Expand description
Program-level safety policy.
Hopper’s “policy-driven zero-copy runtime” model exposes each
safety lever as a bit in a compile-time const struct. The
#[hopper::program(...)] macro parses the attribute args and
emits pub const HOPPER_PROGRAM_POLICY: HopperProgramPolicy = ...;
inside the annotated module. Users read it back through
HopperProgramPolicy to specialize handler paths.
§Named modes
| Mode | Levers |
|---|---|
HopperProgramPolicy::STRICT | strict, enforce_token_checks, allow_unsafe all on. Recommended default. |
HopperProgramPolicy::SEALED | strict + enforce_token_checks on, allow_unsafe off. Adds a default unsafe-code denial on handler items. |
HopperProgramPolicy::RAW | Typed-validation and token-check intent off; unsafe code permitted. Typed handlers still bind. |
HopperProgramProfile::TINY | Binary-size profile for compact programs: one-byte instruction discriminators and no handler-level modifier instrumentation. |
§Zero runtime cost
The policy is consumed by the program macro at compile time.
allow_unsafe = false emits #[deny(unsafe_code)] on each
handler so unsafe code in that item is denied by default. Called helpers
and dependencies are outside this lint’s scope. The handler’s parameter
type determines whether ContextSpec::bind(ctx)? runs: typed handlers
bind regardless of strict, and raw handlers receive the raw context.
strict and enforce_token_checks are author intent markers, not checks
automatically inserted into arbitrary handler code. Authors can consult
the constants when selecting explicit token helpers such as
invoke_strict() and invoke_signed_strict(). The *Checked builder
names describe SPL Token’s mint/decimals checks; they do not mean the
program policy automatically inserted Hopper authority pre-checks.
No runtime flag, no thread-local, no syscall. Users who need to branch on the policy inside a handler read the const directly:
if super::HOPPER_PROGRAM_POLICY.enforce_token_checks {
hopper_runtime::require!(authority.is_signer());
}§Per-instruction overrides
A handler can override the program-level policy with
#[instruction(N, unsafe_memory, skip_token_checks, allow_arbitrary_cpi)]. The macro
emits pub const <HANDLER>_POLICY: HopperInstructionPolicy = ...;
alongside the handler so the same const-branch pattern works at
the per-instruction grain.
Structs§
- Hopper
Instruction Policy - Per-instruction policy override.
- Hopper
Program Policy - Program-level safety policy emitted by
#[hopper::program(...)].
Enums§
- Hopper
Program Profile - Program-size/audit profile emitted by
#[hopper::program(profile = "...")].