Expand description
Instruction introspection – stack height and sibling instruction access.
These wrappers support security patterns based on transaction and call-stack introspection:
-
CPI guard: Detect if the current instruction is running inside a CPI call (stack height > 1). Prevents unauthorized composition – e.g., a governance instruction that must be top-level only.
-
Precompile inspection: Read a previous sibling’s program ID and data. Program-ID checks alone do not authorize an action. Validate signature count, offsets, referenced instruction bytes, and the expected key/message.
-
Secp256k1 recovery: Same pattern for Ethereum-compatible signatures.
Hopper wraps these syscalls behind small typed helpers so programs do not need to repeat raw unsafe glue at every call site.
Structs§
- Processed
Instruction - Metadata about a previously processed sibling instruction.
- Processed
Instruction Account - Account metadata returned by the sibling-instruction syscall.
- Processed
Instruction View - A processed sibling copied into caller-owned scratch buffers.
Constants§
- ED25519_
PROGRAM_ ID - Well-known precompile address for Ed25519 signature verification.
- SECP256
K1_ PROGRAM_ ID - Well-known precompile address for Secp256k1 signature recovery.
- SECP256
R1_ PROGRAM_ ID - Well-known precompile address for Secp256r1 (P-256) signature verification (SIMD-0075). This is the precompile that backs passkey / WebAuthn signature checks on Solana.
Functions§
- get_
processed_ instruction - Convenience reader for up to 1,232 data bytes and 64 account metas.
- get_
processed_ instruction_ into - Read a processed sibling without heap allocation or fixed-size scratch space.
- get_
stack_ height - Get the current instruction stack height.
- is_cpi
- Returns true if the current instruction is running inside a CPI.
- is_
top_ level - Returns true if the current instruction is at the top level (not running inside a CPI).
- require_
cpi - Require that the current instruction IS inside a CPI.
- require_
ed25519_ instruction - Check that a previous sibling instruction was to the Ed25519 precompile.
- require_
secp256k1_ instruction - Check that a previous sibling instruction was to the Secp256k1 precompile. Checks only the program ID, not payload validity or application authorization.
- require_
secp256r1_ instruction - Check that a previous sibling instruction was to the Secp256r1 (P-256) precompile, the verification path for passkeys / WebAuthn.
- require_
top_ level - Require that the current instruction is NOT a CPI call.