Skip to main content
Account flags: S signer, W writable. Accounts marked derived are PDAs the generated client fills in for you. Every instruction also takes event_authority and program (Anchor’s self-CPI event accounts); they are omitted from the tables. Amounts are in base units: USDC 6 decimals, shares 9.

Wagers

open_wager

Opens a wager. Signed by the app and the stake owner. Checks, in order. No remaining accounts; new wagers not paused; new apps not paused if this creates the record; app not paused; fee account is a USDC account and matches the record; nonce; paytable shape (BucketCount, ProbabilityRange, ProbabilitySum, MultiplierCeiling); expected return (PaytableOverpays); app fee bound (IntegratorFeeTooHigh); edge floor (EdgeFloor); drawdown breaker; stake bounds; per-wager cap, app ceiling, utilisation, κ and gross solvency against the pool after this wager. Then it moves the protocol fee, the app fee and the pool credit from the stake, prefunds vrf_payer with twice ORAO’s fee plus a pending request’s rent, moves the crank fee into the wager, updates the books and snapshots everything into the wager. Emits IntegratorCreated (first wager) and WagerOpened.

request_randomness

Binds the wager to an ORAO request. Anyone, from open_slot + 2 until expiry_slot. Checks. Request window (RequestWindow); finds s*, the first slot in SlotHashes after open_slot (EntropyUnavailable if none); derives seed = SHA256("FADE/ORAO-SEED/v1" ‖ program ‖ wager ‖ open_slot ‖ s* ‖ h*); requires request to be ORAO’s account for that seed (WrongRandomnessAccount) and the treasury to match (TreasuryMismatch). A request account someone already created at that address is accepted after owner and type checks. Stores s*, h*, the seed and the request; status becomes Requested. Emits RandomnessRequested.

settle_wager

Draws the outcome and pays it. Anyone, once ORAO has fulfilled; no deadline. Checks. No remaining accounts; status; the randomness account is ORAO’s, bound to this wager, fulfilled, with the stored seed and a non-zero value. The outcome is SHA256("FADE/OUTCOME/v1" ‖ program ‖ wager ‖ seed ‖ R ‖ i) read as 128-bit words with rejection sampling, mapped onto the stored paytable’s cumulative probabilities. Releases the reservation, pays stake × m / 10 000 to the beneficiary (or to the escrow, status PayoutPending), returns the prefund, pays the settler and closes the wager. Never re-reads live parameters or caps. Emits WagerSettled.

expire_wager

Forfeits a wager whose randomness never arrived. Anyone, after expiry_slot. Checks. NotExpired before expiry_slot; AlreadyFulfilled if the randomness has arrived. The pool keeps the pool credit; the reservation is released; SOL returns to the payer. Emits WagerExpired.

claim_payout

Delivers a payout parked at settlement. Anyone. Fails while the beneficiary still cannot receive; retry later. Emits PayoutClaimed.

set_fee_account

The only way to move an app’s fee destination. Signed by integrator_authority. Emits FeeAccountChanged.

Liquidity

request_deposit

Checks. Allowlist of top-level instructions (ForbiddenComposition); deposits not paused; amount ≥ min_deposit, and ≥ min_first_deposit while no share exists. Joins the epoch computed from the queue and the clock (never an argument). Moves the USDC to the deposit queue and the SOL fees into the request and, if below target, the strike fund. Emits DepositRequested.

request_withdraw

Accounts mirror request_deposit, with owner_shares (W) as the source, owner_usdc derived (the owner’s associated USDC account) and share_escrow instead of the deposit queue. Checks. Allowlist; at least one share or the owner’s whole balance. Never blocked by a pause. Emits WithdrawRequested.

strike_epoch

Prices the live epoch. Anyone. Checks. A live epoch (NoLiveEpoch); its close has passed (EpochNotClosed); no wager opened before the close is still open (StrikeNotClean). Prices on settled assets at the close, mints for deposits, burns for withdrawals (rationed if needed), writes the EpochRecord, promotes the next epoch, pays the striker. Emits EpochStruck.

claim_deposit

Delivers the shares of a struck deposit request. Anyone; the request’s CLAIM_FEE pays the caller. Emits DepositClaimed, or ClaimDelivered for a parked request.

claim_withdraw

Delivers the USDC of a struck withdrawal request, possibly served across several epochs. Anyone; same fee. Emits WithdrawClaimed, or ClaimDelivered.

Governance

initialize

One-time setup by the program’s upgrade authority: creates Config, Pool, Queue and the vault’s token accounts, sets the council, guardian, treasury and parameters, and seeds the strike fund. Args: council: Pubkey, guardian: Pubkey, params: RiskParams.

set_params

Council only. Arg: params: RiskParams. Applies at once if every change tightens; otherwise queues it behind the longest delay of the fields it loosens. Emits ParamsChanged.

apply_params

Anyone, once the pending change is due (ChangeNotDue before). Emits ParamsApplied.

cancel_params

Council only. Drops the pending change. Emits ParamsCancelled.

set_pause_flags

Args: pause_flags: u8, integrator_paused: Option<bool>. Signed by the guardian or the council. The guardian may only set flags; clearing any flag, globally or for one app, requires the council (GuardianCannotUnpause). Optional integrator account to pause one app. Emits PauseFlagsChanged. No flag affects settlement, expiry, payout claims, the strike, LP claims or withdrawal requests.