URUOIdocs

Architecture

URUOI is one Anchor program, uruoi, with five kinds of account and one Token-2022 mint. This page lists every account, how its address is derived, and who may change it.

Accounts

AccountAddress (PDA seeds)One perHolds
Protocol["protocol"]programadmin, pending admin, the uSOL mint, how many collaterals exist
uSOL mint["usol_mint"]programthe Token-2022 mint; the Protocol PDA is its only mint authority
Collateral["collateral", lst_mint]LST mintkind, rate source, vault, borrow limit, unwind threshold, debt ceiling, totals, buffer
Vault["vault", collateral]collateralthe LST token account holding every position's shares and the buffer
Position["position", collateral, owner]owner and collateralshares, debt (lamports of uSOL), rate snapshot

Because the Collateral address is derived from the LST mint, there can only ever be one collateral per mint, and because the Position address is derived from the collateral and the owner, each owner has exactly one position per collateral.

Collateral fields

FieldTypeMeaning
indexu8position in the redemption account list, 0..collateral_count
kindCollateralKindSplStakePool or Marinade
lst_mintPubkeythe LST
rate_sourcePubkeythe pool or Marinade state account the rate is read from
vaultPubkeythe vault PDA
max_ltv_bpsu16borrow limit: debt may not pass this share of the SOL value
unwind_ltv_bpsu16above this, anyone may unwind the position at par
debt_ceilingu64cap on uSOL debt backed by this LST
total_debtu64uSOL debt across all positions
position_sharesu64LST held for positions
buffer_sharesu64LST swept from yield or repaid with collateral, owed to uSOL redeemers
minting_pausedboolnew borrowing switched off for this LST

Position fields

FieldTypeMeaning
ownerPubkeywho may borrow, withdraw and close
collateralPubkeythe Collateral account
sharesu64LST base units held as collateral
debtu64uSOL owed, in lamports
rate_snapshotu128pool rate (Q64.64 lamports per share) at the last settle

Who can do what

InstructionSignerNotes
initializethe program's upgrade authoritycreates Protocol and the uSOL mint; nobody can front-run the deploy to take the admin seat
add_collateral, configure_collateraladminat most 4 collaterals; limits bounded by constants (below)
propose_admin, accept_adminadmin, then the new admintwo-step handover
set_usol_uriadminrepoints the uSOL metadata link (name and image in wallets); nothing else
open_position, deposit, borrow, repay_with_collateral, withdraw, close_positionposition owner
repayanyoneburns uSOL against any position; can only lower a debt
syncnobody (permissionless)settles a position's yield
redeemany uSOL holderburns uSOL for LST pro rata from every buffer
unwindanyoneonly above the unwind threshold, at par

Hard limits in the code

ConstantValueWhat it bounds
MAX_LTV_LIMIT_BPS8,000the highest borrow limit an admin can ever set (80%)
MAX_UNWIND_LTV_BPS9,500the highest unwind threshold (95%)
MAX_COLLATERALS4redemption walks every collateral in one transaction
USOL_DECIMALS9uSOL base units match lamports

The unwind threshold must sit above the borrow limit, and once set it can only be raised (UnwindLtvLowered). An admin can therefore never make an existing position unwindable by changing settings.

Component view

Diagram, in Mermaidflowchart LR
    Owner -- deposit / withdraw --> Vault
    Owner -- borrow --> Mint[uSOL mint]
    Program -- reads rate --> Pool[Stake pool or Marinade state]
    Program -- sweep --> Buffer[buffer_shares in Vault]
    Holder[uSOL holder] -- redeem --> Buffer
    Keeper -- sync --> Program

Programs it touches

ProgramAddress
SPL stake poolSPoo1Ku8WFXoNDMHPsrGSTSG1Y47rzgn41SLUNakuHy
MarinadeMarBmsSgKXdrN1egZf5sqe1TMai9K1rChYNDJgjq7aD
Token (LST vaults)TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA
Token-2022 (uSOL)TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb

The URUOI program's own address is published here once it is deployed.