Instructions Reference#
All Seesaw protocol instructions, with discriminators, accounts, and arguments. The complete account-list appendix includes every live instruction's ordered accounts, shared groups, conditional tails, and signer/writable roles, generated from the SDK builders and checked against the Rust live-tag inventory.
Instruction Overview#
Instruction Discriminators#
The live public ABI has 77 instructions spanning 0x00–0x5A. Live blocks are 0x00–0x30, 0x33–0x37,
0x40–0x49, 0x4D–0x4E, 0x50–0x56, and 0x57–0x5A. Tags 0x31–0x32 are
reserved wire holes; 0x38–0x3F, 0x4A–0x4C, and 0x4F are frozen
legacy-Reclaim tombstones. Reclaim V1 uses 0x52–0x56, and native oracle observations use 0x57–0x5A; internal binary event
recording uses 0xFF. The retired
oracle-governance tags and config fields are absent. Consequently, there is no live pending Pyth program-ID update to apply.
| # | Instruction | Discriminator | Category |
|---|---|---|---|
| 0 | initialize_config | 0x00 | Configuration |
| 1 | update_authority | 0x01 | Authority |
| 2 | claim_authority | 0x02 | Authority |
| 3 | create_market | 0x03 | Market Lifecycle |
| 4 | snapshot_end | 0x04 | Market Lifecycle |
| 5 | resolve_market | 0x05 | Market Lifecycle |
| 6 | expire_market | 0x06 | Market Lifecycle |
| 7 | mint_shares | 0x07 | Token/Settlement |
| 8 | deposit_funds | 0x08 | Free Funds |
| 9 | withdraw_funds | 0x09 | Free Funds |
| 10 | withdraw_shares | 0x0A | Token/Settlement |
| 11 | place_order | 0x0B | Trading |
| 12 | place_multiple_post_only_orders | 0x0C | Trading |
| 13 | swap_with_free_funds | 0x0D | Trading |
| 14 | place_limit_order_with_free_funds | 0x0E | Trading |
| 15 | place_multiple_post_only_orders_with_free_funds | 0x0F | Trading |
| 16 | cancel_order | 0x10 | Trading |
| 17 | cancel_multiple_orders_by_id | 0x11 | Trading |
| 18 | cancel_all_orders | 0x12 | Trading |
| 19 | cancel_up_to | 0x13 | Trading |
| 20 | reduce_order | 0x14 | Trading |
| 21 | cancel_multiple_orders_by_id_with_free_funds | 0x15 | Trading |
| 22 | cancel_all_orders_with_free_funds | 0x16 | Trading |
| 23 | cancel_up_to_with_free_funds | 0x17 | Trading |
| 24 | reduce_order_with_free_funds | 0x18 | Trading |
| 25 | reclaim_expired_order | 0x19 | Trading |
| 26 | redeem | 0x1A | Token/Settlement |
| 27 | force_close | 0x1B | Token/Settlement |
| 28 | mark_position_settled | 0x1C | Token/Settlement |
| 29 | close_position | 0x1D | Token/Settlement |
| 30 | close_market | 0x1E | Market Lifecycle |
| 31 | update_fee_config | 0x1F | Admin |
| 32 | update_treasury_recipients | 0x20 | Admin |
| 33 | set_referrer | 0x21 | Referral |
| 34 | init_referrer_earnings_account | 0x22 | Referral |
| 35 | claim_creator_fees | 0x23 | Fees |
| 36 | claim_referrer_earnings | 0x24 | Referral |
| 37 | pause | 0x25 | Admin |
| 38 | unpause | 0x26 | Admin |
| 39 | enable_post_only_mode | 0x27 | Admin |
| 40 | disable_post_only_mode | 0x28 | Admin |
| 41 | update_tick_size | 0x29 | Admin |
| 42 | update_min_resting_notional | 0x2A | Admin |
| 43 | update_market_cap | 0x2B | Admin |
| 44 | set_market_emergency_status | 0x2C | Admin |
| 45 | force_cancel_market_orders | 0x2D | Admin |
| 46 | ensure_trader_ledger_space | 0x2E | Market Lifecycle |
| 47 | update_operational_params | 0x2F | Admin |
| 48 | recover_spline | 0x30 | Splines |
| 51 | ensure_deep_orderbook_space | 0x33 | Market Lifecycle |
| 52 | set_pauser | 0x34 | Admin |
| 53 | top_up_closer_rewards | 0x35 | Market Lifecycle |
| 54 | rollup_referral_fees | 0x36 | Referral |
| 55 | initialize_referrer_treasury_shard | 0x37 | Referral |
| — | frozen legacy Reclaim bridge | 0x38–0x3F | Tombstone |
| 64 | init_spline | 0x40 | Splines |
| 65 | update_spline_shape | 0x41 | Splines |
| 66 | update_spline_mid | 0x42 | Splines |
| 67 | attach_spline | 0x43 | Splines |
| 68 | settle_spline | 0x44 | Splines |
| 69 | deposit_spline_vault | 0x45 | Splines |
| 70 | withdraw_spline_vault | 0x46 | Splines |
| 71 | close_spline | 0x47 | Splines |
| 72 | init_resolver_registry | 0x48 | Resolver Registry |
| 73 | update_resolver_registry | 0x49 | Resolver Registry |
| — | frozen legacy external lifecycle | 0x4A–0x4C | Tombstone |
| 77 | expire_external_market | 0x4D | External Markets |
| 78 | shrink_preallocated_child | 0x4E | External Markets |
| — | frozen legacy external preallocation | 0x4F | Tombstone |
| 80 | reclaim_external_market_preallocation | 0x50 | External Markets |
| 81 | top_up_external_progress_reserve | 0x51 | External Markets |
| 82 | begin_reclaim_external_market_v1 | 0x52 | Reclaim V1 |
| 83 | open_reclaim_external_market_v1 | 0x53 | Reclaim V1 |
| 84 | resolve_external_market_with_reclaim_v1 | 0x54 | Reclaim V1 |
| 85 | halt_external_market_with_reclaim_v1 | 0x55 | Reclaim V1 |
| 86 | extend_external_close_with_reclaim_v1 | 0x56 | Reclaim V1 |
| 87 | record_oracle_observation | 0x57 | Native Oracle |
| 88 | submit_oracle_observation | 0x58 | Native Oracle |
| 89 | finalize_oracle_observation | 0x59 | Native Oracle |
| 90 | close_oracle_observation | 0x5A | Native Oracle |
| - | log | 0xFF | Internal Event |
Per-instruction sections below do not yet cover the external-market block (
0x48–0x56). For their accounts, arguments, and validation rules usespec/IX.md, which is drift-checked againstprogram/src/instruction.rsbymake idl-check.See Market-maker spline live surface for the full spline account layout, instruction data, and attachment model.
Compute units: The "Compute Units" figures in the per-instruction sections below are approximate estimates for budgeting only. Actual consumption varies with account state, matching depth, and runtime version — always benchmark against the deployed program and size your transaction CU limits with headroom.
Account-list convention#
Tables below list base accounts before the recorder suffix. On the current
native dispatch surface, every live public route except 0x33, 0x42, 0x48,
0x4E and 0x51 requires the terminal read-only pair
[self_program, log_authority]. Append it after any instruction-specific tails.
self_program must be this executable program; log_authority must be its
canonical PDA. A missing or malformed pair rejects before instruction parsing.
The five exceptions are intentionally eventless; follow their exact account
contracts rather than appending a recorder pair indiscriminately.
This reference describes the currently shipped native ABI. Reserved tags and
permanent tombstones have no usable account or argument surface. LOG is an
internal self-CPI route, not a public transaction instruction.
initialize_config#
One-time protocol initialization. Creates the config PDA, records the initial authority and treasury, validates the default settlement mint, and writes the default capped-linear-decay fee curve and four-way allocation.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | config | - | W | Config PDA |
| 1 | authority | S | W | Upgrade authority and rent payer |
| 2–9 | treasury_recipients[0..7] | - | - | Eight distinct settlement-token fee recipients |
| 10 | default_settlement_mint | - | - | Settlement mint |
| 11 | system_program | - | - | System Program |
| 12 | program_data | - | - | Upgradeable program data |
InitializeConfig has 13 base accounts plus the required recorder pair: 15 total.
<!-- src: program/src/processor/initialize_config.rs:49 INITIALIZE_CONFIG_BASE_ACCOUNT_COUNT -->Arguments#
| Field | Type | Description |
|---|---|---|
| tick_size_bps | u16 | Price tick size |
The fee fields are initialized from shipped protocol defaults:
fee_cap_bps = 200, decay_rate_bps = 400, protocol_fee_bps = 5_000,
maker_rebate_share_bps = 4_000, default_creator_fee_bps = 500,
referral_share_bps_of_fee = 500, and maker_rebate_min_rest_seconds = 10.
These are initialization values, not an attestation of deployed config.
The shipped allocation is 50% protocol / 5% creator / 5% referral / 40% maker rebate. Eligible maker fills credit the maker's free quote balance; ineligible maker allocation and rounding dust go to protocol, as does the referral allocation without an eligible referrer. See fee constants and allocation details.
<!-- src: program/src/logic/fee.rs:168 FeeSplit4::TARGET --> <!-- F-01: update with builder fee allocation -->Constraint: authority must sign and must match the upgrade authority stored in program_data.
Compute Units#
~6,000 CU
create_market#
Create a new market for a configured Pyth feed and duration. The instruction initializes all market PDAs, validates the settlement mint, captures the first valid price from a transient Receiver PriceUpdateV2 account, and transitions the market into trading. Pyth Pull is the only supported oracle path.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | orderbook | - | W | Orderbook PDA |
| 2 | vault | - | W | SPL Token vault PDA |
| 3 | yes_mint | - | W | YES mint PDA |
| 4 | no_mint | - | W | NO mint PDA |
| 5 | asset_state | - | W | Per-feed asset state PDA |
| 6 | config | - | W | Protocol config; increments markets_created |
| 7 | price_update | - | - | Pyth price feed: transient Receiver PriceUpdateV2 |
| 8 | settlement_mint | - | - | USDT/SPL settlement mint |
| 9 | payer | S | W | Rent payer and market creator |
| 10 | system_program | - | - | System Program |
| 11 | token_program | - | - | SPL Token Program |
| 12 | yes_escrow | - | W | Market-owned YES escrow token account |
| 13 | no_escrow | - | W | Market-owned NO escrow token account |
| 14 | trader_ledger | - | W | Market-owned trader ledger PDA |
Arguments#
| Field | Type | Description |
|---|---|---|
| max_confidence_ratio_bps | u16 | Max Pyth confidence interval as bps of price; 0 disables this market guard |
| duration_seconds | u64 | Market duration, bounded by protocol min/max |
| max_oracle_jump_bps | u32 | Optional per-market start-to-end jump guard; 0 uses the protocol default |
| bids_size | u32 | Deep-orderbook bid-side capacity tier: 64, 128, 256, 512, 1024, 2048, or 4096 |
| asks_size | u32 | Deep-orderbook ask-side capacity tier; must equal bids_size |
| num_seats | u32 | Trader-ledger seat count; must be one of the twelve recognized layout tiers; activation is capped at 4,225 seats |
market_id is derived from the current timestamp and duration_seconds; clients do not pass it directly in the current instruction data. bids_size and asks_size select the symmetric deep-orderbook tier and must be one of 64, 128, 256, 512, 1024, 2048, 4096. num_seats must be one of TRADER_LEDGER_SEAT_OPTIONS and no greater than
MAX_ACTIVATABLE_TRADER_LEDGER_SEATS — see Market Capacity.
