erc_4626.vault_protocol.ipor.deposit_redeem

Documentation for eth_defi.erc_4626.vault_protocol.ipor.deposit_redeem Python module.

Caller-aware deposit and redemption flow for IPOR Fusion vaults.

Module Attributes

IPOR_AUTOPILOT_USDC_MORPHO_BASE_ADDRESS

Exact Base Autopilot deployment whose PlasmaVault redemption path needs a protocol-specific liquidity simulation.

Classes

IPORDepositManager

IPOR Fusion manager with OpenZeppelin AccessManager pre-flights.

IPOR_AUTOPILOT_USDC_MORPHO_BASE_ADDRESS = '0xd6701905c59ee618dc36dc747506bce0a4ac760a'

Exact Base Autopilot deployment whose PlasmaVault redemption path needs a protocol-specific liquidity simulation. Other IPOR vaults retain their existing access-manager-only flow until their deployed market fuses are characterised separately.

IPOR_FAILED_INNER_CALL_SELECTOR = HexBytes('0x1425ea42')

FailedInnerCall() emitted by OpenZeppelin’s Address utility when PlasmaVault cannot withdraw enough underlying from one of its configured markets. keccak("FailedInnerCall()")[:4].

class IPORDepositManager

Bases: eth_defi.erc_4626.deposit_redeem.ERC4626DepositManager

IPOR Fusion manager with OpenZeppelin AccessManager pre-flights.

IPOR Fusion vaults are standard synchronous ERC-4626 vaults guarded by an OpenZeppelin :solidity:`AccessManager`. Once a caller is admitted, both deposit and redemption are ordinary ERC-4626 transactions; the only protocol-specific behaviour this manager adds is an admission preflight that converts a predictable access rejection or scheduling requirement into a typed VaultFlowUnavailable before any approval or transaction is broadcast. Deployments without a readable AccessManager fall back to the generic ERC-4626 manager (see IPORVault.get_deposit_manager()) and do not use this class.

Deposit process

Synchronous ERC-4626 after access admission. create_deposit_request() first calls _assert_immediate_access() for the deposit selector (deposit(uint256,address)), then delegates to the base manager for the shared approve + deposit calls, maxDeposit capacity check and balance check. IPOR is utilisation-based, so deposits close when maxDeposit reads zero; an optional atomist-configured deposit fee is already reflected in previewDeposit.

Redemption process

Synchronous ERC-4626 after access admission. create_redemption_request() calls _assert_immediate_access() for the redemption selector (redeem(uint256,address,address)) — resolved independently, because the access policy can differ from the deposit selector — then delegates to the base manager. The characterised Autopilot USDC Morpho deployment on Base also simulates its exact redeem() path and refuses a full-fill request that its market fuses cannot satisfy immediately. Other IPOR deployments retain the inherited ERC-4626 checks, because their market liquidity has not been characterised.

Queues and settlement

None (synchronous). There is no request queue, ticket or operator settlement; an admitted redeem completes in one transaction.

Lockups and cooldowns

Access-manager driven. IPOR’s AccessManager exposes REDEMPTION_DELAY_IN_SECONDS (surfaced by IPORVault.get_redemption_delay() and IPORVault.get_estimated_lock_up()) and a per-account getAccountLockTime (IPORVault.get_redemption_delay_over()). On many IPOR vaults this delay is zero, but when configured it manifests as a non-zero access_delay in the redemption preflight below.

Whitelisting / access control

OpenZeppelin AccessManager, checked per caller and selector. _assert_immediate_access() reads canCall(caller, vault, selector) returning (immediate, delay): immediate admits the transaction; a delay > 0 means the call must be scheduled and is refused as VaultFlowUnavailable ("IPOR access requires delayed execution", carrying access_delay); a (False, 0) result — an unauthorised caller, a closed target or an IPOR-specific temporary redemption lock — is refused as "IPOR AccessManager does not allow immediate vault flow". Both refusals carry the guarded function_selector. A deployment without a readable AccessManager raises NotImplementedError from the preflight (and, at vault construction, is routed to the generic manager instead). IPORVault.is_whitelisted_deposit() reports whether the deposit selector is restricted away from PUBLIC_ROLE.

Anvil settlement (force_settle)

No-op. Both directions are synchronous, so force_settle() accepts None for the shared synchronous no-op; there is no ticket to settle.

