Instruction Account & Validation Reference#
This reference lists, for every Seesaw instruction, the accounts it expects and the validation it performs on them. Integrators building transactions can use it to assemble the correct account list and to understand which conditions cause a given instruction to reject.
The 77 public instructions span 0x00–0x5A. The live blocks include bootstrap, trading, spline, external-market, Reclaim, and native-oracle routes. Tags
0x31–0x32 are reserved; named legacy bridge tombstones are
frozen legacy-Reclaim tombstones. Reclaim V1 is live at 0x52–0x56; native
oracle observations use 0x57–0x5A. Internal LOG is at 0xFF; 78 live payloads are dispatched including LOG,
which is never invoked directly by users.
Since v2.17.0 every event-producing route rejects a missing, malformed, or
writable trailing [self_program, log_authority] pair before entering the
handler (processor/mod.rs::requires_recorder_tail). Only 0x33, 0x42,
0x48, 0x4E, 0x51, and internal 0xFF take no tail.
Legend: S = signer, W = writable, R = read-only, PDA = program-derived address validation, ATA = SPL token account mint/authority validation.
Shared Validation Primitives#
| Primitive | Validation performed |
|---|---|
load_config_context | Program owner, exact size, account discriminator, config PDA/bump, authority fields, treasury recipients, settlement mint, fee/limit/pause/post-only fields. |
load_market_context | Program owner, exact size, account discriminator, market PDA derived from feed id/duration/market id/creator/bump, settlement mint, vault/escrow/mint bumps, emergency status, dynamic num_seats. |
load_orderbook_context | Program owner, exact size, discriminator, orderbook.market == market, orderbook PDA. |
load_position_context | Program owner, exact size, discriminator, position PDA from market/owner/bump. |
load_trader_ledger_context | Dynamic v2 ledger only: nonzero market seat count, header market/capacity, exact PDA. |
| Token loaders | SPL Token v1 owner/layout, mint equality, authority equality, vault/escrow/mint PDAs, treasury-recipient index/address binding, referrer-treasury shard PDA and authority. |
| Recorder tail splitter | Fixed-shape processors accept exact base accounts + self-program + log-authority. Lone recorder accounts and surplus accounts reject. |
| Referral triple loader | Place-order referral accounts are all-or-none and exact: referral PDA, referrer earnings PDA, treasury shard PDA, expiry, referee/referrer identity, treasury index, mint, and authority all validate. |
| Resolver registry loader | Program owner, exact 1,024-byte layout, literal RESOLREG discriminator, singleton PDA/bump, bounded counted prefix, and resolver lookup. Unknown statuses fail closed when used. |
| Market metadata loader | Program owner, exact 384-byte layout, literal MKTMETA\0 discriminator, PDA/bump, and stored market binding. Instruction-specific logic validates resolution fields when needed. |
Instruction Matrix#
| Disc | Instruction | Accounts received | Current validation |
|---|---|---|---|
0x00 | InitializeConfig | config W, authority S/W, treasury_recipient_0..7 R, default_settlement_mint R, system_program R, program_data R | Exact 13 base accounts plus the mandatory recorder tail. Authority signs. Config PDA is uninitialized/system/rent-valid. Settlement mint is valid. All 8 treasury recipients are SPL Token v1 accounts for the default mint, nonzero, and pairwise distinct. Program-data account is owned by the upgradeable loader and its upgrade authority equals authority. Fee, tick, duration, and limit args validate before write. |
0x01 | UpdateAuthority | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Current authority signs. Nonzero self-succession rejects. Zero new authority is the explicit pending-rotation cancel sentinel. |
0x02 | ClaimAuthority | config W, pending_authority S | Exact 2 base accounts plus the mandatory recorder tail. Pending authority signs. 48h timelock must have elapsed. Pending authority fields clear after claim. |
0x03 | CreateMarket | market W, orderbook W, vault W, yes_mint W, no_mint W, asset_state W, config W, pyth_feed R, settlement_mint R, payer S/W, system_program R, token_program R, yes_escrow W, no_escrow W, trader_ledger W | Exact 15 base accounts plus the mandatory recorder tail. Config not paused. Payer signs. Current 27-byte payload only: confidence guard, duration, oracle jump guard, symmetric supported deep-orderbook tier, valid dynamic seat count, oracle mode. Current epoch, duration bounds, Pyth owner/feed/freshness/confidence/jump checks, settlement mint, all PDAs, writable account distinctness, fee config, and dynamic ledger initialization validate. |
0x04 | SnapshotEnd | market W, pyth_feed R, caller S/W, config R | Exact 4 base accounts plus the mandatory recorder tail. Caller signs. Config and market load. Pyth feed address/id/owner/freshness/confidence validate. End snapshot is idempotent and closer reward is paid only on state update with rent-safe lamport arithmetic. |
0x05 | ResolveMarket | market W, asset_state W, caller S/W, config R, vault W, creator_token_account W, settlement_mint R, token_program R | Exact 8 base accounts plus the mandatory recorder tail. Caller signs. Config, market, asset-state PDA/feed binding, state transition, outcome computation, vault mint/authority, creator destination mint/authority, and creator-fee disbursement/defer logic validate. Already-resolved idempotence still validates asset-state binding. |
0x06 | ExpireMarket | Base: market W, asset_state R, caller S/W, config R, vault W, creator_token_account W, settlement_mint R, token_program R. Optional exact pyth_feed R late-resolution group. | Exact 8 or 9 base accounts plus the mandatory recorder tail. Caller signs. Config/market/asset-state/feed binding, expiry eligibility, optional late Pyth capture, fallback expiry, closer reward, and creator-fee transfer/defer token checks validate. |
0x07 | MintShares | market W, yes_mint W, no_mint W, user_yes_ata W, user_no_ata W, user_stablecoin_ata W, vault W, user S, config R, token_program R, settlement_mint R | Exact 11 base accounts plus the mandatory recorder tail. User signs. Config/market/token context validates. Amount, trading window, pause, emergency, cap, vault post-balance, and market solvency checks run. |
0x08 | DepositFunds | market W, trader_ledger W, user_position W, user_stablecoin_ata W, vault W, user S/W, config R, token_program R, settlement_mint R | Exact 9 base accounts plus the mandatory recorder tail. User signs. Config/market/position/ledger load. Config pause enforced. Vault, settlement mint, and user ATA mint/authority validate. Nonzero amount transfers to vault and credits signer-keyed slot.quote_free. |
0x09 | WithdrawFunds | Same as DepositFunds | Exact 9 base accounts plus the mandatory recorder tail. User and account bundle validate. Native transfer is market-signed; unresolved external transfer is vault-self-signed. Every resolved external market returns AlreadyResolved before solvency/mutation and routes through MarketMeta-aware Redeem; native Expired retains free-quote withdrawal. |
0x0A | WithdrawShares | market W, user_position W, selected mint W, user_token_account W, user S, config R, token_program R, trader_ledger W, vault R | Exact 9 base accounts plus the mandatory recorder tail. User signs. Config, market, position, and trader-ledger load. Token type selects the canonical YES/NO mint PDA. User token account mint/authority and the vault PDA/solvency balance validate before debiting ledger free shares and minting SPL shares. WithdrawShares never reads or locks the orderbook. |
0x0B | PlaceOrder | 18 base place accounts: market, orderbook, position, user stablecoin/vault/treasury token accounts, user S/W, config, token/system programs, settlement/share mints, YES/NO escrows, user YES/NO ATAs, trader ledger; optional exact referral triple then the mandatory recorder tail | User signs. Exact allowed account totals only. Config, market, orderbook, position binding, trader-ledger slot, token/PDA bundle, pause/emergency, order args, self-trade behavior, match limit, expiry, post-only/IOC policy, treasury index/address, maker price band, fee conservation, and optional referral triple validate before settlement. |
0x0C | PlaceMultiplePostOnlyOrders | Same place-order surface | User signs. Shared place-order loaders validate once. Every batch entry must be post-only, in limits, within maker price band, and non-crossing under the reject flag. Any invalid entry reverts the whole instruction. |
0x0D | SwapWithFreeFunds | Same place-order surface | User signs. Shared place-order validation. Wrapper coerces IOC/take-only semantics and routes user-side collateral/share movement through trader-ledger free buckets. Fee/referral token CPIs still use the validated token bundle. |
0x0E | PlaceLimitOrderWithFreeFunds | Same place-order surface | User signs. Shared place-order validation. IOC/take-only payloads reject at wrapper boundary; resting user-side settlement routes through free funds. |
0x0F | PlaceMultiplePostOnlyOrdersWithFreeFunds | Same place-order surface | User signs. Shared place-order validation and atomic post-only batch semantics; user-side settlement routes through free funds. |
0x10 | CancelOrder | 15 cancel/refund accounts: market, orderbook, position, user token account, vault, user S, token program, settlement mint, YES/NO escrows, user YES/NO ATAs, YES/NO mints, trader ledger | Exact 15 base accounts plus the mandatory recorder tail. User signs. Market/orderbook/position/ledger bind. Market cancelability and token refund bundle validate. Target order must exist and belong to the position. |
0x11 | CancelMultipleOrdersById | Same cancel/refund surface | Exact 15 base accounts plus the mandatory recorder tail. User signs. Empty explicit id list rejects. Each order id must exist and belong to the position before cancel/refund. |
0x12 | CancelAllOrders | Same cancel/refund surface | Exact 15 base accounts plus the mandatory recorder tail. User signs and position binds before scanning. Empty owned set is a post-validation no-op. Scan/cancel loop is bounded by MAX_BULK_CANCEL_LIMIT. |
0x13 | CancelUpTo | Same cancel/refund surface | Exact 15 base accounts plus the mandatory recorder tail. User signs. Side, price threshold, max count, owner, and market cancelability validate before bounded scan/refund. |
0x14 | ReduceOrder | Same cancel/refund surface | Exact 15 base accounts plus the mandatory recorder tail. User signs. Target order owner and nonzero reduce quantity validate. Full-size delegates to cancel; partial reduce preserves priority and releases exact collateral/share delta. |
0x15 | CancelMultipleOrdersByIdWithFreeFunds | Lean FF cancel accounts: market W, orderbook W, user_position W, user S, trader_ledger W | Exact 5 base accounts plus the mandatory recorder tail. User signs. Market/orderbook/position/ledger bind. Each id must exist and belong to the position. Refunds credit slot.{quote,yes,no}_free; no token refund accounts are accepted. |
0x16 | CancelAllOrdersWithFreeFunds | Same lean FF cancel surface | Exact 5 base accounts plus the mandatory recorder tail. User signs and position binds before scanning. Empty set is post-validation no-op. Loop is bounded. |
0x17 | CancelUpToWithFreeFunds | Same lean FF cancel surface | Exact 5 base accounts plus the mandatory recorder tail. User signs. Side/price/max-count/owner criteria mirror CancelUpTo; refunds route to ledger free buckets. |
0x18 | ReduceOrderWithFreeFunds | Same lean FF cancel surface | Exact 5 base accounts plus the mandatory recorder tail. User signs. Full-size delegates to lean FF cancel; partial reduce releases quote/YES/NO locks into free buckets. |
0x19 | ReclaimExpiredOrder | Native head: 16 reclaim accounts, optional bounty at 16. External head inserts authenticated MarketMeta at 16, optional bounty at 17. Either must append the exact recorder pair. | Split only an exact canonical recorder suffix, then require native 16/17 or external 17/18 head. External metadata authenticates before mutation. Normal refunds preserve amount semantics and use vault-self signing externally; terminal asks burn escrow and credit the authenticated graded leg rate, with no vault transfer or bounty. |
0x1A | Redeem | Common 10-account token prefix. External market adds authenticated MarketMeta at 10. Optional position/orderbook/ledger trio follows the native prefix or metadata; the mandatory exact recorder pair is terminal. | Market-kind-dependent shape is exact. Native uses Outcome rates; external binary/scalar uses only resolved MarketMeta numerators and vault-self signing. Position shape binds position/orderbook/ledger, debits ledger free shares first, burns SPL remainder, transfers floored payout, and advances settled count only when all buckets are empty. |
0x1B | ForceClose | market W, position W, vault W, user_stablecoin_ata W, caller S/W, config R, token_program R, settlement_mint R, orderbook W, trader_ledger W, YES/NO escrows W, YES/NO mints W | Exact 14 base accounts plus the mandatory recorder tail. Caller signs. Config, market, position, vault, owner ATA, orderbook, dynamic ledger, escrow/mint PDAs validate. Eligibility requires unresolved market past expiration window; resolved/expired outcomes reject. |
0x1C | MarkPositionSettled | Native head is the existing 8 accounts. External head requires authenticated MarketMeta at 8. Either must append the exact recorder pair. | Account shape and metadata authenticate before idempotent return. Caller, bindings, terminal/grace state, token bundle, graded owed value, and projected remaining liability validate. CEI advances settled state/counter before the payout CPI; transaction rollback preserves atomicity on failure. Native signing is unchanged; external payout uses MarketMeta rates and vault-self signing. |
0x1D | ClosePosition | position W, market R, owner W, caller S, system_program R | Exact 5 base accounts plus the mandatory recorder tail. Loads position and market, verifies owner/caller policy, requires closeable settled or erased-market conditions, and closes lamports to owner. |
0x1E | CloseMarket | Fixed 12-account prefix; authenticated tail is native none/registry/mint-pair/registry+mint-pair or external metadata/metadata+mint-pair | Recorder is split first, fixed prefix is authenticated, then exact market-kind tail is selected. Native base lengths 12/13/14/15 remain; external requires 13 or 15 and rejects 12/14. External metadata owner/size/discriminator/PDA/bump/market/resolved/legs/vector validate before mutation, closes to creator, and parent market closes last. Tokenkeg mints remain; event rent reports only market lamports. |
0x1F | UpdateFeeConfig | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. One-hour cooldown after first update. Fee cap/decay bounds and protocol/creator/referrer shares summing to 10_000 validate before write. |
0x20 | UpdateTreasuryRecipients | config W, authority S, treasury_recipient_0..7 R | Exact 10 base accounts plus the mandatory recorder tail. Authority signs. Rate limit, recipient SPL Token v1 owner/layout, mint equality, nonzero addresses, and pairwise distinctness validate before atomic replacement. |
0x21 | SetReferrer | referral W, referee S/W, referrer R, referrer_earnings R, system_program R | Exact 5 base accounts plus the mandatory recorder tail. Referee signs. Self-referral rejects. Referral PDA must be uninitialized. Referrer earnings PDA must match referrer and be program-owned/typed. |
0x22 | InitReferrerEarningsAccount | referrer_earnings W, referrer S/W, referrer_treasury W, settlement_mint R, config R, system_program R, token_program R | Exact 7 base accounts plus the mandatory recorder tail. Referrer signs and pays rent. Treasury index is in range. Referrer earnings PDA is uninitialized. Settlement mint equals config default. Treasury shard PDA is either valid existing SPL token account or is created with shard PDA authority. |
0x23 | ClaimCreatorFees | market W, vault W, creator_token_account W, settlement_mint R, caller S, token_program R | Exact 6 base accounts plus the mandatory recorder tail. Destination and terminal fee state validate. Native transfer is market-signed; external is vault-self-signed. With no metadata slot, external post-transfer solvency uses conservative max-side liability and may defer the claim rather than infer graded rates from the Expired mirror. |
0x24 | ClaimReferrerEarnings | referrer_earnings W, referrer_treasury W, referrer_token_account W, settlement_mint R, referrer S, token_program R, config R | Exact 7 base accounts plus the mandatory recorder tail. Referrer signs. Earnings PDA/type/referrer, nonzero accumulated amount, settlement mint, bounded treasury index, shard PDA/token account, and destination mint/authority validate before shard-signed transfer and same-amount debit. |
0x25 | Pause | config W, authority_or_pauser S | Exact 2 base accounts plus the mandatory recorder tail. Current config authority or configured nonzero pauser signs. Sets global pause flag. Zero pauser grants no access; any other signer returns UnauthorizedPauser. |
0x26 | Unpause | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Clears global pause flag. |
0x27 | EnablePostOnlyMode | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Enables global post-only mode. |
0x28 | DisablePostOnlyMode | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Disables global post-only mode. |
0x29 | UpdateTickSize | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Tick size bounds/divisibility validate before write. |
0x2A | UpdateMinRestingNotional | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Minimum resting notional validates before write. |
0x2B | UpdateMarketCap | market W, config R, authority S | Exact 3 base accounts plus the mandatory recorder tail. Protocol admin or market creator signs. Market must be trading. Nonzero cap cannot be below current YES/NO supply; zero clears cap. |
0x2C | SetMarketEmergencyStatus | config R, market W, authority_or_pauser_or_creator S | Exact 3 base accounts plus the mandatory recorder tail. Protocol admin may set any value. Configured nonzero pauser may only impose or raise severity and may not clear/lower emergency state. Market creator may only set/clear PostOnly while not overriding stronger admin states. Market must be trading. |
0x2D | ForceCancelMarketOrders | config R, market/orderbook/position/vault/escrow/mint/refund token bundle, maker R, authority S, trader ledger W | Exact 17 base accounts plus the mandatory recorder tail. Admin signs. Market must be ForceCancelOnly. Order exists and maker/token/PDA/ledger bundle validate. Cancel/reclaim delta applies before token CPIs; no TTL or bounty path. |
0x2E | EnsureTraderLedgerSpace | Native: payer S/W, trader_ledger W, market R, system_program R. External appends receipt R. | Exact 4 native or 5 receipt-aware base accounts plus the mandatory recorder tail. External form requires canonical Active receipt, matching creator/payer and market, and exact 1,025-seat target. Native behavior and the legacy four-account zeroed-donation compatibility remain unchanged. |
0x2F | UpdateOperationalParams | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Authority signs. Admin-only setter for nine operational parameters: closer reward, max price staleness, expiration window, min/max duration, max order size, spline flags, nonzero spline minimum commitment, and midpoint-jump reset bps. The exact payload is 60 bytes including discriminator; all values validate before atomic write. |
0x30 | RecoverSpline | creator S, spline W, spline_vault W, market W, market_vault W, yes_mint W, no_mint W, creator_yes W, creator_no W, token_program R | Exact 10 base accounts plus the mandatory recorder tail; empty payload. Creator signs and must equal the spline's creator. All ten accounts are pairwise distinct and accounts 1-8 are writable. Spline, spline vault, market vault, and both mints are PDA-bound; the two creator destinations are mint/authority-bound. The market must be unresolved and the spline attached, with the market's spline commitment equal to the spline's. The market vault's authority is the market PDA for native Pyth markets and the vault PDA for external markets. Returns the full commitment to the spline vault and mints the accumulated internal inventory to the creator; the market's share totals are unchanged and the post-CPI vault balances are re-asserted. Clears the market's spline commitment/feature bit, detaches the spline, and bumps its generation. |
0x32 | Reserved | None | Retired prelaunch compatibility identity; every payload rejects as InvalidInstructionData. |
0x33 | EnsureDeepOrderbookSpace | Native: payer S/W, orderbook W, market R, system_program R. External appends receipt R. | Exact 4 native or 5 receipt-aware base accounts; no recorder tail. External form requires canonical Active receipt, matching creator/payer and market, and exact capacity 512. Native tier behavior and the legacy four-account zeroed-donation compatibility remain unchanged. |
0x34 | SetPauser | config W, authority S | Exact 2 base accounts plus the mandatory recorder tail. Current config authority signs. Writes ConfigAccount.pauser; the all-zero key disables pauser access fail-closed. The pauser cannot call this instruction. |
0x35 | TopUpCloserRewards | market W, payer S/W, config R, system_program R | Exact 4 accounts plus the mandatory recorder tail. Permissionless payer signs. Config and market PDAs load, market settlement mint must match config default, system program validates, and the payer funds only the rent-safe closer-reward budget shortfall up to closer_reward_lamports * CLOSER_REWARDS_PER_MARKET. No-op if the market already has enough reward budget. |
0x36 | RollupReferralFees | market/vault/earnings/treasury/positions W, mint/token program R, caller S | Exact 7 base accounts plus 1–8 sorted positions plus the mandatory recorder tail. Pending liabilities transfer atomically: native market signer or external vault-self signer. Because this ABI has no metadata slot, external pre/post checks use conservative max-side solvency and may defer rollup rather than derive graded liability from the Expired mirror. |
0x37 | InitializeReferrerTreasuryShard | treasury shard W, settlement mint/config R, payer S/W, system/token programs R | Exact 6 accounts plus the mandatory recorder tail. Treasury index must be 0–7. Permissionlessly creates or validates the canonical Tokenkeg treasury-shard PDA for the configured settlement mint. |
0x3C | UpdateReclaimWitnessEpoch | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x3D | UpdateExternalCloseTime | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x3E | VerifyReclaimClaim | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x3F | CloseReclaimClaim | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x40 | InitSpline | creator S/W, spline/spline-vault W, settlement mint/config/token/system programs R | Exact 7 accounts plus the mandatory recorder tail. Creator signs. Spline and vault PDAs must be canonical and uninitialized. Feed/duration/mid/age/flags/default commitment and sixteen fixed CurveLevel entries per side validate before creating the 896-byte version-1 account and Tokenkeg vault. |
0x41 | UpdateSplineShape | creator S/W, spline W; attached form adds market W | Exact 2 detached or 3 attached base accounts plus the mandatory terminal recorder pair. Creator, spline PDA/version, compiled-level count/order/exposure, frozen attachment tick, and attached market binding validate before replacing the complete shape and resetting eligibility. |
0x42 | UpdateSplineMid | creator-or-quote-authority S, spline W | Exact 2 accounts. The creator or configured quote authority and spline PDA/version validate. Sequence must advance monotonically; midpoint/flags validate. Activation, stale refresh, or material midpoint jump resets eligibility. |
0x43 | AttachSpline | creator S/W, spline/vault/market/market-vault W, config/token/system programs R | Exact 8 accounts plus the mandatory recorder tail. Authenticated external markets reject before mutation. Native paths validate every PDA, owner, mint, creator, Pyth series, market state, feature flag, commitment floor, compiled-level exposure, cap, and solvency projection. |
0x44 | SettleSpline | caller S, spline/vault/market/market-vault W, token program R; external markets add market_meta R | Exact 6 native or 7 external base accounts plus the mandatory recorder pair. Authenticated external markets require the read-only market_meta before the detached replay fast path. Native settlement remains permissionless after terminal outcome and validates canonical bindings, payout, supply/commitment decrements, and post-transfer balances before detaching. |
0x45 | DepositSplineVault | creator S, spline/spline-vault/creator-token-account W, config/token program R | Exact 6 accounts plus the mandatory recorder tail. Creator, spline/vault PDAs, mint, authority, source token account, amount, and unpaused config validate before Tokenkeg transfer into the spline vault. |
0x46 | WithdrawSplineVault | creator S, spline/spline-vault/creator-token-account W, token program R | Exact 5 accounts plus the mandatory recorder tail. Creator, canonical vault, mint, and destination validate. The instruction can address only idle spline-vault funds; committed collateral is already in the market vault and is not an account to this instruction. The spline PDA signs the transfer, which remains available during pause. |
0x47 | CloseSpline | creator S/W, spline/spline-vault W, token program R | Exact 4 accounts plus the mandatory recorder tail. Canonical creator and PDA bindings validate. Attached state or nonempty SPL vault rejects. The spline signs vault close and all remaining vault/account lamports return to the creator. |
0x48 | InitResolverRegistry | registry W, config R, authority S/W, system program R | Exact 4 accounts. Config authority signs. Canonical singleton PDA must be vacant or prefunded-system-safe; rent, owner, size, discriminator, bump, and fully zeroed initial policy validate. |
0x49 | UpdateResolverRegistry | registry W, config R, authority S, mandatory recorder tail | Exact 3 base accounts plus the mandatory recorder tail. Emits ResolverRegistryUpdated when the tail is present; the registry is a singleton so the monotonic epoch, not a market sequence, orders the events. Authority signs. Epoch must advance exactly by one and the 3,600-second treasury-update cooldown must elapse. Count is at most 8; the raw fixed-width entries and enabled-kind mask are atomically replaced. Unknown status values fail closed when an entry is later used. |
0x4A | OpenExternalMarket | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x4B | SubmitResolution | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x4C | HaltMarket | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x4D | ExpireExternalMarket | market W, market meta W, config R, optional resolver registry R, reporter S/W, mandatory recorder tail | Exact 4 base accounts, or 5 with the read-only resolver registry inserted before the reporter, plus the mandatory recorder tail. The reporter signs and must be writable. Bumps market.event_sequence and emits ExternalMarketExpired; the recorder header signer slot is written as the zero sentinel rather than the reporter. Canonical external market/meta/config load; unresolved one-shot state required. Strictly requires now > close_ts + max(config expiration window, 2,592,000 seconds), then writes the 5,000/5,000 payout, reserved expiry provenance 2, template version 0, Expired mirror, and resolved marker. Native markets reject with WrongResolver. |