Compute Units#
~25,000 CU
snapshot_end#
Capture the closing price from a transient Pyth Receiver PriceUpdateV2.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | price_update | - | - | Transient Receiver PriceUpdateV2 |
| 2 | settler | S | W | Permissionless settlement caller |
| 3 | config | - | - | Protocol config |
The four base accounts require the two-account recorder suffix: six total.
<!-- src: program/src/processor/mod.rs:135 requires_recorder_tail -->Arguments#
None.
Compute Units#
~15,000 CU (includes order cancellation)
Side Effects#
- All open orders are cancelled
- Collateral/shares returned to users
place_order#
Submit a Limit, PostOnly or ImmediateOrCancel order.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | orderbook | - | W | Orderbook PDA |
| 2 | user_position | - | W | User position PDA |
| 3 | user_token_account | - | W | User's settlement-token account |
| 4 | vault | - | W | Market vault |
| 5 | user | S | W | Order owner |
| 6 | config | - | - | Protocol config |
| 7 | treasury_token_account | - | W | Protocol fee recipient |
| 8 | token_program | - | - | SPL Token Program |
| 9 | system_program | - | - | System Program, used when creating position PDA |
| 10 | settlement_mint | - | - | Settlement mint |
| 11 | yes_escrow | - | W | Market-owned YES escrow |
| 12 | no_escrow | - | W | Market-owned NO escrow |
| 13 | user_yes_ata | - | W | User YES token account |
| 14 | user_no_ata | - | W | User NO token account |
| 15 | yes_mint | - | W | YES mint PDA |
| 16 | no_mint | - | W | NO mint PDA |
| 17 | trader_ledger | - | W | Market-owned trader ledger PDA |
After the 18-account prefix, a spline-enabled market requires its one writable
creator spline at index 18. Next comes an optional single taker_referral_account
(read-only ReferralAccount), then the mandatory recorder pair. The old
referrer-wallet/earnings/treasury triple is not accepted. Total accounts: 20–21
without a spline, 21–22 with the creator spline.
Arguments#
| Field | Type | Description |
|---|---|---|
| side | u8 | 0=BuyYes, 1=SellYes, 2=BuyNo, 3=SellNo |
| price_bps | u16 | Limit price [1, 9999] |
| quantity | u64 | Share quantity |
| order_type | u8 | 0=Limit, 1=PostOnly, 2=IOC |
| worst_acceptable_price_bps | u16 | IOC-only bound; 0 on canonical Bid or 10000 on canonical Ask disables it; ignored for Limit/PostOnly |
| min_fill_quantity | u64 | IOC-only atomic minimum matched quantity; 0 disables; ignored for Limit/PostOnly |
| match_limit | u8 | Wire domain 0..=12; 0 uses the protocol default; counts maker iterations including evictions and self-trade hits |
| self_trade_behavior | u8 | 0=Abort, 1=CancelProvide, 2=DecrementTake |
| max_age_seconds | u32 | TTL for this order's resting remainder; zero selects market close, nonzero is capped at that close |
| reject_post_only_would_cross | u8 | PostOnly: 1 rejects with WouldCross; 0 slides one tick beyond the crossing maker, rejecting if no valid price remains |
| protocol_treasury_index | u8 | Preference in [0,8); the supplied config-approved recipient determines the effective index; unregistered recipient rejects |
Compute Units#
~15,000 - 50,000 CU (depends on matching)
cancel_order#
Remove an open order.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | orderbook | - | W | Orderbook PDA |
| 2 | user_position | - | W | User position PDA |
| 3 | user_token_account | - | W | User settlement-token account |
| 4 | vault | - | W | Market vault |
| 5 | user | S | - | Order owner |
| 6 | token_program | - | - | SPL Token Program |
| 7 | settlement_mint | - | - | Settlement mint |
| 8 | yes_escrow | - | W | YES escrow |
| 9 | no_escrow | - | W | NO escrow |
| 10 | user_yes_ata | - | W | User YES token account |
| 11 | user_no_ata | - | W | User NO token account |
| 12 | yes_mint | - | W | YES mint |
| 13 | no_mint | - | W | NO mint |
| 14 | trader_ledger | - | W | Trader-ledger PDA |
Fifteen base accounts plus the required recorder pair: 17 total.
