conceptualv0.1 · skeleton docs
Architecture
How a call travels from a Solana program to an EVM hook and back.
SOLANAsource
- HookCalleryour program / client
- plannedWormHookRoutervalidates caller · posts message
WORMHOLEtransport
- Wormhole Coremessage posted
- Guardians13/19 signatures → VAA
- Executordelivery to destination
EVMdestination
- plannedWormHookGatewayverify · replay · expiry · caps
- plannedHookRegistryhookId → adapter, permissions
- plannedAdapterIMD · POOL4 · Custom
- Hookexecutes action
Return pathHook output → HookReceipt → Wormhole → Router records receipt on Solana
The path, end to end
conceptual
SOLANA
HookCaller (your program)
│ CPI: call(hook_id, action, payload, max_spend, ttl)
▼
WormHookRouter
│ checks caller is a registered app, assigns nonce, derives call ID,
│ posts the HookCall to Wormhole Core, records pending call state
▼
WORMHOLE
Core message → guardians observe at source finality → VAA (13/19)
│
Executor picks up the request and delivers the VAA to the destination
▼
EVM
WormHookGateway
│ verifies VAA + emitter, checks expiry, consumes call ID (replay),
│ enforces spend caps, looks up the hook
▼
HookRegistry → Adapter (IMD | POOL4 | Custom) → Hook
│
receipt ← output hash, amount spent, status (try/catch: reverts become failed receipts)
▼
WORMHOLE (return message)
▼
SOLANA
WormHookRouter records the receipt and closes the pending callComponents
| Component | Chain | Responsibility | Skeleton status |
|---|---|---|---|
| HookCaller | Solana | Your program. Builds the call and CPIs into the router. | Mock |
| WormHookRouter | Solana | Caller auth, nonce, call ID, message posting, receipt state. | Planned |
| Wormhole Core | Both | Message emission and VAA verification. | External, integration pending |
| Executor | Off-chain | Delivers the signed message to the destination; paid at the source. | External, integration pending |
| WormHookGateway | EVM | Verification, replay, expiry, caps, dispatch, receipt emission. | Planned |
| HookRegistry | EVM | Hook ID → adapter, status, permissions, spend policy. | Planned |
| Adapters | EVM | Translate a call into a hook's native interface. | Planned |
| Indexer | Off-chain | Joins source, Wormhole, destination and receipt data into executions. | Mock service |
Design choices
- Receipts always come home. The gateway wraps adapter execution in try/catch. A revert produces a failed receipt instead of a stuck call, so Solana-side state always reaches a terminal status.
- The call carries its own safety. Nonce, expiry and
maxSpendare inside the signed message, so the gateway can enforce them without trusting the executor. - The executor is untrusted. It can delay or decline delivery but cannot forge, alter or replay a call. See Executor model.
- Adapters are the blast-radius boundary. The gateway never calls hook contracts directly.
Services in the app
The UI only talks to typed service interfaces (ExecutionService, RegistryService, AppService, WormholeService, ReceiptService, SearchService). The skeleton binds them to mock implementations; phase 2 binds indexer- and RPC-backed implementations in one place without changing components.