Expand description
Verified CPI – pre/post state assertions around cross-program invocations.
Hopper can bind a CPI call to explicit post-conditions instead of treating a successful return code as proof of the application-level result.
The pattern: snapshot relevant state before CPI, invoke, then assert
post-conditions. These helpers return an error on mismatch. Propagate that
error to the instruction boundary (?) to roll back the transaction; catching
or ignoring it does not undo the CPI. They do not grant transfer authority.
§Usage
ⓘ
use hopper_native::verify::LamportSnapshot;
// Before CPI transfer:
let snap = LamportSnapshot::capture(source, destination);
// Do the CPI:
system_transfer(&source, &destination, amount)?;
// Verify the transfer actually happened correctly:
snap.verify_transfer(source, destination, amount)?;This catches:
- Called program transferring wrong amount
- Called program not deducting from source
- Called program crediting wrong destination
- Integer overflow in lamport accounting
Structs§
- Balance
Snapshot - Snapshot of a single account’s lamports for simple balance assertions.
- Data
Fingerprint - Fast integrity check for account data using FNV-1a hash.
- Lamport
Snapshot - Snapshot of lamport balances for two accounts before a CPI.