Bind the manager to an IPOR vault.

Parameters

vault – IPOR Fusion vault exposing its AccessManager address.

__init__(vault)

Bind the manager to an IPOR vault.

Parameters

vault (IPORVault) – IPOR Fusion vault exposing its AccessManager address.

Return type

None

property vault: IPORVault

Return the manager’s IPOR vault with a precise type.

fetch_redeemable_raw_shares(owner)

Find the largest immediate full-fill redemption for Autopilot shares.

The verified PlasmaVault implementation repeatedly invokes _withdrawFromMarkets() before its ERC-4626 transfer. A redemption is monotonic in requested shares for this deployment, so binary search over the owner balance yields the actual immediately executable cap without mutating onchain state. Read or simulation failures fail closed to zero.

Parameters

owner (eth_typing.evm.HexAddress) – Address whose Autopilot shares are being preflighted.

Returns

Maximum raw shares that can be redeemed in full immediately.

Return type

int

create_deposit_request(owner, to=None, amount=None, raw_amount=None, check_max_deposit=True, check_enough_token=True)

Create a standard ERC-4626 deposit after access admission.

Parameters
Returns

Preflighted deposit request.

Return type

eth_defi.erc_4626.deposit_redeem.ERC4626DepositRequest

create_redemption_request(owner, to=None, shares=None, raw_shares=None, check_max_deposit=True, check_enough_token=True, check_max_redeem=True)

Create a standard ERC-4626 redemption after access and liquidity preflight.

Parameters
  • owner (eth_typing.evm.HexAddress) – Account submitting and signing the redemption.

  • to (Optional[eth_typing.evm.HexAddress]) – Optional receiver, limited by the shared ERC-4626 manager.

  • shares (Optional[decimal.Decimal]) – Human-readable share amount.

  • raw_shares (Optional[int]) – Raw share amount.

  • check_max_deposit (bool) – Compatibility argument forwarded to the shared manager.

  • check_enough_token (bool) – Whether to run the shared share-balance check.

  • check_max_redeem (bool) – Whether to check immediately redeemable capacity.

Returns

Preflighted redemption request.

Return type

eth_defi.erc_4626.deposit_redeem.ERC4626RedemptionRequest

can_create_deposit_request(owner)

Return whether an account can immediately call IPOR deposit.

Parameters

owner (eth_typing.evm.HexAddress) – Account to evaluate.

Returns

True only for immediate selector access.

Return type

bool

analyse_deposit(claim_tx_hash, deposit_ticket)

Analyse a mined ERC-4626 deposit or guarded SimpleVault wrapper.

A ticket permits a settlement call through a non-vault wrapper, such as a SimpleVault Safe or its module. The event analyser still filters events by the underlying vault address.

Parameters
Returns

Decoded executed deposit quantities or a revert description.

Return type

Union[eth_defi.vault.deposit_redeem.DepositRedeemEventAnalysis, eth_defi.vault.deposit_redeem.DepositRedeemEventFailure]

analyse_redemption(claim_tx_hash, redemption_ticket)

Analyse a mined ERC-4626 redemption or guarded SimpleVault wrapper.

A ticket permits a non-vault transaction target for a guarded settlement; the decoded Withdraw event must still originate from this vault.

Parameters
Returns

Decoded executed redemption quantities or a revert description.

Return type

Union[eth_defi.vault.deposit_redeem.DepositRedeemEventAnalysis, eth_defi.vault.deposit_redeem.DepositRedeemEventFailure]

can_create_redemption_request(owner)

Return whether an account can immediately call IPOR redemption.

Parameters

owner (eth_typing.evm.HexAddress) – Account to evaluate.

Returns

True only for immediate selector access.

Return type

bool

can_finish_deposit(deposit_ticket)

Synchronous deposits can be finished immediately.

Parameters

deposit_ticket (eth_defi.erc_4626.deposit_redeem.ERC4626DepositTicket) –

can_finish_redeem(redemption_ticket)

Synchronous redemptions can be finished immediately.

Parameters

redemption_ticket (eth_defi.erc_4626.deposit_redeem.ERC4626RedemptionTicket) –

check_deposit_whitelist(owner)

Reject a deposit when the vault’s whitelist excludes the owner.

Shared deposit-preflight helper implementing the whitelisting contract every manager must honour: when a vault applies a deposit whitelist policy that is applicable and queryable, and owner is not a member of it, raise WhitelistingRequired before any transaction is broadcast so the caller can surface a “whitelisting required” state instead of paying gas for a guaranteed revert.

The check is intentionally conservative — it only raises when the whitelist information can be obtained and is applicable:

  • if is_whitelisted_deposit() raises NotImplementedError, the vault-wide policy cannot be determined for this adapter/version, so no exception is raised;

  • if the vault is permissionless, no exception is raised;

  • if is_account_whitelisted() raises NotImplementedError, per-account membership cannot be queried, so no exception is raised;

  • only when the policy is applicable and the owner is provably not admitted is WhitelistingRequired raised.

Adapters that need a stricter fail-closed policy for an unknown admission state should override their own preflight and raise VaultFlowUnavailable in addition to calling this helper (see the Lagoon manager for an example).

Parameters

owner (eth_typing.evm.HexAddress) – Deposit owner and controller whose whitelist membership is checked.

Raises

WhitelistingRequired – When the vault applies an applicable, queryable whitelist policy and owner is not permitted to deposit.

Return type

None

create_deposit_request_for_guard_validation(owner, raw_amount)

Build ERC-4626 deposit calldata after a proven global closure.

This Anvil-only diagnostic path is available only when the selected vault’s authoritative global closure reader reports that deposits are unavailable to every account. It preserves the normal protocol admission preflight and all permanent amount constraints, while omitting the temporary closed-deposit capacity and token-balance checks needed to encode the production-equivalent deposit call.

Parameters
  • owner (eth_typing.evm.HexAddress) – Safe/SimpleVault address that would own the minted shares.

  • raw_amount (int) – Raw denomination-token amount from the rejected real-deposit attempt.

Returns

Single ERC-4626 deposit request for isolated GuardV0 validation.

Raises
Return type

eth_defi.erc_4626.deposit_redeem.ERC4626DepositRequest

estimate_deposit(owner, amount, block_identifier='latest')

How many shares we get for a deposit.

Parameters
Return type

decimal.Decimal

estimate_redeem(owner, shares, block_identifier='latest')

How many denomination tokens we get for a redeem.

Parameters
Return type

decimal.Decimal

estimate_redemption_delay()

Get the redemption delay for this vault.

  • What is overall redemption delay: not related to the current moment

  • How long it takes before a redemption request is allowed

  • This is not specific for any address, but the general vault rule

  • E.g. you get 0xa592703b is an IPOR Fusion error code AccountIsLocked, if you try to instantly redeem from IPOR vaults

Returns

Redemption delay as a datetime.timedelta

Raises

NotImplementedError – If not implemented for this vault protocoll.

Return type

datetime.timedelta

fetch_completed_redemption_tx_hash(ticket)

Find an operator-owned terminal redemption transaction when available.

Claim-based protocols finish through finish_redemption() and do not need this lookup. Operator-finalised protocols override the hook to find and validate the transaction that paid the requested receiver.

Parameters

ticket (eth_defi.vault.deposit_redeem.RedemptionTicket) – Persisted redemption request to locate.

Returns

Terminal transaction hash, or None if the protocol has not observed one yet.

Return type

Optional[hexbytes.main.HexBytes]

fetch_depositable_raw_assets(owner)

Read the vault’s current raw deposit limit for an owner.

Overridable deposit-limit hook. The base implementation reads the standard ERC-4626 maxDeposit(). Multi-asset or non-standard vaults that do not implement maxDeposit (for example Upshift’s multi-asset vault) override this to answer from their own limit reader, so the deposit preflight does not depend on the ERC-4626 method being present.

Parameters

owner (eth_typing.evm.HexAddress) – Account the deposit limit is queried for.

Returns

Raw deposit limit, or None when the vault exposes no limit. A zero maxDeposit is omitted from this owner-specific capacity hook (EIP-4626 is not universally honoured), consistent with eth_defi.erc_4626.flow.deposit_4626(). The normal deposit preflight separately recognises a meaningful global zero through ERC4626Vault.fetch_deposit_closed_reason().

Raises

VaultFlowUnavailable – When the vault does not expose a readable ERC-4626 maxDeposit and no protocol-specific override is provided, instead of leaking a raw web3 ABI/read error.

Return type

Optional[int]

fetch_vault_flow_events(hypersync_client, start_block, end_block)

Fetch asynchronous vault request events from an indexed backend.

The base implementation returns no events for vault managers that do not have a two-phase deposit or redemption flow.

Parameters
  • hypersync_client – Configured Hypersync client for this vault’s chain.

  • start_block (int) – Inclusive start block.

  • end_block (int) – Inclusive end block.

Returns

Iterator of protocol-neutral pending vault flow events.

Return type

collections.abc.Iterator[eth_defi.vault.flow_events.PendingVaultFlow]

finish_deposit(deposit_ticket)

Can we finish the deposit process in async vault.

  • We can claim our shares from the vault now

Parameters

deposit_ticket (eth_defi.vault.deposit_redeem.DepositTicket) –

Return type

web3.contract.contract.ContractFunction

finish_redemption(redemption_ticket)

Build the depositor-owned final redemption transaction when one exists.

Some asynchronous vaults, such as Ember, transfer funds directly from an operator transaction. They deliberately return None here: an asset manager must not attempt to invoke an operator-only settlement method on behalf of its depositor.

Parameters

redemption_ticket (eth_defi.vault.deposit_redeem.RedemptionTicket) – Persisted asynchronous redemption request.

Returns

Bound depositor claim call, or None when the protocol has no depositor-owned finish action.

Return type

web3.contract.contract.ContractFunction

force_redemption_liquidity(owner, raw_shares, failure)

Provision an unavailable synchronous redemption on an Anvil fork.

Concrete managers may implement this only for a source-proven liquidity failure. The default is deliberately unsupported: this hook must never bypass admission, minimums, maturity or time locks.

Parameters
Returns

Structured intervention evidence from a concrete manager.

Raises

UnsupportedVaultSimulation – Always for managers without a protocol-specific implementation.

Return type

eth_defi.vault.deposit_redeem.VaultRedemptionSimulationIntervention

force_settle(ticket, *, mock=None, ignore_liquidity=False)

Force the selected ticket forward on an Anvil simulation.

Synchronous managers do not require settlement and return a no-op result when called with None. Asynchronous managers must override this method and supply their request ticket.

Parameters
  • ticket (Optional[Union[eth_defi.vault.deposit_redeem.DepositTicket, eth_defi.vault.deposit_redeem.RedemptionTicket]]) – Pending async request ticket, or None for a synchronous flow.

  • mock (Optional[object]) – Optional deployed protocol mock used only by focused local tests. Concrete asynchronous managers may use it to execute their operator/keeper settlement path without broadening production Anvil-fork authority. Passing a mock to a manager that does not implement mock settlement remains a typed unsupported simulation.

  • ignore_liquidity (bool) – Permit a protocol-specific, Anvil-only mock or fork driver to bypass an otherwise unavailable redemption-liquidity gate. This base implementation defaults to False; a documented protocol override may choose a different Anvil-only default. Managers must reject this request unless they have a tested, explicit implementation; it must never weaken a production preflight or live settlement path.

Returns

Settlement outcome with before/after status and transaction hashes.

Raises

UnsupportedVaultSimulation – If the provider is not Anvil or an async manager lacks a driver.

Return type

eth_defi.vault.deposit_redeem.VaultForcedSettlementResult

get_deposit_approval_target()

Return the ERC-20 spender required for a deposit request.

Standard ERC-4626 and the currently supported async adapters pull denomination tokens from the vault address itself. An adapter using a different router or silo must override this method; guarded callers use it to whitelist and validate the exact approval calldata.

Returns

ERC-20 approval spender address.

Return type

eth_typing.evm.HexAddress

get_deposit_delay_over(address)

Estimate when a pending async deposit request will settle.

  • Mirror of get_redemption_delay_over() for the deposit side.

  • Used to show an estimated settlement time for unsettled deposits (e.g. in the trade-executor trade-ui table).

  • Default returns None: the protocol has no deterministic onchain settlement schedule (e.g. operator-driven ERC-7540 vaults like Lagoon). Subclasses with a predictable settlement cadence (e.g. Ostium V1.5) override this to return an estimated UTC timestamp.

Parameters

address (Union[eth_typing.evm.HexAddress, str]) – Owner of the pending deposit request.

Returns

Naive UTC timestamp when the deposit is expected to settle, or None when no onchain estimate is available.

Return type

Optional[datetime.datetime]

get_deposit_request_status(ticket)

Query the current status of an async deposit request.

Default implementation probes via can_finish_deposit(). Subclasses should override for more accurate status reporting (e.g. distinguishing reclaimable from pending).

Parameters

ticket (eth_defi.vault.deposit_redeem.DepositTicket) –

Return type

eth_defi.vault.deposit_redeem.AsyncVaultRequestStatus

get_max_deposit(owner)

How much we can deposit

Parameters

owner (eth_typing.evm.HexAddress) –

Return type

Optional[decimal.Decimal]

get_redemption_delay_over(address)

Get the redemption timer left for an address.

  • How long it takes before a redemption request is allowed

  • This is not specific for any address, but the general vault rule

  • E.g. you get 0xa592703b is an IPOR Fusion error code AccountIsLocked, if you try to instantly redeem from IPOR vaults

Returns

UTC timestamp when the account can redeem.

Naive datetime, or None when the protocol has no deterministic onchain deadline.

Raises

NotImplementedError – If not implemented for this vault protocoll.

Parameters

address (Union[eth_typing.evm.HexAddress, str]) –

Return type

datetime.datetime

get_redemption_request_status(ticket)

Query the current status of an async redemption request.

Default implementation probes via can_finish_redeem(). Subclasses should override for more accurate status reporting.

Parameters

ticket (eth_defi.vault.deposit_redeem.RedemptionTicket) –

Return type

eth_defi.vault.deposit_redeem.AsyncVaultRequestStatus

has_synchronous_deposit()

Does this vault support synchronous deposits?

  • E.g. ERC-4626 vaults

Return type

bool

has_synchronous_redemption()

Does this vault support synchronous deposits?

  • E.g. ERC-4626 vaults

Return type

bool

is_deposit_in_progress(owner)

Check if the owner has an active deposit request.

Parameters

owner (eth_typing.evm.HexAddress) – Owner of the shares

Returns

True if there is an active redemption request

Return type

bool

is_redemption_in_progress(owner)

Check if the owner has an active redemption request.

Parameters

owner (eth_typing.evm.HexAddress) – Owner of the shares

Returns

True if there is an active redemption request

Return type

bool

reclaim_deposit(ticket)

Return a function to recover funds after a failed async deposit settlement.

Returns None if the protocol does not support reclaim.

Parameters

ticket (eth_defi.vault.deposit_redeem.DepositTicket) –

Return type

Optional[web3.contract.contract.ContractFunction]

reclaim_withdrawal(ticket)

Return a function to recover shares after a failed async withdrawal settlement.

Returns None if the protocol does not support reclaim.

Parameters

ticket (eth_defi.vault.deposit_redeem.RedemptionTicket) –

Return type

Optional[web3.contract.contract.ContractFunction]

reconstruct_deposit_ticket(data)

Reconstruct a deposit ticket from a serialised dict.

Default returns a base DepositTicket. Subclasses override for protocol-specific ticket types.

Parameters

data (dict) –

Return type

eth_defi.vault.deposit_redeem.DepositTicket

reconstruct_redemption_ticket(data)

Reconstruct a redemption ticket from a serialised dict.

Async vault managers must override this to return their protocol-specific ticket subclass. The base implementation raises NotImplementedError because RedemptionTicket has abstract methods.

Parameters

data (dict) –

Return type

eth_defi.vault.deposit_redeem.RedemptionTicket

serialize_deposit_ticket(ticket)

Serialise a deposit ticket to a dict for persistence.

The trade-executor stores this in trade.other_data so that the settlement retry module can reconstruct the ticket after a process restart.

Default implementation stores base DepositTicket fields. Subclasses override to add protocol-specific fields (e.g. settlement_id for Ostium, requestId for ERC-7540).

Parameters

ticket (eth_defi.vault.deposit_redeem.DepositTicket) –

Return type

dict

serialize_redemption_ticket(ticket)

Serialise a redemption ticket to a dict for persistence.

Default implementation stores base RedemptionTicket fields. Subclasses override to add protocol-specific fields.

Parameters

ticket (eth_defi.vault.deposit_redeem.RedemptionTicket) –

Return type

dict