Expand description
Verified CPI – pre/post state assertions around cross-program invocations.
Hopper can bind a CPI call to explicit post-conditions instead of treating a successful return code as proof of the application-level result.
The pattern: snapshot relevant state before CPI, invoke, then assert post-conditions. If the assertion fails, the instruction aborts before the corrupted state can be read by downstream logic.
§Usage
ⓘ
use hopper_native::verify::{LamportSnapshot, verify_transfer};
// Before CPI transfer:
let snap = LamportSnapshot::capture(source, destination);
// Do the CPI:
system_transfer(&source, &destination, amount)?;
// Verify the transfer actually happened correctly:
snap.verify_transfer(source, destination, amount)?;This catches:
- Called program transferring wrong amount
- Called program not deducting from source
- Called program crediting wrong destination
- Integer overflow in lamport accounting
Structs§
- Balance
Snapshot - Snapshot of a single account’s lamports for simple balance assertions.
- Data
Fingerprint - Fast integrity check for account data using FNV-1a hash.
- Lamport
Snapshot - Snapshot of lamport balances for two accounts before a CPI.