Add instruction decode registry with effect cross-check - #55
Open
abhay wants to merge 1 commit into
Open
Conversation
A Squad proposal arrives as raw Solana instructions. This decodes them into a plain-English action you can read before signing, working down a tier order: bundled primitives, a signed spec registry, the on-chain Anchor IDL, then raw bytes. The decoder lives in the Rust core, shared by the relay and the app, which reaches it through one decodeProposal call across the FFI. It fetches the IDLs, specs, and mints it needs, then cross-checks the decode against the relay's independent simulation: agreement earns the confidence cap, a mismatch drops the confident statement and shows a warning that never blocks. Fail-safe throughout. Unresolved data falls through to raw plus the full simulation, never a confident wrong statement, and a decode never loosens the existing high-risk type-to-confirm gate. The app verifies the signed bundle on-device against a shipped key. Ships 4 curated specs (Kamino deposit, Orca and Raydium swaps, SPL Stake Pool deposit) over real instruction bytes. The production signing key and the relay redeploy are a separate gated step.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A Squad proposal arrives as raw Solana instructions. This decodes them into a plain-English action you can read before signing, working down a tier order: bundled primitives, a signed spec registry, the on-chain Anchor IDL, then raw bytes.
The decoder lives in the Rust core, shared by the relay and the app, which reaches it through one decodeProposal call across the FFI. It fetches the IDLs, specs, and mints it needs, then cross-checks the decode against the relay's independent simulation: agreement earns the confidence cap, a mismatch drops the confident statement and shows a warning that never blocks.
Fail-safe throughout. Unresolved data falls through to raw plus the full simulation, never a confident wrong statement, and a decode never loosens the existing high-risk type-to-confirm gate. The app verifies the signed bundle on-device against a shipped key.
Ships 4 curated specs (Kamino deposit, Orca and Raydium swaps, SPL Stake Pool deposit) over real instruction bytes. The production signing key and the relay redeploy are a separate gated step.