API reference
Every instruction of the uruoi program with its arguments, accounts and checks. Accounts are listed in order; w = writable, s = signer.
initialize
initialize(uri: String): creates the protocol and the uSOL mint (Token-2022, 9 decimals, name "URUOI SOL", symbol "uSOL", metadata uri).
| Account | Flags | |
|---|---|---|
| admin | w, s | must be the program's upgrade authority (NotUpgradeAuthority) |
| program | the URUOI program | |
| program_data | its program data account | |
| protocol | w | PDA ["protocol"], created |
| usol_mint | w | PDA ["usol_mint"], created; mint authority = protocol; no freeze authority |
| token_2022_program, system_program |
Fails with UriTooLong if uri is over 200 bytes.
add_collateral
add_collateral(params: CollateralParams) with CollateralParams { max_ltv_bps: u16, unwind_ltv_bps: u16, debt_ceiling: u64 }.
| Account | Flags | |
|---|---|---|
| admin | w, s | NotAdmin otherwise |
| protocol | w | |
| lst_mint | the LST | |
| rate_source | an SPL stake pool or the Marinade state pricing lst_mint | |
| collateral | w | PDA ["collateral", lst_mint], created |
| vault | w | PDA ["vault", collateral], created (Token program) |
| token_program, system_program |
Checks: 0 < max_ltv_bps <= 8000 (InvalidMaxLtv); max_ltv_bps < unwind_ltv_bps <= 9500 (InvalidUnwindLtv); fewer than 4 collaterals (TooManyCollaterals); the rate source's owner and layout (UnsupportedRateSource, InvalidRateSource, RateSourceMintMismatch).
configure_collateral
configure_collateral(params: CollateralParams, minting_paused: bool). Accounts: admin (s), protocol, collateral (w). The unwind threshold may only rise (UnwindLtvLowered); the other bounds are as in add_collateral.
propose_admin, accept_admin
propose_admin(new_admin: Pubkey): admin (s), protocol (w). accept_admin(): the proposed key (s), protocol (w); NotPendingAdmin for anyone else.
set_usol_uri
set_usol_uri(uri: String): admin (w, s), protocol, usol_mint (w), token_2022_program, system_program. Replaces the uSOL metadata uri (the JSON wallets read for the name and image) and nothing else. The admin pays any extra rent a longer URI needs. NotAdmin for anyone else, UriTooLong over 200 bytes.
open_position
open_position(): owner (w, s), collateral, position (w, PDA ["position", collateral, owner], created), system_program.
deposit
deposit(amount: u64): owner (s), collateral (w), rate_source, position (w), vault (w), source LST account (w), token_program. Settles, then moves amount LST into the vault. ZeroAmount if amount is 0.
borrow
borrow(amount: u64): owner (s), protocol, collateral (w), rate_source, position (w), usol_mint (w), destination uSOL account (w), token_2022_program.
Settles, needs a fresh rate (StaleRate), then requires: not paused (MintingPaused); (debt + amount) x 10000 <= value x max_ltv_bps (ExceedsMaxLtv); total_debt + amount <= debt_ceiling (DebtCeilingReached). Mints amount uSOL. Emits Borrowed.
repay
repay(amount: u64): payer (s), protocol, collateral (w), rate_source, position (w), usol_mint (w), source uSOL account (w), token_2022_program. Anyone may pay any position. Settles, then burns min(amount, debt); the rest stays in the payer's account. NoDebt if there is nothing to pay. Emits Repaid.
repay_with_collateral
repay_with_collateral(amount: u64): owner (s), collateral (w), rate_source, position (w). Settles, needs a fresh rate, then moves LST worth min(amount, debt) lamports (shares rounded up) from the position to the buffer and lowers the debt by the same amount. InsufficientShares if the position cannot cover it. Emits Repaid with with_collateral = true.
withdraw
withdraw(amount: u64): owner (s), collateral (w), rate_source, position (w), vault (w), destination LST account (w), token_program. Settles; InsufficientShares if amount is more than the shares; with debt open, needs a fresh rate and the remaining shares must keep the position within its borrow limit (ExceedsMaxLtv).
sync
sync(): collateral (w), rate_source, position (w). No signer. Settles. Emits Synced if anything was swept.
close_position
close_position(): owner (w, s), position (w). Requires zero shares and zero debt (PositionNotEmpty); returns the rent to the owner.
redeem
redeem(amount: u64): redeemer (s), protocol, usol_mint (w), source uSOL account (w), token_program, token_2022_program, then for every collateral in index order: collateral (w), rate_source, vault (w), destination LST account (w).
Burns amount uSOL and pays LST worth amount lamports, split across buffers in proportion to each buffer's SOL value at fresh rates. Fails with CollateralAccountsMismatch (wrong list), InsufficientBuffer (buffers too small), ZeroOutput (too small to pay a base unit). Emits Redeemed.
unwind
unwind(amount: u64): unwinder (s), protocol, collateral (w), rate_source, position (w), vault (w), usol_mint (w), source uSOL account (w), destination LST account (w), token_program, token_2022_program.
Settles, needs a fresh rate, and requires the position's loan to value to be above the unwind threshold (PositionHealthy otherwise). Burns up to amount uSOL, capped at what brings the position back to its borrow limit, and pays the same SOL value of the position's LST at the pool rate. Emits Unwound.
Account layouts
| Account | Size | Fields |
|---|---|---|
| Protocol | 8 + 32 + 33 + 32 + 1 + 1 + 1 | admin, pending_admin (Option), usol_mint, collateral_count, bump, usol_mint_bump |
| Collateral | see Architecture | index, kind, lst_mint, rate_source, vault, max_ltv_bps, unwind_ltv_bps, debt_ceiling, total_debt, position_shares, buffer_shares, minting_paused, bump, vault_bump |
| Position | 105 bytes | owner, collateral, shares, debt, rate_snapshot, bump |