Skip to content

SWAP-449 fix: let callers override the wrapped tx fee payer - #80

Merged
ioanSL merged 1 commit into
mainfrom
evan/swap-449-fix-rfq-squads-fee-payer
May 28, 2026
Merged

ioanSL merged 1 commit into
mainfrom
evan/swap-449-fix-rfq-squads-fee-payer

Conversation

@xianlinc

@xianlinc xianlinc commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds an optional fee_payer: Option<Pubkey> field to SquadsWrapConfig. When set, the given pubkey is used as the outer transaction's fee payer instead of members[0]. The override must be a multisig member or a signer pulled from the swap instructions, otherwise the build fails with InvalidConfig. When unset, behavior is identical to today.

The RFQ squads flow needs this. The maker is a signer on the inner Fill but never the outer fee payer, so the multisig member ends up paying gas and ultra-api's confirmation lookup can't match the maker's signature to the wrapped message. Once rfq-api passes fee_payer: Some(maker), the maker sits at account_keys[0] and the existing ultra-api logic works.

Linear: SWAP-449.

No breaking change

fee_payer defaults to None, which keeps members[0] as the fee payer. Existing callers see no behavioral or wire-format change. Recompiling against the new SDK requires adding fee_payer: None to existing SquadsWrapConfig { ... } literals, that's it.

Market maker validation is unaffected. is_squads_message, unwrap_transaction, and validate_fill_sanitized_message read the inner Fill instruction, not the outer fee-payer slot, so they don't care which signer sits at index 0 of the wrapped message.

PR #78's signer check operates on the unwrapped inner Fill message, not on the squads-wrapped outer message, so it doesn't collide with this change either.

Test plan

  • cargo test -p squads-sdk (29/29 pass, including 2 new tests covering the override path and the invalid pubkey rejection)
  • cargo clippy -p squads-sdk --tests clean
  • cargo fmt --check clean
  • Pair with rfq-api change to pass fee_payer: Some(maker) and re-run a mainnet RFQ swap on a Squads vault, confirm execute returns Success

Adds an optional `fee_payer` field to `SquadsWrapConfig`. When set it
must be a multisig member or a signer pulled from the swap instructions.
Defaults to `members[0]` so existing callers are unaffected.

This is what the RFQ squads path needs: the maker is a signer on the
inner Fill but was never the outer fee payer, so the multisig member
ended up paying gas and ultra-api's confirmation lookup couldn't match
the maker's signature against the message.
@xianlinc
xianlinc requested a review from ioanSL May 26, 2026 05:27
@xianlinc xianlinc self-assigned this May 26, 2026
@github-actions

Copy link
Copy Markdown
Coverage report
Filename Lines Covered (%) Functions Covered (%)
order-engine-sdk/src/fill.rs 94.92 84
order-engine-sdk/src/lib.rs 0 0
order-engine-sdk/src/transaction.rs 0 0
programs/order-engine/src/error.rs 100 100
programs/order-engine/src/instructions/fill.rs 98.29 80
programs/order-engine/src/lib.rs 90.91 75
server-example/src/config.rs 0 0
server-example/src/server.rs 0 0
squads-sdk/src/accounts.rs 93.51 100
squads-sdk/src/config.rs 39.68 50
squads-sdk/src/error.rs 0 0
squads-sdk/src/lib.rs 100 100
squads-sdk/src/pda.rs 98.04 100
squads-sdk/src/serialize.rs 70.83 60
squads-sdk/src/settings.rs 94.02 100
squads-sdk/src/transaction.rs 44.33 44.44
squads-sdk/src/unwrap.rs 89.43 71.43
squads-sdk/src/wrap.rs 84.28 85.71
webhook-api/src/enums.rs 88.75 18.18
webhook-api/src/requests.rs 0 0
webhook-api/src/responses.rs 0 0

Copy link
Copy Markdown
Contributor Author

@ioan bump for the review on this issue, once its merged in we need to switch the rfq repo to use this new version of squads SDK

@ioanSL ioanSL left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍🏽

@ioanSL
ioanSL merged commit e8c5803 into main May 28, 2026
7 checks passed
@ioanSL
ioanSL deleted the evan/swap-449-fix-rfq-squads-fee-payer branch May 28, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants