Developers
Architecture
The pieces, the trust boundaries and how they fit together.
AppNext.js 16 · Privy wallets · reads chain state directly
Keeperprice feed, yield cranks, relays, expiries
Solana · devnet · base layer
tesoro_coreAccounts, Positions, Gemas, Debt, Matches, Fees, Backingblock_puzzleholdemtrading_duelsettle by CPIsim_lstsimulated staking token Simulated.tesoro_bridgeLayerZero V2 OApp
MagicBlock Private Ephemeral RollupIntel TDX TEE · hidden state: Boards, Seed, Deck, hole cards, Books
Ethereum Hoodi · HyperEVMPositionVaultOApp + SimLST on each chain
One ledger on Solana, Games as on-chain programs that run their hidden state inside MagicBlock Private Ephemeral Rollups, Positions on their home chains, and LayerZero V2 carrying four messages between them. There are no game servers in the settlement path.
Components
| Piece | Role | Where |
|---|---|---|
tesoro_core | The money rules. A pure, property-tested accounting core wrapped by thin Anchor instructions: Accounts, Positions, Sources, Holdings, Matches and Pots, Fees, Backing, the Game registry and the devnet price feed. | programs/tesoro_core |
block_puzzle, holdem, trading_duel | Game programs. Each keeps its Match state in a rollup, computes the result itself, and settles by CPI into tesoro_core signed by its own authority PDA. | programs/* |
sim_lst | Simulated liquid staking token (simSOL). Simulated | programs/sim_lst |
tesoro_bridge | Solana side of the LayerZero V2 OApp. Records inbound facts, applies them to tesoro_core as the registered source authority, and sends Unlock and PayYield out. | bridge/ |
PositionVaultOApp | EVM vault that locks the staking token and speaks LayerZero. Releases Principal only on Unlock and pays at most the accrued yield. | contracts/src |
| Keeper | Off-chain liveness: price feed, yield cranks, bridge relays, expiries, stalled-Match settlement. A fee payer only; every job is permissionless. | keeper/ |
| App | Next.js 16, desktop first. Reads chain state directly and signs with Privy embedded or linked wallets. A few server routes fund test fees and relay Ethereum steps. | app/ |
Design rules the code enforces
- Principal is never played and never pays Debt. No ledger function reads Principal after an Advance is sized. The only paths that lower Debt are the Position's own yield and the owner returning their own Gemas. Property-tested.
- A Gema is a claim on its Source. The dollar price is used once, at issuance. Debt is kept in Gemas and converted to the Source asset on demand. See ADR 0001.
- Games are programs, not services. A Studio integrates by shipping a program and registering it, not by running a server (ADR 0003).
- One transport. LayerZero V2 carries every cross-chain message; every payload carries a sequence number and a Position id and every handler is idempotent (ADR 0002).
- PvP only. Gemas are spent only on zero-sum contests between Players, never on purchases (ADR 0004).
Trust boundaries
| Boundary | Trusted for | Where it is checked |
|---|---|---|
| Registered Game authority | Declaring a Match result. | tesoro_core `settle_match` accepts only the signer registered for that Game. The authority is a PDA of the Game program. |
| Oracle key | Issuance price (Solana: the on-chain `PriceFeed`, at most 24 h old; Ethereum: signed with the Advance) and oracle-reported Positions. | Single key today. Pyth is planned as a replacement for the source, not for the instruction. |
| MagicBlock TEE validator | Keeping hidden state private; running the Game programs' rollup logic. | Delegation is pinned to one approved validator per Game program (audit F-01). |
| LayerZero DVNs | Truthful delivery of the four messages. | Default pathway config. Handlers are idempotent per sequence; the vault caps a payout at its accrued yield. |
| Admin key | Registering Games, fees, source authorities, program upgrades. | One key. No multisig or timelock. |
Read next
- Programs and addresses for IDs and explorer links.
- How settlement works for the Game-to-ledger interface.
- Run it locally to build and test.