SWAP-449 fix: let callers override the wrapped tx fee payer - #80
Merged
Merged
Conversation
Adds an optional `fee_payer` field to `SquadsWrapConfig`. When set it must be a multisig member or a signer pulled from the swap instructions. Defaults to `members[0]` so existing callers are unaffected. This is what the RFQ squads path needs: the maker is a signer on the inner Fill but was never the outer fee payer, so the multisig member ended up paying gas and ultra-api's confirmation lookup couldn't match the maker's signature against the message.
Coverage report
|
Contributor
Author
|
@ioan bump for the review on this issue, once its merged in we need to switch the rfq repo to use this new version of squads SDK |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds an optional
fee_payer: Option<Pubkey>field toSquadsWrapConfig. When set, the given pubkey is used as the outer transaction's fee payer instead ofmembers[0]. The override must be a multisig member or a signer pulled from the swap instructions, otherwise the build fails withInvalidConfig. When unset, behavior is identical to today.The RFQ squads flow needs this. The maker is a signer on the inner Fill but never the outer fee payer, so the multisig member ends up paying gas and ultra-api's confirmation lookup can't match the maker's signature to the wrapped message. Once rfq-api passes
fee_payer: Some(maker), the maker sits ataccount_keys[0]and the existing ultra-api logic works.Linear: SWAP-449.
No breaking change
fee_payerdefaults toNone, which keepsmembers[0]as the fee payer. Existing callers see no behavioral or wire-format change. Recompiling against the new SDK requires addingfee_payer: Noneto existingSquadsWrapConfig { ... }literals, that's it.Market maker validation is unaffected.
is_squads_message,unwrap_transaction, andvalidate_fill_sanitized_messageread the inner Fill instruction, not the outer fee-payer slot, so they don't care which signer sits at index 0 of the wrapped message.PR #78's signer check operates on the unwrapped inner Fill message, not on the squads-wrapped outer message, so it doesn't collide with this change either.
Test plan
cargo test -p squads-sdk(29/29 pass, including 2 new tests covering the override path and the invalid pubkey rejection)cargo clippy -p squads-sdk --testscleancargo fmt --checkcleanfee_payer: Some(maker)and re-run a mainnet RFQ swap on a Squads vault, confirm execute returns Success