the mechanism is one solana program. it owns the fee vault, keeps the two running fee totals, holds the thresholds and the minimum holding, and records every sweep and release. once deployed, this page would read the config account straight from a solana rpc, so the numbers would be the program's own state and not a copy kept somewhere else.
| field | value |
|---|---|
| program id | not deployed |
| config account | not deployed |
| fee vault | not deployed |
| mint | not deployed |
| authority | not deployed |
the config account is a fixed header followed by two length prefixed strings and one state byte. every cell below is one byte, in order.
| field | value |
|---|---|
| sweep threshold | 0 sol |
| release threshold | 0 sol |
| minimum holding | 0 zxr |
| total swept to zcash | 0 sol |
| total swept to monero | 0 sol |
| sweep count | 0 |
| release count | 0 |
| reserve address | not deployed |
| viewing key | not deployed |
| state | balanced |
five instructions. two can only be signed by the authority and are used once each at setup. three can only be signed by the keeper, and none of them can move value anywhere except the destinations already written in the config account.
| instruction | signer | effect |
|---|---|---|
| initialize | authority | writes the config account once: the mint, the fee vault, the thresholds and the minimum holding. |
| record fee | keeper | adds an incoming creator fee to the buy side or sell side total and updates the state byte. |
| sweep | keeper | claims the buy side total, records the intent hash for the sol to zec settlement and raises the sweep count. |
| release | keeper | claims the sell side total on a trigger sell, records the intent hash for the sol to xmr settlement and raises the release count. |
| set reserve | authority | writes the zcash reserve address and the optional viewing key. |
the keeper signs sweeps and releases, and that is all. it cannot change a threshold, the minimum holding or the reserve address, cannot mint, cannot move tokens, and cannot send the vault anywhere the config does not already point. if the keeper stops, fees pile up in the vault and wait. nothing is lost and nothing is redirected.
once deployed: open the config account on a solana explorer and read the raw data against the layout above. the byte offsets are the same ones this page decodes with, and every number on the mechanism, reserve and releases pages comes from those bytes or from a transaction linked next to it.