Overview
Trusted fillers enable asynchronous order execution during Folio rebalancing auctions. Instead of executing swaps directly on-chain through the bid() function, trusted fillers can route orders to external protocols like CoW Swap for potentially better execution.
How Trusted Fillers Work
When trusted fillers are enabled, an AUCTION_LAUNCHER or any authorized party can create a trusted fill during an active auction:
This function:
- Validates the auction is ongoing
- Calculates the sell and buy amounts based on current auction prices
- Creates a new trusted filler contract via the
TrustedFillerRegistry
- Approves the sell token to the filler
- Initializes the filler with swap parameters
CoW Swap Integration
CoW Swap is currently the only supported trusted filler. It enables:
- MEV protection through batch auctions
- Better execution via solver competition
- Gas optimization through order batching
- Price improvement beyond standard dutch auction curves
Example: Creating a CoW Swap Fill
State Management
The Folio tracks an active trusted fill at activeTrustedFill. While a trusted fill is active:
- Token balances include balances held by the filler
- The
stateChangeActive() function returns (false, true) if the swap is ongoing
- The
_poke() function automatically closes completed fills
Checking Async State
When asyncActive is true, view functions like totalAssets(), toAssets(), and getBid() may return unreliable data mid-swap. Always check stateChangeActive() before trusting view data in consuming protocols.
Configuration
Trusted fillers are configured through the FolioRegistryIndex during deployment or via governance:
Enabling Trusted Fillers
The trusted filler registry can only be set once. After initial configuration, you can only enable/disable the existing registry, not replace it.
Token Compatibility
When trusted fillers are enabled, tokens must be supported by both:
- The Folio contract (see Security Considerations)
- The external trusted fillers whitelisted in the registry
For CoW Swap specifically, tokens must:
- Be listed on CoW Protocol
- Have sufficient liquidity for solver routing
- Not be pausable, fee-on-transfer, or have callbacks
Auction Lifecycle with Trusted Fills
The complete rebalancing flow with trusted fillers:
- Start Rebalance -
REBALANCE_MANAGER initiates
- Open Auction -
AUCTION_LAUNCHER opens with price ranges
- Create Trusted Fill - Optional async execution via CoW Swap
- Order Settlement - CoW solvers compete to fill the order
- Close Fill - Folio automatically claims tokens when complete
- Close Auction - Optional early closure or natural expiration
Best Practices
For AUCTION_LAUNCHER
- Use trusted fillers for large trades where MEV is a concern
- Monitor fill status and close auctions if fills fail
- Combine with
PriceControl.ATOMIC_SWAP for maximum control
For Consuming Protocols
Events
Security Considerations
- Trusted fillers execute within the same auction price bounds as regular bids
- The
AUCTION_LAUNCHER must still act within ranges set by REBALANCE_MANAGER
- Failed fills do not revert; the Folio reclaims tokens automatically
- Only one trusted fill can be active at a time per Folio