<!-- src: program/src/processor/cancel_order.rs:81 CancelOrderAccounts -->Arguments#
| Field | Type | Description |
|---|---|---|
| order_id | u64 | Order to cancel |
Compute Units#
~8,000 CU
resolve_market#
Determine outcome from snapshots.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | asset_state | - | W | Asset-state PDA bound to the market feed |
| 2 | caller | S | W | Permissionless caller; receives closer reward |
| 3 | config | - | - | Protocol config |
| 4 | vault | - | W | Market vault |
| 5 | creator_token_account | - | W | Creator fee destination |
| 6 | settlement_mint | - | - | Settlement mint |
| 7 | token_program | - | - | SPL Token Program |
Eight base accounts plus the required recorder pair: 10 total.
<!-- src: program/src/processor/resolve.rs:49 ResolveMarketAccounts -->Arguments#
None.
Compute Units#
~6,000 CU
Resolution Logic#
mint_shares (0x07)#
Deposit USDT to receive equal YES + NO tokens.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | yes_mint | - | W | YES mint |
| 2 | no_mint | - | W | NO mint |
| 3 | user_yes_ata | - | W | User YES token account |
| 4 | user_no_ata | - | W | User NO token account |
| 5 | user_stablecoin_ata | - | W | User settlement-token account |
| 6 | vault | - | W | Market vault |
| 7 | user | S | - | User |
| 8 | config | - | - | Protocol config |
| 9 | token_program | - | - | SPL Token Program |
| 10 | settlement_mint | - | - | Settlement mint |
Eleven base accounts plus the required recorder pair: 13 total.
<!-- src: program/src/processor/mint_shares.rs:32 MintSharesAccounts -->Arguments#
| Field | Type | Description |
|---|---|---|
| amount | u64 | Amount of USDT to deposit |
Compute Units#
~15,000 CU
redeem (0x1A)#
Burn winning tokens for USDT after resolution.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | yes_mint | - | W | YES mint |
| 2 | no_mint | - | W | NO mint |
| 3 | user_yes_ata | - | W | User YES token account |
| 4 | user_no_ata | - | W | User NO token account |
| 5 | user_stablecoin_ata | - | W | User settlement-token account |
| 6 | vault | - | W | Market vault |
| 7 | user | S | - | User |
| 8 | token_program | - | - | SPL Token Program |
| 9 | settlement_mint | - | - | Settlement mint |
External markets require read-only market_meta next; native markets omit it.
An optional all-or-none writable trio [user_position, orderbook, trader_ledger]
follows. The recorder pair is always last. Native totals are 12 or 15 accounts;
external totals are 13 or 16.
Arguments#
| Field | Type | Description |
|---|---|---|
| amount | u64 | Amount of tokens to redeem |
| token_type | u8 | Which token to redeem (0=Yes, 1=No) |
Compute Units#
~15,000 CU
Payout Calculation#
withdraw_shares (0x0A)#
Convert trader-ledger free YES/NO share credits to SPL tokens.
Compute Units#
~10,000 CU
force_close (0x1B)#
Force-close position in expired/unresolved market. Returns full collateral.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | position | - | W | User position PDA |
| 2 | vault | - | W | Market vault |
| 3 | user_stablecoin_ata | - | W | User's USDT account |
| 4 | caller | S | - | Caller (permissionless) |
| 5 | config | - | - | Protocol config |
| 6 | token_program | - | - | SPL Token Program |
| 7 | settlement_mint | - | - | Settlement token mint |
Prerequisites#
current_time >= t_end + expiration_window AND outcome == 0
Compute Units#
~12,000 CU
close_market (0x1E)#
Close resolved market after 7-day timeout. Transfers rent to creator.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | creator | - | W | Market creator (rent target) |
| 2 | caller | S | - | Caller (permissionless) |
| 3 | config | - | - | Protocol config |
| 4 | system_program | - | - | System Program |
| 5 | vault | - | W | Market settlement vault |
| 6 | token_program | - | - | SPL Token Program |
| 7 | orderbook | - | W | Market orderbook PDA |
| 8 | yes_escrow | - | W | YES escrow PDA |
| 9 | no_escrow | - | W | NO escrow PDA |
| 10 | trader_ledger | - | W | Dynamic ledger PDA |
| 11 | creator_stablecoin_ata | - | W | Creator settlement ATA |
After the 12-account prefix, native tails are empty or the writable
[yes_mint, no_mint] pair. External tails are [market_meta] or
[market_meta, yes_mint, no_mint]; market_meta is writable. The mint pair is
needed when donated share surplus must be burned. Every form then appends the
mandatory recorder pair. Native totals are 14 or 16; external totals are 15 or 17.
Prerequisites#
current_time >= resolved_at + 604800 AND outcome != 0
Compute Units#
~8,000 CU
State Transitions#
Error Codes#
Seesaw uses a custom #[repr(u32)] error enum (SeesawError) with
category-prefixed hex codes that surface as ProgramError::Custom(code). Codes
are not in the Anchor 6000+ range. A representative selection (see the
SeesawError enum in the program source for the exhaustive list):
| Code | Name | Category | Description |
|---|---|---|---|
| 0x1001 | MarketExists | Market | Market already exists |
| 0x1002 | InvalidState | Market | Wrong market state for the operation |
| 0x1005 | AlreadyResolved | Market | Market already resolved |
| 0x1011 | InvalidStateTransition | Market | Illegal lifecycle transition |
| 0x2001 | OracleMismatch | Oracle | Oracle account does not match market |
| 0x2002 | StaleOracle | Oracle | Oracle price too old |
| 0x2003 | InvalidPrice | Oracle | Non-positive / invalid oracle price |
| 0x2005 | FeedIdMismatch | Oracle | Pyth feed id mismatch |
| 0x3001 | InvalidQuantity | Order | Order quantity out of range |
| 0x3004 | WouldCross | Order | Post-only order would cross the book |
| 0x3007 | SlippageExceeded | Order | Fill price worse than slippage guard |
| 0x4001 | MathOverflow | Math | Checked arithmetic overflowed |
| 0x5003 | InvalidPDA | Account | PDA derivation mismatch |
| 0x5005 | InsolvencyDetected | Account | Solvency invariant would break |
| 0x6001 | ProtocolPaused | Position | Protocol is paused |
| 0x7004 | SolvencyViolation | Token | Token operation breaks solvency |
| 0x8002 | InvalidFeeSplit | Fee | Fee split does not sum to 10,000 |
| 0x9001 | NoPendingAuthority | Authority | No pending authority to claim |
Category ranges: Market 0x1001+, Oracle 0x2001+, Order 0x3001+, Math
0x4001, Account 0x5001+, Position 0x6001, Token 0x7001+, Fee/Treasury
0x8001+, Authority 0x9001+.
claim_creator_fees (0x23)#
Sweep deferred creator fees from the market vault to the creator's token account.
Permissionless — anyone may call it, but fees are always sent to market.creator.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | market | - | W | Market PDA |
| 1 | vault | - | W | Market vault (SPL Token, holds accumulated fees) |
| 2 | creator_token_account | - | W | Creator's token account for market.settlement_mint |
| 3 | settlement_mint | - | - | Settlement mint (TransferChecked) |
| 4 | caller | S | - | Permissionless caller (signer) |
| 5 | token_program | - | - | SPL Token Program |
Arguments#
None.
