feat(solana): add swap_v2 without the deprecated whitelist account - #22
Open
vigaash-cb wants to merge 3 commits into
Open
vigaash-cb wants to merge 3 commits into
vigaash-cb wants to merge 3 commits into
Conversation
`swap` still carries the deprecated `whitelist` PDA at account index 12 so callers that encode the pre-deprecation account list keep working (#21). Anchor's instruction discriminator depends only on the instruction name, so the account list of `swap` cannot change without breaking those callers. Add `swap_v2`: same arguments, same validation and fee logic, same account order and constraints, minus the `whitelist` slot (15 accounts instead of 16). Both handlers delegate to a shared `do_swap` body via a `SwapAccounts` view so the two cannot drift. `swap` is unchanged and will be removed in a follow-up once all live callers have confirmed cutover to `swap_v2`. Tests build both instructions by hand with explicit account lists and verify: legacy discriminator and 16-account layout are unchanged; swap_v2 accepts the 15-account layout with identical balance effects; each rejects the other's layout; both enforce the fee-recipient address constraint, min_amount_out > 0, pause_swaps, and charge the fee in from_mint. Co-authored-by: Toshi <toshi-noreply@coinbase.com>
✅ Heimdall Review Status
|
Co-authored-by: Toshi <toshi-noreply@coinbase.com>
denys-cb
reviewed
Oct 2, 2026
denys-cb
reviewed
Oct 2, 2026
…account test - README: list swap_v2 under Core Instructions and note the deprecated whitelist slot kept in the legacy swap layout. - tests: the legacy-swap 15-account rejection test passed on any error; assert the specific InvalidProgramId Anchor raises (slot 13 is read as token_program and holds the Associated Token program).
denys-cb
reviewed
Oct 2, 2026
| ); | ||
| Ok(()) | ||
| /// `swap` without the deprecated `whitelist` account. Same args, logic, and effects. | ||
| pub fn swap_v2(ctx: Context<SwapV2>, amount_in: u64, min_amount_out: u64) -> Result<()> { |
There was a problem hiding this comment.
We need to update CSA logic to correctly index swap_v2 txs before Flipcash switches
denys-cb
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
swapstill carries the deprecatedwhitelistPDA at account index 12 so callers that encode the pre-deprecation account list keep working (#21). Anchor's instruction discriminator depends only on the instruction name, so the account list ofswapcannot change without breaking those callers.This PR adds
swap_v2: same arguments, same validation and fee logic, same account order and constraints, minus thewhitelistslot (15 accounts instead of 16).swapis left untouched.Changes
lib.rsswapmoves verbatim into a privatedo_swap(&SwapAccounts, ..).SwapandSwapV2each project ontoSwapAccounts, so both instructions share one body and cannot drift.swap_v2handler andSwapV2<'info>accounts struct:Swapwith thewhitelistfield removed, everything else unchanged.swap/Swapunchanged apart from doc comments noting the legacy instruction will be removed in a follow-up once callers have cut over.tests/stable-swapper.ts: newSwap V2block. Instructions are built by hand with explicit account lists so the exact layouts and discriminators are exercised. Covers: legacy discriminator and 16-account layout unchanged;swap_v2accepts the 15-account layout with identical effects; each rejects the other's layout; both enforce thepool.fee_recipientaddress constraint (not visible in the IDL),min_amount_out > 0,pause_swaps, and charge the fee infrom_mint.Account layout
swap(unchanged)swap_v2pool…userwhitelisttoken_programtoken_programassociated_token_programassociated_token_programsystem_programsystem_programAdditive upgrade with no state or layout changes; rollback to the current build is safe. Removing legacy
swapis out of scope.Testing
Full Anchor suite against a local validator configured like CI (ephemeral program ID, upgradeable deploy): 100 passing, 0 failing (93 existing + 7 new).
cargo fmt --check,cargo check, andyarn lintpass.Type of Change
Checklist