (ADR-0022). coherence_tol_bps <= 10_000 (0–10_000; Median coherence band, inert for Plurality, immutable β€” ADR-0025). juror_credential/juror_schema both-or-neither: both default β‡’ stake-only; a half-bound pool reverts (ADR-0024). InvalidOptions, MaxAppealsLimitExceeded, AppealWindowTooShort, InvalidThreshold, AttestationBindingPartial
stake amount, leaf_path + attestation (remaining_accounts[0] on gated pools) juror SPL transfer juror→vault; credits real delta (fee-on-transfer safe). First stake (0→+) appends a leaf, assigns tree_index, increments staker_count. Verifies leaf_path vs accumulator root; recomputes root (O(log N)). Gated pool (ADR-0024): the juror's SAS attestation is supplied in remaining_accounts[0]; credential/schema/wallet must match and (unless expiry==0 ⇒ never expires) it must outlive the max dispute lifecycle. ProgramPaused, InvalidAmount, InvalidMembershipProof, ArithmeticOverflow, AttestationMissing, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationExpired
unstake amount, leaf_path juror PDA-signed vault→juror. Full unstake (+→0) zeros the leaf, decrements staker_count. Never halted by pause. Verifies leaf_path vs accumulator root; recomputes root. InvalidAmount, StakeLocked, InsufficientBalance, InvalidMembershipProof, ArithmeticOverflow
πŸ” prune_juror leaf_path + expired attestation (remaining_accounts[0]) caller Gated pools only (ADR-0024). Permissionless crank evicting a Juror whose attestation has a real expiry (!= 0) that has passed (≀ now) β€” the juror does NOT sign. Mirrors request_withdraw for the full staked: zeros the leaf, recomputes the root, banks tokens into pending_withdrawal, decrements staker_count. Requires no outstanding slash_reserve (⇔ no in-flight draws). AttestationMissing, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationNotExpired, PendingSettlement, WithdrawalPending, InvalidAmount, InsufficientBalance, InvalidMembershipProof, ArithmeticOverflow
πŸ”’ propose_subaccord_update nonce, payload: UpdatePayload authority Writes PendingUpdate; executable after UPDATE_TIMELOCK_SLOTS. ImmutableSubaccord, Unauthorized, ArithmeticOverflow
πŸ” execute_subaccord_update β€” caller Applies timelocked payload to Subaccord; closes PendingUpdate. TimelockNotElapsed
create_dispute options: Vec<[u8;32]>, evidence_hash, nonce, fee filer Arbitrable CPI entry. Custodies (min_jury_size + 1) Β· fee_per_juror (the extra unit banks into the flip-bounty pool dispute.bounty_pool, ADR-0030 β€” refundable via claim_filing_bounty if never appealed). Requires staker_count >= min_jury_size. Options gate (ADR-0025): Plurality disputes pass 2..=8 (MAX_OPTIONS) option hashes; Median (scalar) disputes pass none β€” the vote is a u64 fixed-point value. Does not freeze the root (capital stays live). ProgramPaused, InvalidOptions, FeeMismatch, InsufficientJurors, ArithmeticOverflow
πŸ” request_vrf β€” caller CPI into VRF oracle if committed_vrf.is_none(). One-shot. VrfAlreadyCommitted
commit_vrf_callback randomness: [u8;32] vrf_program_identity Stores VRF result and freezes dispute.frozen_root = subaccord.root. Only the VRF program can call (identity-constrained). VrfAlreadyCommitted
πŸ” draw_seat seat_index, membership: JurorMembership + subaccord (+ attestation remaining_accounts[1] on gated pools) caller Verifies MST membership + sortition (prefix ≀ r_i < prefix + stake) vs frozen_root + inflation guard; active_draws += 1; fills one seat of Round. The drawn juror's JurorStake is remaining_accounts[0]. Gated pool (ADR-0024): the subaccord account is now passed (read-only) and the juror's SAS attestation rides in remaining_accounts[1] for a defense-in-depth freshness re-check (expiry==0 or expiry > now). One seat per tx; deterministic sampling without replacement. InvalidState, InvalidPanelSize, VrfNotCommitted, InvalidMembershipProof, InsufficientStake, SortitionMismatch, DuplicateJuror, InflatedStake, ArithmeticOverflow, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationExpired
commit commitment: [u8;32] juror commitment = hash(vote_le8 β€– salt β€– juror_pubkey) β€” the vote (option index or scalar) hashed as an 8-byte little-endian u64 (ADR-0025). Window: review_end ≀ now < commit_end. InvalidState, CommitWindowClosed, NotDrawnJuror, CommitAlreadyExists, ArithmeticOverflow
reveal vote: u64, salt juror Recomputes hash(vote_le8 β€– salt β€– juror_pubkey); stores the vote. Gate by aggregation (ADR-0025): Plurality vote < num_options; Median vote != u64::MAX (no-reveal sentinel β€” any other u64 fixed-point scalar passes). Window: commit_end ≀ now < reveal_end ∨ all committed (panel-full commit flips to Reveal early). InvalidState, InvalidVote, RevealWindowClosed, NotDrawnJuror, CommitMissing, AlreadyRevealed, RevealMismatch, ArithmeticOverflow
πŸ” finalize_round β€” caller After reveal_end (or once all jurors revealed), quorum met: tally per terms.aggregation β€” Plurality: modal option index, a top-count tie (β‰₯2 options share the max) β†’ non-decisive round β†’ RedrawEligible (ADR-0026); Median: median of revealed scalars (even reveal-count β†’ upper middle, sorted[n/2]) β€” write result (ADR-0025), β†’RoundResolved. Quorum shortfall or tie β†’ RedrawEligible (ADR-0021). InvalidState, RoundNotFinalizable
πŸ” finalize_dispute β€” caller After appeal window: slashes incoherent (Ξ±Β·min_stake), distributes the round's ENTIRE fee pot to the final-ruling-coherent (ADR-0029 β€” base fees + forfeited no-flip bonds; round 0's pot leaves fee_paid), decrements active_draws, writes final_ruling, β†’Final. InvalidState, AppealWindowOpen, InvalidPanelSize, InvalidMembershipProof, ArithmeticOverflow
appeal β€” appellant Permissionless. Pays N_newΒ·fee_per_juror + bond (== new fee). current_round++, β†’Created. ProgramPaused, InvalidState, MaxAppealsReached, AppealWindowClosed, InsufficientJurors, ArithmeticOverflow
πŸ” claim_appeal_refund round_idx caller Returns a flipped bond to its appellant after Final. Idempotent (zeroes on payout). InvalidState, InvalidMembershipProof, InvalidAmount
πŸ“– get_ruling β€” caller Returns Option<u64> (None until Final; then the winning option index for Plurality, the final median for Median β€” ADR-0025). β€”

UpdatePayload variants (append-only, borsh variant-index stable β€” ADR-0028): MinStake, AlphaBps, ReviewWindow, CommitWindow, RevealWindow, AppealWindow, MaxAppeals, FeePerJuror, Authority, EvidenceOperator, RevealThresholdBps, MaxDrawAttempts.

See: state machine, accounts, errors. Draw trust chain in sortition & VRF.