chordDocs

Developers

Program reference

Instructions, accounts and the checks each one makes.

Chord’s settlement program is written with Anchor 0.31.1 and supports the classic SPL Token program only. Its source is the authoritative contract; this page summarizes it.

#Instructions

InstructionSigned byWhat it does
initializeUpgrade authorityCreates the one immutable config: auctioneer, treasury, chain domain, bond size
register_solverSolverCreates the solver account with a bond of at least the config’s size, if the solver’s CHORD stake meets the minimum
top_up_solverSolverAdds lamports to the bond
withdraw_solverSolverWithdraws unlocked bond
create_batchAuctioneerOpens a batch for an enabled market, with that market’s slot windows and order cap
commit_batchAuctioneer and solverWrites the price and budgets, escrows reserves, locks a bond; the solver’s stake must meet the minimum
settle_fillAuctioneer, after the owner’s Ed25519 verificationFills one signed order against the committed price
finalize_batchAnyoneCompletes a fully filled batch; unlocks the bond, refunds reserves
timeout_batchAnyoneAfter the deadline with budget unfilled; slashes the bond, burns 10% of the solver’s stake, refunds reserves
expire_uncommittedAnyoneAfter the deadline, closes a batch that never committed
claim_refundAnyoneRetries a reserve refund once frozen accounts thaw
cancel_nonceOrder ownerWrites a cancelled receipt for one nonce
advance_nonceOrder ownerRaises the owner’s nonce floor
initialize_stakingUpgrade authorityCreates the stake pool for a CHORD mint with no mint or freeze authority
set_stake_authorityPool authorityHands parameter changes to a governance of the pool’s realm; any other account is refused
set_stake_timingPool authoritySets the unstaking cooldown and the vote window, each 1 to 365 days
set_min_solver_stakePool authoritySets the minimum stake to register and commit
set_marketPool authorityLists, retimes or pauses a pair: windows, order cap, enabled
stakeStakerMoves CHORD into the staking vault
unstakeStakerStarts the cooldown; refused while the staker’s solver has a batch open
withdraw_stakeStakerReturns cooled-down CHORD
update_voter_weight_recordAnyoneWrites a staker’s voting weight for one governance action, valid for one slot

#Phases

Slots strictly increase through a batch: creation, then collection end, then solve end, then the settlement deadline. Quotes compete between collection end and solve end. Commit is allowed from solve end to the deadline, fills until the deadline, and timeout or expiry strictly after it.

#Errors

ErrorMeaning
InvalidParameterA zero or out-of-range value
UnauthorizedThe signer isn’t allowed to do this
InsufficientBondNot enough unlocked bond
InvalidWindowBatch slots don’t strictly increase, or don’t match the market’s windows
InvalidPairTokens don’t match the batch pair
WrongPhaseNot allowed in the batch’s current phase
InsufficientReserveReserves don’t cover every gross output
ExpiredThe order’s expiry slot has passed
IntentMismatchAn account or the signed message doesn’t match the order
TokenOwnerSource or destination isn’t the owner’s
DelegationRevokedThe allowance was revoked or is too small
NonceInvalidatedThe nonce is below the owner’s floor
CancelledThe nonce was cancelled
NonceAlreadyUsedThe nonce is bound to another order or batch
OverfillThe fill exceeds the signed sell amount
PartialForbiddenA partial fill of an order that doesn’t allow one
LimitPriceThe rounded output misses the signed minimum
BudgetExceededThe fill exceeds the committed budget
UnfilledBudgetFinalize was called before both budgets filled
MathOverflowChecked arithmetic failed
SignatureInstructionThe Ed25519 verification before the fill isn’t the one canonical layout
StaleFillThe receipt changed since the fill was prepared
MarketDisabledThe pair has no enabled market
OrderCapThe batch already filled its market’s order cap
StakeTooLowThe solver’s stake is below the minimum
StakeLockedThe solver has a committed batch that isn’t finished
CooldownActiveUnstaked CHORD is still cooling down
NothingToWithdrawNo cooled-down CHORD to withdraw
InvalidProposalThe vote target isn’t a proposal voting with CHORD
MintAuthorityThe staked mint can still mint
VoteWindowClosedThe vote comes after the pool’s vote window for that proposal

#Arithmetic

All products are computed in u128 and checked back into u64. Outputs round down; minimums and reserves round up. Every rounding choice favours the trader’s limit or the escrow’s sufficiency, never the solver’s margin.

#Upgrade authority

The program is upgradeable, and its upgrade authority is a trust assumption like any upgradeable Solana program. The config is not: once initialized, its auctioneer, treasury, chain domain and bond size can’t change.

#Governance plugin

The program is the realm’s voter weight plugin on spl-governance. update_voter_weight_record writes a VoterWeightRecord for one action and target, expiring in the same slot, so it goes in the same transaction as the vote or proposal it serves. For a vote, the weight is the staker’s active stake less every deposit made in or after the proposal’s voting slot; for anything else, it is the active stake. CHORD in its cooldown never counts.