Prerequisites#
market.outcome != 0 (resolved or expired)
market.accumulated_creator_fees > 0
creator_token_account.owner == market.creator
creator_token_account.mint == market.settlement_mint
Compute Units#
~10,000 CU
Side Effects#
- Transfers
accumulated_creator_feesUSDT from vault to creator's token account viaTransferChecked. - Zeroes
market.accumulated_creator_fees. - Emits
CreatorFeesClaimedevent.
update_fee_config (0x1F)#
Admin-only. Retunes the capped-linear-decay curve, four-way allocation and maker resting-age gate atomically. Instruction argument names below differ from the stored config fields.
<!-- src: program/src/instruction.rs:1464 UpdateFeeConfigArgs --> <!-- src: program/src/logic/fee.rs:168 FeeSplit4::TARGET --> <!-- F-01: update with builder fee allocation -->Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | config | - | W | Config PDA |
| 1 | authority | S | - | Protocol authority |
Arguments#
| Field | Type | Description |
|---|---|---|
| fee_cap_bps | u16 | New curve ceiling in bps of notional |
| decay_rate_bps | u16 | New curve slope in bps of notional |
| protocol_share_bps | u16 | Protocol share (bps of total fee) |
| creator_share_bps | u16 | Creator share (bps of total fee) |
| referral_share_bps | u16 | Referral share (bps of total fee) |
| maker_rebate_share_bps | u16 | Eligible maker share (bps of total fee) |
| maker_rebate_min_rest_seconds | u32 | Minimum age for rebate eligibility |
Constraints:
protocol_share_bps + creator_share_bps + referral_share_bps + maker_rebate_share_bps == 10_000fee_cap_bps <= 500(hard ceiling of 5.00%)
Compute Units#
~3,500 CU
set_referrer (0x21)#
Permissionless. Binds a ReferralAccount PDA to a user, recording the referrer and the attribution timestamp. First-touch and immutable; an existing referral account cannot be overwritten.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | referral_account | - | W | ReferralAccount PDA (user-scoped, to create) |
| 1 | user | S | W | User being attributed (pays rent) |
| 2 | referrer | - | - | Referrer wallet |
| 3 | referrer_earnings_account | - | - | Existing ReferrerEarningsAccount PDA for referrer |
| 4 | system_program | - | - | System Program |
Arguments#
None (referrer is read from accounts[2]).
Prerequisites#
referral_account does not yet exist
referrer != user (self-referral rejected)
referrer_earnings_account.referrer == referrer
Compute Units#
~5,000 CU
Side Effects#
- Writes
ReferralAccount { referee: user, referrer, created_at: now, expires_at: now + REFERRAL_DURATION_SECONDS, ... }to PDA. - Emits
ReferrerSetevent.
init_referrer_earnings_account (0x22)#
Permissionless. Creates the per-referrer earnings escrow (ReferrerEarningsAccount PDA) if it doesn't exist. The referrer signs and pays rent. Also records which treasury shard the referrer is associated with for future claim_referrer_earnings calls.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | referrer_earnings_account | - | W | Earnings PDA to create |
| 1 | referrer | S | W | Referrer and rent payer |
| 2 | treasury_shard | - | - | Preprovisioned canonical shard for treasury_index |
| 3 | settlement_mint | - | - | Config default settlement mint |
| 4 | config | - | - | Protocol config |
| 5 | system_program | - | - | System Program |
Six base accounts plus the required recorder pair: eight total. The shard must
already exist via InitializeReferrerTreasuryShard (0x37); this instruction does
not create it and takes no token-program account.
