Browse documentation
Protocol reference
This is the map for readers who want to move from the product surface into the Solidity contracts. The source of truth is the checked-in code and its generated ABIs; this page explains the responsibilities and boundaries.
Contract architecture
| Contract | Responsibility | Important boundary |
|---|---|---|
PoolFactory | Registers pools, creates them through the deployer, manages approved modules, curation, and emergency factory pause authority. | Permissionless creation is distinct from curated verification. |
PoolDeployer | Factory-only creation-code container for LendingPool. | Its factory identity is immutable. |
LendingPool | Per-pool deposits, shares, collateral, debt, interest, liquidation, recovery, reserves, and pause state. | All token-moving writes use exact-delta and custody checks. |
PoolVerifier | Computes configuration hashes and validates canonical module, oracle, token, and ledger health. | It attests current state; it does not control external governance. |
OracleAdapter | Stores feeds and validates normalized prices, rounds, staleness, bounds, aggregators, and phases. | Feed owner and market-data risk remain external. |
InterestRateModel | Immutable two-slope utilization/kink model used by a pool. | Economic suitability still requires policy review. |
PoolMath | Full-precision share, asset, debt, and health-factor arithmetic. | Rounding boundaries are explicit and tested. |
Read surfaces
Integrations should use bounded registry reads and pin the factory address. The frontend reads a bounded pool directory, then verifies factory identity, pool identity, runtime code hashes, token metadata, and oracle state before displaying write controls.
PoolFactory.getPools(cursor, limit)
PoolFactory.isVerifiedPool(pool)
PoolFactory.verifiedPoolConfigHash(pool)
LendingPool.collateralToken()
LendingPool.borrowToken()
LendingPool.collateralLedgerHealthy()
LendingPool.borrowTokenLedgerHealthy()
Do not use an unbounded registry read in a production integration. The legacy
allPools surface is retained for compatibility; use pagination and a bounded response budget.State-changing surfaces
| Surface | Function family | Preconditions to re-check |
|---|---|---|
| Lender | deposit, withdraw | Token approval, exact delta, custody health, pause state, caps, share quote, and minimum output. |
| Borrower | depositCollateral, borrow, repay, withdrawCollateral | Wallet network, pool identity, oracle price, health factor, debt bound, ledger health, and current pause reasons. |
| Liquidator | liquidate, resolveBadDebt | Preview against current debt/collateral and preserve recovery-specific custody rules. |
| Governance | setApproved*, setVerifiedPool, ownership and pause controls | Safe roles, finalized state, proposal intent, and post-execution re-curation. |
Accounting invariants
- Token transfers must match the requested amount exactly; fee-on-transfer behavior is not silently accepted.
- Actual borrow-token custody must cover represented net cash before normal risk-increasing writes.
- Actual collateral custody must cover the aggregate collateral ledger before collateral-moving writes.
- Shares and borrow shares must convert through the same full-precision pool totals used by previews.
- Debt-bearing exits must preserve health or follow an explicit risk-reducing recovery path.
- Pool curation hashes include the configuration and relevant governance/oracle/token identity state.