Skip to content

feat(solana): add swap_v2 without the deprecated whitelist account - #22

Open
vigaash-cb wants to merge 3 commits into
mainfrom
vigaashsivasothy/stble-4468-swap-v2
Open

vigaash-cb wants to merge 3 commits into
mainfrom
vigaashsivasothy/stble-4468-swap-v2

Conversation

@vigaash-cb

@vigaash-cb vigaash-cb commented Oct 2, 2026 •

Copy link
Copy Markdown

Description

swap still carries the deprecated whitelist PDA at account index 12 so callers that encode the pre-deprecation account list keep working (#21). Anchor's instruction discriminator depends only on the instruction name, so the account list of swap cannot change without breaking those callers.

This PR adds swap_v2: same arguments, same validation and fee logic, same account order and constraints, minus the whitelist slot (15 accounts instead of 16). swap is left untouched.

Changes

  • lib.rs
    • The body of swap moves verbatim into a private do_swap(&SwapAccounts, ..). Swap and SwapV2 each project onto SwapAccounts, so both instructions share one body and cannot drift.
    • New swap_v2 handler and SwapV2<'info> accounts struct: Swap with the whitelist field removed, everything else unchanged.
    • swap / Swap unchanged apart from doc comments noting the legacy instruction will be removed in a follow-up once callers have cut over.
  • tests/stable-swapper.ts: new Swap V2 block. Instructions are built by hand with explicit account lists so the exact layouts and discriminators are exercised. Covers: legacy discriminator and 16-account layout unchanged; swap_v2 accepts the 15-account layout with identical effects; each rejects the other's layout; both enforce the pool.fee_recipient address constraint (not visible in the IDL), min_amount_out > 0, pause_swaps, and charge the fee in from_mint.

Account layout

# swap (unchanged) swap_v2
0–11 pool … user same
12 whitelist token_program
13 token_program associated_token_program
14 associated_token_program system_program
15 system_program —

Additive upgrade with no state or layout changes; rollback to the current build is safe. Removing legacy swap is out of scope.

Testing

Full Anchor suite against a local validator configured like CI (ephemeral program ID, upgradeable deploy): 100 passing, 0 failing (93 existing + 7 new). cargo fmt --check, cargo check, and yarn lint pass.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation
  • Refactor / cleanup
  • Other (describe below)

Checklist

  • Tests are included and passing
  • Code is formatted and linted
  • Build succeeds
  • Documentation is updated for any public API changes
  • All commits are signed

`swap` still carries the deprecated `whitelist` PDA at account index 12 so
callers that encode the pre-deprecation account list keep working (#21).
Anchor's instruction discriminator depends only on the instruction name, so
the account list of `swap` cannot change without breaking those callers.

Add `swap_v2`: same arguments, same validation and fee logic, same account
order and constraints, minus the `whitelist` slot (15 accounts instead of
16). Both handlers delegate to a shared `do_swap` body via a `SwapAccounts`
view so the two cannot drift. `swap` is unchanged and will be removed in a
follow-up once all live callers have confirmed cutover to `swap_v2`.

Tests build both instructions by hand with explicit account lists and
verify: legacy discriminator and 16-account layout are unchanged; swap_v2
accepts the 15-account layout with identical balance effects; each rejects
the other's layout; both enforce the fee-recipient address constraint,
min_amount_out > 0, pause_swaps, and charge the fee in from_mint.

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
@vigaash-cb
vigaash-cb requested a review from denys-cb October 2, 2026 15:42
@cb-heimdall

cb-heimdall commented Oct 2, 2026 •

Copy link
Copy Markdown

✅ Heimdall Review Status

Requirement Status More Info
Reviews ✅ 1/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

@linear

linear Bot commented Oct 2, 2026

Copy link
Copy Markdown

STBLE-4468

Co-authored-by: Toshi <toshi-noreply@coinbase.com>
Comment thread solana/programs/stable-swapper/src/lib.rs
Comment thread solana/tests/stable-swapper.ts
…account test

- README: list swap_v2 under Core Instructions and note the deprecated
  whitelist slot kept in the legacy swap layout.
- tests: the legacy-swap 15-account rejection test passed on any error;
  assert the specific InvalidProgramId Anchor raises (slot 13 is read as
  token_program and holds the Associated Token program).
);
Ok(())
/// `swap` without the deprecated `whitelist` account. Same args, logic, and effects.
pub fn swap_v2(ctx: Context<SwapV2>, amount_in: u64, min_amount_out: u64) -> Result<()> {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to update CSA logic to correctly index swap_v2 txs before Flipcash switches

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants