The Settler contract is provided by RockawayX. It atomically settles fixed-price token redemption intents authorized by a user through a single Permit2 EIP-712 signature.

<aside> 📍

Production deployment

What the contract does

A user signs an IntentOrder specifying the exact input token and amount they will provide, the exact output token and amount they will receive, a Permit2 nonce, and a deadline. An approved operator submits that signed order to fill.

Settlement happens atomically in one transaction:

  1. Permit2 validates the user's signature, deadline, nonce, and signed order witness.
  2. Permit2 transfers the input tokens directly from the user to an approved input recipient.
  3. The Settler contract transfers the output tokens from the calling operator directly to the user.
  4. The contract emits IntentFilled as the canonical confirmation of completion.

If any step fails, the entire transaction reverts. No partial settlement is possible.

sequenceDiagram
    autonumber
    actor U as User
    participant O as Approved operator
    participant S as Settler
    participant P as Permit2
    participant R as Input recipient

    U-->>O: Signed IntentOrder
    O->>S: fill(order, signature, inputRecipient)
    S->>S: Validate operator, deadline, amounts, and recipient
    S->>P: Verify Permit2 signature and consume nonce
    P->>R: Transfer input token from user
    S->>U: Transfer output token from operator
    S-->>O: Emit IntentFilled

The signed order

IntentOrder commits the user to all economically relevant settlement terms:

Field Meaning
user Signature owner and recipient of the output tokens
nonce Permit2 unordered nonce preventing replay
deadline Last timestamp at which the order can be filled
inputToken Token transferred from the user
inputAmount Exact input amount in base units
outputToken Token supplied by the operator
outputAmount Exact output amount in base units

The order is hashed with INTENT_ORDER_TYPEHASH and used as the witness in Permit2's PermitWitnessTransferFrom signature. Because the user and nonce are both included in the signed witness, the resulting orderHash uniquely identifies the order.

Settlement flow inside fill

1. Access and state checks

Only an address approved in isOperator may call fill, and settlement must not be paused. The supplied inputRecipient must also be an approved operator address.

This separates two roles: