On this page

Author an Adapter

Write a Pool adapter and submit its route for publisher review.

Add a synchronous venue#

A synchronous venue may fit the current action interface and spend proof. Its adapter must define asset behavior and permitted calls, check live contract identities and have client and relay drivers. Shared-Pool use also needs publisher admission.

You can deploy a separate Pool with your own publisher and routes. That creates separate custody, configuration and privacy set, so test the new deployment rather than inheriting the shared Pool's results.

A private input, a public action and its returned note
A private input, a public action and its returned note

Implement the interface#

Declare the Pool and accept operation, input amount, minimum output, deadline and one actionData word. The proof covers actionData. If the route needs no parameter, reject nonzero actionData.

Allow only the configured Pool to execute. Set the venue and asset pair at deployment, and do not accept arbitrary targets, recipients, spenders, calldata or delegatecall choices.

solidity
interface IFuyuActionAdapter {
    function privacyPool() external view returns (address);
    function execute(
        uint8 operation,
        uint256 amountIn,
        uint256 minOut,
        uint256 deadline,
        bytes32 actionData
    ) external returns (address tokenOut, uint256 amountOut);
}

Measure the token movements#

Consume exactly amountIn, return the actual output to the Pool and enforce minOut. Clear temporary allowances and prevent reentrancy. Leave no extra adapter balance or unexpected change to other Pool reserves; the Pool also checks its token deltas.

The interface expects a supported token back before execution finishes. NFTs, delayed multiple outputs, nontransferable debt and rebasing or fee-on-transfer assets need another design. For asynchronous venues, a reviewed ticket can represent pending value if the action actually returns that supported token.

Prepare the route manifest#

Describe the chain and Pool domain and runtime, adapter code and route tuple, tokens and decimals. Include external contracts and proxy implementations, identity checks, quote method, capacity and an ordinary exit for the output token.

Approve the digest through a separate release review or authenticated publisher. The API serving a manifest cannot grant it permission itself. The publisher must admit tokens and actions onchain; setting a client flag does not do that.

Test before admission#

Test supply and redeem, or both swap directions. Exercise short output and changed code, check reserves and allowances, then finalize and recover the result. Test ordinary token or share exit too. Use a disposable fork to change proxies or revoke routes and observe the failure behavior.

A route used for spending needs a separate review if its outputs will support disclosure proofs. Record the source revision and deployment identity so the review applies to the code that was tested.

  • Check the original transaction after a lost response before permitting another spend.
  • Display share quantities separately from estimated underlying value.
  • Test ordinary exit after revoking the action route.
  • List the devices, liquidity conditions, recovery paths and deployments you have not tested.