Skip to main content

Module policy

Module policy 

Source
Expand description

Program-level safety policy.

Hopper’s “policy-driven zero-copy runtime” model exposes each safety lever as a bit in a compile-time const struct. The #[hopper::program(...)] macro parses the attribute args and emits pub const HOPPER_PROGRAM_POLICY: HopperProgramPolicy = ...; inside the annotated module. Users read it back through HopperProgramPolicy to specialize handler paths.

§Named modes

ModeLevers
HopperProgramPolicy::STRICTstrict, enforce_token_checks, allow_unsafe all on. Recommended default.
HopperProgramPolicy::SEALEDstrict + enforce_token_checks on, allow_unsafe off. Adds a default unsafe-code denial on handler items.
HopperProgramPolicy::RAWTyped-validation and token-check intent off; unsafe code permitted. Typed handlers still bind.
HopperProgramProfile::TINYBinary-size profile for compact programs: one-byte instruction discriminators and no handler-level modifier instrumentation.

§Zero runtime cost

The policy is consumed by the program macro at compile time. allow_unsafe = false emits #[deny(unsafe_code)] on each handler so unsafe code in that item is denied by default. Called helpers and dependencies are outside this lint’s scope. The handler’s parameter type determines whether ContextSpec::bind(ctx)? runs: typed handlers bind regardless of strict, and raw handlers receive the raw context. strict and enforce_token_checks are author intent markers, not checks automatically inserted into arbitrary handler code. Authors can consult the constants when selecting explicit token helpers such as invoke_strict() and invoke_signed_strict(). The *Checked builder names describe SPL Token’s mint/decimals checks; they do not mean the program policy automatically inserted Hopper authority pre-checks.

No runtime flag, no thread-local, no syscall. Users who need to branch on the policy inside a handler read the const directly:

ⓘ
if super::HOPPER_PROGRAM_POLICY.enforce_token_checks {
    hopper_runtime::require!(authority.is_signer());
}

§Per-instruction overrides

A handler can override the program-level policy with #[instruction(N, unsafe_memory, skip_token_checks, allow_arbitrary_cpi)]. The macro emits pub const <HANDLER>_POLICY: HopperInstructionPolicy = ...; alongside the handler so the same const-branch pattern works at the per-instruction grain.

Structs§

HopperInstructionPolicy
Per-instruction policy override.
HopperProgramPolicy
Program-level safety policy emitted by #[hopper::program(...)].

Enums§

HopperProgramProfile
Program-size/audit profile emitted by #[hopper::program(profile = "...")].