Skip to content

fix(swap): follow the Coinbase Stable Swapper authority migration - #747

Merged
bmc08gt merged 1 commit into
mainfrom
fix/coinbase-stable-swapper-upgrade
Sep 10, 2026
Merged

bmc08gt merged 1 commit into
mainfrom
fix/coinbase-stable-swapper-upgrade

Conversation

@bmc08gt

@bmc08gt bmc08gt commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

The 2026-09-08 MigrateAuthorities instruction on the mainnet Coinbase pool replaced operations_authority with pause, unpause, treasury, and configure authorities, which moves fee_recipient from byte 72 to byte 136. PoolAccount still read byte 72, so WalletConnection.resolveFundSwapPool was handing the old treasury_authority slot to the swap as the fee recipient. The same upgrade dropped the address_whitelist account from swap, so the instruction now carries 15 accounts with the three programs following the user. This is the iOS side of code-payments/ocp-server#257.

Changes:

  • PoolAccount parses the fee recipient at 8 + 32 * 4.
  • CoinbaseStableSwapperProgram.Swap and SwapAccounts lose the whitelist field; the address_whitelist PDA and its call sites in the stateless, USDC to USDF, and USDF to USDC builders are gone.
  • The pool-account suite gains a fixture built from the migrated mainnet pool bytes (the same bytes the server test checks in) and asserts the parsed fee recipient is 4ZnFXk7KyB5khDqjWSHqHBQH1nQCnmvkr1pRFivWcP7e. The swap builder tests replace their whitelist assertions with checks on accounts 12 to 14 and the account count.

The server's compute-unit-limit bump to 200k needs no client change. The stateless and USDF to USDC builders take the limit from server parameters, and the USDC to USDF builder already sets 200k.

Android's parallel Kotlin implementation needs the same offset and account-list change; that is not covered here.

The 2026-09-08 MigrateAuthorities instruction on the mainnet pool replaced
`operations_authority` with pause, unpause, treasury, and configure
authorities, which moves `fee_recipient` from byte 72 to byte 136.
`PoolAccount` still read byte 72, so the wallet-connection deposit flow was
handing the old `treasury_authority` slot to the swap as the fee recipient.

The same program upgrade dropped the `address_whitelist` account from
`swap`, so the instruction now carries 15 accounts with the three programs
following the user. This mirrors ocp-server#257.

The pool-account suite gains a fixture built from the migrated mainnet pool
bytes and asserts the parsed fee recipient. The swap builder tests replace
their whitelist assertions with checks on accounts 12 to 14 and the count.

The server's compute-unit-limit bump to 200k needs no client change: the
stateless and USDF to USDC builders take the limit from server parameters,
and the USDC to USDF builder already sets 200k.
@bmc08gt bmc08gt self-assigned this Sep 9, 2026
@bmc08gt
bmc08gt merged commit 22dabe4 into main Sep 10, 2026
1 check passed
bmc08gt added a commit that referenced this pull request Sep 10, 2026
bmc08gt added a commit that referenced this pull request Sep 10, 2026
bmc08gt added a commit that referenced this pull request Sep 10, 2026
This reverts commit 22dabe4.

Coinbase rolled back the authority migration on-chain, so the client change
that followed it no longer matches the deployed program. Restores the pool
account layout and the swap instruction account lists that shipped in
2026.8.5, across CoinbaseStableSwapperProgram and the three
SwapInstructionBuilder extensions, along with their tests.

The 2026.9.1 release branch carries the matching revert, so the submitted
build and main stay on the same swap code.
bmc08gt added a commit that referenced this pull request Sep 10, 2026
… (#750)

This reverts commit 22dabe4.

Coinbase rolled back the authority migration on-chain, so the client change
that followed it no longer matches the deployed program. Restores the pool
account layout and the swap instruction account lists that shipped in
2026.8.5, across CoinbaseStableSwapperProgram and the three
SwapInstructionBuilder extensions, along with their tests.

The 2026.9.1 release branch carries the matching revert, so the submitted
build and main stay on the same swap code.
bmc08gt added a commit that referenced this pull request Sep 11, 2026
…discrete-curve

* origin/main: (27 commits)
  fix(database): share one SQLite writer per owner and take write locks up front (#759)
  feat(chat): declare the payment action on tip DM payments (#752)
  refactor(chat): drop the deprecated new_messages overlay (#757)
  feat(notifications): write prefetched messages into the shared store (#756)
  refactor(store): move the persistence layer into a shared FlipcashStore package (#755)
  feat(database): move the SQLite store into the App Group container (#754)
  feat(database): open the store on demand, close it on background (#753)
  feat(nse): extension crash reporting, a WAL checkpoint, and on-device push hooks (#751)
  feat(home): long-press the You tab to open the account switcher (#749)
  fix(tests): reset Photos access before the previous app instance lingers (#746)
  chore: bump version to 2026.9.2 (#745)
  revert: back out the Coinbase Stable Swapper authority migration (#747) (#750)
  fix(swap): follow the Coinbase Stable Swapper authority migration (#747)
  fix(tests): cancel a cash link through the details screen (#744)
  fix(chat): make the whole Send Cash pill tappable while it stands alone (#743)
  fix(username): drop a leading @ in the validator (#742)
  fix(chat): scope the send-button spring to the button (#741)
  fix(transactions): tighten the details card stack and drop the header badge (#740)
  fix(transactions): draw View in Chat as a card, not the primary action (#739)
  feat(chat): flash the message a reply-quote jump lands on (#738)
  ...

# Conflicts:
#	Code.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved
#	FlipcashCore/Package.swift
@bmc08gt
bmc08gt deleted the fix/coinbase-stable-swapper-upgrade branch September 15, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant