ArchitectureCore release 0.1.0

Transaction flows

Accounts and state transitions for Shield, Public Swap, Private Swap and Unshield.

Shield

Depositor signer + source SPL account
  → classic token transfer into ShieldedState custody
  → ShieldedNoteAppended event
  → commitment appended to active TreeState / LeafPage

The source wallet and amount are public. The depositor pays any account-rent top-up needed to append to the active page when using the normal SDK path.

Public Swap

Trader signer + source token account
  → fee-adjusted CPMM quote against LP vault balances
  → input and output transfers between trader accounts and LP vaults
  → fee transfers into protocol / creator vaults

The trader is a public signer and no zero-knowledge proof is involved.

Private Swap

Input note + accepted root + private witness
  → Groth16 proof, public statement and nullifier
  → canonical root / account / nullifier checks
  → custody input → LP input and fee vaults
  → LP output vault → shielded custody output
  → change/output commitments appended to pages

The transaction shows the public statement, fee payer and token-account changes. The input note's spend secret, randomness and path are not transaction plaintext.

Unshield

Private note witness + proof
  → accepted root and unused nullifier check
  → shielded custody transfer
  → public recipient ATA
  → Unshielded event

The recipient is public and bound into the proof. Private Send is an SDK product flow over this same Unshield instruction.

See Solana design and confirmation lifecycle for transaction construction and finality.

PreviousProgram accounts & PDAsNext Solana design
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.