metaspace
Reference / Accounts

Reference

Accounts

Vault and WithdrawalRequest: seeds, fields, byte sizes.

Two account types. Both are Anchor accounts, so each begins with an 8-byte discriminator. Byte sizes below are the Borsh encoding that follows it.

Vault

What it does not hold is the thing worth noticing: there is no authority key on the withdrawal path. owner_hint exists so a wallet can find its own vaults, and the program never checks a signature against it for anything that moves value.

Seeds
seeds = [b"vault", owner_hint.as_ref(), label.as_ref()]
FieldTypeBytesMeaning
commitment[u8; 32]32Where the lock is. The only thing between the balance and the world.
nonceu648Increments on every completed withdrawal. Part of the signed digest.
owner_hintPubkey32Lets a wallet find its vaults. Never consulted when authorising anything.
label[u8; 16]16Seed so one owner can hold several vaults.
created_ati648Unix time the vault was opened.
rotationsu648How many times the lock has rotated.
bumpu81PDA bump.

Total: 8 + 105 = 113 bytes. The vault stays rent exempt; finalize_withdrawal never pays below the minimum for 113 bytes.

WithdrawalRequest

An in-flight withdrawal. The intent is written here before any signature material is revealed, and the chain endpoints land here as they are verified.

Seeds
seeds = [b"request", vault.key().as_ref(), &vault.nonce.to_le_bytes()]
FieldTypeBytesMeaning
vaultPubkey32The vault being withdrawn from.
nonceu648The vault nonce the request was opened against.
amountu648Lamports to pay.
destinationPubkey32Who is paid. May be a wallet, a PDA or a program-owned account.
next_commitment[u8; 32]32What the lock becomes once this withdrawal lands. Signed over.
chain_endpointsVec<[u8; 32]>4 + 34 × 32 = 1,092Up to 34 endpoints, filled as chunks arrive.
chains_filledu81How many chains have been accepted. Doubles as the cursor.
opened_ati648Unix time the request was opened. Expiry is measured from it.
payerPubkey32Who paid the rent, and who gets it back.
bumpu81PDA bump.

Total: 8 + 1,246 = 1,254 bytes. Closed on finalise or cancel, with the rent returned to payer.

Constants

ConstantValueMeaning
WINTERNITZ_W256One chain per byte of the digest.
MESSAGE_CHAINS32Chains covering the 32-byte digest.
CHECKSUM_CHAINS2Chains covering the checksum, maximum 8,160.
TOTAL_CHAINS34MESSAGE_CHAINS + CHECKSUM_CHAINS.
CHAIN_LENGTH255Steps in a full chain.
SIGNATURE_BYTES1,088TOTAL_CHAINS × 32.
CHAINS_PER_PUSH8Most chains one push_signature may carry.
REQUEST_EXPIRY_SECONDS86,400After which anyone may cancel a live request.
VAULT_SEED"vault"PDA seed prefix.
REQUEST_SEED"request"PDA seed prefix.