conceptualv0.1 · skeleton docs
Executor model
Who delivers messages, who pays, and why they don't need to be trusted.
Role
An executor watches for delivery requests, fetches the signed VAA, and submits it to the destination gateway. In return it is paid the fee quoted at the source.
What an executor can and can't do
| Can | Can't |
|---|---|
| Deliver late | Execute an expired call (the gateway refuses, WH-201) |
| Decline to deliver | Change the call or payload (signatures and hash) |
| Deliver twice | Run the hook twice (call ID is consumed, WH-302) |
| Choose gas price within the quote | Exceed the hook's gas limit |
So the executor affects liveness, not correctness. That's the property WORMHOOK is designed around.
Quote → request → delivery
conceptual
1. quote SDK asks for a delivery quote for (route, gas limit)
2. request router tx pays Wormhole fee + quote; delivery request recorded
3. observe guardians sign the message → VAA
4. deliver executor submits VAA + payload to WormHookGateway
5. return gateway posts receipt; return delivery to Solana (same model)When delivery is slow
The explorer marks a call delayed when the executor hasn't delivered within the route's expected window (WH-202). Nothing is lost, because the VAA is valid. Two outcomes follow:
- it's delivered before expiry and executes normally; or
- it's delivered after expiry and the gateway returns a failed receipt (
WH-201).
Manual redelivery (anyone submitting the VAA) is planned so liveness doesn't depend on one executor.
See the relay pending demo and the expired demo.