Instructions¶
Every handler in #[program]. Marked π = permissionless crank (any signer may advance it); π = authority-gated; π = read-only.
| Instruction | Args | Signer | Semantics | Errors |
|---|---|---|---|---|
health |
β | caller |
Liveness probe; emits HealthChecked{version:1}. |
β |
initialize_pause |
β | authority |
One-time init of AccordState singleton; caller becomes pause authority. |
β |
π pause |
β | authority |
Instant freeze; clears any pending unpause. | NotPauseAuthority, AlreadyPaused |
π propose_unpause |
β | authority |
Arms unpause at slot + UNPAUSE_TIMELOCK_SLOTS. |
NotPauseAuthority, NotPaused, ArithmeticOverflow |
π execute_unpause |
β | caller |
Lands unpause once notice slot passes; no authority check. | NoPendingUnpause, UnpauseTimelockNotElapsed |
create_subaccord |
domain_ref, evidence_spec, staking_token, fee_token, min_stake, min_jury_size, alpha_bps, review_window, commit_window, reveal_window, appeal_window, max_appeals, aggregation, coherence_tol_bps, reveal_threshold_bps, shortfall_policy, max_draw_attempts, fee_per_juror, authority, evidence_operator, juror_credential, juror_schema |
creator |
Permissionless pool init. domain_ref != [0;32]. max_appeals <= MAX_APPEALS. appeal_window >= MIN_APPEAL_WINDOW_SECS (ADR-0022). coherence_tol_bps <= 10_000 (0β10_000; Median coherence band, inert for Plurality, immutable β ADR-0025). juror_credential/juror_schema both-or-neither: both default β stake-only; a half-bound pool reverts (ADR-0024). |
InvalidOptions, MaxAppealsLimitExceeded, AppealWindowTooShort, InvalidThreshold, AttestationBindingPartial |
stake |
amount, leaf_path + attestation (remaining_accounts[0] on gated pools) |
juror |
SPL transfer jurorβvault; credits real delta (fee-on-transfer safe). First stake (0β+) appends a leaf, assigns tree_index, increments staker_count. Verifies leaf_path vs accumulator root; recomputes root (O(log N)). Gated pool (ADR-0024): the juror's SAS attestation is supplied in remaining_accounts[0]; credential/schema/wallet must match and (unless expiry==0 β never expires) it must outlive the max dispute lifecycle. |
ProgramPaused, InvalidAmount, InvalidMembershipProof, ArithmeticOverflow, AttestationMissing, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationExpired |
unstake |
amount, leaf_path |
juror |
PDA-signed vaultβjuror. Full unstake (+β0) zeros the leaf, decrements staker_count. Never halted by pause. Verifies leaf_path vs accumulator root; recomputes root. |
InvalidAmount, StakeLocked, InsufficientBalance, InvalidMembershipProof, ArithmeticOverflow |
π prune_juror |
leaf_path + expired attestation (remaining_accounts[0]) |
caller |
Gated pools only (ADR-0024). Permissionless crank evicting a Juror whose attestation has a real expiry (!= 0) that has passed (β€ now) β the juror does NOT sign. Mirrors request_withdraw for the full staked: zeros the leaf, recomputes the root, banks tokens into pending_withdrawal, decrements staker_count. Requires no outstanding slash_reserve (β no in-flight draws). |
AttestationMissing, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationNotExpired, PendingSettlement, WithdrawalPending, InvalidAmount, InsufficientBalance, InvalidMembershipProof, ArithmeticOverflow |
π propose_subaccord_update |
nonce, payload: UpdatePayload |
authority |
Writes PendingUpdate; executable after UPDATE_TIMELOCK_SLOTS. |
ImmutableSubaccord, Unauthorized, ArithmeticOverflow |
π execute_subaccord_update |
β | caller |
Applies timelocked payload to Subaccord; closes PendingUpdate. |
TimelockNotElapsed |
create_dispute |
options: Vec<[u8;32]>, evidence_hash, nonce, fee |
filer |
Arbitrable CPI entry. Custodies (min_jury_size + 1) Β· fee_per_juror (the extra unit banks into the flip-bounty pool dispute.bounty_pool, ADR-0030 β refundable via claim_filing_bounty if never appealed). Requires staker_count >= min_jury_size. Options gate (ADR-0025): Plurality disputes pass 2..=8 (MAX_OPTIONS) option hashes; Median (scalar) disputes pass none β the vote is a u64 fixed-point value. Does not freeze the root (capital stays live). |
ProgramPaused, InvalidOptions, FeeMismatch, InsufficientJurors, ArithmeticOverflow |
π request_vrf |
β | caller |
CPI into VRF oracle if committed_vrf.is_none(). One-shot. |
VrfAlreadyCommitted |
commit_vrf_callback |
randomness: [u8;32] |
vrf_program_identity |
Stores VRF result and freezes dispute.frozen_root = subaccord.root. Only the VRF program can call (identity-constrained). |
VrfAlreadyCommitted |
π draw_seat |
seat_index, membership: JurorMembership + subaccord (+ attestation remaining_accounts[1] on gated pools) |
caller |
Verifies MST membership + sortition (prefix β€ r_i < prefix + stake) vs frozen_root + inflation guard; active_draws += 1; fills one seat of Round. The drawn juror's JurorStake is remaining_accounts[0]. Gated pool (ADR-0024): the subaccord account is now passed (read-only) and the juror's SAS attestation rides in remaining_accounts[1] for a defense-in-depth freshness re-check (expiry==0 or expiry > now). One seat per tx; deterministic sampling without replacement. |
InvalidState, InvalidPanelSize, VrfNotCommitted, InvalidMembershipProof, InsufficientStake, SortitionMismatch, DuplicateJuror, InflatedStake, ArithmeticOverflow, AttestationMalformed, AttestationMismatch, AttestationSubjectMismatch, AttestationExpired |
commit |
commitment: [u8;32] |
juror |
commitment = hash(vote_le8 β salt β juror_pubkey) β the vote (option index or scalar) hashed as an 8-byte little-endian u64 (ADR-0025). Window: review_end β€ now < commit_end. |
InvalidState, CommitWindowClosed, NotDrawnJuror, CommitAlreadyExists, ArithmeticOverflow |
reveal |
vote: u64, salt |
juror |
Recomputes hash(vote_le8 β salt β juror_pubkey); stores the vote. Gate by aggregation (ADR-0025): Plurality vote < num_options; Median vote != u64::MAX (no-reveal sentinel β any other u64 fixed-point scalar passes). Window: commit_end β€ now < reveal_end β¨ all committed (panel-full commit flips to Reveal early). |
InvalidState, InvalidVote, RevealWindowClosed, NotDrawnJuror, CommitMissing, AlreadyRevealed, RevealMismatch, ArithmeticOverflow |
π finalize_round |
β | caller |
After reveal_end (or once all jurors revealed), quorum met: tally per terms.aggregation β Plurality: modal option index, a top-count tie (β₯2 options share the max) β non-decisive round β RedrawEligible (ADR-0026); Median: median of revealed scalars (even reveal-count β upper middle, sorted[n/2]) β write result (ADR-0025), βRoundResolved. Quorum shortfall or tie β RedrawEligible (ADR-0021). |
InvalidState, RoundNotFinalizable |
π finalize_dispute |
β | caller |
After appeal window: slashes incoherent (Ξ±Β·min_stake), distributes the round's ENTIRE fee pot to the final-ruling-coherent (ADR-0029 β base fees + forfeited no-flip bonds; round 0's pot leaves fee_paid), decrements active_draws, writes final_ruling, βFinal. |
InvalidState, AppealWindowOpen, InvalidPanelSize, InvalidMembershipProof, ArithmeticOverflow |
appeal |
β | appellant |
Permissionless. Pays N_newΒ·fee_per_juror + bond (== new fee). current_round++, βCreated. |
ProgramPaused, InvalidState, MaxAppealsReached, AppealWindowClosed, InsufficientJurors, ArithmeticOverflow |
π claim_appeal_refund |
round_idx |
caller |
Returns a flipped bond to its appellant after Final. Idempotent (zeroes on payout). |
InvalidState, InvalidMembershipProof, InvalidAmount |
π get_ruling |
β | caller |
Returns Option<u64> (None until Final; then the winning option index for Plurality, the final median for Median β ADR-0025). |
β |
UpdatePayload variants (append-only, borsh variant-index stable β ADR-0028): MinStake, AlphaBps, ReviewWindow, CommitWindow, RevealWindow, AppealWindow, MaxAppeals, FeePerJuror, Authority, EvidenceOperator, RevealThresholdBps, MaxDrawAttempts.
See: state machine, accounts, errors. Draw trust chain in sortition & VRF.