event_authority and program (Anchor’s self-CPI event accounts); they are omitted from the tables. Amounts are in base units: USDC 6 decimals, shares 9.
Wagers
open_wager
Opens a wager. Signed by the app and the stake owner.
Checks, in order. No remaining accounts; new wagers not paused; new apps not paused if this creates the record; app not paused; fee account is a USDC account and matches the record; nonce; paytable shape (
BucketCount, ProbabilityRange, ProbabilitySum, MultiplierCeiling); expected return (PaytableOverpays); app fee bound (IntegratorFeeTooHigh); edge floor (EdgeFloor); drawdown breaker; stake bounds; per-wager cap, app ceiling, utilisation, κ and gross solvency against the pool after this wager. Then it moves the protocol fee, the app fee and the pool credit from the stake, prefunds vrf_payer with twice ORAO’s fee plus a pending request’s rent, moves the crank fee into the wager, updates the books and snapshots everything into the wager. Emits IntegratorCreated (first wager) and WagerOpened.
request_randomness
Binds the wager to an ORAO request. Anyone, from open_slot + 2 until expiry_slot.
Checks. Request window (
RequestWindow); finds s*, the first slot in SlotHashes after open_slot (EntropyUnavailable if none); derives seed = SHA256("FADE/ORAO-SEED/v1" ‖ program ‖ wager ‖ open_slot ‖ s* ‖ h*); requires request to be ORAO’s account for that seed (WrongRandomnessAccount) and the treasury to match (TreasuryMismatch). A request account someone already created at that address is accepted after owner and type checks. Stores s*, h*, the seed and the request; status becomes Requested. Emits RandomnessRequested.
settle_wager
Draws the outcome and pays it. Anyone, once ORAO has fulfilled; no deadline.
Checks. No remaining accounts; status; the randomness account is ORAO’s, bound to this wager, fulfilled, with the stored seed and a non-zero value. The outcome is
SHA256("FADE/OUTCOME/v1" ‖ program ‖ wager ‖ seed ‖ R ‖ i) read as 128-bit words with rejection sampling, mapped onto the stored paytable’s cumulative probabilities. Releases the reservation, pays stake × m / 10 000 to the beneficiary (or to the escrow, status PayoutPending), returns the prefund, pays the settler and closes the wager. Never re-reads live parameters or caps. Emits WagerSettled.
expire_wager
Forfeits a wager whose randomness never arrived. Anyone, after expiry_slot.
Checks.
NotExpired before expiry_slot; AlreadyFulfilled if the randomness has arrived. The pool keeps the pool credit; the reservation is released; SOL returns to the payer. Emits WagerExpired.
claim_payout
Delivers a payout parked at settlement. Anyone.
Fails while the beneficiary still cannot receive; retry later. Emits
PayoutClaimed.
set_fee_account
The only way to move an app’s fee destination. Signed by integrator_authority.
Emits
FeeAccountChanged.
Liquidity
request_deposit
Checks. Allowlist of top-level instructions (
ForbiddenComposition); deposits not paused; amount ≥ min_deposit, and ≥ min_first_deposit while no share exists. Joins the epoch computed from the queue and the clock (never an argument). Moves the USDC to the deposit queue and the SOL fees into the request and, if below target, the strike fund. Emits DepositRequested.
request_withdraw
Accounts mirror
request_deposit, with owner_shares (W) as the source, owner_usdc derived (the owner’s associated USDC account) and share_escrow instead of the deposit queue. Checks. Allowlist; at least one share or the owner’s whole balance. Never blocked by a pause. Emits WithdrawRequested.
strike_epoch
Prices the live epoch. Anyone.
Checks. A live epoch (
NoLiveEpoch); its close has passed (EpochNotClosed); no wager opened before the close is still open (StrikeNotClean). Prices on settled assets at the close, mints for deposits, burns for withdrawals (rationed if needed), writes the EpochRecord, promotes the next epoch, pays the striker. Emits EpochStruck.
claim_deposit
Delivers the shares of a struck deposit request. Anyone; the request’s CLAIM_FEE pays the caller.
Emits
DepositClaimed, or ClaimDelivered for a parked request.
claim_withdraw
Delivers the USDC of a struck withdrawal request, possibly served across several epochs. Anyone; same fee.
Emits
WithdrawClaimed, or ClaimDelivered.
Governance
initialize
One-time setup by the program’s upgrade authority: creates Config, Pool, Queue and the vault’s token accounts, sets the council, guardian, treasury and parameters, and seeds the strike fund. Args: council: Pubkey, guardian: Pubkey, params: RiskParams.
set_params
Council only. Arg: params: RiskParams. Applies at once if every change tightens; otherwise queues it behind the longest delay of the fields it loosens. Emits ParamsChanged.
apply_params
Anyone, once the pending change is due (ChangeNotDue before). Emits ParamsApplied.
cancel_params
Council only. Drops the pending change. Emits ParamsCancelled.
set_pause_flags
Args: pause_flags: u8, integrator_paused: Option<bool>. Signed by the guardian or the council. The guardian may only set flags; clearing any flag, globally or for one app, requires the council (GuardianCannotUnpause). Optional integrator account to pause one app. Emits PauseFlagsChanged.
No flag affects settlement, expiry, payout claims, the strike, LP claims or withdrawal requests.