0x4E | ShrinkPreallocatedChild | child W, market R, active preallocation receipt R/W | Exact 3 accounts, no signer (permissionless). Authenticates the canonical Active receipt before inspecting or mutating the child; a vacant receipt cannot authorize native PRE-Begin truncation. The receipt pins creator, external market, child kind, and the exact orderbook-tier or trader-ledger-byte target. Re-derives the selected child PDA, requires program ownership, wholly-zero data, and current length greater than the committed target, then resizes with no lamport movement. Receipt writability is tolerated for transaction-unioned Begin→Shrink bundles. |
0x4F | BeginExternalMarketPreallocation | None accepted | Frozen legacy-Reclaim tombstone. Every payload/account shape rejects as FrozenLegacyReclaim before parsing or account access. |
0x50 | ReclaimExternalMarketPreallocation | receipt/orderbook/ledger/creator destination W, market/meta R, caller S, system program R | Exact 8 base accounts plus the mandatory recorder tail and empty payload. Creator may reclaim immediately; any signer may at/after 86,400 seconds, but destination is immutable creator. Validates vacant market/meta and canonical bounded wholly-zero children, checked-adds all refunds, emits Reclaimed, and closes receipt last. Does not close the policy sidecar; a later Begin replaces it while market/meta stay vacant. |
0x51 | TopUpExternalProgressReserve | market/meta/payer W, payer S, system program R | Exact 4 accounts and no recorder tail. Permissionlessly restores only the reserve required for unprocessed lifecycle steps; checked arithmetic, authenticated external market/meta, and System Program transfer remain atomic. |
0x52 | BeginReclaimExternalMarketV1 | preallocation/policy W, vacant market children R, config R, creator S/W, System Program R, verifier/config/snapshot R, proof buffer/receipt W, consumer authority R; mandatory recorder tail | Exact 15 base accounts plus the mandatory recorder tail and exact 32-byte payload. Recomputes and consumes a signed definition claim, pins every verifier/template/source/time commitment in an immutable policy, and creates the external preallocation receipt atomically. |
0x53 | OpenReclaimExternalMarketV1 | market/meta/orderbook/vault/mints/escrows/ledger W, config/mint/programs R, creator S/W, preallocation receipt/refund W, policy/consumer authority R; mandatory recorder tail | Exact 18 base accounts plus the mandatory recorder tail and exact 16-byte payload. Requires the authenticated definition operation, canonical preallocation and child identities, exact economics, and creator funding before opening the binary market. |
0x54 | ResolveExternalMarketWithReclaimV1 | market/meta/policy/proof buffer/receipt W, orderbook/verifier/config/snapshot/consumer authority/System Program R, reporter S/W; mandatory recorder tail | Exact 12 base accounts plus the mandatory recorder tail and a 32-byte proof-buffer hash. Verifies the exact terminal condition through CPI, independently revalidates every receipt/proof/policy binding, derives outcome and fact hash onchain, consumes receipt and buffer, then resolves atomically. |
0x55 | HaltExternalMarketWithReclaimV1 | market/meta/policy/proof buffer/receipt W, verifier/config/snapshot/consumer authority/System Program R, reporter S/W; mandatory recorder tail | Exact 11 base accounts plus the mandatory recorder tail and a 32-byte proof-buffer hash. Requires the reviewed post-finality left-open condition, derives the halt fact, consumes verifier state, and applies the one-way halt in one transaction. |
0x56 | ExtendExternalCloseWithReclaimV1 | Same account shape as 0x55 | Exact 11 base accounts plus the mandatory recorder tail and a 32-byte proof-buffer hash. Requires the reviewed signed extension condition, enforces monotonic bounded close time, consumes verifier state, and updates the market/policy atomically. |
0xFF | LOG | log_authority S plus binary recorder payload | Intercepted before public parser. Exact one account. Signer must be log-authority PDA. Payload version, authority kind, length, and event count validate. This is internal self-CPI only, not a public user instruction. |