URUOI is one Anchor program, uruoi, with five kinds of account and one Token-2022 mint. This page lists every account, how its address is derived, and who may change it.
Accounts
Account
Address (PDA seeds)
One per
Holds
Protocol
["protocol"]
program
admin, pending admin, the uSOL mint, how many collaterals exist
uSOL mint
["usol_mint"]
program
the Token-2022 mint; the Protocol PDA is its only mint authority
the LST token account holding every position's shares and the buffer
Position
["position", collateral, owner]
owner and collateral
shares, debt (lamports of uSOL), rate snapshot
Because the Collateral address is derived from the LST mint, there can only ever be one collateral per mint, and because the Position address is derived from the collateral and the owner, each owner has exactly one position per collateral.
Collateral fields
Field
Type
Meaning
index
u8
position in the redemption account list, 0..collateral_count
kind
CollateralKind
SplStakePool or Marinade
lst_mint
Pubkey
the LST
rate_source
Pubkey
the pool or Marinade state account the rate is read from
vault
Pubkey
the vault PDA
max_ltv_bps
u16
borrow limit: debt may not pass this share of the SOL value
unwind_ltv_bps
u16
above this, anyone may unwind the position at par
debt_ceiling
u64
cap on uSOL debt backed by this LST
total_debt
u64
uSOL debt across all positions
position_shares
u64
LST held for positions
buffer_shares
u64
LST swept from yield or repaid with collateral, owed to uSOL redeemers
minting_paused
bool
new borrowing switched off for this LST
Position fields
Field
Type
Meaning
owner
Pubkey
who may borrow, withdraw and close
collateral
Pubkey
the Collateral account
shares
u64
LST base units held as collateral
debt
u64
uSOL owed, in lamports
rate_snapshot
u128
pool rate (Q64.64 lamports per share) at the last settle
Who can do what
Instruction
Signer
Notes
initialize
the program's upgrade authority
creates Protocol and the uSOL mint; nobody can front-run the deploy to take the admin seat
add_collateral, configure_collateral
admin
at most 4 collaterals; limits bounded by constants (below)
propose_admin, accept_admin
admin, then the new admin
two-step handover
set_usol_uri
admin
repoints the uSOL metadata link (name and image in wallets); nothing else
burns uSOL against any position; can only lower a debt
sync
nobody (permissionless)
settles a position's yield
redeem
any uSOL holder
burns uSOL for LST pro rata from every buffer
unwind
anyone
only above the unwind threshold, at par
Hard limits in the code
Constant
Value
What it bounds
MAX_LTV_LIMIT_BPS
8,000
the highest borrow limit an admin can ever set (80%)
MAX_UNWIND_LTV_BPS
9,500
the highest unwind threshold (95%)
MAX_COLLATERALS
4
redemption walks every collateral in one transaction
USOL_DECIMALS
9
uSOL base units match lamports
The unwind threshold must sit above the borrow limit, and once set it can only be raised (UnwindLtvLowered). An admin can therefore never make an existing position unwindable by changing settings.
Component view
Diagram, in Mermaidflowchart LR
Owner -- deposit / withdraw --> Vault
Owner -- borrow --> Mint[uSOL mint]
Program -- reads rate --> Pool[Stake pool or Marinade state]
Program -- sweep --> Buffer[buffer_shares in Vault]
Holder[uSOL holder] -- redeem --> Buffer
Keeper -- sync --> Program
Programs it touches
Program
Address
SPL stake pool
SPoo1Ku8WFXoNDMHPsrGSTSG1Y47rzgn41SLUNakuHy
Marinade
MarBmsSgKXdrN1egZf5sqe1TMai9K1rChYNDJgjq7aD
Token (LST vaults)
TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA
Token-2022 (uSOL)
TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb
The URUOI program's own address is published here once it is deployed.