Arguments#
| Field | Type | Description |
|---|---|---|
| treasury_index | u8 | Treasury shard index ∈ [0, 8) for this referrer's fees |
Compute Units#
~5,000 CU
claim_referrer_earnings (0x24)#
Sweep accumulated referrer earnings from the sharded referrer_treasury_k PDA to the referrer's token account. Permissionless — anyone may call it, but funds always go to the referrer.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | referrer_earnings_account | - | W | Referrer's ReferrerEarningsAccount PDA |
| 1 | referrer_treasury_k | - | W | Sharded referral escrow token account selected by the earnings account treasury_index |
| 2 | referrer_token_account | - | W | Referrer's token account for settlement_mint |
| 3 | settlement_mint | - | - | Settlement mint (TransferChecked) |
| 4 | referrer | S | - | Referrer wallet |
| 5 | token_program | - | - | SPL Token Program |
| 6 | config | - | - | Config PDA |
Arguments#
None.
Prerequisites#
referrer_earnings_account.accumulated > 0
referrer_token_account.owner == referrer
referrer_token_account.mint == config.default_settlement_mint
Compute Units#
~10,000 CU
Side Effects#
- Transfers
accumulatedUSDT fromreferrer_treasury_ktoreferrer_token_accountviaTransferChecked. - Zeroes
referrer_earnings_account.accumulated, bumpstotal_claimed, and writeslast_claim_at. - Emits
ReferralClaimedevent.
ensure_trader_ledger_space (0x2E)#
Pre-grow the TraderLedgerAccount PDA before CreateMarket. Because Solana
caps account growth at MAX_PERMITTED_DATA_INCREASE (10,240 bytes) per
instruction, ledgers larger than ~141 seats require multiple invocations.
CreateMarket rejects a ledger that has not been fully pre-grown.
Idempotent: a no-op once the PDA is at target_size.
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | trader_ledger | - | W | Trader-ledger PDA (may not yet exist) |
| 1 | market | - | - | Parent market PDA (seeds for ledger PDA) |
| 2 | payer | S | W | Rent payer (any caller) |
| 3 | system_program | - | - | System Program |
Arguments#
| Field | Type | Description |
|---|---|---|
| target_size | u32 | Final byte size the ledger should reach (56 + num_seats × 72) |
Compute Units#
~5,000 CU per call
Usage#
ceil(target_size / 10240) invocations required before CreateMarket.
SDKs (@seesaw/core, sdk-rust, sdk-python) bundle this prelude automatically.
update_operational_params (0x2F)#
Admin-only. Post-deploy setter for nine operational parameters, including the
currently shipped creator-spline controls listed below. Rate-limited to once per
OPERATIONAL_PARAMS_RATE_LIMIT_SECONDS (3,600 s).
Accounts#
| # | Account | Signer | Writable | Description |
|---|---|---|---|---|
| 0 | config | - | W | Config PDA |
| 1 | authority | S | - | Protocol authority |
Arguments#
| Field | Type | Description |
|---|---|---|
| closer_reward_lamports | u64 | Lifecycle reward in lamports; 0 disables the bounty |
| max_price_staleness_seconds | u64 | Oracle freshness seconds; 0 selects protocol default |
| market_expiration_window_seconds | u64 | Expiry delay seconds; 0 selects protocol default |
| min_market_duration_seconds | u64 | Minimum duration seconds; 0 selects protocol default |
| max_market_duration_seconds | u64 | Maximum duration seconds; 0 selects protocol default |
| max_order_size | u64 | Maximum share-token base units; must be nonzero |
| spline_flags | u8 | Bit 0 enables spline attachment |
| spline_min_commitment | u64 | Minimum stablecoin base-unit commitment; must be nonzero |
| spline_mid_jump_reset_bps | u16 | Material mid-price jump threshold for resetting eligibility |
All fields are supplied atomically; zero does not mean “leave unchanged.”
<!-- src: program/src/instruction.rs:1163 UpdateOperationalParamsArgs -->Constraint: Rate-limited by last_operational_params_update_at; returns
OperationalParamsRateLimit (0x800D) if called within the cooldown window.
Compute Units#
~3,500 CU
Reserved discriminators 0x31–0x32#
Neither tag has an account or argument surface; dispatch rejects both with
InvalidInstructionData. RecoverSpline occupies 0x30 and takes no payload
after its discriminator. See the current spline account contract.