Protocol
Save and Orca
The two protocols Yoke can call, the exact accounts it is allowed to touch, and how it notices when either one changes.
Save
Save (formerly Solend) is a lending market. Yoke deposits USDC into its main-market USDC reserve and redeems the reserve's collateral tokens. It never opens an obligation in Save, so it never borrows there.
| Account | Address |
|---|---|
| Program | So1endDq2YkqhipRh3WViPa8hdiSpxWy6z3Z6tMCpAo |
| USDC reserve | BgxfHJDzm44T7XG68MYKx7YisTjZu73tVovyZSjJMpmw |
| Lending market | 4UpD2fh7xH3VP9QQaXtsS1YY3bxzWhtfpks7FatyKvdY |
| Reserve USDC vault | 8SheGtsopRUDzdiD6v6BR9a6bqZ9QwywYQY99Fp5meNf |
| Collateral token mint | 993dVFL2uXWYeoXuEBFXR4BijeXdTv4s6BzsCjJZuwqk |
Deposits and redemptions are Save's own instructions 4 and 5. Save refreshes the reserve's interest inside both, so neither needs a price account.
Orca
Yoke provides liquidity to Orca's legacy SOL–USDC constant-product pool: it deposits both tokens in the pool's ratio and withdraws both. It never swaps, and never deposits one side alone.
| Account | Address |
|---|---|
| Program | 9W959DqEETiGZocYWCQPaJ6sBmUzgfxXfqGeTEdp3aQP |
| SOL–USDC pool | EGZ7tiLeH62TPV1gL8WwbXGzEPa9zmcpVnnkPKKnrE2U |
| USDC vault | 75HgnSvXbWKZBpZHveX68ZzAhDqMzNDS29X6BGLtxMo1 |
| SOL vault | ANP74VNsHwSrq9uUSjiSNyNWvf6ZPrKTmE4gHoNd13Lg |
| LP token mint | APDFRM3HMr8CAGXwKHiu2f5ePSpaiEJhaURwhsRrUUt9 |
Deposits and withdrawals are the pool's instructions 2 and 3. Withdrawals pay Orca's owner withdrawal fee in LP tokens.
The sixteen accounts
Every move, borrow and open passes the same sixteen accounts in this order, and the program compares each one with the registry:
| # | Account | Written in a move |
|---|---|---|
| 0 | Save program | No |
| 1 | Save program data | No |
| 2 | Save USDC reserve | Yes |
| 3 | Save lending market | Yes, when redeeming |
| 4 | Save market authority | No |
| 5 | Save reserve USDC vault | Yes |
| 6 | Save collateral token mint | Yes |
| 7 | Orca program | No |
| 8 | Orca program data | No |
| 9 | Orca pool | No |
| 10 | Orca pool authority | No |
| 11 | Orca USDC vault | Yes |
| 12 | Orca SOL vault | Yes |
| 13 | Orca LP mint | Yes |
| 14 | Orca fee account | Yes, when withdrawing |
| 15 | SPL Token program | No |
Program IDs and the USDC and SOL mints are compiled into Yoke; the registry can't point an adapter anywhere else.
Version pins
The registry records the slot at which each target program was last deployed, read from its program data account. Every call into a target, and every valuation, checks the slot again. If Save or Orca upgrades, the slot changes and the adapter fails with error 701.
Because health reads both targets, that stops every move, borrow, open and liquidation, not only the ones touching the upgraded target. Repaying never calls a target, and an account with no debt can always release its assets. Supporting the upgraded program means a new registration, which YOKE governance approves by vote (update_adapters). It keeps the same custody mints.
What each step checks
After the call into the target, the adapter reads the account's token balances again and requires:
- the receipts or tokens received to be at least the step's minimums,
- the tokens spent to be at most the step's maximums,
- nothing to have moved from any account other than the expected custody accounts and the target's vaults.